Troubleshooting MACsec Operational Down on Cloud Interconnect

Cloud Interconnect Security
Answer Correct answer: D — Ensure that the active pre-shared key matches on both the on-premises and Google edge routers.

You work for a large organization that recently implemented a 100GB Cloud Interconnect connection between your Google Cloud and your on-premises edge router. While routinely checking the connectivity, you noticed that the connection is operational but there is an error message that indicates MACsec is operationally down. You need to resolve this error. What should you do?

  1. Ensure that the Cloud Interconnect connection supports MACsec.
  2. Ensure that the on-premises router is not down.
  3. Ensure that the active pre-shared key created for MACsec is not expired on both the on-premises and Google edge routers.
  4. Ensure that the active pre-shared key matches on both the on-premises and Google edge routers. Correct Answer

Community Votes

D
100%

100% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

Tests MACsec authentication requirements, with the common trap being confusion between key expiration and key mismatch during initial setup.

This question tests troubleshooting MACsec session failures on Google Cloud Interconnect by verifying endpoint authentication. It establishes that mismatched pre-shared keys are the primary cause of an operationally down MACsec state.

Candidates often choose C (key expiration) instead of D (key mismatch), overlooking that a newly provisioned link will fail immediately if the configured PSKs do not align exactly on both routers.

Community Discussion (4 comments)

Pime13 👍 1 Selected: D
You successfully enabled MACsec on your Cloud Interconnect connection and on your on-premises router, but the MACsec session displays that it is operationally down on your Cloud Interconnect connection links. The issue could be caused by one of the following: The active keys on your on-premises router and Google's edge routers don't match. A MACsec protocol mismatch exists between your on-premises router and Google's edge router. https://cloud.google.com/network-connectivity/docs/interconnect/how-to/macsec/troubleshoot-macsec
MoAk 👍 1 Selected: D
D, rather than C here since its a new implementation and unlikely that it will be the PSK expired.
BondleB 👍 2
https://cloud.google.com/network-connectivity/docs/interconnect/how-to/macsec/troubleshoot-macsec D
abdelrahman89 👍 2 Selected: D
Answer D

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

MACsec relies on identical cryptographic keys at both endpoints to negotiate a secure data plane. When the active pre-shared key (PSK) configured on the on-premises router differs from the one set on Google’s edge router, the MACsec association fails to establish, resulting in an operationally down status. Verifying and aligning these keys restores the encrypted tunnel.

Why the Other Options Are Wrong

Option A is incorrect because the connection is already provisioned and operational at Layer 2/3, meaning MACsec support is inherently available. Option B contradicts the prompt, which explicitly states the underlying connectivity is up. Option C focuses on key expiration, which is highly improbable for a freshly deployed interconnect and is secondary to the fundamental requirement of key parity during initial negotiation.

Community Comment Notes

Learners consistently validate D by referencing official troubleshooting documentation that lists key mismatches as a primary failure mode. BondleB shared the direct vendor troubleshooting page confirming this behavior. Several users noted that since this is a new deployment, expiration (Option C) is unrealistic compared to configuration alignment. Multiple commenters confirmed that matching the PSKs directly resolves the operational down state without requiring additional policy changes.

Official Reference

Exam Strategy

When troubleshooting security features like MACsec or IPsec, always verify cryptographic alignment first. Mismatched keys, algorithms, or lifetimes are the most frequent causes of negotiation failures, especially on newly provisioned links.

Frequently Asked Questions

Why is key expiration (C) incorrect for a new MACsec setup?

Expiration applies to long-running deployments; a newly provisioned link fails immediately due to configuration mismatch, making alignment the priority.

Can MACsec be operationally down if the underlying VLAN is up?

Yes. MACsec operates at Layer 2 for encryption and authentication, negotiating independently of the base transport path status.

Related Analysis

← Back to PCSE Study Guide