Home / Podcasts / Episode 3
Tech Lounge Podcast · Episode 3

Why Firewall Sizing & Decryption Matter | Data-Center Security with MACsec

Published September 28 · Ehsan Emad

Episode Summary

In this technical episode S1E3 we cover two tightly related topics: why firewall sizing — especially CPU capacity
for TLS/SSL decryption — matters for detection and prevention, and how enabling MACsec on data-center links
stops many MITRE ATT&CK techniques based on sniffing and frame injection.

Key Takeaways

  • Understand why firewall sizing matters when TLS/SSL decryption is enabled.
  • Learn why CPU capacity affects inspection and prevention performance.
  • Understand how MACsec protects data-center links.
  • Review how MACsec can reduce exposure to sniffing and frame-injection techniques.

Chapters

  1. Firewall sizing
  2. TLS/SSL decryption load
  3. CPU capacity and inspection
  4. MACsec in the data center
  5. Sniffing and frame-injection threats

Detailed Notes

The episode connects two data-center security topics: firewall sizing for decryption workloads and link-layer protection with MACsec.
It highlights the performance impact of decryption and the security value of protecting Ethernet links.

Speaker

Ehsan Emad