Using tagged or untagged VXCs
MACsec-encrypted traffic can be carried transparently over untagged VXCs, or over tagged VXCs when the VLAN is not encrypted.Some equipment does not support unencrypted VLANs. Check whether the equipment you use supports unencrypted VLANs, also known as clear tag mode, before using MACsec-encrypted traffic over tagged VXCs.
Most Cloud Service Providers (CSP) support MACsec from 10 Gbps or above (10 Gbps or 100 Gbps). Check with your Cloud Service Provider. Megaport supports both 10 Gbps and 100 Gbps options.
Creating a customer-to-customer encrypted connection
You can use a MACsec connection between two of your own devices using Megaport services. Prerequisites To create a MACsec-encrypted link between two of your own devices, you need:- MACsec capable customer equipment, for example, a switch or router, at each end.
- Two Megaport Ports.
- One in a location where you can create a physical cross connect to your first MACsec capable device.
- One in a location where you can create a physical cross connect to your second MACsec capable device.
- From your first MACsec capable device, create a physical link to the first Port.
- From your second MACsec capable device, create a physical link to the second Port
- Create an untagged VXC to connect your first Port to your second Port. For more information, see Using tagged or untagged VXCs.
- Configure MACsec on your devices, on the interfaces connected to Megaport.
Creating a customer-to-cloud encrypted connection
You can use a MACsec connection between your device and a CSP using Megaport services. Prerequisites To create a MACsec-encrypted link from customer to cloud, you need:- MACsec capable customer equipment, for example, a switch or router.
- Two Megaport Ports.
- One in a location where you can create a physical cross connect to your MACsec capable router.
- One in a location where you can create a physical cross connect to the cloud onramp.
- A dedicated connection service from your cloud provider. For example, AWS Dedicated Direct Connect, or ExpressRoute Direct.
- From your MACsec capable device, create a physical cross connect to the first Megaport Port.
- Create a physical link from the second Port to the CSP onramp, which is ExpressRoute in this case. You will need to contact your Megaport account team for this step.
- Create an untagged VXC to connect your first Port to your second Port. For more information, see Using tagged or untagged VXCs.
- Configure MACsec on the CSP service and on your device.
Creating a cloud-to-cloud encrypted connection
You can use a MACsec connection between cloud providers using Megaport services. Prerequisites Before creating a MACsec-encrypted link from cloud to cloud, you need:- Dedicated connection services from your cloud providers. For example, AWS Direct Connect or ExpressRoute Direct.
- Two Megaport Ports.
- One in a location where you can create a physical cross connect to your first cloud connection.
- One in a location where you can create a physical cross connect to your second cloud connection.
- Create a physical connection from your dedicated AWS Direct Connect to your first Megaport Port. You will need to contact your Megaport account team for this step.
- Create a physical connection from your second Megaport Port to your Azure ExpressRoute Direct. You will need to contact your Megaport account team for this step.
-
Create a tagged or untagged VXC to connect your Ports.
For more information, see Using tagged or untagged VXCs.