MACsec Encryption on AWS
MACsec line-rate Layer 2 encryption is not available on AWS connections delivered through IZO™+ Multi Cloud Connect.
AWS supports MACsec only on Dedicated Direct Connect and since every IZO™+ Multi Cloud Connect AWS service is a Hosted Connection, so the restriction applies to both delivery paths. Strong Layer 3 alternatives are available.
What MACsec is
MACsec (IEEE 802.1AE) is line-rate Layer 2 encryption between two Ethernet devices on the same physical link, with keys shared at both ends of that link.
Availability on IZO™+ Multi Cloud Connect for AWS
MACsec is not available. This is an AWS-side constraint, not a Tata Communications limitation: AWS supports MACsec only on Dedicated Direct Connect. Both the Tata Communications-managed direct interconnect and the partner-routed path deliver Hosted Connections, so the restriction applies to every IZO™+ Multi Cloud Connect AWS service today.
Why AWS draws the line this way
MACsec is point-to-point encryption between two devices on the same physical link. A Hosted Connection is a logically partitioned slice of a shared interconnect rather than a dedicated physical link to the customer, so the single-link key relationship MACsec depends on isn’t present.
Supported encryption alternatives
|
Pattern |
Where encryption terminates |
Typical use |
|
IPsec overlay to AWS |
Customer CPE ↔ AWS endpoint (Virtual Private Gateway, Transit Gateway, or a customer-managed appliance in a VPC) |
Layer 3 encryption end to end without changing the application |
|
Application-layer (TLS / mTLS) |
The application stack at both ends |
Already in place for HTTPS, gRPC, modern database protocols |
|
Customer-managed encryption appliances |
Customer firewall, SD-WAN device, or hardware encryptor |
Customers with an existing encryption estate; Multi Cloud Connect carries the ciphertext as transit |
For most regulated workloads, an IPsec overlay terminated at a Transit Gateway is the closest functional equivalent to MACsec – Layer 3 rather than Layer 2, but cryptographically strong and widely accepted by auditors where the regulation does not specify Layer 2 explicitly.
When MACsec is a hard requirement
Some compliance regimes specify Layer 2 line-rate encryption and do not accept IPsec or TLS as equivalent. A Dedicated Direct Connect arrangement (which supports MACsec) is a separate engagement outside the IZO™+ Multi Cloud Connect product line – talk to your account team if this is a firm requirement.
Related pages
- BGP Configuration for AWS – MD5 authentication that secures the BGP session itself
- AWS Direct Connect Overview
- Tata Communications-Managed Direct Interconnect