Skip to main content

What Is MACsec? Layer 2 Encryption Explained

·1 min read·154 words

MACsec (802.1AE) is the IEEE standard for L2 (Ethernet) encryption between switches/endpoints. It encrypts frames on the fly using AES-128 or AES-256-GCM. It protects against eavesdropping on fiber/copper cables. It is mandatory for NIS2 compliance in certain configurations.

How It Works

  • Hop-by-hop encryption between 2 devices
  • AES-128 or AES-256-GCM
  • Performance: hardware ASIC (no latency impact)
  • Uses 802.1X or MKA (MACsec Key Agreement) to negotiate keys
  • Transparent to higher-layer applications

Use Cases

  • Inter-site DC links over leased fiber
  • Inter-building campus links
  • Data centers: enhanced microsegmentation
  • Compliance: protecting sensitive data across the network

Vendor Support

  • Cisco Catalyst 9300/9500: MACsec 128/256
  • Juniper EX4300/4400/9200: 128/256
  • Aruba CX 6300M/8325: 256
  • Arista 7050X3: 256
  • Requires a compatible hardware ASIC (cannot be retrofitted)

vs IPsec

  • MACsec: L2, between adjacent switches, low overhead
  • IPsec: L3, end-to-end, flexible multi-hop deployment
  • MACsec: wire-speed performance
  • IPsec: overhead of ~10-15% throughput

Order from OPTINOC

MACsec switches from Cisco/Juniper/Aruba/Arista. Inter-site configuration + keys. Quote within 48 hours.

Frequently Asked Questions

Reply within 2 business hours

Need a quote?

Our technical team responds within 2 business hours. European delivery 24-72h.

Request a quote