Hey Rahul,
thank you for your answers.
1)
root@vx-sw-b7-01> show interfaces ge-0/0/0
Physical interface: ge-0/0/0, Enabled, Physical link is Up
Interface index: 648, SNMP ifIndex: 514
Description: MacSec Trunk zu VC
Link-level type: Ethernet, MTU: 1514, LAN-PHY mode, Link-mode: Full-duplex, Speed: Auto, BPDU Error: None,
Loop Detect PDU Error: None, Ethernet-Switching Error: None, MAC-REWRITE Error: None, Loopback: Disabled,
Source filtering: Disabled, Flow control: Disabled, Auto-negotiation: Enabled, Remote fault: Online,
Media type: Copper, IEEE 802.3az Energy Efficient Ethernet: Disabled, Auto-MDIX: Enabled
Device flags : Present Running
Interface flags: SNMP-Traps Internal: 0x4000
Link flags : None
CoS queues : 12 supported, 12 maximum usable queues
Current address: b8:c2:53:ef:6f:cb, Hardware address: b8:c2:53:ef:6f:cb
Last flapped : 1970-01-01 02:39:45 UTC (2583w0d 03:27 ago)
Input rate : 4234936 bps (914 pps)
Output rate : 12690648 bps (1207 pps)
Active alarms : None
Active defects : None
PCS statistics Seconds
Bit errors 0
Errored blocks 0
Ethernet FEC statistics Errors
FEC Corrected Errors 0
FEC Uncorrected Errors 0
FEC Corrected Errors Rate 0
FEC Uncorrected Errors Rate 0
PRBS Statistics : Disabled
Interface transmit statistics: Disabled
Logical interface ge-0/0/0.0 (Index 555) (SNMP ifIndex 555)
Flags: Up SNMP-Traps 0x24024000 Encapsulation: Ethernet-Bridge
Input packets : 6682657
Output packets: 2278226
Protocol eth-switch, MTU: 1514
Flags: Is-Primary, Trunk-Mode
I Think the "Last flapped" time is wrong. The interface was simply up, before the switch got his time from our ntp server. I flapped the Interface manually and this is the output now:
root@vx-sw-b7-01> show interfaces ge-0/0/0
Physical interface: ge-0/0/0, Enabled, Physical link is Up
Interface index: 648, SNMP ifIndex: 514
Description: MacSec Trunk zu VC
Link-level type: Ethernet, MTU: 1514, LAN-PHY mode, Link-mode: Full-duplex, Speed: Auto, BPDU Error: None,
Loop Detect PDU Error: None, Ethernet-Switching Error: None, MAC-REWRITE Error: None, Loopback: Disabled,
Source filtering: Disabled, Flow control: Disabled, Auto-negotiation: Enabled, Remote fault: Online,
Media type: Copper, IEEE 802.3az Energy Efficient Ethernet: Disabled, Auto-MDIX: Enabled
Device flags : Present Running
Interface flags: SNMP-Traps Internal: 0x4000
Link flags : None
CoS queues : 12 supported, 12 maximum usable queues
Current address: b8:c2:53:ef:6f:cb, Hardware address: b8:c2:53:ef:6f:cb
Last flapped : 2019-07-04 06:40:15 UTC (00:19:25 ago)
Input rate : 5228232 bps (2551 pps)
Output rate : 9539160 bps (941 pps)
Active alarms : None
Active defects : None
PCS statistics Seconds
Bit errors 0
Errored blocks 0
Ethernet FEC statistics Errors
FEC Corrected Errors 0
FEC Uncorrected Errors 0
FEC Corrected Errors Rate 0
FEC Uncorrected Errors Rate 0
PRBS Statistics : Disabled
Interface transmit statistics: Disabled
Logical interface ge-0/0/0.0 (Index 555) (SNMP ifIndex 555)
Flags: Up SNMP-Traps 0x24024000 Encapsulation: Ethernet-Bridge
Input packets : 6692511
Output packets: 2281164
Protocol eth-switch, MTU: 1514
Flags: Is-Primary, Trunk-Mode
But still, the "Status: inuse Create time" is on 00:00:00 after I disabled the interface and enabled it again:
root@vx-sw-b7-01> show security macsec connections
Interface name: ge-0/0/0
CA name: b6
Cipher suite: GCM-AES-128 Encryption: on
Key server offset: 0 Include SCI: yes
Replay protect: off Replay window: 0
Outbound secure channels
SC Id: B8:C2:53:EF:6F:CB/1
Outgoing packet number: 1040013
Secure associations
AN: 3 Status: inuse Create time: 00:00:00
Inbound secure channels
SC Id: CC:E1:94:29:36:83/1
Secure associations
AN: 3 Status: inuse Create time: 00:00:00
Strange behaviour.
2)
So you are telling me, that this is common behaviour to throw like 300 debug messages per minute? Is there something official, like a KB or anything? Dont get me wrong, I simply want to be sure that everything is allright with our encrypted connection and our data is safe.
The strange thing is simply, that on our EX4300 everything is fine. No syslog messages and "Status: inuse Create time" has a fitting time.
Thank you for your time Rahul,
Julian_V