flync_4_security

MACsec Configuration

Expand for Schematic
        classDiagram

    class Category {
        <<Enumeration>>
        VALUE_RANGE: int = 1
        REQUIRED: int = 2
        CONSISTENCY: int = 3
        UNIQUENESS: int = 4
        REFERENCE: int = 5
        FORMAT: int = 6
        COMPATIBILITY: int = 7
        STRUCTURAL: int = 8
        LIFECYCLE: int = 9
    }

    class IntegrityWithoutConfidentiality {
        cipher_suite: Literal['GCM-AES-128', 'GCM-AES-256', 'GCM-AES-XPN-128', 'GCM-AES-XPN-256'] | None = 'GCM-AES-XPN-256'
        type: Literal['integrity_without_confidentiality'] = 'integrity_without_confidentiality'
        confidentiality_offset: Literal[0] | None = 0
    }

    class MACsecConfig {
        vlan_bypass: list[int]
        ethertype_bypass: list[Ethertype] = []
        src_mac_address_bypass: list[MacAddress] = []
        dest_mac_address_bypass: list[MacAddress] = []
        ckn: str
        mka_enabled: bool | None = True
        hello_time: int
        bounded_hello_time: int
        life_time: int
        sak_retire_time: int
        hello_time_rampup: list[int] = []
        sak_rekey_time: int | None = 3
        macsec_mode: Literal['disabled', 'integrity', 'integrity_confidentiality']
        kay_on: bool
        key_role: Literal['key_server_always', 'key_server_never']
        delay_protect: bool
        participant_activation: Literal['disabled', 'onoperup', 'always']
        sci_included: bool | None = False
        replay_protection_window: int = 0
        cipher_preference: list[IntegrityWithoutConfidentiality | IntegrityWithConfidentiality] = <lambda>
    }

    class Ethertype {
        <<Enumeration>>
        ARP: int = 2054
        ASAM_CMP: int = 39422
        AVTP: int = 8944
        EAPoL: int = 34958
        ETH_FLOWCTRL: int = 34824
        HSR: int = 35119
        IPv4: int = 2048
        IPv6: int = 34525
        LLDP: int = 35020
        MACsec: int = 35045
        PRP: int = 35067
        PTP: int = 35063
        QinQ: int = 34984
        SRP: int = 8938
        VLAN: int = 33024
        WAKE_ON_LAN: int = 2114
    }

    class IntegrityWithConfidentiality {
        cipher_suite: Literal['GCM-AES-128', 'GCM-AES-256', 'GCM-AES-XPN-128', 'GCM-AES-XPN-256'] | None = 'GCM-AES-XPN-256'
        type: Literal['integrity_with_confidentiality'] = 'integrity_with_confidentiality'
        confidentiality_offset: Literal[0, 30, 50] | None = 0
    }

    class CipherSuiteBaseModel {
        cipher_suite: Literal['GCM-AES-128', 'GCM-AES-256', 'GCM-AES-XPN-128', 'GCM-AES-XPN-256'] | None = 'GCM-AES-XPN-256'
    }

    class FLYNCBaseModel {
    }

    MACsecConfig ..> IntegrityWithoutConfidentiality
    MACsecConfig ..> IntegrityWithConfidentiality
    MACsecConfig ..> Ethertype
    MACsecConfig ..> MacAddress


    

Hint

Find a YAML example for MACsec inside the Controller example (key macsec_config).

class MACsecConfig

Bases: FLYNCBaseModel

Configuration for MACsec (Media Access Control Security).

Includes global MKA (MACsec Key Agreement) settings and per-port security configuration.

Parameters

vlan_bypasslist of int

VLANs which shall not be protected with MACsec.

ethertype_bypasslist of Ethertype, optional

Ethertypes which shall not be protected with MACsec (defaults to []).

src_mac_address_bypasslist of FLYNCMacAddress, optional

Source MAC addresses which shall not be protected with MACsec (defaults to []).

dest_mac_address_bypasslist of FLYNCMacAddress, optional

Destination MAC addresses which shall not be protected with MACsec (defaults to []).

cknstr

Connectivity Association Key Name (CKN) used to identify the CAK. 1-32 octets (characters in the range 0x00-0xFF).

mka_enabledbool

Whether MACsec Key Agreement (MKA) is enabled. Default is True.

hello_timeint

MKPDU period when a connection is established, applicable when delay_protect is disabled (milliseconds).

bounded_hello_timeint

Hello time applicable with delay_protect enabled (milliseconds).

life_timeint

Life time for a peer to transmit MKPDU’s in order to consider it alive (milliseconds).

sak_retire_timeint

During a key rotation, time to retire the previous SAK key (milliseconds).

hello_time_rampuplist of int, optional

Periods between initial MKA messages after linkup in milliseconds (defaults to []).

sak_rekey_timeint, optional

Minimum interval in seconds before rekeying the SAK (defaults to 3).

macsec_modeLiteral[“disabled”, “integrity”, “integrity_confidentiality”]

MACsec operation mode. Options include disabled, integrity-only, and full encryption.

kay_onbool

Whether to activate the KaY (Key Agreement Entity) module. When disabled, MACsec is not negotiated.

key_roleLiteral[“key_server_always”, “key_server_never”]

Role of the device in key negotiation.

delay_protectbool

When enabled, performs frequent updates of the packet number on the receiving side to prevent attackers from delaying MACsec frames.

participant_activationLiteral[“disabled”, “onoperup”, “always”]

Strategy for participant activation.

sci_includedbool, optional

Whether to include the Secure Channel Identifier (SCI) in MACsec frames (defaults to False).

replay_protection_windowint, optional

Size of the replay protection window (defaults to 0). Any value other than 0 emits a warning.

cipher_preferencelist of DiscriminatedCipher

List of preferred ciphers to negotiate, ordered by priority. Defaults to using integrity-only without confidentiality.

class CipherSuiteBaseModel

Bases: FLYNCBaseModel

Common configuration items for MACsec cipher suites.

Parameters

cipher_suiteLiteral[GCM-AES-128, GCM-AES-256, GCM-AES-XPN-128, GCM-AES-XPN-256], optional

MACsec Cipher Suite defined in IEEE (defaults to "GCM-AES-XPN-256").

class IntegrityWithoutConfidentiality

Bases: CipherSuiteBaseModel

Cipher configuration representing integrity protection without confidentiality.

This configuration supports authentication and integrity checks but does not encrypt the data.

Parameters

typeLiteral[“integrity_without_confidentiality”]

Identifier for the cipher type. Always "integrity_without_confidentiality".

confidentiality_offsetLiteral[0], optional

Preference for offset timing (defaults to 0). Always 0 for this cipher.

class IntegrityWithConfidentiality

Bases: CipherSuiteBaseModel

Cipher configuration representing both integrity protection and confidentiality.

This configuration includes both encryption and authentication features.

Parameters

typeLiteral[“integrity_with_confidentiality”]

Identifier for the cipher type. Always "integrity_with_confidentiality".

confidentiality_offsetLiteral[0, 30, 50], optional

Confidentiality Offset preference for transmission in bytes (defaults to 0). Allows choosing between no offset, 30 bytes, or 50 bytes.

Firewall Configuration

Expand for Schematic
        classDiagram

    class Category {
        <<Enumeration>>
        VALUE_RANGE: int = 1
        REQUIRED: int = 2
        CONSISTENCY: int = 3
        UNIQUENESS: int = 4
        REFERENCE: int = 5
        FORMAT: int = 6
        COMPATIBILITY: int = 7
        STRUCTURAL: int = 8
        LIFECYCLE: int = 9
    }

    class Firewall {
        default_action: Literal['reject', 'accept', 'drop'] | None = 'reject'
        input_rules: list[FirewallRule] | None = []
        output_rules: list[FirewallRule] | None = []
        forward_rules: list[FirewallRule] | None = []
    }

    class FrameFilter {
        ethertype: Ethertype | list[Ethertype] | None = None
        src_mac: str | MACAddressEntry | list[str | MACAddressEntry] | None = None
        dst_mac: str | MACAddressEntry | list[str | MACAddressEntry] | None = None
        vlan_tagged: bool | None = None
        vlanid: int | ValueRange | list[int | ValueRange] | None = None
        pcp: int | list[int] | None = None
        src_ipv4: IPv4AddressEntry | IPv4Address | list[IPv4AddressEntry | IPv4Address] | None = None
        dst_ipv4: IPv4AddressEntry | IPv4Address | list[IPv4AddressEntry | IPv4Address] | None = None
        src_ipv6: IPv6AddressEntry | IPv6Address | list[IPv6AddressEntry | IPv6Address] | None = None
        dst_ipv6: IPv6AddressEntry | IPv6Address | list[IPv6AddressEntry | IPv6Address] | None = None
        protocol: Literal['tcp'] | Literal['udp'] | None = None
        src_port: int | ValueRange | list[int | ValueRange] | None = None
        dst_port: int | ValueRange | list[int | ValueRange] | None = None
    }

    class FLYNCBaseModel {
    }

    class FirewallRule {
        name: str
        action: Literal['reject', 'accept', 'drop']
        pattern: FrameFilter
    }

    FrameFilter ..> IPv4AddressEntry
    FrameFilter ..> MACAddressEntry
    FrameFilter ..> IPv6Address
    FrameFilter ..> IPv6AddressEntry
    FrameFilter ..> IPv4Address
    FrameFilter ..> Ethertype
    FrameFilter ..> ValueRange
    FirewallRule ..> FrameFilter
    Firewall ..> FirewallRule


    
class Firewall

Bases: FLYNCBaseModel

Represents a set of firewall rules with a default action.

Parameters

default_actionLiteral[‘reject’, ‘accept’, ‘drop’], optional

The action to apply to packets that do not match any rule (defaults to 'reject'). Can be one of 'reject', 'accept', or 'drop'.

input_ruleslist of FirewallRule, optional

A list of FirewallRule objects that define input traffic matching conditions and actions.

output_ruleslist of FirewallRule, optional

A list of FirewallRule objects that define output traffic matching conditions and actions.

forward_ruleslist of FirewallRule, optional

A list of FirewallRule objects that define forwarded traffic matching conditions and actions.

class FirewallRule

Bases: FLYNCBaseModel

Defines a single firewall rule for matching and handling frames.

Parameters

namestr

A unique name identifying the rule.

actionLiteral[‘reject’, ‘accept’, ‘drop’]

The action to take when the pattern matches. Can be one of 'reject', 'accept', or 'drop'.

patternFrameFilter

The filter pattern used to match frames for this rule.