Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

MACSec without NDAC

Is it possible to do downlink macsec without the full NDAC/SGA setup?

I am trying to set up encryption from the PC's to the switchport and it is attempting, but never completes. I keep getting these two logs:
(I have researched these logs but couldn't really find anything that worked)
(It gets a little confusing when MACSec/NDAC and SGA are all explained at the same time in some of the documents and in the official Cisco Press book!)

%MKA-4-KEEPALIVE_TIMEOUT: Peer has stopped sending MKPDUs for RxSCI.... 
%MKA-4-SESSION_UNSECURED: MKA Session was stopped by MKA and not secured for RxSCI..... 



This is my related interface config:
interface GigabitEthernetX/Y/Z
 switchport access vlan XYZ
 switchport mode access
 switchport voice vlan XYZ
 ip access-group PREAUTH in
 authentication event fail action next-method
 authentication event server dead action authorize vlan 712
 authentication event server dead action authorize voice
 authentication event server alive action reinitialize 
 authentication host-mode multi-domain
 authentication order dot1x mab
 authentication priority dot1x mab
 authentication port-control auto
 authentication violation restrict
 mka default-policy

 dot1x pae authenticator
 dot1x timeout tx-period 10
 spanning-tree portfast

- Attached a picture of related ISE and Anyconnect Config


Thank You for any advice or input!!  :)

  • AAA Identity and NAC
New Member

I found the solution and

I found the solution and wanted to post it in case anyone else ran into this problem!

I had to update the NIC driver and all of a sudden it started working with no other changes!

I had an Intel 82579LM NIC adapter and updating to the latest Intel driver fixed the issue! Currently it seems to work best with Intel from what I am seeing.

Thanks!! :)

This widget could not be displayed.