Na caixa de diálogo de confirmação, leia a mensagem e clique em Confirmar
para confirmar que você quer desativar o MACsec, ou em Cancelar para cancelar.
gcloud
Para desativar o MACsec para o Cloud Interconnect, execute o seguinte comando:
A seção Link circuit info mostra as seguintes informações:
ID do circuito do Google: o nome do circuito de link.
Estado do link: o estado físico do link do membro do LACP exibe uma verificação
e ativacheck_circle para indicar que o link do membro do LACP está para cima.
Nome da chave MACsec: o campo fica vazio quando o MACsec está desativado.
Potência óptica de recebimento: uma check_circleverificação indica uma
conexão aceitável. O nível de luz óptica que a interface
física detecta no transmissor remoto é exibido em
dBm.
Transmissão óptica de potência: uma verificação de check_circle indica uma
conexão aceitável e o nível de luz óptica que a interface
física está transmitindo ao receptor remoto exibidos em dBm.
A Configuração do MACsec exibe Desativado para indicar que a criptografia do MACsec está desativada no link.
gcloud
Para verificar a configuração do MACsec do Cloud Interconnect, execute o seguinte comando:
Os itens a seguir especificam a configuração das conexões MACsec:
macsec.failOpen: o comportamento da conexão se o Cloud Interconnect
não conseguir estabelecer uma sessão MKA com o roteador. O valor é um dos seguintes:
false: se uma sessão MKA não puder ser estabelecida, o Cloud Interconnect descartará todo o tráfego.
true: se uma sessão MKA não puder ser estabelecida, o Cloud Interconnect transmitirá o tráfego não criptografado.
macsec.preSharedKeys.name: a lista de todas as chaves pré-compartilhadas
configuradas para o Cloud Interconnect neste link.
macsec.preSharedKeys.startTime: quando a chave pré-compartilhada atual se torna válida. Todas as chaves têm validade infinita.
macsecEnabled: status MACsec para o Cloud Interconnect neste link. O valor é um dos seguintes:
false: o MACsec para o Cloud Interconnect está desativado.
true: o MACsec para o Cloud Interconnect está ativado.
Esse comando não exibe o status operacional MACsec.
[[["Fácil de entender","easyToUnderstand","thumb-up"],["Meu problema foi resolvido","solvedMyProblem","thumb-up"],["Outro","otherUp","thumb-up"]],[["Difícil de entender","hardToUnderstand","thumb-down"],["Informações incorretas ou exemplo de código","incorrectInformationOrSampleCode","thumb-down"],["Não contém as informações/amostras de que eu preciso","missingTheInformationSamplesINeed","thumb-down"],["Problema na tradução","translationIssue","thumb-down"],["Outro","otherDown","thumb-down"]],["Última atualização 2025-04-21 UTC."],[],[],null,["# Disable MACsec\n\nThis page describes how to disable MACsec for Cloud Interconnect.\n\nYou can disable MACsec, which can be useful when troubleshooting your\nconnection.\n| **Important:** When you disable MACsec on your Cloud Interconnect connection, the connection temporarily experiences packet loss. To avoid disruption to your connectivity, verify that there is no traffic on your Cloud Interconnect VLAN attachments before disabling MACsec for Cloud Interconnect.\n\nDisable MACsec for Cloud Interconnect\n-------------------------------------\n\nSelect one of the following options: \n\n### Console\n\n1. In the Google Cloud console, go to the Cloud Interconnect **Physical\n connections** tab.\n\n [Go to Physical connections](https://console.cloud.google.com/hybrid/interconnects/list?tab=interconnects)\n2. Select the connection that you want to modify.\n\n3. On the **MACsec** tab, click **Disable**.\n\n In the confirmation dialog, read the message, and then click **Confirm**\n to confirm that you want to disable MACsec, or **Cancel** to cancel.\n\n### gcloud\n\nTo disable MACsec for Cloud Interconnect, run the following command: \n\n gcloud compute interconnects macsec update \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e \\\n --no-enabled\n\nReplace \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e with the name of your\nCloud Interconnect connection.