No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


Configuration Guide - Security

CloudEngine 8800, 7800, 6800, and 5800 V200R005C10

This document describes the configurations of Security, including ACL, local attack defense, MFF, attack defense, traffic suppression and storm control, ARP security, Port security, DHCP snooping, ND snooping, PPPoE+, IPSG, SAVI, separating the management plane from the service plane, security risks.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Licensing Requirements and Limitations for MACsec

Licensing Requirements and Limitations for MACsec

This section provides the points of attention when configuring MACsec.

Involved Network Elements

Other network elements need to support MACsec.

Licensing Requirements

MACsec is controlled by the license. By default, MACsec is disabled on a newly purchased switch. To use MACsec, apply for and purchase the license from the equipment supplier.

Version Requirements

Table 12-2 Products and versions supporting MACsec


Software Version



Feature Limitations

  • Only point-to-point MACsec is supported.
  • Only 100GE physical interfaces support MACsec in Layer 2 or Layer 3 mode. MACsec can be supported when 100GE interfaces are split or 100GE interfaces are negotiated to 40GE interfaces.
  • The switch and client cannot be interconnected through MACsec.

  • MACsec can encrypt both Layer 2 and Layer 3 packets. If intermediate devices do not support MACsec, they only perform Layer 2 forwarding.
  • MACsec and 802.1x cannot be configured together on the same interface.
  • MACsec and PFC cannot be configured together on the same interface.
Updated: 2019-04-20

Document ID: EDOC1100074765

Views: 22962

Downloads: 93

Average rating:
This Document Applies to these Products
Related Documents
Related Version
Previous Next