R&S®SITLine
Layer 2 network encryption with VS-NfD and EU/NATO RESTRICTED approval for security-critical communications
Sensitive data is at risk not only where it is stored, but also while in transit between networks. Reliable protection of data transmission is therefore essential, particularly in government, sovereign, and critical sectors, as well as in security-sensitive areas of the private sector.
R&S®SITLine ETH network encryptors were specifically designed to meet these requirements. Advanced Layer 2 cryptography protects Ethernet connections against unauthorized access and ensures the confidentiality and integrity of transmitted data. With scalable product variants ranging from 1 Gbps to 2 x 100 Gbps and high port density, a wide variety of network architectures can be secured without compromising performance – from site and edge connectivity to high-performance data center and backbone connections.
- High-performance Ethernet encryption for the secure transmission of sensitive data at the network layer
- High data throughput with low latency for secure communications without unnecessarily impacting network performance
- Broad performance range: Scalable product variants from 1 Gbps to 2 x 100 Gbps for a wide range of requirements – from site and edge connectivity to high-performance data center and backbone connections; lower data rates are also supported
- Centralized security management for efficient administration of encryption devices via R&S®Trusted Objects Manager (TOM)
- 100% Made in Germany: Entirely developed, manufactured, and serviced in Germany at Rohde & Schwarz Group locations
- Security approvals: VS-NfD, NATO RESTRICTED, EU RESTRICTED
- Symmetric encryption using 256-bit AES in GCM (Galois / Counter Mode)
- Authentication using asymmetric cryptography; 384-bit ECC for peer authentication (ECGDSA) and 512-bit ECC (Brainpool) for management (TLS 1.2)
- Automatic, uninterrupted key rotation (master key default: 36,000 s / session key default: 180 s; individually configurable as required)
- Post-quantum ready (PQC) thanks to the BOTAN cryptographic library developed on behalf of the German Federal Office for Information Security
Sovereign and future-ready security
R&S®SITLine ETH network encryption solutions are approved by the German Federal Office for Information Security for VS-NfD and EU/NATO RESTRICTED. They follow the “Security Made in Europe” principle, enabling users to achieve digital sovereignty, transparency, and control across the entire value chain. All development, manufacturing, and service activities take place in Germany, drawing on more than 30 years of in-depth cryptographic expertise and ensuring compliance with the strictest national security requirements, e.g. the exclusion of backdoors. This enables sovereign obsolescence management: Technological iterations and component discontinuations are proactively addressed behind the scenes, ensuring unparalleled long-term availability and reliable system stability. The post-quantum readiness (PQC) of R&S®SITLine provides additional future-proofing: The BOTAN cryptographic library, developed on behalf of the German Federal Office for Information Security, makes it possible to integrate new post-quantum algorithms into the existing infrastructure via software updates, eliminating the need for costly hardware replacement programs.
Complete operational autonomy without key servers
R&S®SITLine ETH delivers uncompromising autonomy, eliminates single points of failure, and ensures full control over data. Unlike conventional architectures, SITLine ETH does not require external key servers. The encryption devices negotiate session keys fully autonomously and directly with one another. This not only drastically reduces the attack surface but also eliminates by design the risk of a central server failure or compromise bringing down the entire encryption network. Cryptographic key material never leaves the secure hardware (tamper-resistant security module) of the endpoint devices. As the customer, you retain complete and exclusive control over the security of your communications.
Easy management, rapid rollout, and high service efficiency
Our Layer 2 encryptors not only secure your network but also help optimize your total cost of ownership (TCO) by minimizing deployment, administration, and maintenance efforts. Zero Touch Provisioning (ZTP) enables fast and automated commissioning – even across hundreds of branch offices or substations. SNMP support further facilitates integration into existing network management systems without requiring changes to routing, QoS, or SLAs. The centralized and intuitive R&S®Trusted Objects Manager (TOM) gives administrators a clear overview of complex network topologies and security and certificate management, including tamper detection for secure operation even without on-site monitoring. In the event of a service case, no highly qualified IT specialist is required on site to reconfigure the device: Smartcard-based Plug & Play allows the existing smartcard to be inserted into a replacement device, which then automatically reads all configuration parameters (including SNMP parameters) and certificates and establishes an authenticated, secure connection.
