Switch-router family at up to 4.8 Tbps with wire-speed TunnelSec and AES-256-GCM MACsec for secure leaf-spine fabrics and data center interconnect.
The Arista 7280R3 Series with Encryption is the MACsec-enabled variant of the 7280R3 universal leaf switch router, adding hardware IEEE 802.1AE encryption on every port while retaining the full 7280R3 feature set: MPLS, Segment Routing, EVPN-VXLAN, BGP-LU, 512K IPv4 host routes, 256K IPv4 LPM routes, and 128K MAC addresses across fixed 1RU and 2RU form factors delivering 4.8 to 12.8 Tbps. Models with the -K suffix in the product designation indicate hardware MACsec capability, and both AES-128-GCM and AES-256-GCM cipher suites are supported per port at line rate.
The encryption-enabled 7280R3 addresses deployments where a fixed switch-router must simultaneously encrypt inter-rack or inter-site links and perform full L3 routing with route-scale tables. Rather than requiring separate router and encryption appliance hardware in series, which doubles the failure domain count and port overhead, the 7280R3-K models consolidate both functions. Typical deployment positions include border-leaf nodes in regulated-industry fabrics where uplinks to the spine must be encrypted, DCI gateway positions where dark-fibre or metro-Ethernet links require MACsec, and carrier-edge aggregation where MACsec protects inter-PE links in MPLS networks.
Hardware MACsec in AES-128-GCM or AES-256-GCM modes operates at full port line rate on every 10G/25G/100G/400G interface. Enabling encryption does not reduce the 4.8–12.8 Tbps forwarding capacity of the platform, so network engineers do not need to account for an encryption overhead factor when sizing port capacity for encrypted leaf-to-spine or inter-DC paths.
Full MPLS label forwarding and Segment Routing Traffic Engineering operate simultaneously with MACsec encryption, allowing the 7280R3-K to serve as an encrypted MPLS PE router or SR-TE path endpoint. This combination is specifically required in IP/MPLS carrier networks that must encrypt inter-PE links under data-sovereignty regulations without introducing a separate encryption overlay layer above the MPLS data plane.
Deploying a 7280R3-K model as the border-leaf node in a regulated-industry fabric places both the routing function (BGP, EVPN, ECMP load balancing) and the encryption function (MACsec of uplinks to spine) in a single device per border position. Removing the inline encryption appliance eliminates one hop, one management system, and one power/cooling overhead entry per border rack from the facility design.
A 512K IPv4 host-route table capacity allows the encrypted 7280R3-K to operate as a cloud-native border-leaf terminating /32 host routes from every VM and container in the data centre. At this scale, no route summarisation is required between the cloud workload fabric and the encrypted external-facing interfaces, simplifying BGP policy and enabling per-workload traffic engineering from the border outward.
Full specifications for Arista 7280R3 with Encryption
Download product documentation and resources
Explore other configurations and models that might suit your needs.
Recommended
#7020R4-48Y-8QC
Recommended
#DCS-7280PR3-24
Recommended
#DCS-7280R4-32PE
Our team of experts is ready to help you find the perfect solution for your business needs. Get personalized advice and competitive quotes.
We're here to help with any questions