confidentiality-offset
Use confidentiality-offset to set the MACsec confidentiality offset in an MKA policy.
Use undo confidentiality-offset to restore the default.
Syntax
confidentiality-offset offset-value
undo confidentiality-offset
Default
The MACsec confidentiality offset is 0. The entire frame is encrypted.
Views
MKA policy view
Predefined user roles
network-admin
mdc-admin
Parameters
offset-value: Specifies the confidentiality offset in bytes. The value can be 0, 30 or 50.
Usage guidelines
The MACsec confidentiality offset specifies the number of bytes starting from the frame header. MACsec encrypts only the bytes after the offset in a frame.
When an MKA policy is applied to a port, the MACsec confidentiality offset in the policy overwrites the confidentiality offset previously configured on the port. However, MACsec uses the confidentiality offset propagated by the key server.
Examples
# Set the MACsec confidentiality offset to 30 bytes in MKA policy abcd.
<Sysname> system-view [Sysname] mka policy abcd [Sysname-mka-policy-abcd] confidentiality-offset 30
Related commands
macsec confidentiality-offset
mka apply policy