13.3 Cisco TrustSec (Security Group Tags) and MACsec (802.1AE) Layer 2 Encryption

Key Takeaways

  • Cisco TrustSec delivers software-defined network segmentation by abstracting access policy from IP addresses and network topology using 16-bit Security Group Tags (SGTs).

  • The TrustSec operational lifecycle spans three distinct phases: Classification (assigning SGTs at ingress), Propagation (transporting SGTs across the fabric), and Enforcement (filtering via SGACLs at egress).

  • SGT propagation employs two primary methods: hardware Inline Tagging within the Cisco Meta Data (CMD) frame header or VXLAN-GPO encapsulation, and SGT Exchange Protocol (SXP) over TCP port 64999 across devices that cannot tag inline.

  • Security Group ACLs (SGACLs) enforce permissions at egress switches by referencing a matrix of Source SGT and Destination SGT, drastically minimizing TCAM rule complexity compared to traditional IP ACLs.

  • Media Access Control Security (MACsec / IEEE 802.1AE) provides line-rate hardware encryption on point-to-point Ethernet links, encapsulating payloads with a 16-byte SecTAG and Integrity Check Value (ICV) to protect against eavesdropping, tampering, and replay attacks.

Last updated: October 2026

Cisco TrustSec (Security Group Tags) and MACsec (802.1AE) Layer 2 Encryption

Traditional enterprise network segmentation relies on subnetting, Virtual Local Area Networks (VLANs), and IP-based Access Control Lists (ACLs). As enterprise environments expand to accommodate mobile users, hybrid cloud resources, and dynamic virtual machines, IP-based access controls encounter critical scaling limits. IP addresses represent topological locations rather than organizational roles; when users roam across campus subnets, static IP ACLs become fragile, complex to maintain, and consume excessive Ternary Content Addressable Memory (TCAM) on switch hardware.

Cisco TrustSec resolves these architectural limitations by implementing identity-based, software-defined segmentation. In parallel, point-to-point physical transmission links require cryptographic protection against physical tapping, eavesdropping, and man-in-the-middle attacks. IEEE 802.1AE (MACsec) provides line-rate Layer 2 hardware encryption, securing Ethernet frames as they traverse physical campus trunks and service provider connections.


Cisco TrustSec Architecture and Security Group Tags (SGT)

Cisco TrustSec decouples network security policy from network topology. Rather than filtering traffic based on source and destination IP addresses, TrustSec assigns a 16-bit numeric identifier known as a Security Group Tag (SGT) to traffic as it enters the network. The tag is a 16-bit value; 0 means Unknown, and 65535 is reserved to mean Any. The SGT represents the privilege level, role, or sensitivity of the endpoint (e.g., SGT 4 = Employees, SGT 5 = Contractors, SGT 10 = PCI_Servers).

+-------------------------------------------------------------------------+
|                    TRADITIONAL IP-BASED SEGMENTATION                    |
|  ACL rule count grows exponentially: [Source Subnets] x [Dest Subnets]  |
|  Topology-dependent; high TCAM consumption; breaks when users roam      |
+-------------------------------------------------------------------------+
                                     |
                                     v [Replaced By]
+-------------------------------------------------------------------------+
|                  CISCO TRUSTSEC SOFTWARE-DEFINED POLICY                 |
|  Identity-based matrix: [Source SGT] x [Destination SGT] = SGACL        |
|  Topology-independent; constant TCAM size; mobile user consistency      |
+-------------------------------------------------------------------------+

TrustSec enforces access policy through a three-phase operational lifecycle: Classification, Propagation, and Enforcement.

