MACsec Overview

Media Access Control Security (MACsec) is a Layer 2 security technology that provides point-to-point security on Ethernet links between nodes.
Note: MACsec is supported on ICX 7550, ICX 7650, and ICX 7850 devices.

MACsec, defined in the IEEE 802.1AE-2006 standard, is based on symmetric cryptographic keys. MACsec Key Agreement (MKA) protocol, defined as part of the IEEE 802.1x-2010 standard, operates at Layer 2 to generate and distribute the cryptographic keys used by the MACsec functionality installed in the hardware.

As a hop-to-hop Layer 2 security feature, MACsec can be combined with Layer 3 security technologies such as IPsec for end-to-end data security.

Supported MACsec Hardware Configurations

MACsec key-enabled security can be deployed on a point-to-point LAN between two connected ICX devices over interfaces that share a preconfigured static key, the Connectivity Association Key (CAK).

On a licensed ICX 7550, ICX 7650, or ICX 7850 device, 10-Gbps ports can be configured for MACsec. Licenses are available per device as described in the RUCKUS FastIron Software Licensing Guide.

    Note:
  1. On ICX 7550 devices, MACsec is available only on 4 X 10GF modules installed in slot 3.
  2. On ICX 7650 devices, MACsec is available only on 10-Gbps fiber ports, that is, ports 25 through 48 of the base module for ICX 7650-48F devices or on slot 2 when a 4 X 10GF module is installed.
  3. MACsec is available on 10-Gbps ports of ICX 7850-48FS devices only.

MACsec RFCs and Standards

FastIron MACsec complies with the following industry standards:

  • IEEE Std 802.1X-2010: Port-Based Network Access Control
  • IEEE Std 802.1AE-2006: Media Access Control (MAC) Security
  • RFC 3394: Advanced Encryption Standard (AES) Key Wrap Algorithm
  • RFC 5649: Advanced Encryption Standard (AES) Key Wrap with Padding Algorithm

MACsec Considerations

Review the following considerations before deploying MACsec:

  • As a prerequisite, MACsec must be licensed on each device where it is used.
  • MACsec introduces an additional transit delay, due to the increase in the MAC Service Data Unit (MSDU) size.
  • MACsec and Flexible authentication cannot be configured on the same port.
  • On an ICX 7550 device, ports on a 4 X 10GF removable module installed in slot 3 can be used for MACsec or stacking but not both simultaneously.