Uncompromising performance and scalable Layer 2 efficiency
Encryption must not become a bottleneck. That is why the R&S®SITLine ETH architecture is designed for high-speed performance without compromise. Dedicated hardware encryption (FPGA) and cut-through processing deliver exceptionally low latency (e.g., < 3 microseconds at 100 Gbps) – essential for…
Management security for Operational Technology (OT) and critical infrastructure networks
With security features such as hardware hardening, strict management separation, and group encryption for multicast traffic, R&S®SITLine ETH is specifically designed for use in sensitive environments such as critical infrastructure and Operational Technology (OT) environments. Each device permits…
Symmetric high-speed encryption (AES-256 GCM)
Data is encrypted using the Advanced Encryption Standard (AES) with a 256-bit key in Galois / Counter Mode (GCM). This not only ensures complete confidentiality but also provides cryptographically strong integrity protection that immediately detects and discards manipulated packets (configurable…
Asymmetric cryptography for authentication
Device authentication is based on Elliptic Curve Cryptography (ECC). 384-bit ECC keys (ECGDSA) are used for connections to peer devices, while highly secure 512-bit Brainpool curves are used for management connections (TLS 1.2). These methods provide a very high level of security while requiring…
Hitless key rotation
Fully autonomous key negotiation using authenticated Diffie-Hellman ECKAS-DH (Elliptic Curve Key Agreement Scheme) provides Perfect Forward Secrecy. The hardware-integrated True Random Number Generator (PTG.3) generates high-entropy key material. By default, the master key is rotated every 10 hours…
Cut-through architecture
Standard routers and software VPNs use the store-and-forward principle, in which each packet is first received in full and buffered. SITLine ETH NG processes data streams using dedicated Field Programmable Gate Arrays (FPGAs) in a cut-through architecture. Encryption begins while the frame is still…
Fully meshed topologies with MEFSec (vs. MACsec)
Unlike MACsec (IEEE 802.1AE), which is primarily designed for point-to-point (hop-by-hop) protection over a direct physical link, R&S®SITLine ETH with MEFSec technology provides end-to-end support for virtually any network topology. From simple point-to-point links and multipoint configurations to…
Strict network separation using crypto groups
To enforce the “need-to-know” principle at the network layer in large and complex infrastructures, devices and ports can be organized into closed crypto groups. Secure connections are established exclusively within a defined group. This reliably prevents unwanted all-to-all communication, enables…
Carrier Ethernet & VLAN flexibility
The systems support highly complex topologies (VLAN, Q-in-Q according to IEEE 802.1ad, IEEE 802.1ah). The encryption offset is configurable (up to three VLAN tags can remain readable in unencrypted form), allowing carriers and service providers to continue forwarding encrypted packets across their…
|
R&S®SITLine ETH-XL The modular data center and backbone system |
R&S®SITLine ETH-S The compact edge powerhouse |
|
|---|---|---|
|
Throughput & modularity |
Available in configurations of 4 × 1 or 10 Gbps, 8 × 1 or 10 Gbps, and 1 × or 2 × 100 Gbps; user-selectable transceivers, with speeds adaptable to requirements |
Scalable from 10 Mbps to 10 Gbps in full-duplex operation |
|
Cryptography |
384-bit ECC keys, 256-bit AES keys, PTG.3 true random number generator |
384-bit ECC keys, 256-bit AES keys, PTG.3 true random number generator |
|
Power supply |
Redundant, hot-swappable for maximum availability |
1–2 external power supplies, hot-swappable, energy-efficient (max. 20 W) |
|
Cooling |
2 chassis fans, replaceable during operation – for high availability in continuous operation |
Fanless (passive cooling) |
|
Dimensions / size |
19-inch rack, 1U |
Approx. 4.5 inches, 1U |
|
Ideal deployment scenarios |
Data center interconnect (DCI), high-performance backbone connections, federal core networks, carrier infrastructures |
Remote critical infrastructure components, small government branch offices, substations (DIN rail mounting available), mobile deployment scenarios, environments without conventional server room cooling |
Site-to-site connectivity – securely transmitting sensitive data between two locations
When data is exchanged between geographically separate locations, sensitive information leaves the protected local infrastructure and must be transmitted over external or shared networks. Typical examples include secure point-to-point connections between two government sites, a corporate site and…
Multipoint and fully meshed networks – securely connecting complex, distributed infrastructures
Organizations with many locations often require more than individual point-to-point connections. R&S®SITLine ETH enables encrypted communications in multipoint and meshed network structures, making it suitable for scalable infrastructures with numerous communication relationships. One example is …
Data center interconnect and backbone – secure, high-performance encryption for high-bandwidth connections
Large volumes of business-critical or sensitive data are transmitted between data centers and across central backbone connections. The challenge is to protect this data without allowing encryption to become a bottleneck for high-speed connectivity. This is particularly important, for example, when …
Perimeter and edge security – protection extending to the edge of the infrastructure
Security-critical communications are not limited to central data centers; they increasingly originate at geographically distributed and decentralized locations. At these locations in particular, a compact form factor, low power consumption, and protection of the integrity of transmitted information…
Secure transmission path – protection over shared transport networks
Organizations cannot always control the entire infrastructure over which their sensitive data is transported. Carrier, service provider, or other shared networks therefore represent a potential trust boundary. R&S®SITLine ETH encrypts data at the boundaries of the organization’s own infrastructure,…
A range of transceivers for different interfaces and data rates as well as various security and system tokens, including a smartcard reader, are available for R&S®SITLine ETH. This allows the equipment to be tailored to the specific network environment and required security classification.
Available accessories for R&S®SITLine: