二层安全技术802.1ae简单介绍

引用CISCO DOCUMENTS “Cisco Data Center Interconnect Design and Implementation Guide”中的内容:In 2006 the IEEE ratified the 802.1AE standard, also known as MAC security standard (MACsec). MACsec encrypts all Ethernet frames, irrespective of the upper layer protocol. With MACsec, not only routed IP packets but also IP packets where the source and destination is in the same subnet or even non-IP traffic are encrypted.
我们可以了解到802.1AE是一种二层封装技术,通过封装所有以太网针,从而实现加密的安全效果。

802.1AE not only protects data from being read by others sniffing the link, it assures message integrity. Data tampering is prevented by authenticating relevant portions of the frame. Figure 1-14 shows how a regular Layer 2 frame is encrypted.
802.1AE可以保护数据内容被抓包获取,同时也能保证数据的完整性
格式如下:



其中ICV是Integrity Check Value 的简称,采用32Bytes,主要用于校验

本文出自 “cedric's study” 博客,谢绝转载!

你可能感兴趣的:(职场,休闲,交换,802.1ae)