Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityHard

A network engineer is configuring a Cisco Catalyst switch to implement MACsec (802.1AE) between two switches to provide hop-by-hop encryption and integrity for all traffic on the link. After configuring the necessary MKA (MACsec Key Agreement) and enabling MACsec on the interfaces, the engineer notices that the MACsec secure channel is not establishing. Which of the following is a common reason for MACsec failure between two switches?

  1. AMismatched MKA policy parameters (e.g., encryption cipher)
  2. BMismatched IPsec transform sets
  3. CIncorrect 802.1X supplicant credentials
  4. DMissing DHCP snooping configuration
Show answer & explanation

Correct answer: A. Mismatched MKA policy parameters (e.g., encryption cipher)

MACsec relies on the MACsec Key Agreement (MKA) protocol to establish and maintain the secure channel. Mismatched MKA policy parameters, such as the encryption cipher (e.g., AES-128 vs. AES-256) or the pre-shared key (if using static CAK), are common causes for the secure channel not establishing, similar to how IKE/IPsec parameters must match for VPNs.

Why the other options are wrong

  • B. IPsec transform sets are relevant for IPsec VPNs, not MACsec (802.1AE) which operates at Layer 2.
  • C. 802.1X supplicant credentials are used for port-based authentication, typically at the edge, not for hop-by-hop MACsec between switches.
  • D. DHCP snooping is a Layer 2 security feature for DHCP integrity and has no direct impact on MACsec tunnel establishment.

MACsec Key Agreement (MKA)

The protocol used by MACsec (802.1AE) to discover MACsec-capable devices, negotiate MACsec parameters, and create and manage the security keys (SAKs) for encrypting and authenticating Layer 2 traffic.

  • Operates over Ethernet (Layer 2).
  • Negotiates the Cipher Suite and Key Server role.
  • Requires matching MKA policy parameters on both ends of the link.
  • Essential for establishing and maintaining the MACsec secure channel.

Memory trick: MACsec Needs Matching MKA for Secure Links

More Security questions