MACsec Intel® FPGA System Design User Guide

ID 767516
Date 3/31/2024
Public
Document Table of Contents

6.5.1.5. RX Rekeying Sequence

When PN is about to expire, rekeying occurs and below is an example of the rekeying sequence. All of the configuration that needs to happen as part of the rekeying sequence can be programmed.
  • Set “Enable Receive enable” to False (default value is False) for new SA.
  • Program the per-MACsec instance configuration and Rx Configuration (section 5.1.3) for the new SA.
  • Set “Enable Receive enable” to True (default value is False) for new SA.
  • Ensure RX traffics entering MACsec IP which using new SA is observed.
  • Set “Enable Receive enable” to False (default value is False) for expire SA.