R&S®SITLine

Layer 2 network encryption with VS-NfD and EU/NATO RESTRICTED approval for security-critical communications

Sensitive data is at risk not only where it is stored, but also while in transit between networks. Reliable protection of data transmission is therefore essential, particularly in government, sovereign, and critical sectors, as well as in security-sensitive areas of the private sector.

R&S®SITLine ETH network encryptors were specifically designed to meet these requirements. Advanced Layer 2 cryptography protects Ethernet connections against unauthorized access and ensures the confidentiality and integrity of transmitted data. With scalable product variants ranging from 1 Gbps to 2 x 100 Gbps and high port density, a wide variety of network architectures can be secured without compromising performance – from site and edge connectivity to high-performance data center and backbone connections.

Technical features

  • High-performance Ethernet encryption for the secure transmission of sensitive data at the network layer
  • High data throughput with low latency for secure communications without unnecessarily impacting network performance
  • Broad performance range: Scalable product variants from 1 Gbps to 2 x 100 Gbps for a wide range of requirements – from site and edge connectivity to high-performance data center and backbone connections; lower data rates are also supported
  • Centralized security management for efficient administration of encryption devices via R&S®Trusted Objects Manager (TOM)
  • 100% Made in Germany: Entirely developed, manufactured, and serviced in Germany at Rohde & Schwarz Group locations
  • Security approvals: VS-NfD, NATO RESTRICTED, EU RESTRICTED
  • Symmetric encryption using 256-bit AES in GCM (Galois / Counter Mode)
  • Authentication using asymmetric cryptography; 384-bit ECC for peer authentication (ECGDSA) and 512-bit ECC (Brainpool) for management (TLS 1.2)
  • Automatic, uninterrupted key rotation (master key default: 36,000 s / session key default: 180 s; individually configurable as required)
  • Post-quantum ready (PQC) thanks to the BOTAN cryptographic library developed on behalf of the German Federal Office for Information Security

Highlights

Sovereign and future-ready security

R&S®SITLine ETH network encryption solutions are approved by the German Federal Office for Information Security for VS-NfD and EU/NATO RESTRICTED. They follow the “Security Made in Europe” principle, enabling users to achieve digital sovereignty, transparency, and control across the entire value chain. All development, manufacturing, and service activities take place in Germany, drawing on more than 30 years of in-depth crypto­graphic expertise and ensuring compliance with the strictest national security requirements, e.g. the exclusion of backdoors. This enables sovereign obsolescence manage­ment: Technological iterations and component discontinuations are proactively addressed behind the scenes, ensuring unparalleled long-term availability and reliable system stability. The post-quantum readiness (PQC) of R&S®SITLine provides additional future-proofing: The BOTAN cryptographic library, developed on behalf of the German Federal Office for Information Security, makes it possible to integrate new post-quantum algorithms into the existing infrastructure via software updates, eliminating the need for costly hardware replacement programs.

Complete operational autonomy without key servers

R&S®SITLine ETH delivers uncompromising autonomy, eliminates single points of failure, and ensures full control over data. Unlike conventional architectures, SITLine ETH does not require external key servers. The encryption devices negotiate session keys fully autonomously and directly with one another. This not only drastically reduces the attack surface but also eliminates by design the risk of a central server failure or compromise bringing down the entire encryption network. Cryptographic key material never leaves the secure hardware (tamper-resistant security module) of the endpoint devices. As the customer, you retain complete and exclusive control over the security of your communications.

Easy management, rapid rollout, and high service efficiency

Our Layer 2 encryptors not only secure your network but also help optimize your total cost of ownership (TCO) by minimizing deployment, administration, and maintenance efforts. Zero Touch Provisioning (ZTP) enables fast and automated commissioning – even across hundreds of branch offices or substations. SNMP support further facilitates integration into existing network management systems without requiring changes to routing, QoS, or SLAs. The centralized and intuitive R&S®Trusted Objects Manager (TOM) gives administrators a clear overview of complex network topologies and security and certificate management, including tamper detection for secure operation even without on-site monitoring. In the event of a service case, no highly qualified IT specialist is required on site to reconfigure the device: Smartcard-based Plug & Play allows the existing smartcard to be inserted into a replacement device, which then automatically reads all configuration parameters (including SNMP parameters) and certificates and establishes an authenticated, secure connection.

