En el cuadro de diálogo de confirmación, lee el mensaje y, luego, haz clic en Confirmar para confirmar que deseas inhabilitar MACsec, o Cancelar a fin de cancelar.
gcloud
Inhabilita MACsec para Cloud Interconnect mediante la ejecución del siguiente comando:
En la sección Información del circuito de los vínculos, se muestra la siguiente información:
ID de circuito de Google: el nombre del circuito de vínculo.
Estado del vínculo: El estado físico del vínculo del miembro de LACP muestra un mensaje Verificar y Activocheck_circle para indicar que el vínculo del miembro del LACP está funcionando.
Nombre de la clave MACsec: el campo está vacío cuando MACsec está inhabilitado.
Recibir potencia óptica: Una verificacióncheck_circle indica una conexión aceptable. El nivel de luz óptica que la interfaz física detecta en el transmisor remoto se muestra en dBm.
Transmisión de potencia óptica: una verificacióncheck_circle indica una conexión aceptable y el nivel de luz óptica que transmite la interfaz física al receptor remoto se muestra en dBm.
La configuración de MACsec muestra Inhabilitada para indicar que la encriptación MACsec está inhabilitada en el vínculo.
gcloud
Para verificar tu configuración de MACsec de Cloud Interconnect, ejecuta el siguiente comando:
En los siguientes elementos, se especifica la configuración de las conexiones MACsec:
macsec.failOpen: es el comportamiento de la conexión si Cloud Interconnect no puede establecer una sesión de MKA con tu router. El valor es cualquiera de los siguientes:
false: Si no se puede establecer una sesión de MKA, Cloud Interconnect descarta todo el tráfico.
true: Si no se puede establecer una sesión de MKA, Cloud Interconnect pasa el tráfico no encriptado.
macsec.preSharedKeys.name: la lista de todas las claves precompartidas configuradas para Cloud Interconnect en este vínculo.
macsec.preSharedKeys.startTime: cuando la clave precompartida actual se vuelve válida. Todas las claves tienen una validez infinita.
macsecEnabled: Es el estado de MACsec para Cloud Interconnect en este vínculo. El valor es cualquiera de los siguientes:
false: MACsec para Cloud Interconnect está desactivado.
true: MACsec para Cloud Interconnect está activado.
Este comando no muestra el estado operativo MACsec.
[[["Fácil de comprender","easyToUnderstand","thumb-up"],["Resolvió mi problema","solvedMyProblem","thumb-up"],["Otro","otherUp","thumb-up"]],[["Difícil de entender","hardToUnderstand","thumb-down"],["Información o código de muestra incorrectos","incorrectInformationOrSampleCode","thumb-down"],["Faltan la información o los ejemplos que necesito","missingTheInformationSamplesINeed","thumb-down"],["Problema de traducción","translationIssue","thumb-down"],["Otro","otherDown","thumb-down"]],["Última actualización: 2025-04-21 (UTC)"],[],[],null,["# Disable MACsec\n\nThis page describes how to disable MACsec for Cloud Interconnect.\n\nYou can disable MACsec, which can be useful when troubleshooting your\nconnection.\n| **Important:** When you disable MACsec on your Cloud Interconnect connection, the connection temporarily experiences packet loss. To avoid disruption to your connectivity, verify that there is no traffic on your Cloud Interconnect VLAN attachments before disabling MACsec for Cloud Interconnect.\n\nDisable MACsec for Cloud Interconnect\n-------------------------------------\n\nSelect one of the following options: \n\n### Console\n\n1. In the Google Cloud console, go to the Cloud Interconnect **Physical\n connections** tab.\n\n [Go to Physical connections](https://console.cloud.google.com/hybrid/interconnects/list?tab=interconnects)\n2. Select the connection that you want to modify.\n\n3. On the **MACsec** tab, click **Disable**.\n\n In the confirmation dialog, read the message, and then click **Confirm**\n to confirm that you want to disable MACsec, or **Cancel** to cancel.\n\n### gcloud\n\nTo disable MACsec for Cloud Interconnect, run the following command: \n\n gcloud compute interconnects macsec update \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e \\\n --no-enabled\n\nReplace \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e with the name of your\nCloud Interconnect connection.