[INGRESS SWITCH]                   [TRANSIT INFRASTRUCTURE]               [EGRESS SWITCH]
+------------------+              +------------------------+              +------------------+
| 1. CLASSIFICATION|              |     2. PROPAGATION     |              |  3. ENFORCEMENT  |
| Maps endpoint to |              | Transports SGT across  |              | Evaluates SGACL  |
| SGT at ingress:  |              | network infrastructure |              | matrix at egress:|
| - Dynamic: 802.1X|              | - Inline Tagging (CMD) |              | [Src SGT] x      |
| - Static: IP/VLAN|              | - SXP (TCP 64999)      |              | [Dst SGT]        |
+------------------+              +------------------------+              +------------------+
         |                                    |                                    |
         v                                    v                                    v
 [SGT Assigned: 5] ───────> [Frame Carries SGT: 5] ───────> [Target SGT: 10 -> DENY]

The Three Phases of Cisco TrustSec

Phase 1: Classification (Ingress)

Classification is the process of binding an incoming packet to an SGT as it enters the TrustSec domain. Classification occurs at the ingress access switch through two methods:

  1. Dynamic Classification: Occurs during endpoint network admission via IEEE 802.1X, MAC Authentication Bypass (MAB), or Central Web Authentication (CWA). When the endpoint successfully authenticates, Cisco ISE evaluates its authorization policy and returns an assigned SGT within a RADIUS Cisco AV-Pair attribute (cisco-av-pair = cts:security-group-tag=XXXX). The access switch caches this IP-to-SGT binding in its local forwarding tables.
  2. Static Classification: Used for infrastructure nodes that do not authenticate via 802.1X, such as data center servers, default gateways, and network management platforms. Administrators configure static mappings on Cisco ISE or locally on the switch:
    • IP-to-SGT Mapping: Directly associates a specific host IPv4/IPv6 address or subnet prefix with an SGT (cts role-based ip-to-sgt <ip-address> <sgt-tag>).
    • VLAN-to-SGT Mapping: Assigns a uniform SGT to all endpoints residing within a specific Layer 2 broadcast domain.
    • Port-to-SGT Mapping: Binds all traffic entering a physical switch port to a designated SGT, commonly applied to dedicated server farm uplinks.

Phase 2: Propagation (Transport)

Once a packet is classified, its SGT must be transported across the intermediate network infrastructure to the egress switch where policy enforcement occurs. Two primary propagation mechanisms exist:

1. Inline Tagging (Hardware-Based)

Inline tagging embeds the SGT directly into the data frame at the physical switching layer:

  • Cisco Meta Data (CMD): On TrustSec-capable Ethernet links, the switch inserts a Cisco Meta Data (CMD) field, identified by EtherType 0x8909, after the source MAC address; the CMD carries the 16-bit SGT. The link can also protect the tagged frames with MACsec.
  • VXLAN-GPO: In Cisco Software-Defined Access (SD-Access) fabrics, the SGT is carried inside the 16-bit Group Policy ID field of the Virtual Extensible LAN Group Policy Option (VXLAN-GPO) header, eliminating proprietary Layer 2 encapsulation.
  • Requirement: Inline tagging executes at line rate within switch hardware Application-Specific Integrated Circuits (ASICs). Every intermediate switch in the forwarding path must support inline tagging to parse, preserve, and rewrite the CMD field.

2. SGT Exchange Protocol (SXP)

When enterprise transit networks contain legacy switches, third-party routers, or WAN circuits that lack hardware support for inline tagging, the network uses SGT Exchange Protocol (SXP):

  • SXP is a Cisco control-plane peering protocol, published to the IETF as an informational draft rather than an RFC. It runs over TCP port 64999 and uses MD5 for authentication and integrity checks.
  • SXP peers exchange IP-to-SGT binding databases across routed IP boundaries. When an endpoint connects to an ingress switch, the switch advertises the endpoint's IP address and assigned SGT to its SXP peers (or to Cisco ISE acting as a central SXP reflector).
  • SXP operates across three functional peering roles:
    • SXP Speaker: Transmits local IP-to-SGT binding records to remote peers.
    • SXP Listener: Receives IP-to-SGT bindings and installs them into local hardware forwarding tables.
    • SXP Bi-directional (Both): Concurrently originates and receives binding records.

