2026-11-04 –, Room 1 Language: English
Corporate networks are increasingly facing internal threats as well. As a result, there is a growing demand for the encryption of all packets transmitted between switches or between end devices and switches instead of only authentication at the beginning of a session. MACsec defined in 802.1AE can offer a solution in this area. Manufacturers are now increasingly offering MACsec-compatible components and since version 4.6, Wireshark has also provided advanced analysis functions through a specialised form of decryption.
MACsec was defined in 2006, but its prevalence has only been rising in recent years. It can provide Hop-by-Hop Encryption in Line-Rate between Switches or between Hosts and Switches. So analysts are looking for ways to analyze it.
We will provide an overview about MACsec and its use cases before we dive in to frame structure, key distribution concepts in conjunction with their decryption possibilities in Wireshark. We will go over some example captures and take a look how to analyze them.
- Head of Networking and Telecommunication at City of Kassel
- Author for several IT-Magazines (Heise, iX, IT-Administrator)
- VoIP and Network Consultant
- Freelance Trainer
- System Administrator for Telecommunication and Networking at City of Kassel
- Service Technician at Deutsche Telekom