Configuration Guide for Cisco NCS 1004, IOS XR Release 25.x.x

PDF

Configuration Guide for Cisco NCS 1004, IOS XR Release 25.x.x

Layer 1 Encryption

Details the implementation of Layer 1 encryption using OTNSec and IKEv2 on Cisco NCS 1004 platforms. This chapter guides users through configuring authentication methods, managing security associations, ensuring FIPS compliance, and troubleshooting common session issues to secure client traffic across fiber-optic networks.


Note

In this chapter, "layer 1 encryption" is referred to as "OTNSec".

Table 1. Feature History

Feature Name

Release Information

Feature Description

Encryption Support on 1.2TL Card

Cisco IOS XR Release 7.3.1

AES 256 GCM authenticated OTNSec encryption on 1.2TL line cards is supported. It uses only pre-shared keys for authentication. Optical encryption secures the communications link in and out of a facility, rendering all data undecipherable to hackers who tap into networks.

Encryption Support on OTN-XP Card

Cisco IOS XR Release 7.8.1

AES 256-GCM authenticated OTNSec encryption is supported on the OTN-XP card. The encryption is enabled on the ODUC4 controller.

This encryption secures the data across different datapaths of the OTN-XP card.

Encryption for 10G clients and 100GE clients on OTN-XP Card

Cisco IOS XR Release 7.9.1

OTN-XP card now supports AES 256-GCM authenticated OTNSec encryption for 10G and 100GE clients in the 40x10G-4x100G-MXP mode. As this authentication method uses a key size of 256 bits, it provides considerably strong cryp­togra­phy acceptable by enterprise, and public sector organizations.