MACsec: Layer-2 Encryption for Transport Networks
IEEE 802.1AE MACsec gives you wire-speed encryption for every Ethernet frame between two routers: no IPsec tunnel overhead, no MTU penalty beyond the SecTAG, no software bottleneck. OcNOS implements MACsec with 256-bit AES-GCM, EAPoL-MKA key management, and hitless rekey on validated 100G and 400G platforms.
Encrypted Hop Between Two OcNOS Routers
A point-to-point MACsec link between two PE routers. Each frame is wrapped with a SecTAG, an ICV, and a packet number; the AES-GCM 256 cipher runs in the ASIC at line rate, with EAPoL-MKA negotiating SAKs in the control plane.

Why MACsec for transport networks
Operators carrying multi-tenant traffic over leased fibre, dark wave, or shared metro infrastructure increasingly need encryption at every hop, not just at the IP layer. MACsec wraps every Ethernet frame in a SecTAG and an integrity check value (ICV), with the cipher running on the ASIC at line rate. There is no MTU penalty beyond the ~32 bytes of MACsec overhead, no software bottleneck, and no per-flow tunnel state: just an encrypted hop.
The OcNOS MACsec implementation
AES-GCM 128 / 256
Both GCM-AES-128 and GCM-AES-256 cipher suites are supported, with extended packet numbering (XPN) for high-bandwidth links to avoid premature SA rollover.
EAPoL-MKA + PSK
Pre-shared CAK with EAPoL-MKA negotiation of SAKs. CKN/CAK pairs roll on a configurable schedule with no operator intervention required.
Zero-loss rotation
SAK rotation happens in-band without packet loss using overlapping receive associations. Rekey on time, packet-count, or operator-trigger.
100G / 400G line rate
Validated MACsec on UfiSpace and Edgecore platforms with per-port encryption at full link rate: no aggregate cap, no port-group limits.
Selective enablement
Enable MACsec per physical port or per channel; mix encrypted and clear-text ports on the same chassis to fit hybrid deployments.
Counters + state
gNMI sensors for SecY counters, MKA participant state, packet number high-watermarks, and ICV failures: enough to alert before a key expires.
Operational guarantees with OcNOS MACsec
- Standards-aligned. Full IEEE 802.1AE-2018 plus 802.1X-2020 MKA, interoperable with major vendor implementations on the wire.
- No per-port encryption license. MACsec ships in the base OcNOS-SP image on supported platforms.
- Hitless software upgrades. ISSU on supported chassis preserves MACsec sessions across NOS upgrades. Encryption stays up.
- Mature operations. CLI, NETCONF, and gNMI configuration paths; ZTP-friendly for Day-0 provisioning of CKN/CAK pairs.
Designing an encrypted transport network?
Request a Technical Demo →Frequently asked questions
What cipher suites does OcNOS MACsec support?
How does MACsec differ from IPsec?
Does MACsec rekey cause packet loss?
Is MACsec line-rate on all ports?
Does OcNOS MACsec require a separate license?
Go deeper. Take it with you.
The product datasheet plus short, technical downloads that go further than this page.
OcNOS-SP Datasheet
Full OcNOS-SP specification: the access, cell site and aggregation feature set, software SKUs, supported hardware platforms, and the solution ordering guide.
Get the datasheetSR-MPLS Upgrade with OcNOS
Migrate SR-MPLS onto OcNOS on open hardware: Flex-Algo, TI-LFA, and a proven Cisco-alternative cutover path.
Get the briefCloud & Service Provider WAN Transport
Cloud and service-provider WAN transport on open hardware: SR-MPLS, EVPN, and scale-tested forwarding.
Get the briefOcNOS-SP Datasheet
Quick form. Your PDF opens in a new tab immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.
SR-MPLS Upgrade with OcNOS
Quick form. Your PDF opens in a new tab immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.
Cloud & Service Provider WAN Transport
Quick form. Your PDF opens in a new tab immediately after submit.
✓ Opening your PDF in a new tab…
If it didn't open, use the link below.