Media Access Control Security

To protect your network from data link layer attacks and provide total Ethernet links security, you can use Media Access Control Security (MACsec), which is based on an 802.1 AE standard. MACsec is like IPsec in the network layer, it provides integrity and confidentiality protection using a hop-by-hop encryption (GCM-AES-128) with the use of a MACsec Key Agreement (MKA) between the network nodes. Thus, it encrypts all the Ethernet packets but without touching the source and destination MAC addresses. MACsec in switch-to-switch mode is not the same with switch-to-host mode. The first is named downlink MACsec, where the host goes through the 802.1x authentication process. The second is named uplink MACsec. It is ...

Get Advanced Infrastructure Penetration Testing now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.