Further advantages

Uncompromising performance and scalable Layer 2 efficiency

Encryption must not become a bottleneck. That is why the R&S®SITLine ETH architecture is designed for high-speed perfor­mance without compromise. Dedicated hardware encryption (FPGA) and cut-through processing deliver exceptionally low latency (e.g., < 3 microseconds at 100 Gbps) – essential for…

Encryption must not become a bottleneck. That is why the R&S®SITLine ETH architecture is designed for high-speed perfor­mance without compromise. Dedicated hardware encryption (FPGA) and cut-through processing deliver exceptionally low latency (e.g., < 3 microseconds at 100 Gbps) – essential for latency-critical applications such as synchronous data center replication or real-time control in critical infrastructure environments. Unlike Layer 3 VPNs such as IPsec, Layer 2 encryption operates with virtually no protocol overhead. 100% of the available bandwidth can be used for payload data. This enables data rates of up to 2 × 100 Gbps and up to 1,000 secure connections per link for complex network topologies, with a port density of up to 8 links (16 ports) in a single rack unit. SITLine behaves like an invisible encrypted cable within the network. Because it operates entirely at Layer 2, it encrypts payload data while passing higher-layer protocols such as SD-WAN, MPLS, and IP routing through completely unchanged (protocol and SD-WAN trans­parency, or bump-in-the-wire operation). Data flows seamlessly without requiring any changes to the existing network logic.

Management security for Operational Technology (OT) and critical infrastructure networks

With security features such as hardware hardening, strict management separation, and group encryption for multicast traffic, R&S®SITLine ETH is specifically designed for use in sensitive environments such as critical infrastructure and Operational Technology (OT) environments. Each device permits…

With security features such as hardware hardening, strict management separation, and group encryption for multicast traffic, R&S®SITLine ETH is specifically designed for use in sensitive environments such as critical infrastructure and Operational Technology (OT) environments. Each device permits only firmware to boot that has been crypto­graphi­cally signed by the manufacturer, Rohde & Schwarz (Secure Boot). In addition, integrated hardware monitoring continuously monitors system integrity, temperature, and encryptor status. R&S®SITLine ETH also provides complete logical and physical separation of management and operational networks. A dedi­­cated RJ-45 port is available for out-of-band management, while remote management is securely handled via TLS 1.2 over the data channels using in-band manage­ment. OT networks and critical infrastructure control networks often require commands to be sent to multiple endpoints simultaneously. SITLine's Layer 2 group encryption therefore enables secure multicast and broadcast applications without the performance penalties associated with serial point-to-point encryption.

Symmetric high-speed encryption (AES-256 GCM)

Data is encrypted using the Advanced Encryption Standard (AES) with a 256-bit key in Galois / Counter Mode (GCM). This not only ensures complete confidentiality but also provides cryptographically strong integrity protection that immediately detects and discards manipulated packets (configurable…

Data is encrypted using the Advanced Encryption Standard (AES) with a 256-bit key in Galois / Counter Mode (GCM). This not only ensures complete confidentiality but also provides cryptographically strong integrity protection that immediately detects and discards manipulated packets (configurable with up to 16 bytes of overhead).

Asymmetric cryptography for authentication

Device authentication is based on Elliptic Curve Cryptography (ECC). 384-bit ECC keys (ECGDSA) are used for connections to peer devices, while highly secure 512-bit Brainpool curves are used for management connections (TLS 1.2). These methods provide a very high level of security while requiring…

Device authentication is based on Elliptic Curve Cryptography (ECC). 384-bit ECC keys (ECGDSA) are used for connections to peer devices, while highly secure 512-bit Brainpool curves are used for management connections (TLS 1.2). These methods provide a very high level of security while requiring relatively little computational effort.

Hitless key rotation

Fully autonomous key negotiation using authenticated Diffie-Hellman ECKAS-DH (Elliptic Curve Key Agreement Scheme) provides Perfect Forward Secrecy. The hardware-integrated True Random Number Generator (PTG.3) generates high-entropy key material. By default, the master key is rotated every 10 hours…

Fully autonomous key negotiation using authenticated Diffie-Hellman ECKAS-DH (Elliptic Curve Key Agreement Scheme) provides Perfect Forward Secrecy. The hardware-integrated True Random Number Generator (PTG.3) generates high-entropy key material. By default, the master key is rotated every 10 hours (36,000 s) and the session key every 3 minutes (180 s) – completely transparently and without any interruption to the connection (hitless rekeying).

