Implementing and Operating Cisco Enterprise Network Core Technologies (ENCOR) v1.2SecurityEasy
A network security team is deploying MACsec (802.1AE) between two switches to provide hop-by-hop encryption and integrity protection for all traffic traversing the link. Which key management protocol is typically used with MACsec to establish and maintain the secure session keys?
- AIKEv2
- BKMIP (Key Management Interoperability Protocol)
- CEAP-TLS
- DMKA (MACsec Key Agreement)
Show answer & explanationAnswer & explanation
Correct answer: D. MKA (MACsec Key Agreement)
MACsec (802.1AE) uses the MACsec Key Agreement (MKA) protocol to exchange and manage the session keys necessary for encrypting and authenticating Ethernet frames between two directly connected MACsec-enabled devices.
Why the other options are wrong
- A. IKEv2 is used for IPsec VPNs, not MACsec.
- B. KMIP is a protocol for managing cryptographic keys across enterprise systems, not directly for MACsec session key agreement.
- C. EAP-TLS is an EAP method used for 802.1X authentication, not directly for MACsec key management.
MACsec Key Agreement (MKA)
The protocol used by MACsec (802.1AE) to discover MACsec-capable peers, negotiate and establish a secure association, and manage the session keys (Secure Association Keys - SAKs) used for encryption and integrity protection on a point-to-point Ethernet link.
- Operates at Layer 2.
- Manages SAKs for MACsec encryption and integrity.
- Can use pre-shared keys (PSK) or 802.1X for initial authentication.
Memory trick: MACsec keys are 'MKA' magic!