Cisco WS-C3550-12G Switch Guide - Page 185
MACsec
View all Cisco WS-C3550-12G manuals
Add to My Manuals
Save this manual to your list of manuals |
Page 185 highlights
Software Features MACsec The Cisco Catalyst 3750-X Series Switches offer exceptional security with integrated hardware support for MACsec defined in IEEE 802.1AE. MACsec provides MAC layer encryption over wired networks using out-of-band methods for encryption keying. The MACsec Key Agreement (MKA) protocol provides the required session keys and manages the keys required for encryption when configured. MKA and MACsec are implemented following successful authentication using 802.1x Extensible Authentication Protocol (EAP) framework. In Cisco Catalyst 3750-X and 3560-X Series Switches both the user/downlink ports (links between the switch and endpoint devices such as a PC or IP phone) and, using the service module, the network/up-link ports can be secured using MACsec. With the service module you can encrypt switch to switch links such as access to distribution, or encrypt dark fiber links within a building or between buildings. The three feature sets available with all Cisco Catalyst 3750-X Series Switches are: • LAN Base: Enhanced Intelligent Services • IP Base: Baseline Enterprise Services • IP Services: Enterprise Services The LAN Base feature set offers enhanced intelligent services that includes comprehensive Layer 2 features, with up-to 255 VLANs. The IP Base feature set provides baseline enterprise services in addition to all LAN Base features, with 1K VLANs. IP Base also includes the support for routed access, StackPower (available only on the Catalyst 3750-X), MACsec, and the new Cisco Service Module. The IP Services feature set provides full enterprise services that includes advanced Layer 3 features such as Enhanced Interior Gateway Routing Protocol (EIGRP), Open Shortest Path First (OSPF), Border Gateway Protocol (BGP), Protocol Independent Multicast (PIM), and IPv6 routing such as OSPFv3 and EIGRPv6. All software feature sets support advanced security, QoS, and management features. The Cisco Catalyst 3750-X Series Switches with LAN Base feature set can only stack with other Cisco Catalyst 3750 X Series LAN Base switches. A mixed stack of LAN Base switch with IP Base or IP Services features set is not supported. Customers can transparently upgrade the software feature set in the Cisco Catalyst 3750-X Series Switches through Cisco IOS® Software activation. Software activation authorizes and enables the Cisco IOS Software feature sets. A special file contained in the switch, called a license file, is examined by Cisco IOS Software when the switch is powered on. Based on the license's type, Cisco IOS Software activates the appropriate feature set. License types can be changed, or upgraded, to activate a different feature set. For detailed information about Software Activation, visit http://www.cisco.com/go/sa. 183