Solution Track icon

MACsec

Solution Track

AVAILABLE FOR:

Z100qx Loki

KEY FEATURES

  • IEEE 802.1AE-2018 MACsec support
  • Supports both Point-to-point and group Connectivity Associations (CAs)
  • Traffic type can be L2 (Ethernet, VLAN) and L3 (IPv4, IPv6) and a mix of MACsec and non-MACsec.
  • 128 Secure Channels per port, up to 4 SAKs
  • PN exhaust or configurable packet number based rekeying
  • Suitable for Z100qx Loki 4-port traffic generators: 4 x 25G or 4 x 10G
  • Requires Xena Release 106 (or later) and XM3

MACsec delivers strong, hardware‑based security at the Link Layer, protecting data on local network segments with integrity, confidentiality, and defense against on‑link attacks. This offers a key advantage over Layer 3 security protocols, which cannot stop threats  originating within the same Layer 2 domain.

In addition to the standard Ethernet testing options offered by XenaManager 3 (XM3), the MACsec Solution Track adds IEEE 802.1AE functionality for testing MACsec on 10G and 25G ports.

Available for use with the four-port Z100qx Loki traffic generators, the MACsec Solution Track can generate MACsec‑encrypted frames at wire speed, control re-keying behavior, and log throughput and key performance metrics, providing comprehensive validation of MACsec implementations.

The MACsec Solution Track is primarily intended for:

  • Developers of devices that support MACsec and need to verify performance under realistic traffic loads.
  • Operators of secure networks who must validate performance before deployment and troubleshoot issues during operation.

It enables verification and performance testing of a device’s reception, forwarding and transmission of MACsec encrypted frames.

Testing can be performed with various traffic loads up to wire speed 100Gbps.

Once enabled, all these extra features are made available via the XenaManager3 interface.

MACsec White Paper

Best practices for testing the performance of MACsec under real world conditions

Ethernet is the foundation of modern connectivity, but traditional security protocols like IPsec and TLS do not protect data at the Ethernet (Layer 2) level. MACsec (IEEE 802.1AE) addresses this gap by providing encryption and authentication directly on Ethernet links, ensuring secure, low-latency data transmission.

To ensure MACsec performs as intended, rigorous testing is essential. This includes validating functionality (e.g., encryption, key rollover, replay protection), assessing performance at wire speed (latency, jitter, throughput), and conducting negative testing to simulate failures and attacks.

The White Paper explains MACsec’s role in securing networks, outlines best practices for comprehensive testing under real-world conditions, and highlights how Teledyne LeCroy solutions enable accurate validation without compromising performance.

MACsec-White-Paper