DPDK 22.11.5
Data Fields
rte_security_macsec_xform Struct Reference

#include <rte_security.h>

Data Fields

enum rte_security_macsec_direction dir
 
enum rte_security_macsec_alg alg
 
uint8_t cipher_off
 
uint64_t sci
 
uint16_t sc_id
 
uint16_t mtu
 
uint8_t sectag_off
 
uint16_t protect_frames: 1
 
uint16_t sectag_insert_mode: 1
 
uint16_t icv_include_da_sa: 1
 
uint16_t ctrl_port_enable: 1
 
uint16_t sectag_version: 1
 
uint16_t end_station: 1
 
uint16_t send_sci: 1
 
uint16_t scb: 1
 
uint16_t encrypt: 1
 
uint16_t reserved: 7
 
uint32_t replay_win_sz
 
uint16_t validate_frames: 2
 
uint16_t preserve_sectag: 1
 
uint16_t preserve_icv: 1
 
uint16_t replay_protect: 1
 

Detailed Description

MACsec security session configuration

Definition at line 447 of file rte_security.h.

Field Documentation

◆ dir

Direction of flow/secure channel

Definition at line 449 of file rte_security.h.

◆ alg

MACsec algorithm to be used

Definition at line 451 of file rte_security.h.

◆ cipher_off

uint8_t cipher_off

Cipher offset from start of Ethernet header

Definition at line 453 of file rte_security.h.

◆ sci

uint64_t sci

SCI to be used for RX flow identification or to set SCI in packet for TX when send_sci is set

Definition at line 458 of file rte_security.h.

◆ sc_id

uint16_t sc_id

Receive/transmit secure channel ID created by rte_security_macsec_sc_create

Definition at line 460 of file rte_security.h.

◆ mtu

uint16_t mtu

MTU for transmit frame (valid for inline processing)

Definition at line 464 of file rte_security.h.

◆ sectag_off

uint8_t sectag_off

Offset to insert sectag from start of ethernet header or from a matching VLAN tag

Definition at line 469 of file rte_security.h.

◆ protect_frames

uint16_t protect_frames

Enable MACsec protection of frames

Definition at line 471 of file rte_security.h.

◆ sectag_insert_mode

uint16_t sectag_insert_mode

Sectag insertion mode If 1, Sectag is inserted at fixed sectag_off set above. If 0, Sectag is inserted at relative sectag_off from a matching VLAN tag set.

Definition at line 478 of file rte_security.h.

◆ icv_include_da_sa

uint16_t icv_include_da_sa

ICV includes source and destination MAC addresses

Definition at line 480 of file rte_security.h.

◆ ctrl_port_enable

uint16_t ctrl_port_enable

Control port is enabled

Definition at line 482 of file rte_security.h.

◆ sectag_version

uint16_t sectag_version

Version of MACsec header. Should be 0

Definition at line 484 of file rte_security.h.

◆ end_station

uint16_t end_station

Enable end station. SCI is not valid

Definition at line 486 of file rte_security.h.

◆ send_sci

uint16_t send_sci

Send SCI along with sectag

Definition at line 488 of file rte_security.h.

◆ scb

uint16_t scb

enable secure channel support EPON - single copy broadcast

Definition at line 490 of file rte_security.h.

◆ encrypt

uint16_t encrypt

Enable packet encryption and set RTE_MACSEC_TCI_C and RTE_MACSEC_TCI_E in sectag

Definition at line 495 of file rte_security.h.

◆ reserved

uint16_t reserved

Reserved bitfields for future

Definition at line 497 of file rte_security.h.

◆ replay_win_sz

uint32_t replay_win_sz

Replay Window size to be supported

Definition at line 501 of file rte_security.h.

◆ validate_frames

uint16_t validate_frames

Set bits as per RTE_SECURITY_MACSEC_VALIDATE_*

Definition at line 503 of file rte_security.h.

◆ preserve_sectag

uint16_t preserve_sectag

Do not strip SecTAG after processing

Definition at line 509 of file rte_security.h.

◆ preserve_icv

uint16_t preserve_icv

Do not strip ICV from the packet after processing

Definition at line 511 of file rte_security.h.

◆ replay_protect

uint16_t replay_protect

Enable anti-replay protection

Definition at line 513 of file rte_security.h.


The documentation for this struct was generated from the following file: