show security macsec connections (SRX)
Syntax
show security macsec connections <interface interface-name>
Description
Display the status of the active MACsec connections on the device.
Options
| none | Display MACsec connection information for all interfaces on the device. |
| interface interface-name | (Optional) Display MACsec connection information for the specified interface only. |
Required Privilege Level
view
Output Fields
Table 1 lists the
output fields for the show security macsec connections command.
Output fields are listed in the approximate order in which they appear.
Field Name |
Field Description |
|---|---|
| Fields for Interface | |
|
|
Name of the interface. |
|
|
Name of the connectivity association. A connectivity association is named using the
|
|
|
Name of the cipher suite used for encryption. |
|
|
Offset setting. The offset is set using the |
|
|
Replay protection setting. Replay protection is enabled when this output is
You can enable replay protection using the |
|
Outbound secure channels |
Displays outgoing packet number. |
|
Inbound secure channels |
Displays source identifier and secure associations detail. |
Sample Output
show security macsec connections
user@host> show security macsec connections
Interface name: fxp1
CA name: ca1
Cipher suite: GCM-AES-128 Encryption: on
Key server offset: 0 Include SCI: no
Replay protect: off Replay window: 0
show security macsec connections (SRX1600, SRX2300, and SRX4120)
user@host> show security macsec connections
Interface name: em0
CA name: ca_mka_01
Cipher suite: GCM-AES-128 Encryption: on
Key server offset: 0 Include SCI: no
Replay protect: off Replay window: 0
Outbound secure channels
SC Id: 02:00:00:01:01:04/1
Outgoing packet number: 1914287
Secure associations
AN: 0 Status: inuse Create time: 07:33:26
Inbound secure channels
SC Id: 02:00:00:02:01:04/1
Secure associations
AN: 0 Status: inuse Create time: 07:33:26
Interface name: em1
CA name: ca_mka_01
Cipher suite: GCM-AES-128 Encryption: on
Key server offset: 0 Include SCI: no
Replay protect: off Replay window: 0
Outbound secure channels
SC Id: 02:00:01:01:01:04/1
Outgoing packet number: 108885
Secure associations
AN: 0 Status: inuse Create time: 07:33:26
Inbound secure channels
SC Id: 02:00:01:02:01:04/1
Secure associations
AN: 0 Status: inuse Create time: 07:33:26Release Information
Command introduced in Junos OS Release 15.1X49-D60.