Hacker Timesnew | past | comments | ask | show | jobs | submitlogin

802.1x is a secure login procedure, and then the port is open until link is dropped. There's no encryption or authentication per packet (it would be way too expensive), and if you put a switch between the ont and the modem, when you disconnect the modem, the ont doesn't see the link drop.

Managed switches or software ethernet bridges don't always propigate 802.1x packets, but unmanaged switches don't care.



> There's no encryption or authentication per packet (it would be way too expensive) […]

It is possible to tie together 802.1X and MACsec, and plenty of (Ethernet) chipsets can do MACsec at wire speed, even up to 400G and 800G:

* https://www.arista.com/assets/data/pdf/Datasheets/7800R3_MAC...

* https://www.juniper.net/us/en/solutions/400g-and-800g.html

I don't know the telco space well enough to know if there's a MACsec-equivalent for GPON, but given the 'only' 25G speeds involved I doubt it would be much of a challenge.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: