Help us improve your experience.

Let us know what you think.

Do you have time for a two-minute survey?

 
 

show security mka sessions

Syntax

Description

Display MACsec Key Agreement (MKA) session information for all interfaces. The MKA protocol is responsible for maintaining MACsec on the link, and decides which router on the point-to-point link becomes the key server.

Options

  • interface interface-name—Display the MKA session information for the specified interface only.

  • summary | brief | detail—Display the specified level of output.

  • none (same as brief)—Display the MKA session information for all interfaces.

Required Privilege Level

view

Output Fields

Table 1 lists the output fields for the show security mka sessions command. Output fields are listed in the approximate order in which they appear.

Table 1: show security mka sessions Output Fields

Field Name

Field Description

Interface name

Name of the interface.

Interface state

Shows whether the interface is secured or not. If it is secured, the CAK type is also displayed.

Member identifier

Name of the member identifier.

CAK name

Name of the connectivity association key (CAK). The CAK is configured using the cak keyword when configuring the pre-shared key.

CAK type

The CAK type: primary, fallback, or preceding.

Transmit interval

The transmit interval. Both ends of the point-to-point link should be configured to the same value. Default value is 2000 seconds. Possible values: 2000 through 6000 milliseconds.

Outbound SCI

Name of the outbound secure channel identifier.

Message number

Number of the last data message.

Key number

Key number.

Key server

Key server status.

The router is the key server when this output is yes. The router is not the key server when this output is no.

Key server priority

Displays the priority of the key server. Lower value indicates higher priority. Use the key-server-priority statement to set the priority. Possible values: 0 through 255.

Latest SAK AN

Name of the latest secure association key (SAK) association number.

Latest SAK KI

Name of the latest secure association key (SAK) key identifier.

Table 2: show security mka sessions Output Fields for Peer List

Field Name

Field Description

Member identifier

Name of the member identifier.

Hold time

Hold time, in seconds.

Message number

Number of the last data message

SCI

Name of the secure channel identifier.

Lowest acceptable PN

Number of the lowest acceptable packet number (PN).

Table 3: show security mka sessions Output Fields for CAK List (detail only)

Field Name

Field Description

CAK name

Name of the connectivity association key (CAK).

CAK type

The CAK type: primary, fallback, or preceding.

Status

The CAK status: live, active, or in-progress.

Member identifier

Name of the member identifier.

Message number

Number of the last data message

MKA ICV Indicator

Whether the ICV TLV is included in the MKA hello packet. If this field reads disabled, the user has configured the disable-icv-indicator option and the ICV TLV is not sent as part of the MKA hello packet.

Sample Output

show security mka sessions

show security mka sessions detail

Release Information

Command introduced in Junos OS Release 13.2X50-D15.