MACsec on Centos 7

MACsec = Media Access Control Security (802.1AE IEEE). It provides point-to-point encryption (AES-GCM-128 by default) over ethernet traffic. MACsec support is included from kernel 4.6 or in Centos/RHEL 7.


HOST A:
ip link add link eth1 macsec0 type macsec
ip macsec add macsec0 tx sa 0 pn 1 on key 01 11111111111111111111111111111111
ip macsec add macsec0 rx address bb:bb:bb:bb:bb:bb port 1
ip macsec add macsec0 rx address bb:bb:bb:bb:bb:bb port 1 sa 0 pn 100 on key 02 22222222222222222222222222222222
ip link set dev macsec0 up
ip address add 172.16.16.1/24 dev macsec0
HOST B:
ip link add link eth1 macsec0 type macsec
ip macsec add macsec0 tx sa 0 pn 1 on key 02 22222222222222222222222222222222
ip macsec add macsec0 rx address aa:aa:aa:aa:aa:aa port 1
ip macsec add macsec0 rx address aa:aa:aa:aa:aa:aa port 1 sa 0 pn 100 on key 01 11111111111111111111111111111111
ip link set dev macsec0 up
ip address add 172.16.16.2/24 dev macsec0

view raw

MACsec Centos7

hosted with ❤ by GitHub


Discover more from Vladimir Smitka

Subscribe to get the latest posts sent to your email.

One response to “MACsec on Centos 7”

  1. Brady

    Loved reading this thank yyou

    Like

Leave a comment

About Me

My name is Vladimir Smitka and I’m a security researcher/hobbyist from the Czech Republic. I’m also the owner of Lynt, a PPC Agency. I’m also an active member of the Czech WordPress community and one of the WordCamp Prague organizers.

OPEN .GIT GLOBAL SCAN

  • 230 000 000 sites scanned 🔍
  • 390 000 sites affected 😥
  • 100 000 mail send to the developers 📧
  • 150 000+ sites fixed 
  • 100+ possitive comments 🗨️
  • 3500+ thankyou mails ❤️
  • Thousands and thousands sites with another serious issue found 😑

For my research I use affordable Virtual Private Servers from Digital Ocean (they have a great infrascruture), Linode (they have a great understanding for my work) and dedicted servers from Hetzner.

If you like my research, you can make a small donation for coffee and VPS – two basic ingredients for my future security scans.

Follow me

Our Projects

Latest Articles