400-007 · Question #40
You have been tasked with designing a data center interconnect to provide business continuity. You want to encrypt the traffic over the DCI using IEEE 802.1AE MACsec to prevent the deployment of any…
The correct answer is A. EoMPLS E. KVPLS. MACsec (IEEE 802.1AE) operates at Layer 2 and requires the transport technology to preserve the Ethernet frame structure end-to-end; only Layer 2 MPLS-based DCI technologies satisfy this requirement.
Question
You have been tasked with designing a data center interconnect to provide business continuity. You want to encrypt the traffic over the DCI using IEEE 802.1AE MACsec to prevent the deployment of any firewall or IPS. Which two interconnect technologies support MACsec? (Choose two.)
Options
- AEoMPLS
- BMPLS Layer 3 VPN
- CDMVPN
- DGET VPN
- EKVPLS
How the community answered
(35 responses)- A86% (30)
- B3% (1)
- C9% (3)
- D3% (1)
Why each option
MACsec (IEEE 802.1AE) operates at Layer 2 and requires the transport technology to preserve the Ethernet frame structure end-to-end; only Layer 2 MPLS-based DCI technologies satisfy this requirement.
EoMPLS (Ethernet over MPLS) is a Layer 2 pseudowire service that transports native Ethernet frames across an MPLS backbone, preserving the Layer 2 header that MACsec encrypts and allowing end-to-end MACsec without requiring a firewall or IPS in the path.
MPLS Layer 3 VPN operates at the IP layer and strips the original Ethernet headers before forwarding traffic, removing the Layer 2 context that MACsec depends on for encrypting frames between endpoints.
DMVPN is a Layer 3 GRE/IPsec overlay that encapsulates IP packets rather than Ethernet frames, so it does not provide the Layer 2 adjacency required for MACsec to function between DCI endpoints.
GET VPN is a group-based IP encryption technology that protects Layer 3 traffic and does not operate on or preserve Ethernet frames, making it fundamentally incompatible with the IEEE 802.1AE MACsec standard.
KVPLS (VPLS - Virtual Private LAN Service) is a multipoint Layer 2 MPLS technology that emulates an Ethernet LAN segment over an MPLS core, maintaining the Ethernet frame structure end-to-end that MACsec requires to encrypt DCI traffic between data centers.
Concept tested: MACsec support over Layer 2 DCI transport technologies
Source: https://www.cisco.com/c/en/us/td/docs/ios-xml/ios/macsec/configuration/xe-16/macsec-xe-16-book/macsec-overview.html
Topics
Community Discussion
No community discussion yet for this question.