2026-08-19 –, MeetUp Room Language: English
This slide deck focuses on infrastructure readiness for Layer 2 (Ethernet) encryption deployments. While Ethernet encryption is a well-established and widely documented technology, critical aspects of the underlying network infrastructure are often overlooked. As a result, encryption may fail to establish successfully or experience frequent disruptions.
The primary focus of this presentation is MACsec encryption and the considerations required to deploy it effectively across Metropolitan Area Networks (MANs) and Wide Area Networks (WANs). It highlights common infrastructure prerequisites, potential challenges, and design considerations that are essential for maintaining stable and uninterrupted encrypted connectivity.
Agenda
Ethernet encryption modes
Industry standards (MACsec) and custom enhancements
What can go wrong with the infrastructure?
Important considerations for
-- VLAN IDs, Ethertype, MAC addresses
-- QoS
-- Tests and verifications
What can go wrong? Typical concerns
“We are not sure what is in the middle…”
“The service should be transparent!”
“Previous SEC devices worked fine here”
“We don’t get the full 10G capacity”
“Why bothering with QoS? We just need a simple L2 line”
“We thought your HW works over any medium”
Considerations: Destination MAC, VLAN tags and Ethertype
A carrier edge device might think that the key exchange frame (EAPOL) is destined to itself and might try to “consume” it, and not forward it any further
The “well-known” DA and Ethertype to blame
Workaround?.. Change those to some other values!
Is it possible to mask the MKA's Ethertype with VLAN tags' Ethertypes? Not really.
Considerations: QoS – the unsung hero of network operations
Check the technical aspects of the contract with your carrier
Know the carrier’s QoS value
Control the key QoS parameters:
-- Buffer size --> larger than 32K
-- CIR --> 9990M, not 10G
-- CBS (Bc) --> lower than carrier policer’s CBS
Considerations: Tests and Verifications
Compare test results in an “apple to apple” manner
-- Same layer, same method, same frame size, same loop types etc.Configure CFM (Connectivity Fault Management) between NNI ports to restore your MACsec session automatically
Configure CFM between UNI ports to see if the traffic passes through encrypted UNI to UNI
Key Takeaway
Know the middle!
Align the configurable parameters with the a carrier:
- QoS agreed
No Ethertype filtering
MACsec pass-through possible
CFM pass-through-possible
L2 MTU agreed
Dmitry Shkurko Network Designer
3 years in dacoso GmbH as Senior Solution Consultant: PON / Carrier Ethernet / L3 networks
13 years in BT (British Telecom) as Pre-Sales Engineer and Lead Designer: SD-WAN / IPSec / DMVPN
Geography of projects: Germany, UK, Belgium, China, Netherlands, Hungary, Ukraine and more
Dedicated to helping others succeed through a positive attitude and easy-to-follow explanations