confidentiality-offset

Use confidentiality-offset to set the MACsec confidentiality offset in an MKA policy.

Use undo confidentiality-offset to restore the default.

Syntax

confidentiality-offset offset-value

undo confidentiality-offset

Default

The MACsec confidentiality offset is 0. The entire frame is encrypted.

Views

MKA policy view

Predefined user roles

network-admin

mdc-admin

Parameters

offset-value: Specifies the confidentiality offset in bytes. The value can be 0, 30 or 50.

Usage guidelines

The MACsec confidentiality offset specifies the number of bytes starting from the frame header. MACsec encrypts only the bytes after the offset in a frame.

When an MKA policy is applied to a port, the MACsec confidentiality offset in the policy overwrites the confidentiality offset previously configured on the port. However, MACsec uses the confidentiality offset propagated by the key server.

Examples

# Set the MACsec confidentiality offset to 30 bytes in MKA policy abcd.

<Sysname> system-view
[Sysname] mka policy abcd
[Sysname-mka-policy-abcd] confidentiality-offset 30

Related commands

macsec confidentiality-offset

mka apply policy