MACsec Overview
MACsec, defined in the IEEE 802.1AE-2006 standard, is based on symmetric cryptographic keys. MACsec Key Agreement (MKA) protocol, defined as part of the IEEE 802.1x-2010 standard, operates at Layer 2 to generate and distribute the cryptographic keys used by the MACsec functionality installed in the hardware.
As a hop-to-hop Layer 2 security feature, MACsec can be combined with Layer 3 security technologies such as IPsec for end-to-end data security.
Supported MACsec Hardware Configurations
MACsec key-enabled security can be deployed on a point-to-point LAN between two connected ICX devices over interfaces that share a preconfigured static key, the Connectivity Association Key (CAK).
On a licensed ICX 7450, ICX 7550, ICX 7650, or ICX 7850 device, 10-Gbps ports can be configured for MACsec. Licenses are available per device as described in the RUCKUS FastIron Software Licensing Guide.
- Note:
- On ICX 7450 devices, MACsec is available only on 4 X 10GF modules installed in slots 2, 3, or 4.
- On ICX 7550 devices, MACsec is available only on 4 X 10GF modules installed in slot 3.
- On ICX 7650 devices, MACsec is available only on 10-Gbps fiber ports, that is, ports 25 through 48 of the base module for ICX 7650-48F devices or on slot 2 when a 4 X 10GF module is installed.
- MACsec is available on 10-Gbps ports of ICX 7850-48FS devices only.
MACsec RFCs and Standards
FastIron MACsec complies with the following industry standards:
- IEEE Std 802.1X-2010: Port-Based Network Access Control
- IEEE Std 802.1AE-2006: Media Access Control (MAC) Security
- RFC 3394: Advanced Encryption Standard (AES) Key Wrap Algorithm
- RFC 5649: Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm
Refer to Port MAC Security (PMS) for information on other IEEE 802.1X features.
MACsec Considerations
Review the following considerations before deploying MACsec:
- As a prerequisite, MACsec must be licensed on each device where it is used.
- MACsec introduces an additional transit delay, due to the increase in the MAC Service Data Unit (MSDU) size.
- MACsec and Flexible authentication cannot be configured on the same port.
- On an ICX 7450 device or an ICX 7550 device, ports on a 4 X 10GF removable module installed in ICX 7450 slot 2 or ICX 7550 slot 3 can be used for MACsec or stacking but not both simultaneously. For more information on converting the ports between MACsec and stacking, refer to the RUCKUS FastIron Stacking Configuration Guide.
- In rear modules 3 and 4 on an ICX 7450 device, MACsec can be supported at all times because stacking is not available on those modules.