Explains how Cisco NCS 1004 uses AES256-based OTNSec encryption to protect 100GE client traffic, and covers prerequisites, IKEv2 protocol, certificate-based authentication, FIPS compliance, configuration tasks, verification, and troubleshooting.
A Cisco NCS 1004 OTNSec encryption mechanism is a data security solution that
-
uses AES256-based OTNSec encryption to secure 100GE and OTU4 client traffic,
-
negotiates secure sessions and device authentication through the IKEv2 protocol and certificate-based authentication, and
-
enables flexible configuration for multiple controller modes and includes features for verification and troubleshooting.
Encryption is supported on the 1.2T and 1.2TL cards.
From Release 7.8.1, layer 1 encryption is supported on the OTN-XP card. For OTN-XP card, different LC modes have different client-side controllers. Hence, encryption has to be enabled under the common ODUCn controller. In release 7.8.1, the OTNSec encryption is enabled under the ODUC4 controller for the following modes with a trunk rate of 400G and with CFP2 DCO Greylock 2 pluggable:
4x100G-MXP of 4x100G-MX-400G-TXP LC mode
FC-MXP mode
From Release 7.91, in addition to 10G client support, the 40x10G-4x100G-MXP LC Mode in OTN-XP cards enables encryption on ODUC1, ODUC2, ODUC3, and ODUC4 controllers for trunk rates from 100G to 400G.
This encryption provides more flexibility across different LC modes and datapaths of the OTN-XP card.
OTNSec encryption uses the IKEv2 protocol to negotiate and establish the IKEv2 and OTNSec Security Associations (SA). IKEv2 is used for authentication of the devices in an encryption session, and the protocol provides pre-shared keys (PSK) or RSA certificate-based authentication. The IKEv2 datagrams are carried as payloads using the point-to-point protocol (PPP) over the GCC channel.
To implement this, an IKE session is established between the two endpoints, Site A and Site B, for overhead control plane communication between the two data centers. Data is then encrypted at Site A using OTNSec encryption and decrypted at Site B.
The recommended deployment is to have a single IKEv2 session running over a GCC2 channel per trunk port which creates the child SAs for each of the OTNSec controllers that are configured on the trunk port.
High-speed encryption requirement:
While most focus is on protecting data within data centers, connecting network infrastructure is equally vulnerable to attacks. As more sensitive information travels across fiber-optic networks, cybercriminals increasingly target in-transit data. For cloud operators, encrypting data leaving data centers is vital. Optical encryption secures all communication over the fiber link, making intercepted data unreadable. Protecting data at line rates is an essential requirement for modern data centers.
OTNSec site-to-site operation:
In a site-to-site OTNSec configuration, an IKE session is established between two sites to negotiate encryption parameters and Security Associations. All client data is encrypted at one site and decrypted at the other. Recommended deployment is a single IKEv2 session over a GCC2 channel per trunk port, generating child SAs for each OTNSec controller.