MACsec

Media Access Control security (MACsec) is an industry standard security technology that provides secure communication for almost all types of traffic on Ethernet links. MACsec provides point-to-point and point-to-multipoint security on Ethernet links between directly connected nodes or nodes connected via a Layer 2 cloud. MACsec can identify and prevent most security threats, including:

  • denial of service

  • intrusion

  • man-in-the-middle

  • masquerading

  • passive wiretapping

  • playback attacks

MACsec Layer 2 encryption is standardized in IEEE 802.1AE. MACsec encrypts anything from the 802.1AE header to the end of the payload, including 802.1Q; it leaves the destination MAC address and source MAC address in clear text. The destination MAC address (DMAC) is used for MACsec packet forwarding.

The following figure shows the 802.1AE LAN mode structure.

Figure 1. 802.1AE LAN mode

MACsec is supported on the 6-port Ethernet 10Gbps Adapter card, version 2.