802.1AE MACsec Progress or Examples ?

We tested the MACsec with 7.9 on CCR2004 and it seems that the performances have drastically increased. We are around 1Gbps when forwarding packets (not generating the traffic from the router itself.) Good job!

Hi,

I noticed MACsec is only available for ethernet interfaces (as of v7.15 and as per the official docs). But what if I would like to secure L2 traffic going through one of my VXLAN interfaces (unicast)? It would be pretty useful to have such a feature.

I submitted a ticket (SUP-147160) about it 2 months ago, but haven’t received any response from MikroTik.

Does anyone know whether there are any limitations preventing MikroTik from implementing MACsec on any interfaces rather than ethernet only?

Example of VXLAN + MACsec

Regards,

even if it remotely possible don’t do it because macsec and vxlan encapsulation/decapsulation is process by CPU for now, some of the marvel hardware is capable but the codebase of mikrotik does not support it that’s what I’m reading here in the forum all the time look at what post https://forum.mikrotik.com/viewtopic.php?p=1076484&sid=86b3def1ac3183e7403f03c37bd2846d#p985747

@loloski, thank you for your input. Shall I care if my VXLAN is between CHRs with x86_64 CPUs and I have no intention to pass a lot of traffic through it?

I believed if you are passing traffic less than 1G i think you are safe, I think someone test this on CCR2004 if my memory serves correctly they were able to get 1G speed, you can certainly try this on your environment before going live

Let just hope they will be releasing next gen equipment that supports macsec hardware offload…

https://www.marvell.com/content/dam/marvell/en/public-collateral/phys-transceivers/marvell-phys-transceivers-alaska-c-88x7121p-product-brief-2020-02.pdf
or
https://www.marvell.com/content/dam/marvell/en/company/media-kit/prestera-dx-7300/prestera-7k-press-analyst-deck.pdf
or
https://www.embedded.com/press-releases/marvell-dual-400gbe-macsec-phy-with-class-c-ptp-timestamping/

one at least may dream about those beasts being placed in a MT soon…

hopefully 2025 will change this and MT decides to enable MACsec hw-offload

Slightly off-topic, but where can one purchase Ethernet card/adapters/NIC’s for consumer PC’s? AFAIK MACSec is not open-source and is rare in non-enterprise enivronments.

still no hardware-offload for MACsec :face_with_steam_from_nose:

Any progress on this front? macsec on selected MT hardware?

afraid not...

Now with the upcoming release of the CRS8xx "SERIES", with the initial flagship model being based on the Marvell 98DX7335 ; 802.11AE HARDWARE OFFLOAD is near..
So its now in MT's corner to ensure its can be flicked on in RoS, so I can stop buying Cisco/Juniper's to do L2 macsec from datacenters to sites(MetroEthernet ).

https://www.marvell.com/content/dam/marvell/en/public-collateral/switching/marvell-switching-prestera-98dx73xx-product-brief.pdf

https://www.marvell.com/content/dam/marvell/en/company/media-kit/prestera-dx-7300/prestera-7k-press-analyst-deck.pdf

where did you get that information and infos about the upcoming product lineup?

I have 2 sources of information.
1 is hidden in firmware.
2. CRS812 DDQ: 400 Gigabit networking is now affordable! - TikTube

thanks.
maybe i just did not get the release in time

looking forward to see this switch in action and for reviews

Are there any news about macsec hardware offload?

Not only for 400G switches, also for normal 10G devices?

All the new CRS8xx / CRS6xx(upcoming), switch chips have hardware offloaded MACSEC onboard according to the Spec sheets.