SECURE LAYER 2 NETWORK BRIDGING

Extend Ethernet securely across sites, clouds and edge locations.

Create one centrally managed Layer 2 fabric across distributed agents. Connect local bridges through encrypted, resilient relay paths—without configuring a separate tunnel or TAP adapter for every remote location.

Start with two locations and extend the authorised fabric when ready.

ONE AUTHENTICATED ETHERNET ENVIRONMENT

Distributed networks, joined as one controlled fabric.

DC Core Ethernet Fabric turns geographically distributed networks into one authenticated Ethernet environment, with central authority separated from the live agent-to-agent data plane.

02 / AUTHORISE

Centralised MAC authority

Central authorises participating agents and source MAC addresses before they use the fabric. Conflicting, unapproved or incorrectly located devices fail closed.

  • Duplicate ownership prevention
  • Moved-device detection and review
03 / PROTECT

Encrypted, resilient transport

Agent-to-agent sessions protect every Ethernet frame with AES-256-GCM and carry traffic over automatic, failover, striped or redundant relay paths.

  • Identity and session data cryptographically bound
  • Relay failures isolated from other participants

LAYER 2 WITHOUT TUNNEL SPRAWL

Simple locally. Governed centrally. Resilient in transit.

The fabric keeps standard Ethernet at each edge while adding explicit identity, encryption and failure handling between locations.

ADAPTERS

One TAP per agent

Connect one local bridge to many remote agents without multiplying tunnel interfaces as the fabric grows.

IDENTITY

MAC addresses fail closed

New, conflicting or incorrectly located MAC addresses must be resolved by Central before traffic is accepted.

ENCRYPTION

Every frame protected

AES-256-GCM binds the network, source and destination agents, session, epoch and sequence to the traffic.

RESILIENCE

Multiple relay policies

Choose automatic routing, failover, striping or redundant delivery. Existing connections can survive an individual relay failure without blocking other participants.

CONTINUITY

Controlled outage behaviour

Active sessions and previously authorised MAC mappings can continue in memory while new authority-dependent activity stays blocked.

COMPATIBILITY

Standard Ethernet at the edge

Hosts, virtual machines, containers and appliances keep communicating through their existing local network model.

HOW IT WORKS

From local bridge to authorised remote network.

Central establishes who may participate. The approved agents then forward Ethernet across protected data-plane sessions and resilient relay infrastructure.

  1. 01 / ATTACH

    Connect each location

    Install an Ethernet attachment on each agent and connect its TAP adapter to the appropriate local bridge.

  2. 02 / AUTHORISE

    Approve network identities

    Central validates agents and MAC addresses, prevents duplicate ownership and establishes secure connectivity.

  3. 03 / FORWARD

    Send frames intelligently

    Known unicast goes only to the destination MAC owner. Broadcast and multicast replicate across authorised connections.

ONE MANAGEMENT EXPERIENCE

Operate a fabric, not a collection of tunnels.

Add locations, review identity, choose resilience and investigate events from one solution. Low-level infrastructure hashes, process IDs and session identifiers remain available for diagnostics without dominating everyday operations.

Discuss fabric management
  • 01Add or remove locationsControl which agents and local networks participate.
  • 02Review discovered MAC addressesAuthorise new identities before they can send traffic.
  • 03Detect duplicate or moved MACsResolve ownership conflicts and unexpected location changes.
  • 04Monitor agent-to-agent connectivitySee data-plane health independently from Central-control health.
  • 05Select resilience policiesApply the right relay, failover, striping or redundancy behaviour.
  • 06Revoke and investigateRemove access immediately and review security or operational events.

SECURITY BY DESIGN

Authority at the control plane. Enforcement at every agent.

Membership, source identity and session state are explicit. Unauthorised traffic fails closed, replayed frames are rejected and unavailable peers cannot consume unbounded resources.

FRAME POLICY

Identity-bound traffic

  • Authorised source-MAC enforcement
  • Network and agent identity binding
  • Duplicate MAC ownership prevention
FAILURE CONTROL

Bounded, fail-closed behaviour

  • Replay protection
  • Unknown-unicast fail-closed behaviour
  • Bounded queues for slow or unavailable peers
OUTAGE CONTINUITYPreviously authorised MAC mappings and active sessions can remain available in agent memory during a temporary Central outage. New devices and new connectivity remain blocked until Central authority is restored.

IDEAL USE CASES

Where distributed systems still need to share Ethernet.

Use the fabric when applications, devices or operational constraints require Layer 2 adjacency across locations—but traditional VPN tunnel sprawl is difficult to secure and operate.

SITES & INDUSTRY

Extend established local networks

Connect branch, industrial and manufacturing Ethernet environments while keeping local devices on familiar network interfaces.

  • Branch-office Ethernet networks
  • Industrial and manufacturing Layer 2
  • Legacy discovery and broadcast-based systems
  • Resilient Layer 2 access across remote sites
CLOUD & EDGE

Join distributed workloads

Bridge hosted and local compute without building a separate point-to-point tunnel for every participating location.

  • Edge and cloud-hosted workloads
  • Virtual machines across distributed hosts
  • Isolated customer or project fabrics
  • Containers, appliances and existing Linux bridges

COMMON QUESTIONS

Ethernet Fabric FAQs.

Start with the locations, local bridge design and Layer 2 behaviours that must cross the fabric. We can then scope identity, relay and continuity policy.

What is a Layer 2 Ethernet fabric?

A Layer 2 Ethernet fabric extends one authenticated Ethernet environment across distributed locations. DC Core connects local bridges through approved agents, encrypted agent-to-agent sessions and resilient relay paths.

Does every remote location need its own TAP adapter?

Each participating agent uses one local TAP attachment. That attachment can connect its bridge to multiple authorised remote agents, avoiding a separate virtual adapter for every point-to-point connection.

How are devices authorised?

Central validates participating agents and discovered MAC addresses, prevents duplicate ownership and authorises source MAC locations before traffic can use the fabric. Unknown or conflicting identities fail closed.

What happens during a temporary Central outage?

Previously authorised MAC mappings and active sessions can remain available in memory. New devices and new connectivity stay blocked until Central authority returns, so a control-plane outage does not silently expand access.

Can the fabric work with an existing Linux bridge?

Yes. Attach the fabric TAP to an existing Linux bridge, or let the agent provision a managed TAP and bridge. Hosts, virtual machines, containers and appliances continue using standard Ethernet.

Can DC Core provide plug-and-play bridge devices for installers?

Yes. DC Core can supply a preconfigured fabric bridge appliance for an agreed site. The installer connects power, the designated Ethernet segment and approved uplink; DC Core handles fabric onboarding and remote path validation. Local switching, cabling, VLAN placement, physical protection and system safety remain part of the site design.

CONNECTED CAPABILITIES

INSTALLER USE CASEConnecting access control, CCTV or building systems? See the multi-site physical-security guide, including preconfigured bridge appliances for installers.

BUILD ONE SECURE ETHERNET FABRIC

Build one secure Ethernet fabric across every location.

Connect distributed networks through centrally authorised identities, encrypted agent-to-agent sessions and resilient relay infrastructure.

Deploy Your First Fabric