Benutzer-Werkzeuge

Webseiten-Werkzeuge


macsec-omniswitch-mikrotik

MACsec (IEEE 802.1AE) mit OmniSwitch (und MikroTik)

Für die Verwendung von MACsec benötigt man auf dem OmniSwitch die OS-SW-MACSEC Lizenz. Diese Lizenz ist für 0 $/€ gelistet und ist eine Site-License (alle OmniSwitches des Endkunden können die gleiche Lizenz verwenden).

-> show license-info 
                                             Time (Days)       Upgrade      Expiration  
VC   device   License            Type        Remaining         Status       Date        
----+------+---------------+---------------+---------------+--------------+----------------
1       0    Advanced           PERM           NA             NA             NA              
1       0    MACSEC             PERM           NA             NA             NA             

MACsec-Verbindung von OmniSwitch 6465T-P12 zu OmniSwitch 6465T-P12

Testaufbau

Bild folgt!

Konfiguration OmniSwitch

Beide OmniSwitch 6465T-P12 verwenden die gleiche Konfiguration!

! Security:
security key 1 algorithm aes-cmac-128 encrypt-key 55e534f7603def330c4e878136a373d4 keyed-name 0x0000000000000000000000000000000000000000000000000000000000000001
security key-chain 1 name "MACsec OmniSwitch"
security key-chain 1 key 1

! MAC Security:
interfaces port 1/1/9 macsec mode dynamic key-chain 1 server-priority 10 transmit-interval 3 encryption
interfaces port 1/1/9 macsec admin-state enable

Datendurchsatz mit MACsec

Der Datendurchsatz liegt hier im Rahmen einer „wire-rate“ 1 Gbps Verbindung (unter Berücksichtigung des zusätzlichen MACsec Headers). Die Ver- und Entschlüsselung von AES-128 wird in Hardware im PHY-Chip des OS6465T-P12 abgebildet.

Der Datendurchsatz ohne MACsec Header/Verschlüsselung liegt in diesem Testaufbau bei 940 Mbps.

