Jaime

Latest posts — page 16

MACsec Explained: 802.1AE Link Encryption

Almost every security control on a network protects traffic at Layer 3 and above. IPsec encrypts IP payloads, TLS encrypts sessions, and VPNs tunnel across untrusted networks. But all of them assume the Layer 2 link underneath is just a

Unicast RPF: Strict vs Loose Mode

Source IP addresses are trivially forged. Nothing in the IP header proves the source is who it claims to be, and a packet with a lie in the source field is the raw material for reflection attacks, spoofed floods, and