Inline Tagging vs. SGT Exchange Protocol (SXP)

Technical AttributeInline Tagging (CMD / VXLAN-GPO)SGT Exchange Protocol (SXP)
MechanismData plane frame header encapsulationControl plane TCP peering (Port 64999)
Header ModificationInserts CMD (0x8909) or VXLAN-GPO headerNo data plane packet modification
Hardware DependencyMandatory ASIC support on all transit switchesStandard IP routing; supported on legacy switches
Scale CharacteristicsUnlimited data plane scale; zero peer stateDependent on switch CPU and memory binding tables
Deployment DomainModern campus fabrics (Catalyst 9000, SD-Access)Multi-vendor backbones, legacy WANs, firewalls

Phase 3: Enforcement (Egress)

Policy enforcement occurs at the egress switch—the network access device directly connected to the destination resource:

Core Design Principle (Egress Enforcement): Enforcement must execute at the egress switch rather than the ingress switch. While the ingress switch knows the Source SGT of the transmitting endpoint, it does not know the Destination SGT of the target server until the packet traverses the network and reaches the egress switch, which holds the destination IP-to-SGT mapping.

When the egress switch receives a packet, it determines:

  1. The Source SGT (Src-SGT) carried within the inline CMD header or learned via SXP.
  2. The Destination SGT (Dst-SGT) derived from its local IP-to-SGT forwarding table for the destination IP.
  3. It references its Security Group ACL (SGACL) matrix downloaded from Cisco ISE. The matrix defines permitted protocols between roles (e.g., Permit TCP 443, Deny IP Any). Because permissions are evaluated per role rather than per IP address, SGACL rules remain concise, static, and fit comfortably within switch hardware TCAM.

TrustSec Three-Phase Operational Lifecycle

Lifecycle PhasePrimary LocationCore TechnologiesPrimary Operational Output
1. ClassificationIngress Switch (Port of Entry)802.1X, MAB, CWA, Static IP/VLAN/Port mappingAssigns 16-bit numeric SGT to the endpoint session
2. PropagationTransit Network InfrastructureInline CMD Tagging (EtherType 0x8909), VXLAN-GPO, SXP (TCP 64999)Transports Source SGT to the remote egress network device
3. EnforcementEgress Switch (Destination Port)SGACL Matrix ([Src SGT] x [Dst SGT]), Egress TCAMFilters data packets based on role-to-role access rules

Media Access Control Security (MACsec / IEEE 802.1AE)

While Cisco TrustSec governs role-based authorization, it does not encrypt payload data across physical circuits. An attacker with physical access to network cabling, patch panels, or optical fibers can tap connections to capture sensitive data, alter frame contents, or inject unauthorized packets. IEEE 802.1AE (MACsec) delivers line-rate, point-to-point hardware encryption directly at the Layer 2 Ethernet link layer.

Standard 802.3 Frame:
+---------------+---------------+----------+---------------------------------+-------+
| Dest MAC (6B) | Src MAC (6B)  | 802.1Q   | User Payload (IPv4/IPv6 Data)   | FCS   |
+---------------+---------------+----------+---------------------------------+-------+

MACsec (802.1AE) Encapsulated Frame:
+---------------+---------------+----------+-------------------------+-------+-------+
| Dest MAC (6B) | Src MAC (6B)  | SecTAG   | ENCRYPTED USER PAYLOAD  | ICV   | FCS   |
| (Cleartext)   | (Cleartext)   | (16B)    | (AES-GCM-128 / 256)     | (16B) | (4B)  |
+---------------+---------------+----------+-------------------------+-------+-------+
                                |                                    |
                                +---> Authenticated Data Range <-----+

MACsec Operational Characteristics

  • Line-Rate Hardware Encryption: MACsec is implemented directly inside switch PHY or MAC ASICs. It encrypts and decrypts frames at line rate (1 Gbps, 10 Gbps, 40 Gbps, 100 Gbps, and 400 Gbps) with sub-microsecond latency, unlike CPU-intensive Layer 3 IPsec VPNs.
  • Full Layer 2 Payload Protection: MACsec encrypts the entire Layer 2 payload, including internal 802.1Q VLAN tags, MPLS labels, IPv4/IPv6 headers, TCP/UDP ports, and application data. Only the outermost source and destination MAC addresses remain unencrypted to permit frame delivery by intermediate physical repeaters.
  • Cryptographic Guarantees:
    • Confidentiality: Uses Advanced Encryption Standard in Galois/Counter Mode (AES-GCM) with 128-bit or 256-bit cryptographic keys.
    • Integrity Validation: An appended 16-byte Integrity Check Value (ICV) detects unauthorized frame alteration.
    • Anti-Replay Protection: A sequential 32-bit (or extended 64-bit) Packet Number (PN) field neutralizes replay attacks. Frames arriving with duplicated or out-of-window packet numbers are immediately dropped.