\n\nVerify MACsec configuration\n---------------------------\n\nSelect one of the following options: \n\n### Console\n\n1. In the Google Cloud console, go to the Cloud Interconnect **Physical\n connections** tab.\n\n [Go to Physical connections](https://console.cloud.google.com/hybrid/interconnects/list?tab=interconnects)\n2. Select the connection that you want to view.\n\n3. The **Link circuit info** section displays the following information:\n\n - **Google circuit ID:** the name of the link circuit.\n\n - **Link state:** the LACP member link's physical state displays a check_circle\n **Check** and **Active** to indicate that the LACP member link is up.\n\n - **MACsec key name:** the field is empty when MACsec is disabled.\n\n - **Receiving optical power:** a check_circle**check** indicates an\n acceptable connection. The optical light level that the physical\n interface detects from the remote transmitter is displayed in\n [dBm](https://en.wikipedia.org/wiki/DBm).\n\n - **Transmitting optical power:** a check_circle**check** indicates an\n acceptable connection and the optical light level that the physical\n interface is transmitting to the remote receiver is displayed in dBm.\n\n4. **MACsec configuration** displays **Disabled** to indicate that MACsec\n encryption is disabled on the link.\n\n### gcloud\n\nTo verify your Cloud Interconnect MACsec configuration, run the\nfollowing command: \n\n gcloud compute interconnects describe \u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e\n\nThe output is similar to the following: \n\n adminEnabled: true\n availableFeatures:\n - IF_MACSEC\n circuitInfos:\n - customerDemarcId: fake-peer-demarc-0\n googleCircuitId: LOOP-0\n googleDemarcId: fake-local-demarc-0\n creationTimestamp: '2021-10-05T03:39:33.888-07:00'\n customerName: Fake Company\n description: something important\n googleReferenceId: '123456789'\n id: '12345678987654321'\n interconnectAttachments:\n - https://www.googleapis.com/compute/v1/projects/my-project1/regions/us-central1/interconnectAttachments/interconnect-123456-987654321-0\n interconnectType: IT_PRIVATE\n kind: compute#interconnect\n labelFingerprint: 12H17262736_\n linkType: LINK_TYPE_ETHERNET_10G_LR\n location: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnectLocations/cbf-zone2-65012\n macsec:\n failOpen: false\n preSharedKeys:\n - name: key1\n startTime: 2023-07-01T21:00:01.000Z\n macsecEnabled: false\n name: \u003cvar translate=\"no\"\u003e\u003cspan class=\"devsite-syntax-l devsite-syntax-l-Scalar devsite-syntax-l-Scalar-Plain\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/span\u003e\u003c/var\u003e\n operationalStatus: OS_ACTIVE\n provisionedLinkCount: 1\n requestedFeatures:\n - IF_MACSEC\n requestedLinkCount: 1\n selfLink: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnects/\u003cvar translate=\"no\"\u003eINTERCONNECT_CONNECTION_NAME\u003c/var\u003e\n selfLinkWithId: https://www.googleapis.com/compute/v1/projects/my-project1/global/interconnects/12345678987654321\n state: ACTIVE\n\nThe following items specify the MACsec connections's configuration:\n\n- **`macsec.failOpen`:** the connection's behavior if\n Cloud Interconnect can't establish an MKA session with your\n router. The value is either of the following:\n\n - **`false`:** if an MKA session can't be established, then\n Cloud Interconnect drops all traffic.\n\n - **`true`:** if an MKA session can't be established, then\n Cloud Interconnect passes unencrypted traffic.\n\n- **`macsec.preSharedKeys.name`:** the list of all pre-shared keys\n configured for Cloud Interconnect on this link.\n\n- **`macsec.preSharedKeys.startTime`:** when the current pre-shared key\n became valid. All keys have infinite validity.\n\n- **`macsecEnabled`:** MACsec status for Cloud Interconnect on this\n link. The value is either of the following:\n\n - **`false`:** MACsec for Cloud Interconnect is off.\n\n - **`true`:** MACsec for Cloud Interconnect is on.\n\nThis command doesn't display MACsec operational status.\n\nWhat's next?\n------------\n\n- [View MACsec status](/network-connectivity/docs/interconnect/how-to/macsec/view-macsec-status)\n- [Rotate MACsec keys](/network-connectivity/docs/interconnect/how-to/macsec/rotate-macsec-keys)"]]