<img height="1" width="1" style="display:none" src="https://www.facebook.com/tr?id=1705902170274878&amp;ev=PageView&amp;noscript=1">
Skip to content
  • There are no suggestions because the search field is empty.

MACsec Encryption on AWS

MACsec line-rate Layer 2 encryption is not available on AWS connections delivered through IZO™+ Multi Cloud Connect.
AWS supports MACsec only on Dedicated Direct Connect and since every IZO™+ Multi Cloud Connect AWS service is a Hosted Connection, so the restriction applies to both delivery paths. Strong Layer 3 alternatives are available.  

What MACsec is

MACsec (IEEE 802.1AE) is line-rate Layer 2 encryption between two Ethernet devices on the same physical link, with keys shared at both ends of that link.

Availability on IZO™+ Multi Cloud Connect for AWS

MACsec is not available. This is an AWS-side constraint, not a Tata Communications limitation: AWS supports MACsec only on Dedicated Direct Connect. Both the Tata Communications-managed direct interconnect and the partner-routed path deliver Hosted Connections, so the restriction applies to every IZO™+ Multi Cloud Connect AWS service today.

Why AWS draws the line this way

MACsec is point-to-point encryption between two devices on the same physical link. A Hosted Connection is a logically partitioned slice of a shared interconnect rather than a dedicated physical link to the customer, so the single-link key relationship MACsec depends on isn’t present.

Supported encryption alternatives  

Pattern

Where encryption terminates

Typical use

IPsec overlay to AWS

Customer CPE ↔ AWS endpoint (Virtual Private Gateway, Transit Gateway, or a customer-managed appliance in a VPC)

Layer 3 encryption end to end without changing the application

Application-layer (TLS / mTLS)

The application stack at both ends

Already in place for HTTPS, gRPC, modern database protocols

Customer-managed encryption appliances

Customer firewall, SD-WAN device, or hardware encryptor

Customers with an existing encryption estate; Multi Cloud Connect carries the ciphertext as transit

For most regulated workloads, an IPsec overlay terminated at a Transit Gateway is the closest functional equivalent to MACsec – Layer 3 rather than Layer 2, but cryptographically strong and widely accepted by auditors where the regulation does not specify Layer 2 explicitly.

When MACsec is a hard requirement

Some compliance regimes specify Layer 2 line-rate encryption and do not accept IPsec or TLS as equivalent. A Dedicated Direct Connect arrangement (which supports MACsec) is a separate engagement outside the IZO™+ Multi Cloud Connect product line – talk to your account team if this is a firm requirement.

Related pages