1RU 32-port 100G leaf switch with wire-speed MACsec encryption on every QSFP port at 800 ns latency for secure data center and interconnect deployments.
The Arista 7050X3 MACsec Series combines the 100G leaf switching density of the standard 7050X3 platform with hardware IEEE 802.1AE MACsec encryption on every QSFP28 100G port, operating at the full 6.4 Tbps line rate without any throughput reduction. Three 1RU models are available: the 7050CX3M-32S (32x QSFP28 100G + 2x SFP+), 7050SX3-48YC8 (48x SFP28 25G + 8x QSFP28 100G), and 7050TX3-48C8 (48x RJ45 10GBase-T + 8x QSFP28 100G), providing MACsec across optical 100G, 25G server-facing, and copper 10GBase-T configurations in a single switch family.
Encryption key management follows the IEEE 802.1X MACsec Key Agreement (MKA) protocol, enabling automated per-session key rotation without manual key provisioning or external key management infrastructure. Both AES-128-GCM and AES-256-GCM cipher suites are supported. Deployment scenarios include encrypted leaf-to-spine uplinks in regulated data centres (PCI DSS, HIPAA), encrypted campus aggregation links where traffic traverses untrusted physical plant, and encrypted DCI paths where the dark-fibre or carrier Ethernet route is not under the operator's physical control.
IEEE 802.1AE hardware MACsec encrypts every 100G QSFP28 port, as well as every 25G SFP28 or 10G RJ45 port depending on model, at the full 6.4 Tbps forwarding rate. No throughput ceiling applies when encryption is enabled, so deploying MACsec does not require overprovisioning port counts to recover lost capacity as would be the case with software-based or external encryption appliances.
MACsec Key Agreement (MKA) per IEEE 802.1X handles session key negotiation and rotation automatically between MKA peers without any manual key provisioning step. Key rotation intervals are configurable from seconds to hours, allowing compliance with key-lifetime requirements that regulated environments impose without creating operational overhead per encrypted link in large-scale deployments.
The 32x QSFP28 100G, 48x SFP28 25G + 8x QSFP28 100G, and 48x RJ45 10G + 8x QSFP28 100G models provide MACsec-capable hardware for pure 100G core positions, 25G server-facing leaf positions with 100G uplinks, and copper 10G deployments with 100G uplinks, without requiring separate encrypted and non-encrypted switch families for each port-speed tier.
Hardware MACsec integrated into the leaf switch eliminates the need for inline encryption appliances between the switch and the upstream link, appliances that add failure domains, increase port count, and introduce a separate management system. The 7050X3 MACsec switch manages both forwarding and encryption from a single EOS instance, simplifying compliance audits and operational runbooks in PCI DSS, HIPAA, and ITAR-regulated facilities.
Full specifications for Arista 7050X3 MACsec Series
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Recommended
#7020R4-48Y-8QC
Recommended
#DCS-7388X5-64D
Recommended
#DCS-7050CX3-32S
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions