MACsec encryption per traffic flow encapsulation matching

MACsec can be applied to a selected subset of the port traffic, based on the type and value of the packet encapsulation. The 7705 SAR can be configured to match and encrypt the following traffic encapsulation types:

  • all encapsulated traffic arriving on the port, including untagged, single-tag, and double-tag traffic. This is the default behavior of MACsec.

  • untagged-only traffic

  • single-tag or dot1q traffic. In this mode, MACsec can be applied to a specific tag or wildcard tag where all single-tag traffic is matched.

  • double-tag or QinQ traffic. In this mode, MACsec can be applied to a specific service tag (S-tag), a specific service tag and customer tag (S-tag and C-tag), or a wildcard for any QinQ traffic.

MACsec key agreement PDUs (MKPDUs) are generated specifically for the traffic encapsulation type that is being matched.