Cut-through architecture

Standard routers and software VPNs use the store-and-forward principle, in which each packet is first received in full and buffered. SITLine ETH NG processes data streams using dedicated Field Programmable Gate Arrays (FPGAs) in a cut-through architecture. Encryption begins while the frame is still…

Standard routers and software VPNs use the store-and-forward principle, in which each packet is first received in full and buffered. SITLine ETH NG processes data streams using dedicated Field Programmable Gate Arrays (FPGAs) in a cut-through architecture. Encryption begins while the frame is still being received. This reduces latency on the ETH-XL to an impressive < 3 microseconds at 100 Gbit/s – consistently, regardless of network utilization.

Fully meshed topologies with MEFSec (vs. MACsec)

Unlike MACsec (IEEE 802.1AE), which is primarily designed for point-to-point (hop-by-hop) protection over a direct physical link, R&S®SITLine ETH with MEFSec technology provides end-to-end support for virtually any network topology. From simple point-to-point links and multipoint configurations to…

Unlike MACsec (IEEE 802.1AE), which is primarily designed for point-to-point (hop-by-hop) protection over a direct physical link, R&S®SITLine ETH with MEFSec technology provides end-to-end support for virtually any network topology. From simple point-to-point links and multipoint configurations to fully meshed networks, a wide range of scenarios can be implemented. With support for up to 1,000 simultaneous secure connections per port, the solution provides exceptional scalability and flexibility in network design.

Strict network separation using crypto groups

To enforce the “need-to-know” principle at the network layer in large and complex infrastructures, devices and ports can be organized into closed crypto groups. Secure connections are established exclusively within a defined group. This reliably prevents unwanted all-to-all communication, enables…

To enforce the “need-to-know” principle at the network layer in large and complex infrastructures, devices and ports can be organized into closed crypto groups. Secure connections are established exclusively within a defined group. This reliably prevents unwanted all-to-all communication, enables granular network segmentation, and provides highly secure multi-tenancy over shared physical infrastructure.

Carrier Ethernet & VLAN flexibility

The systems support highly complex topologies (VLAN, Q-in-Q according to IEEE 802.1ad, IEEE 802.1ah). The encryption offset is configurable (up to three VLAN tags can remain readable in unencrypted form), allowing carriers and service providers to continue forwarding encrypted packets across their…

The systems support highly complex topologies (VLAN, Q-in-Q according to IEEE 802.1ad, IEEE 802.1ah). The encryption offset is configurable (up to three VLAN tags can remain readable in unencrypted form), allowing carriers and service providers to continue forwarding encrypted packets across their networks using EPL, EVPL, or EVPLAN services.

SITLine comparison

 

R&S®SITLine ETH-XL

The modular data center and backbone system

R&S®SITLine ETH-S

The compact edge powerhouse

Throughput & modularity

Available in configurations of 4 × 1 or 10 Gbps, 8 × 1 or 10 Gbps, and 1 × or 2 × 100 Gbps; user-selectable transceivers, with speeds adaptable to requirements

Scalable from 10 Mbps to 10 Gbps in full-duplex operation

Cryptography

384-bit ECC keys, 256-bit AES keys, PTG.3 true random number generator

384-bit ECC keys, 256-bit AES keys, PTG.3 true random number generator

Power supply

Redundant, hot-swappable for maximum availability

1–2 external power supplies, hot-swappable, energy-efficient (max. 20 W)

Cooling

2 chassis fans, replaceable during operation – for high availability in continuous operation

Fanless (passive cooling)

Dimensions / size

19-inch rack, 1U

Approx. 4.5 inches, 1U

Ideal deployment scenarios

Data center interconnect (DCI), high-performance backbone connections, federal core networks, carrier infrastructures

Remote critical infrastructure components, small government branch offices, substations (DIN rail mounting available), mobile deployment scenarios, environments without conventional server room cooling

Possible use cases

Site-to-site connectivity – securely transmitting sensitive data between two locations

When data is exchanged between geographically separate locations, sensitive information leaves the protected local infrastructure and must be transmitted over external or shared networks. Typical examples include secure point-to-point connections between two government sites, a corporate site and…

When data is exchanged between geographically separate locations, sensitive information leaves the protected local infrastructure and must be transmitted over external or shared networks. Typical examples include secure point-to-point connections between two government sites, a corporate site and its data center, or two production facilities. For example, two development sites of an automotive supplier located in different cities can securely exchange design data, CAD files, and other confidential development information on a daily basis. R&S®SITLine ETH encrypts the Ethernet connection between the sites, ensuring that the data remains protected throughout the entire transmission path.

Multipoint and fully meshed networks – securely connecting complex, distributed infrastructures

Organizations with many locations often require more than individual point-to-point connections. R&S®SITLine ETH enables encrypted communications in multipoint and meshed network structures, making it suitable for scalable infrastructures with numerous communication relationships. One example is

Organizations with many locations often require more than individual point-to-point connections. R&S®SITLine ETH enables encrypted communications in multipoint and meshed network structures, making it suitable for scalable infrastructures with numerous communication relationships. One example is federally organized government agencies with central and regional offices, where different locations need to exchange sensitive information directly and securely. Instead of treating each communication relationship in isolation, a scalable encrypted network structure is established, allowing sensitive administrative data to be securely transmitted between authorized locations.

Data center interconnect and backbone – secure, high-performance encryption for high-bandwidth connections

Large volumes of business-critical or sensitive data are transmitted between data centers and across central backbone connections. The challenge is to protect this data without allowing encryption to become a bottleneck for high-speed connectivity. This is particularly important, for example, when

Large volumes of business-critical or sensitive data are transmitted between data centers and across central backbone connections. The challenge is to protect this data without allowing encryption to become a bottleneck for high-speed connectivity. This is particularly important, for example, when securely interconnecting two redundant data centers operated by a company, government agency, or critical infrastructure operator, where large volumes of data are continuously replicated. For instance, if a financial services provider operates two geographically separate data centers to provide redundancy for its business-critical systems, databases, backups, and virtual systems are continuously replicated between them. R&S®SITLine ETH-XL protects high-performance data center interconnects without encryption becoming a bottleneck for data replication.

Perimeter and edge security – protection extending to the edge of the infrastructure

Security-critical communications are not limited to central data centers; they increasingly originate at geographically distributed and decentralized locations. At these locations in particular, a compact form factor, low power consumption, and protection of the integrity of transmitted information

Security-critical communications are not limited to central data centers; they increasingly originate at geographically distributed and decentralized locations. At these locations in particular, a compact form factor, low power consumption, and protection of the integrity of transmitted information can be crucial. R&S®SITLine ETH enables these decentralized Ethernet connections to be cryptographically secured as well. Possible scenarios include small government branch offices or decentralized technical components of critical infrastructure (e.g., those of an energy provider) whose control, status, or operational data must be securely transmitted to a central location. Unauthorized parties must not be able to intercept these communications undetected or manipulate transmitted information. Network encryption therefore protects the connection directly at the decentralized location and secures communications all the way to the central infrastructure.

Secure transmission path – protection over shared transport networks

Organizations cannot always control the entire infrastructure over which their sensitive data is transported. Carrier, service provider, or other shared networks therefore represent a potential trust boundary. R&S®SITLine ETH encrypts data at the boundaries of the organization’s own infrastructure,…

Organizations cannot always control the entire infrastructure over which their sensitive data is transported. Carrier, service provider, or other shared networks therefore represent a potential trust boundary. R&S®SITLine ETH encrypts data at the boundaries of the organization’s own infrastructure, ensuring that the confidentiality and integrity of transmitted information can be protected regardless of the underlying transport network. A specific example: A German federal agency connects its headquarters in Berlin to a data center in another city via leased carrier infrastructure. The agency controls its own networks, but not every component of the transport path in between. SITLine devices encrypt the data before it enters the third-party transport network and decrypt it only after it reaches the controlled destination.

Options & accessories

A range of transceivers for different interfaces and data rates as well as various security and system tokens, including a smartcard reader, are available for R&S®SITLine ETH. This allows the equipment to be tailored to the specific network environment and required security classification.

Available accessories for R&S®SITLine:

Transceiver

  • Transceiver SFP 10/100/1000 BASE-T
  • Transceiver SFP 1000 BASE SX
  • Transceiver SFP 1000 BASE LX
  • Transceiver SFP+ 1G/10G BASE SR
  • Transceiver SFP+ 10G BASE SR
  • Transceiver SFP+ 10G BASE LR
  • Transceiver QSFP28 100G BASE SR
  • Transceiver QSFP28 100G BASE LR

Tokens

  • R&S®SITLine O-Token -13*
  • R&S®SITLine O-Token -23**
  • R&S®SITLine Sys-Token -14*
  • R&S®SITLine Sys-Token - -24**

Note:
* Standard (not VS-NfD)
** VS-NfD

Downloads & links

General information

These and other publications – such as brochures, checklists for more network security, or white papers on SIEM and DPI – can be found here at a glance:

R&S Networks and Cybersecurity publications

Your direct line to us

Most questions can be resolved best in direct contact: We look forward to answering your questions and requests by phone or via the contact form.

Inside Sales International Team
+49 (0)2405 49936 122

Feel free to write us