What Is MACsec? Layer 2 Encryption Explained
MACsec (802.1AE) is the IEEE standard for L2 (Ethernet) encryption between switches/endpoints. It encrypts frames on the fly using AES-128 or AES-256-GCM. It protects against eavesdropping on fiber/copper cables. It is mandatory for NIS2 compliance in certain configurations.
How It Works
- Hop-by-hop encryption between 2 devices
- AES-128 or AES-256-GCM
- Performance: hardware ASIC (no latency impact)
- Uses 802.1X or MKA (MACsec Key Agreement) to negotiate keys
- Transparent to higher-layer applications
Use Cases
- Inter-site DC links over leased fiber
- Inter-building campus links
- Data centers: enhanced microsegmentation
- Compliance: protecting sensitive data across the network
Vendor Support
- Cisco Catalyst 9300/9500: MACsec 128/256
- Juniper EX4300/4400/9200: 128/256
- Aruba CX 6300M/8325: 256
- Arista 7050X3: 256
- Requires a compatible hardware ASIC (cannot be retrofitted)
vs IPsec
- MACsec: L2, between adjacent switches, low overhead
- IPsec: L3, end-to-end, flexible multi-hop deployment
- MACsec: wire-speed performance
- IPsec: overhead of ~10-15% throughput
Order from OPTINOC
MACsec switches from Cisco/Juniper/Aruba/Arista. Inter-site configuration + keys. Quote within 48 hours.
