Skip to content

Commit 3d9012b

Browse files
MACSec secure policies
Signed-off-by: Ruthrapathy Shanmuganandam <rushanmu@cisco.com>
1 parent c15b6d4 commit 3d9012b

File tree

1 file changed

+0
-4
lines changed

1 file changed

+0
-4
lines changed

doc/SAI-Proposal-MACSec-Secure-Policy.md

Lines changed: 0 additions & 4 deletions
Original file line numberDiff line numberDiff line change
@@ -35,8 +35,6 @@ Must Secure is the most stringent secure policy.
3535

3636
- If MKA session remains down, only EAPol(Extensible Authentication Protocol over LAN) packets are exchanged.
3737

38-
- If the peer does not support MACsec, traffic still passes unencrypted (avoiding connectivity loss).
39-
4038
## Should Secure (Fail-Open)
4139

4240
Should Secure is a less stricter policy than Must Secure.
@@ -47,8 +45,6 @@ Should Secure is a less stricter policy than Must Secure.
4745

4846
- The network continues to function, but the traffic on that specific link remains unencrypted.
4947

50-
- If the peer does not support MACsec, traffic still passes unencrypted (avoiding connectivity loss).
51-
5248
# SAI Attribute Enhancement
5349

5450
The below MACSec port attribute is newly introduced to allow configuration of the MACSec secure policy. This attribute controls how the switch’s MACsec security engine enforces link protection. When set, the attribute instructs the hardware to apply the corresponding policy on the specified port.

0 commit comments

Comments
 (0)