Overview
Describes how MACsec encryption on Layer 3 subinterfaces allows for independent encryption control and policy application per VLAN, while retaining unencrypted VLAN tags for proper traffic switching.
MACsec encryption on Layer 3 subinterfaces is a security mechanism that
-
allows encryption and authentication of network data on VLAN-based Layer 3 subinterfaces,
-
enables the application of multiple MACsec policies across different L3 subinterfaces under a single physical interface by retaining VLAN tags in clear text, and
-
provides an additional security layer for communication between separate VLANs or subnets on the same physical link by making each L3 subinterface a distinct MACsec endpoint.
MACsec on Layer 3 subinterfaces uses VLAN encapsulations—802.1Q (single-tag) or 802.1ad (double-tag)—and requires specific VLAN identifiers. Keeping VLAN tags visible enables MACsec endpoints to identify subinterface traffic without encrypting the VLAN metadata. This setup allows traffic segregation at the MACsec level because each VLAN-associated subinterface has independent encryption control.
This flexibility allows for the application of different MACsec policies to Layer 3 subinterfaces under the same physical interface. By retaining unencrypted VLAN tags, Layer 3 subinterfaces can act as MACsec endpoints. Applying MACsec policies to these subinterfaces enhances network security by adding an extra layer of protection for communications between distinct subnets.
MACsec on Layer 3 subinterfaces operates similarly to that on a physical interface. For a MACsec Key Agreement (MKA) session to succeed on any Layer 3 subinterface, an appropriate tagging protocol encapsulation and a specified VLAN identifier are necessary. Although all Layer 3 subinterfaces default to 802.1Q VLAN encapsulation, the VLAN identifier must be explicitly set.
Hardware support matrix for MACsec on Layer 3 subinterfaces
| Cisco IOS XR Software Release |
Product ID |
|---|---|
| Release 25.3.1 |
8711-32FH-M |
| Release 25.1.1 |
8712-MOD-M |
| Release 24.4.1 |
8608 88-LC1-36EH 88-LC1-12TH24FH-E 88-LC1-52Y8H-EM 8212-48FH-M 8711-32FH-M |
| Release 24.3.1 |
88-LC1-52Y8H-EM |
| Release 7.11.1 |
8202-32FH-M |
| 88-LC0-36FH-M |