Skip to content

Commit a8bd7b3

Browse files
authored
Merge pull request #113923 from charwen/patch-201
Update FAQ
2 parents 98b418b + 87b22b0 commit a8bd7b3

File tree

1 file changed

+3
-3
lines changed

1 file changed

+3
-3
lines changed

articles/expressroute/expressroute-about-encryption.md

Lines changed: 3 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -6,7 +6,7 @@ author: cherylmc
66

77
ms.service: expressroute
88
ms.topic: conceptual
9-
ms.date: 12/13/2019
9+
ms.date: 05/05/2020
1010
ms.author: cherylmc
1111

1212
---
@@ -26,8 +26,8 @@ Yes. For the MACsec configuration, we support the pre-shared key mode only. It m
2626
No. If MACsec is configured and a key mismatch occurs, you lose connectivity to Microsoft. In other words, we won't fall back to an unencrypted connection, exposing your data.
2727
### Will enabling MACsec on ExpressRoute Direct degrade network performance?
2828
MACsec encryption and decryption occurs in hardware on the routers we use. There's no performance impact on our side. However, you should check with the network vendor for the devices you use and see if MACsec has any performance implication.
29-
### which cipher suites are supported for encryption?
30-
We support AES128 and AES256.
29+
### Which cipher suites are supported for encryption?
30+
We support the [Extended Packet Numbering](https://1.ieee802.org/security/802-1aebw/) version of AES128 and AES256 only. In addition, please disable [Secure Channel Identifier(SCI)](https://en.wikipedia.org/wiki/IEEE_802.1AE) in MACsec configuration on your device.
3131

3232
## End-to-end encryption by IPsec FAQ
3333
IPsec is an [IETF standard](https://tools.ietf.org/html/rfc6071). It encrypts data at the Internet Protocol (IP) level or Network Layer 3. You can use IPsec to encrypt an end-to-end connection between your on-premises network and your virtual network (VNET) on Azure. See other FAQs below.

0 commit comments

Comments
 (0)