Data traffic between two data centers is vulnerable. The connection bridges physical distance, often passes through shared infrastructure, and thereby forms an attractive target for eavesdropping, manipulation, or interception. Yet data center interconnect security is regularly underestimated in practice, especially when the connection runs through a trusted provider.
In this guide, you will walk through step by step how to secure data traffic between two data centers: from mapping your risk profile to active key management in production. Each step builds on the previous one, so that by the end you have a robust, layered security setup that will stand the test of time.
Map the risk profile of your data center connection
Before you configure encryption or choose security solutions, you need to understand exactly what you are protecting and against which threats. A data center interconnect (DCI) connection that exclusively transports internal backup data requires a different approach than a connection that transmits real-time patient data or financial transactions.
Ask yourself the following questions and record the answers:
- What data classifications are transported over the connection? Think of confidential, business-critical, or personal data (GDPR-relevant).
- What is the nature of the connection? Dedicated dark fiber, a leased wavelength circuit, or a shared carrier Ethernet network?
- What compliance requirements apply? Think of NIS2, ISO 27001, or sector-specific standards such as NEN 7510 in healthcare.
- Who has physical access to the transmission infrastructure between the two locations?
- What is the impact of a data breach or connection interruption on your business operations?
This risk profile forms the basis for all choices that follow. Without this overview, you risk over- or under-securing. Verify at the end of this step that you have a documented overview of data types, connection characteristics, and compliance obligations.
Choose the right encryption level for your connection
With your risk profile in hand, you choose the encryption level that matches the sensitivity of your data and the nature of your connection. For data center security of sensitive data, there are two primary layers at which you can apply encryption: layer 1 (physical/optical) and layer 2 (data link).
Layer 1 encryption
Optical encryption at layer 1 encrypts the full optical signal, including overhead and protocol information. This offers maximum protection with minimal latency, often less than a microsecond of additional delay. It is the preferred choice for connections that transport extremely sensitive data or for which strict latency requirements apply, such as financial trading systems or real-time operational technology.
Layer 2 encryption
Layer 2 encryption operates at the level of Ethernet frames and is applicable to carrier Ethernet and MPLS connections. It offers strong security with good interoperability and is suitable for most enterprise DCI scenarios. Standards such as MACsec (IEEE 802.1AE) are widely supported and provide hardware-accelerated encryption with minimal impact on throughput.
Choose layer 1 if you are working with dedicated fiber and require the highest confidentiality. Choose layer 2 if you are working with carrier Ethernet or if interoperability with existing infrastructure is a requirement. Record your choice, including the rationale based on your risk profile.
Configure encryption on the data center connection
Now that you know which encryption level to apply, you proceed to the actual configuration. The exact steps differ per platform, but the underlying process is consistent.
- Generate or import cryptographic keys via a certified key management system. Use at least AES-256 for symmetric encryption.
- Configure the encryption equipment on both sides of the connection with identical parameters: algorithm, key length, and session parameters.
- Set up automatic key rotation based on time or data volume, depending on your security policy.
- Activate encryption first in a test environment or on a non-production connection to validate its operation.
- Verify that encryption is active by checking the connection status at both endpoints and confirming that traffic is actually being sent encrypted.
Note that encryption on both sides must match exactly in configuration. A mismatch in algorithm or key parameters results in a connection error or, worse, a fallback to unencrypted traffic. After configuration, explicitly verify that the connection is actively encrypted and does not silently fall back to an unsecured mode.
Secure the management channel separately from the data path
A common mistake is managing security equipment via the same network you are securing. If an attacker gains access to the data path, they also gain access to your management access. Separation of the management channel is therefore not a luxury, but a requirement.
Implement an out-of-band management environment (OoBM) for managing your DCI security equipment:
- Set up a separate, physically or logically isolated management network that is independent of the production data path.
- Restrict access to the management channel via strong authentication, preferably multi-factor authentication combined with role-based access control.
- Also encrypt the management traffic itself, at minimum via SSH or TLS with strong cipher suites.
- Log all management sessions centrally and retain logs at minimum in accordance with your retention policy and compliance requirements.
With an out-of-band management solution, you retain access to your equipment even when the production path is disrupted. This is crucial for incident response: you do not want a security incident to simultaneously disable your management capability.
Validate security before taking the connection into production
Encryption that is configured but not validated gives a false sense of security. Before taking the secured DCI connection into production, perform a structured validation.
- Perform a traffic analysis on the connection using a network tap or SPAN port. Verify that the traffic is actually encrypted and not readable in plaintext.
- Test key rotation by performing a planned key rotation and confirming that the connection continues without interruption.
- Simulate a failover: temporarily shut down one endpoint and verify how the connection and security recover.
- Check that management traffic remains strictly separated from the data path during all test scenarios.
- Document the test results and record which configuration is approved for production.
After successful validation, you have a documented baseline: the configuration, key parameters, and test results that serve as a reference for future audits and incident investigations. Store this documentation securely and accessible to your security team.
Maintain security with monitoring and key management
Security is not a one-time action. A secured DCI connection that is not actively monitored can become vulnerable unnoticed due to outdated keys, configuration drift, or new threats. Structural management is the final, but perhaps the most underestimated, step.
Establish the following management practices as recurring processes:
- Key management: Automate key rotation where possible. Set alerts when keys are approaching their maximum lifetime. Manage keys from a central, secured environment.
- Continuous monitoring: Use monitoring and network management to monitor encryption status, connection quality, and anomalous traffic behavior in real time.
- Firmware and patches: Keep encryption equipment up to date. Vulnerabilities in cryptographic implementations are actively exploited.
- Periodic audits: Conduct a security review of the DCI configuration at least annually, including verification that the encryption settings still align with your current risk profile.
- Quantum resilience: Take into account the rise of quantum computing. Protection against quantum threats is a topic that already deserves attention when choosing algorithms and infrastructure for the long term.
With active monitoring and structured key management, your data center interconnect security stays aligned with the threats of today and tomorrow. Want to know which encryption and monitoring solutions best fit your specific DCI environment? We are happy to think along with you, from risk assessment to implementation.