Accepted connection from 192.168.2.19, port 51674
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 51675
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec   109 MBytes   914 Mbits/sec
[  5]   1.00-2.00   sec   109 MBytes   916 Mbits/sec
[  5]   2.00-3.00   sec   109 MBytes   917 Mbits/sec
[  5]   3.00-4.00   sec   109 MBytes   918 Mbits/sec
[  5]   4.00-5.00   sec   109 MBytes   917 Mbits/sec
[  5]   5.00-6.00   sec   109 MBytes   915 Mbits/sec
[  5]   6.00-7.00   sec   109 MBytes   911 Mbits/sec
[  5]   7.00-8.00   sec   109 MBytes   914 Mbits/sec
[  5]   8.00-9.00   sec   109 MBytes   915 Mbits/sec
[  5]   9.00-10.00  sec   109 MBytes   916 Mbits/sec
[  5]  10.00-10.00  sec  46.7 KBytes   621 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec  1.07 GBytes   915 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 51678
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 51679
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec   109 MBytes   916 Mbits/sec
[  5]   1.00-2.00   sec   109 MBytes   918 Mbits/sec
[  5]   2.00-3.00   sec   109 MBytes   913 Mbits/sec
[  5]   3.00-4.00   sec   110 MBytes   919 Mbits/sec
[  5]   4.00-5.00   sec   109 MBytes   915 Mbits/sec
[  5]   5.00-6.00   sec   109 MBytes   916 Mbits/sec
[  5]   6.00-7.00   sec   109 MBytes   917 Mbits/sec
[  5]   7.00-8.00   sec   109 MBytes   918 Mbits/sec
[  5]   8.00-9.00   sec   109 MBytes   916 Mbits/sec
[  5]   9.00-10.00  sec   109 MBytes   917 Mbits/sec
[  5]  10.00-10.00  sec  8.48 KBytes  88.7 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec  1.07 GBytes   916 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 51686
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 51687
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec   108 MBytes   907 Mbits/sec
[  5]   1.00-2.00   sec   109 MBytes   916 Mbits/sec
[  5]   2.00-3.00   sec   109 MBytes   916 Mbits/sec
[  5]   3.00-4.00   sec   109 MBytes   912 Mbits/sec
[  5]   4.00-5.00   sec   109 MBytes   914 Mbits/sec
[  5]   5.00-6.00   sec   109 MBytes   916 Mbits/sec
[  5]   6.00-7.00   sec   109 MBytes   918 Mbits/sec
[  5]   7.00-8.00   sec   109 MBytes   914 Mbits/sec
[  5]   8.00-9.00   sec   108 MBytes   904 Mbits/sec
[  5]   9.00-10.00  sec   109 MBytes   915 Mbits/sec
[  5]  10.00-10.00  sec  42.4 KBytes   457 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec  1.06 GBytes   913 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 51789
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 51790
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec   105 MBytes   877 Mbits/sec
[  5]   1.00-2.00   sec   109 MBytes   914 Mbits/sec
[  5]   2.00-3.00   sec   109 MBytes   915 Mbits/sec
[  5]   3.00-4.00   sec   109 MBytes   913 Mbits/sec
[  5]   4.00-5.00   sec   109 MBytes   914 Mbits/sec
[  5]   5.00-6.00   sec   109 MBytes   914 Mbits/sec
[  5]   6.00-7.00   sec   109 MBytes   913 Mbits/sec
[  5]   7.00-8.00   sec   109 MBytes   914 Mbits/sec
[  5]   8.00-9.00   sec   109 MBytes   914 Mbits/sec
[  5]   9.00-10.00  sec   109 MBytes   912 Mbits/sec
[  5]  10.00-10.00  sec   113 KBytes   882 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec  1.06 GBytes   910 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 51796
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 51797
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec   109 MBytes   911 Mbits/sec
[  5]   1.00-2.00   sec   109 MBytes   915 Mbits/sec
[  5]   2.00-3.00   sec   109 MBytes   916 Mbits/sec
[  5]   3.00-4.00   sec   109 MBytes   914 Mbits/sec
[  5]   4.00-5.00   sec   109 MBytes   915 Mbits/sec
[  5]   5.00-6.00   sec   109 MBytes   914 Mbits/sec
[  5]   6.00-7.00   sec   109 MBytes   913 Mbits/sec
[  5]   7.00-8.00   sec   109 MBytes   917 Mbits/sec
[  5]   8.00-9.00   sec   109 MBytes   915 Mbits/sec
[  5]   9.00-10.00  sec   109 MBytes   914 Mbits/sec
[  5]  10.00-10.00  sec   202 KBytes   822 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec  1.06 GBytes   914 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------

MACsec-Verbindung von OmniSwitch 6465T-P12 zu Mikrotik hAP ax²

Testaufbau

Bild folgt!

Konfiguration OmniSwitch

security key-chain 3 name "MikroTik MACsec"
security key 3 algorithm aes-cmac-128 hex-key 0xf0c20e75ca03c351227f314a5c15683e keyed-name 0x58db407c3ae45b719f395a15ee3934506b765235445dffa07c61bf985cf2e376
security key-chain 3 key 3

interfaces port 1/1/10 macsec mode dynamic key-chain 3 server-priority 10 transmit-interval 3 encryption
interfaces port 1/1/10 macsec admin-state enable

Konfiguration MikroTik

[admin@MikroTik] > /export show-sensitive 
# mar/17/2023 18:23:44 by RouterOS 7.8
# software id = 5S0G-NKK2
#
# model = C52iG-5HaxD2HaxD
# serial number = 
/interface bridge
add name=bridge1
/interface macsec
add cak=f0c20e75ca03c351227f314a5c15683e ckn=58db407c3ae45b719f395a15ee3934506b765235445dffa07c61bf985cf2e376 disabled=no interface=ether2 mtu=1468 \
    name=macsec1 profile=default
/port
set 0 name=serial0
/interface bridge port
add bridge=bridge1 interface=ether3
add bridge=bridge1 interface=macsec1
/ip neighbor discovery-settings
set discover-interface-list=!dynamic
/ipv6 settings
set max-neighbor-entries=15360
/ip address
add address=192.168.2.21/24 interface=bridge1 network=192.168.2.0
/ip dns
set servers=192.168.2.1
/ip route
add disabled=no dst-address=0.0.0.0/0 gateway=192.168.2.10 routing-table=main suppress-hw-offload=no
/system clock
set time-zone-name=Europe/Berlin
/system ntp client
set enabled=yes
/system ntp client servers
add address=192.168.2.1
/tool sniffer
set filter-interface=ether2

Datendurchsatz mit MACsec

In dieser Messung zeigt sich die Auswirkung einer Software-basierten MACsec Implementierung des MikroTik hAP ax². Der Durchsatz ist ~1/3 geringer und von der Auslastung des Prozessors abhängig.

Der Datendurchsatz ohne MACsec Header/Verschlüsselung liegt in diesem Testaufbau bei 940 Mbps.

-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52176
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52177
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   1.00-2.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   2.00-3.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   3.00-4.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   4.00-5.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   5.00-6.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   6.00-7.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   7.00-8.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   8.00-9.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   9.00-10.00  sec  71.2 MBytes   597 Mbits/sec
[  5]  10.00-10.00  sec   181 KBytes   514 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   711 MBytes   596 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52191
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52192
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   1.00-2.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   2.00-3.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   3.00-4.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   4.00-5.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   5.00-6.00   sec  71.2 MBytes   598 Mbits/sec
[  5]   6.00-7.00   sec  71.2 MBytes   598 Mbits/sec
[  5]   7.00-8.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   8.00-9.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   9.00-10.00  sec  71.2 MBytes   597 Mbits/sec
[  5]  10.00-10.00  sec   199 KBytes   539 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   712 MBytes   597 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52199
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52200
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   1.00-2.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   2.00-3.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   3.00-4.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   4.00-5.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   5.00-6.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   6.00-7.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   7.00-8.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   8.00-9.00   sec  71.1 MBytes   597 Mbits/sec
[  5]   9.00-10.00  sec  71.2 MBytes   597 Mbits/sec
[  5]  10.00-10.00  sec   212 KBytes   569 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   711 MBytes   597 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52204
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52205
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   1.00-2.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   2.00-3.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   3.00-4.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   4.00-5.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   5.00-6.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   6.00-7.00   sec  71.2 MBytes   597 Mbits/sec
[  5]   7.00-8.00   sec  71.1 MBytes   596 Mbits/sec
[  5]   8.00-9.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   9.00-10.00  sec  71.0 MBytes   596 Mbits/sec
[  5]  10.00-10.00  sec   175 KBytes   573 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   711 MBytes   596 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52211
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52212
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  63.1 MBytes   529 Mbits/sec
[  5]   1.00-2.00   sec  63.1 MBytes   530 Mbits/sec
[  5]   2.00-3.00   sec  63.4 MBytes   532 Mbits/sec
[  5]   3.00-4.00   sec  63.3 MBytes   531 Mbits/sec
[  5]   4.00-5.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   5.00-6.00   sec  63.5 MBytes   533 Mbits/sec
[  5]   6.00-7.00   sec  63.3 MBytes   531 Mbits/sec
[  5]   7.00-8.00   sec  63.4 MBytes   531 Mbits/sec
[  5]   8.00-9.00   sec  63.1 MBytes   529 Mbits/sec
[  5]   9.00-10.00  sec  63.4 MBytes   532 Mbits/sec
[  5]  10.00-10.00  sec   126 KBytes   530 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   633 MBytes   531 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52216
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52217
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   1.00-2.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   2.00-3.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   3.00-4.00   sec  70.9 MBytes   594 Mbits/sec
[  5]   4.00-5.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   5.00-6.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   6.00-7.00   sec  71.0 MBytes   595 Mbits/sec
[  5]   7.00-8.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   8.00-9.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   9.00-10.00  sec  70.9 MBytes   595 Mbits/sec
[  5]  10.00-10.00  sec   192 KBytes   547 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   709 MBytes   594 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52227
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52228
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  62.7 MBytes   526 Mbits/sec
[  5]   1.00-2.00   sec  62.9 MBytes   528 Mbits/sec
[  5]   2.00-3.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   3.00-4.00   sec  63.1 MBytes   529 Mbits/sec
[  5]   4.00-5.00   sec  63.1 MBytes   530 Mbits/sec
[  5]   5.00-6.00   sec  63.1 MBytes   529 Mbits/sec
[  5]   6.00-7.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   7.00-8.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   8.00-9.00   sec  63.3 MBytes   531 Mbits/sec
[  5]   9.00-10.00  sec  63.1 MBytes   529 Mbits/sec
[  5]  10.00-10.00  sec   164 KBytes   545 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   631 MBytes   529 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52234
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52235
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.5 MBytes   591 Mbits/sec
[  5]   1.00-2.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   2.00-3.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   3.00-4.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   4.00-5.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   5.00-6.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   6.00-7.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   7.00-8.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   8.00-9.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   9.00-10.00  sec  70.7 MBytes   593 Mbits/sec
[  5]  10.00-10.00  sec   208 KBytes   621 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   708 MBytes   594 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52238
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52239
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   1.00-2.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   2.00-3.00   sec  70.9 MBytes   594 Mbits/sec
[  5]   3.00-4.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   4.00-5.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   5.00-6.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   6.00-7.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   7.00-8.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   8.00-9.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   9.00-10.00  sec  70.9 MBytes   595 Mbits/sec
[  5]  10.00-10.00  sec   194 KBytes   556 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   709 MBytes   594 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52247
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52248
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   1.00-2.00   sec  70.7 MBytes   593 Mbits/sec
[  5]   2.00-3.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   3.00-4.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   4.00-5.00   sec  71.0 MBytes   596 Mbits/sec
[  5]   5.00-6.00   sec  71.0 MBytes   596 Mbits/sec
[  5]   6.00-7.00   sec  71.0 MBytes   596 Mbits/sec
[  5]   7.00-8.00   sec  71.0 MBytes   595 Mbits/sec
[  5]   8.00-9.00   sec  71.0 MBytes   595 Mbits/sec
[  5]   9.00-10.00  sec  71.0 MBytes   596 Mbits/sec
[  5]  10.00-10.00  sec   221 KBytes   626 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   709 MBytes   595 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52258
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52260
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  57.0 MBytes   478 Mbits/sec
[  5]   1.00-2.00   sec  57.6 MBytes   483 Mbits/sec
[  5]   2.00-3.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   3.00-4.00   sec  63.3 MBytes   531 Mbits/sec
[  5]   4.00-5.00   sec  63.3 MBytes   531 Mbits/sec
[  5]   5.00-6.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   6.00-7.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   7.00-8.00   sec  62.9 MBytes   528 Mbits/sec
[  5]   8.00-9.00   sec  63.2 MBytes   530 Mbits/sec
[  5]   9.00-10.00  sec  63.3 MBytes   531 Mbits/sec
[  5]  10.00-10.00  sec  79.2 KBytes   401 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   620 MBytes   520 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------
Accepted connection from 192.168.2.19, port 52270
[  5] local 192.168.2.20 port 5201 connected to 192.168.2.19 port 52271
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-1.00   sec  70.5 MBytes   591 Mbits/sec
[  5]   1.00-2.00   sec  70.8 MBytes   594 Mbits/sec
[  5]   2.00-3.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   3.00-4.00   sec  71.0 MBytes   595 Mbits/sec
[  5]   4.00-5.00   sec  71.0 MBytes   595 Mbits/sec
[  5]   5.00-6.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   6.00-7.00   sec  70.9 MBytes   594 Mbits/sec
[  5]   7.00-8.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   8.00-9.00   sec  70.9 MBytes   595 Mbits/sec
[  5]   9.00-10.00  sec  70.9 MBytes   595 Mbits/sec
[  5]  10.00-10.00  sec   187 KBytes   501 Mbits/sec
- - - - - - - - - - - - - - - - - - - - - - - - -
[ ID] Interval           Transfer     Bandwidth
[  5]   0.00-10.00  sec  0.00 Bytes  0.00 bits/sec                  sender
[  5]   0.00-10.00  sec   709 MBytes   594 Mbits/sec                  receiver
-----------------------------------------------------------
Server listening on 5201
-----------------------------------------------------------

WinBox Statistik zur obigen Messung

Detaillierter Verbindungsaufbau: MACsec Key Agreement (MKA)

In den kommenden Tagen füge ich noch weitere Informationen hinzu, unten bereits das Wireshark Capture als ZIP. /Benny

PCAP

macsec-omniswitch-mikrotik.txt · Zuletzt geändert: 2024/06/09 14:26 von benny

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki