DENOG Meetup 2026-08 / Stuttgart

Ethernet Encryption - Infrastructure Challenges
2026-08-19 , MeetUp Room
Language: English

This slide deck focuses on infrastructure readiness for Layer 2 (Ethernet) encryption deployments. While Ethernet encryption is a well-established and widely documented technology, critical aspects of the underlying network infrastructure are often overlooked. As a result, encryption may fail to establish successfully or experience frequent disruptions.

The primary focus of this presentation is MACsec encryption and the considerations required to deploy it effectively across Metropolitan Area Networks (MANs) and Wide Area Networks (WANs). It highlights common infrastructure prerequisites, potential challenges, and design considerations that are essential for maintaining stable and uninterrupted encrypted connectivity.


Agenda

  • Ethernet encryption modes

  • Industry standards (MACsec) and custom enhancements

  • What can go wrong with the infrastructure?

  • Important considerations for
    -- VLAN IDs, Ethertype, MAC addresses
    -- QoS
    -- Tests and verifications

What can go wrong? Typical concerns

  • “We are not sure what is in the middle…”

  • “The service should be transparent!”

  • “Previous SEC devices worked fine here”

  • “We don’t get the full 10G capacity”

  • “Why bothering with QoS? We just need a simple L2 line”

  • “We thought your HW works over any medium”

Considerations: Destination MAC, VLAN tags and Ethertype

  • A carrier edge device might think that the key exchange frame (EAPOL) is destined to itself and might try to “consume” it, and not forward it any further

  • The “well-known” DA and Ethertype to blame

  • Workaround?.. Change those to some other values!

  • Is it possible to mask the MKA's Ethertype with VLAN tags' Ethertypes? Not really.

Considerations: QoS – the unsung hero of network operations

  • Check the technical aspects of the contract with your carrier

  • Know the carrier’s QoS value

  • Control the key QoS parameters:
    -- Buffer size --> larger than 32K
    -- CIR --> 9990M, not 10G
    -- CBS (Bc) --> lower than carrier policer’s CBS

Considerations: Tests and Verifications

  • Compare test results in an “apple to apple” manner
    -- Same layer, same method, same frame size, same loop types etc.

  • Configure CFM (Connectivity Fault Management) between NNI ports to restore your MACsec session automatically

  • Configure CFM between UNI ports to see if the traffic passes through encrypted UNI to UNI

Key Takeaway

Know the middle!
Align the configurable parameters with the a carrier:
- QoS agreed

  • No Ethertype filtering

  • MACsec pass-through possible

  • CFM pass-through-possible

  • L2 MTU agreed

Dmitry Shkurko Network Designer

  • 3 years in dacoso GmbH as Senior Solution Consultant: PON / Carrier Ethernet / L3 networks

  • 13 years in BT (British Telecom) as Pre-Sales Engineer and Lead Designer: SD-WAN / IPSec / DMVPN

  • Geography of projects: Germany, UK, Belgium, China, Netherlands, Hungary, Ukraine and more

  • Dedicated to helping others succeed through a positive attitude and easy-to-follow explanations