MACsec Overview
MACsec, defined in the IEEE 802.1AE-2006 standard, is based on symmetric cryptographic keys. MACsec Key Agreement (MKA) protocol, defined as part of the IEEE 802.1x-2010 standard, operates at Layer 2 to generate and distribute the cryptographic keys used by the MACsec functionality installed in the hardware.
As a hop-to-hop Layer 2 security feature, MACsec can be combined with Layer 3 security technologies such as IPsec for end-to-end data security.
Supported MACsec Hardware Configurations
MACsec key-enabled security can be deployed on a point-to-point LAN between two connected ICX devices over interfaces that share a preconfigured static key, the Connectivity Association Key (CAK).
On a licensed ICX 7550, ICX 7650, or ICX 7850 device, 10-Gbps ports can be configured for MACsec. Licenses are available per device as described in the RUCKUS FastIron Software Licensing Guide.
- Note:
- On ICX 7550 devices, MACsec is available only on 4 X 10GF modules installed in slot 3.
- On ICX 7650 devices, MACsec is available only on 10-Gbps fiber ports, that is, ports 25 through 48 of the base module for ICX 7650-48F devices or on slot 2 when a 4 X 10GF module is installed.
- MACsec is available on 10-Gbps ports of ICX 7850-48FS devices only.
MACsec RFCs and Standards
FastIron MACsec complies with the following industry standards:
MACsec Considerations
Review the following considerations before deploying MACsec:
- As a prerequisite, MACsec must be licensed on each device where it is used.
- MACsec introduces an additional transit delay, due to the increase in the MAC Service Data Unit (MSDU) size.
- MACsec and Flexible authentication cannot be configured on the same port.
- On an ICX 7550 device, ports on a 4 X 10GF removable module installed in slot 3 can be used for MACsec or stacking but not both simultaneously.