MACsec over VXLAN

MACsec over VXLAN is an end-to-end security protocol that provides a secured environment to protect Ethernet frames traveling over IP networks. Though Virtual Extensible Local Area Network (VXLAN) provides a Layer 2 extension across the LAN/WAN, a connection between sites is not secured. MACsec over VXLAN addresses this and achieves a secure Layer 2 extension across the LAN/WAN using cross-connect VXLAN Network Identifiers (VNIs).

In this solution, a Media Access Control security (MACsec) session must be established over a VXLAN tunnel using an external loopback connection. For each MACsec session, from one site to another site there should be a dedicated port for the loopback connection and a dedicated VLAN that is mapped to the VNI. The VNI that is mapped to the dedicated VLAN is the cross-connect VNI which provides point-to-point Layer 2 extensions across the LAN/WAN. The external loopback port connected to the MACsec port must be the only member of the dedicated VLAN. The VLAN that is used for the cross-connect VNI cannot be used as a regular user VLAN, and any other VLAN-level feature must not be enabled. The protocol packets coming to the port which belong to the cross-connect VNI are not copied to the CPU. MAC learning is disabled on the port too. Any packets routed to the MACsec port will be encrypted and tunneled to the remote Virtual Tunnel End Point (VTEP). On the receive path, packets will be decrypted and forwarded.

MACsec over VXLAN Packet Flow

In the example in MACsec over VXLAN Packet Flow, port p1 is connected to the end user. Port p2 is the MACsec port, which has an external loopback connection to port p3. The traffic that enters the device on access port p1 is switched to MACsec port p2. At port p2, traffic is encrypted and sent out of port p2. Because there is an external loopback configuration, encrypted traffic is received on port p3, which is the only member of the dedicated VLAN. This VLAN is VLAN X. VLAN X is mapped to the VNI so that the encrypted traffic is VXLAN-tunneled to the other VTEP. When the traffic is received on the other VTEP, after VXLAN de-tunneling, the payload-encrypted Layer 2 frame is switched to port p3. Due to the external loopback, encrypted traffic is received back on port p2. At port p2, traffic is decrypted and switched to port p1.