For connections between two data centers, Layer 2 encryption (MACsec) or optical encryption at Layer 1 is the preferred choice. Which method fits best depends on your speed requirements, latency sensitivity, and compliance obligations. The sections below answer the most frequently asked questions about encryption for data center interconnects, so you can make an informed decision.
Which encryption methods are suitable for data center interconnects?
For data center interconnects (DCI), three encryption methods are suitable: Layer 1 (optical encryption), Layer 2 (MACsec), and Layer 3 (IPsec). Each operates at a different level of the OSI model and offers a different balance between performance, latency, and manageability. The right choice depends on the architecture of your connection and your security requirements.
With a data center connection, the goal is to protect data that moves continuously and in large volumes between locations. This places different demands than securing individual user connections. You want minimal latency, high throughput, and security that works transparently for the applications above it.
In practice, organizations with high throughput and low latency requirements often choose Layer 1 or Layer 2 encryption. Layer 3 encryption via IPsec is better suited for WAN connections over the public internet, but introduces more overhead for direct DCI connections.
What is the difference between Layer 1, Layer 2, and Layer 3 encryption?
The difference lies in the level at which encryption takes place within the OSI model. Layer 1 encryption secures the physical data stream at the optical signal itself. Layer 2 encryption (MACsec) operates at the Ethernet frame level. Layer 3 encryption (IPsec) encrypts IP packets. The lower the level, the less overhead and the higher the performance.
- Layer 1: Encryption at the optical signal. No visible impact on latency, fully transparent to higher protocols. Ideal for fiber connections with very high speeds.
- Layer 2 (MACsec): Encryption at the Ethernet frame level. Low latency, high throughput, and suitable for direct connections between switches or routers in a DCI environment.
- Layer 3 (IPsec): Encryption of IP packets. Flexibly deployable over the internet, but introduces more processor load and latency. Less suitable for latency-sensitive data center connections.
For data center interconnects, the rule of thumb is: the closer the encryption is to the physical layer, the more efficiently security operates at high speeds.
When should you choose MACsec over IPsec for DCI connections?
Choose MACsec when your data center connections run directly over dedicated fiber or carrier Ethernet and you need minimal latency. MACsec encrypts at Layer 2, meaning there is no IP overhead. IPsec is better suited when the connection runs over the public internet or when you need encryption at the router level.
MACsec offers line-rate encryption: the security adds virtually no latency, even at speeds of 100 Gbps or higher. This makes it the preferred choice for organizations that combine high availability and low latency with strict security requirements, such as data centers, financial institutions, and healthcare organizations.
IPsec has its value for site-to-site VPN connections over the internet, but for direct DCI connections the additional overhead does not outweigh the benefits. Furthermore, MACsec operates per hop, meaning each network segment is secured individually. This provides more control over security per link.
Want to know which encryption solutions fit your DCI architecture? We help you make the right trade-off based on your specific environment.
How does optical encryption work on fiber connections?
Optical encryption encrypts the data signal directly at the physical fiber level, before it is transmitted as light over the fiber. This is done in dedicated encryption modules placed between the network equipment and the fiber infrastructure. The result is an encrypted signal that is fully transparent to all higher network layers.
Because encryption takes place at Layer 1, this approach has virtually no impact on latency or throughput. Encryption and decryption occur in hardware, not in software, which minimizes processing time. This makes optical encryption particularly suitable for DWDM connections and other high-capacity connections between data centers.
An additional advantage is that optical encryption protects against physical attacks on the fiber cable, such as tapping. Even if someone gains access to the physical fiber, the signal is unreadable without the correct keys. This makes it a strong choice for organizations working with sensitive or business-critical data.
Want to learn more about how fiber security works in practice? Check out our information on real-time fiber monitoring for a complete picture of secure optical connections.
What are the performance implications of encryption at high speeds?
At high speeds — think 100 Gbps or more — software-based encryption can become a significant bottleneck. Hardware-based encryption, such as MACsec or optical encryption, prevents this problem by offloading the encryption to dedicated chips. This keeps latency low and throughput at its maximum, regardless of traffic volume.
Software encryption such as IPsec requires CPU capacity. At high speeds, this means you need to deploy additional computing power or your throughput becomes limited. With modern data center connections at 40, 100, or 400 Gbps, that is not an acceptable situation.
MACsec and Layer 1 encryption operate in dedicated hardware and are designed for line-rate performance. They typically add less than a microsecond of latency, which is negligible for most applications. For latency-sensitive applications such as financial transactions or real-time replication, however, this difference is crucial.
When designing a DCI encryption solution, it is therefore wise to look not only at security strength, but also at hardware-based processing and the impact on your existing infrastructure.
Which encryption standard is mandatory for critical infrastructure in the Netherlands?
In the Netherlands, organizations that belong to critical infrastructure are required to comply with the NIS2 directive, which came into full effect in 2025. This directive stipulates that organizations must take appropriate technical measures to secure their network and information systems, including the use of strong encryption for data communications.
In concrete terms, this means that encryption must at minimum meet the standards of the National Cyber Security Centre (NCSC). The NCSC recommends the use of AES-256 as the minimum standard for symmetric encryption and advises also looking at quantum-resistant algorithms for future-proofing.
For data centers and organizations in sectors such as energy, transport, healthcare, and financial services, encryption of data center connections is not an optional measure, but a requirement. In addition, there is increasing attention to the security of the physical layer, including fiber connections.
We advise organizations in critical sectors to look ahead to quantum-resistant security in addition to current obligations. Quantum computers pose a real long-term threat to current encryption standards, and the transition to post-quantum cryptography requires time and preparation. The sooner you take this into account in your architecture, the better prepared you will be for tomorrow’s requirements.
Want to know how your data center connections score in terms of encryption and compliance? Check out our overview of security solutions or get in touch for a no-obligation conversation.
Ready for the next step?
Explore our solutions or get in touch directly with one of our experts.


