MACsec

  • Support for a custom EAPoL EtherType to improve network tunneling of MACsec packets (ACX7100-32C, ACX7332, ACX7348, and ACX7509)—MACsec uses Extensible Authentication Protocol over LAN (EAPoL) as a transport protocol to establish sessions. Some networks filter packets based on their EtherType value. By default, the EtherType for all EAPoL packets is 0x888e. To ensure the network tunnels the MACsec packets properly, you can set a custom EtherType for EAPoL packets.

    To configure an EAPoL profile with a custom EtherType, use the ether-type ether-type-value statement at the [edit forwarding-options custom-eapol-ether-type-profiles eapol-profile-name] hierarchy level. To apply the EtherType to MACsec packets, configure the eapol-ethertype-profile eapol-profile-name statement at the [edit security macsec connectivity-association ca-name mka] hierarchy level.

    [See Media Access Control Security (MACsec) over WAN, custom-eapol-ethertype-profiles, and mka.]