\n\nVerify MACsec configuration\n---------------------------\n\nSelect one of the following options: \n\n### Console\n\n1. In the Google Cloud console, go to the Cloud Interconnect **Physical\n connections** tab.\n\n [Go to Physical connections](https://console.cloud.google.com/hybrid/interconnects/list?tab=interconnects)\n2. Select the connection that you want to view.\n\n3. The **Link circuit info** section displays the following information:\n\n - **Google circuit ID:** the name of the link circuit.\n\n - **Link state:** the LACP member link's physical state displays a check_circle\n **Check** and **Active** to indicate that the LACP member link is up.\n\n - **MACsec key name:** the field is empty when MACsec is disabled.\n\n - **Receiving optical power:** a check_circle**check** indicates an\n acceptable connection. The optical light level that the physical\n interface detects from the remote transmitter is displayed in\n [dBm](https://en.wikipedia.org/wiki/DBm).\n\n - **Transmitting optical power:** a check_circle**check** indicates an\n acceptable connection and the optical light level that the physical\n interface is transmitting to the remote receiver is displayed in dBm.\n\n4. **MACsec configuration** displays **Disabled** to indicate that MACsec\n encryption is disabled on the link.\n\n### gcloud\n\nTo verify your Cloud Interconnect MACsec configuration, run the\nfollowing command: \n\n gcloud compute interconnects describe \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e\n\nThe output is similar to the following: \n\n adminEnabled: true\n availableFeatures:\n - IF_MACSEC\n circuitInfos:\n - customerDemarcId: fake-peer-demarc-0\n googleCircuitId: LOOP-0\n googleDemarcId: fake-local-demarc-0\n creationTimestamp: '2021-10-05T03:39:33.888-07:00'\n customerName: Fake Company\n description: something important\n googleReferenceId: '123456789'\n id: '12345678987654321'\n interconnectAttachments:\n - https://www.googleapis.com/compute/v1/projects/my-project1/regions/us-central1/interconnectAttachments/interconnect-123456-987654321-0\n interconnectType: IT_PRIVATE\n kind: compute#interconnect\n labelFingerprint: 12H17262736_\n linkType: LINK_TYPE_ETHERNET_10G_LR\n location: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnectLocations/cbf-zone2-65012\n macsec:\n failOpen: false\n preSharedKeys:\n - name: key1\n startTime: 2023-07-01T21:00:01.000Z\n macsecEnabled: false\n name: \u003cvar translate=\"no\"\u003e\u003cspan class=\"devsite-syntax-l devsite-syntax-l-Scalar devsite-syntax-l-Scalar-Plain\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/span\u003e\u003c/var\u003e\n operationalStatus: OS_ACTIVE\n provisionedLinkCount: 1\n requestedFeatures:\n - IF_MACSEC\n requestedLinkCount: 1\n selfLink: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnects/\u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e\n selfLinkWithId: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnects/12345678987654321\n state: ACTIVE\n\nThe following items specify the MACsec connections's configuration:\n\n- **`macsec.failOpen`:** the connection's behavior if\n Cloud Interconnect can't establish an MKA session with your\n router. The value is either of the following:\n\n - **`false`:** if an MKA session can't be established, then\n Cloud Interconnect drops all traffic.\n\n - **`true`:** if an MKA session can't be established, then\n Cloud Interconnect passes unencrypted traffic.\n\n- **`macsec.preSharedKeys.name`:** the list of all pre-shared keys\n configured for Cloud Interconnect on this link.\n\n- **`macsec.preSharedKeys.startTime`:** when the current pre-shared key\n became valid. All keys have infinite validity.\n\n- **`macsecEnabled`:** MACsec status for Cloud Interconnect on this\n link. The value is either of the following:\n\n - **`false`:** MACsec for Cloud Interconnect is off.\n\n - **`true`:** MACsec for Cloud Interconnect is on.\n\nThis command doesn't display MACsec operational status.\n\nWhat's next?\n------------\n\n- [View MACsec status](/network-connectivity/docs/interconnect/how-to/macsec/view-macsec-status)\n- [Rotate MACsec keys](/network-connectivity/docs/interconnect/how-to/macsec/rotate-macsec-keys)"]]