MACsec Frame Header Structure

A MACsec frame inserts a 16-byte Security Tag (SecTAG) immediately after the source MAC address:

SecTAG FieldSizeFunctional Description
MACsec EtherType2 BytesFixed value 0x88E5, identifying the frame as IEEE 802.1AE
TCI / AN1 ByteTag Control Information and Association Number (identifies active cryptographic key)
Short Length (SL)1 ByteIndicates payload length if user data is under 48 bytes; set to 0 for standard frames
Packet Number (PN)4 BytesMonotonically incrementing 32-bit counter providing replay attack protection
SCI8 BytesSecure Channel Identifier; concatenates transmitting MAC address with a 2-byte Port ID
ICV (appended after the payload, not part of the SecTAG)16 BytesProvides cryptographic message authentication across the frame

MACsec Key Management and Deployment Scenarios

MACsec encryption requires dynamic cryptographic key negotiation between link peers.

Key Management Protocols: MKA vs. SAP

  1. MACsec Key Agreement (MKA / IEEE 802.1X-2010): Modern industry-standard key exchange protocol. MKA uses 802.1X Extensible Authentication Protocol (such as EAP-TLS) to authenticate endpoints and derive a Master Session Key (MSK), or uses a pre-shared Connectivity Association Key (CAK) paired with a Connectivity Association Key Name (CKN). MKA dynamically negotiates ephemeral Security Association Keys (SAKs) and performs hitless key rollover before the 32-bit packet number counter rolls over, preventing replay protection exhaustion.
  2. Security Association Protocol (SAP): Cisco proprietary legacy key management protocol historically used on early Catalyst platforms; largely superseded by MKA.

MACsec Deployment Topologies

  • Switch-to-Switch (Uplink) MACsec: Secures inter-switch trunks connecting campus access, distribution, and core switches, or across dark fiber and metro-Ethernet provider circuits connecting regional buildings. It protects enterprise transit infrastructure against man-in-the-middle interception.
  • Host-to-Switch (Downlink) MACsec: Secures the access link between an individual workstation running Cisco Secure Client and the physical access switch port. It protects the final physical network hop against rogue hardware wiretaps and rogue packet sniffers plugged into physical office cubicle jacks.
Test Your Knowledge

At which operational point in the Cisco TrustSec architecture are Security Group Access Control Lists (SGACLs) evaluated and enforced, and what is the technical reason for this design?

A

At the egress switch, because the destination SGT is known only at the device connected to the destination host

B

At the ingress switch, because the switch immediately drops unauthorized packets before they consume transit backbone bandwidth

C

At the core distribution switch, because centralized routing tables hold all Global SGT mapping rules

D

At the Cisco ISE policy server, because hardware switches lack the memory capacity to store and apply dynamic SGACL matrices

Test Your Knowledge

An enterprise is deploying Cisco TrustSec across a multi-site campus where several intermediate distribution routers lack hardware ASIC support for inline frame tagging (CMD EtherType 0x8909). Which protocol enables the propagation of IP-to-SGT bindings across these legacy Layer 3 hops?

A

Border Gateway Protocol with EVPN address families (RFC 7432)

B

SGT Exchange Protocol (SXP) communicating over TCP port 64999

C

Generic Routing Encapsulation (GRE) with IPsec transport mode

D

Precision Time Protocol (PTP) operating over UDP port 319

Test Your Knowledge

Which field within the 16-byte MACsec (IEEE 802.1AE) Security Tag (SecTAG) increments monotonically with every transmitted frame to provide hardware anti-replay protection?

A

Association Number (AN)

B

Short Length (SL)

C

Packet Number (PN)

D

Integrity Check Value (ICV)

Sections you finish are checked off in the contents.