interfaces (MACsec)
Syntax
interfaces interface-name { connectivity-association connectivity-association-name; }
Hierarchy Level
[edit security macsec]
Description
Applies the specified connectivity association to the specified interface to enable MACsec.
One connectivity association can be applied to multiple interfaces.
You must always use this statement to apply a connectivity association to an interface to enable MACsec. You must complete this configuration step regardless of whether MACsec is enabled using static connectivity association key (CAK) security mode or static secure association key (SAK) security mode.
If you are enabling MACsec using static SAK security mode and need to configure MACsec on inbound and outbound traffic on the same interface, you must configure a connectivity association with one secure channel for inbound traffic and a second secure channel for outbound traffic. The connectivity association is then applied to the interface using this statement to enable MACsec for traffic entering and leaving the interface.
Default
Interfaces are not associated with any connectivity associations, by default.
Required Privilege Level
admin—To view this statement in the configuration.
admin-control—To add this statement to the configuration.
Release Information
Statement introduced in Junos OS Release 13.2X50-D15.