this op-command allow to see , mac-sec encryption and offload (stats / peer packets)
vyos@macsec-01:~$ sudo ip -s macsec show macsec1 9: macsec1: protect on validate strict sc off sa off encrypt on send_sci on end_station off scb off replay off cipher suite: GCM-AES-128, using ICV length 16 TXSC: 0011223344010001 on SA 0 stats: OutPktsUntagged InPktsUntagged OutPktsTooLong InPktsNoTag InPktsBadTag InPktsUnknownSCI InPktsNoSCI InPktsOverrun 0 0 0 11 0 0 0 0 stats: OutPktsProtected OutPktsEncrypted OutOctetsProtected OutOctetsEncrypted 0 7 0 662 0: PN 8, state on, key 00000000000000000000000000000000 stats: OutPktsProtected OutPktsEncrypted 0 7 RXSC: 0011223344020001, state on stats: InOctetsValidated InOctetsDecrypted InPktsUnchecked InPktsDelayed InPktsOK InPktsInvalid InPktsLate InPktsNotValid InPktsNotUsingSA InPktsUnusedSA 0 564 0 0 6 0 0 0 0 0 0: PN 8, state on, key 01000000000000000000000000000000 stats: InPktsOK InPktsInvalid InPktsNotValid InPktsNotUsingSA InPktsUnusedSA 6 0 0 0 0 offload: off