Configuration Guide for Cisco NCS 1014, IOS XR Releases 26.x.x

PDF

OTNSec Encryption on the NCS1K14-2.4T-K9, NCS1K14-2.4T-X-K9, and NCS1K14-2.4T-A-K9 cards

Provides an overview of how OTNSec encryption operates on the NCS1K14-2.4T-K9 card, including key implementation features and supported workflows.


The 2.4T, 2.4TX, and 2.4TA line card now supports AES-256 GCM authenticated OTNSec encryption using pre-shared keys or certificate-based authentication, ensuring data confidentiality across optical links.

Table 1. Feature History

Feature Name

Release Information

Feature Description

OTNSec encryption support on the 2.4TX and 2.4TA line card

Cisco IOS XR Release 26.1.1

The 2.4TX and 2.4TA line card now supports AES-256 GCM authenticated OTNSec encryption using pre-shared keys or certificate-based authentication, ensuring data confidentiality across optical links.

These pluggable modules are supported:
  • CIM8-CE-K9

  • CIM8-LE-K9

  • CIM8-C-K9

Additionally, PPP over GCC enables secure transmission of control and encryption messages such as IKEv2 exchanges over built-in optical channels, enhancing security and manageability without relying on external interfaces.

OTNSec encryption and PPP support on the 2.4T card

Cisco IOS XR Release 25.2.1

The 2.4T line card now supports AES-256 GCM authenticated OTNSec encryption using pre-shared keys or certificate-based authentication, ensuring data confidentiality across optical links.

Additionally, PPP over GCC enables secure transmission of control and encryption messages such as IKEv2 exchanges over built-in optical channels, enhancing security and manageability without relying on external interfaces.

Note

The NCS1K14-2.4T-X-K9 and NCS1K14-2.4T-A-K9 line cards support Encryption only in slice mode.