Create macsec configuration and macsec interface by default in "admin down" state
set interfaces macsec macsec1 address '10.0.0.1/30' set interfaces macsec macsec1 security cipher 'gcm-aes-128' set interfaces macsec macsec1 security encrypt set interfaces macsec macsec1 security mka cak 'f42e15acecc0c1634582bdd32429efdf' set interfaces macsec macsec1 security mka ckn '0ef5ebf77ba031e45ad270e9f80c804d500a2649789db1c87b751114f329e032' set interfaces macsec macsec1 source-interface 'eth1'
Check interfaces
vyos@r1-roll:~$ show int Codes: S - State, L - Link, u - Up, D - Down, A - Admin Down Interface IP Address S/L Description --------- ---------- --- ----------- eth0 192.168.122.11/24 u/u eth1 192.0.2.1/24 u/u eth2 - u/u lo 127.0.0.1/8 u/u ::1/128 macsec1 10.0.0.1/30 A/D vyos@r1-roll:~$ sudo ip link show | grep macs -A 2 11: macsec1@eth1: <BROADCAST,MULTICAST> mtu 1460 qdisc noqueue state DOWN mode DEFAULT group default qlen 1000 link/ether 52:54:00:b2:38:2c brd ff:ff:ff:ff:ff:ff