In brief
SecOps buyer guide for 400G and 800G optics, covering DAC, AOC, fibre reach, QSFP-DD, OSFP, packet visibility, and supply risk.
Key takeaways
- SecOps buyer guide for 400G and 800G optics, covering DAC, AOC, fibre reach, QSFP-DD, OSFP, packet visibility, and supply risk.
Why Security Operations Teams Cannot Afford to Wait on Optical Planning
Australian enterprise and data center programs are accelerating AI fabric deployments at a pace that outstrips traditional procurement cycles. Data center operators such as Macquarie Data Centres have publicly stated that AI workloads are fundamentally shifting data center design from a real estate model to a chip-out model, with liquid-cooled racks consuming megawatts of power and generating traffic patterns that differ sharply from conventional cloud workloads. When David Hirst, CEO of Macquarie Data Centres, described this shift on the OCP Podcast in January 2026, he emphasized that bursty, unpredictable AI traffic requires planning that accounts for the physical layer, not just the logical topology.
For security operations teams, this planning gap is not academic. When a spine-leaf fabric upgrades from 100G to 400G or 800G, the optics change, the connector types change, and the tap and aggregation points that feed intrusion detection, packet capture, and network detection and response (NDR) tools must change with them. Yet in most Australian programs, SecOps is consulted only after the fabric is built and the optics are already ordered.
This brief examines what SecOps teams need to evaluate before 400G and 800G optical commitments are locked in.
The Market Context: AI Fabrics Are Driving the 400G and 800G Transition
The shift to 400G and 800G Ethernet in Australian data centers is not a standalone optics refresh. It is being pulled forward by AI infrastructure requirements. NVIDIA’s Spectrum-X Ethernet platform, for example, is designed around 800GbE spine switches using OSFP connectors, with silicon photonics options emerging at the switch ASIC level. The SONiC Foundation, a Linux Foundation project, describes SONiC as an open-source network operating system that offers a full suite of network functionality including BGP and RDMA, production-hardened in the data centers of the largest cloud service providers. SONiC runs on switches from multiple vendors and ASICs, which means the optical transceiver ecosystem must support a broader range of hardware than proprietary NOS environments.
The Open Compute Project Networking project, which counts SONiC as a sub-project alongside ONIE and SAI, aims to create fully disaggregated and open networking hardware and software. For Australian buyers, this disaggregation means that optical transceiver selection is not just a function of the switch vendor’s catalog. It becomes a cross-platform compatibility decision that touches the NOS, the ASIC, the cable plant, and the security tool chain.
DAC, AOC, or Fiber: The Three Options SecOps Must Understand
At 400G and 800G line rates, there are three primary interconnect options. Each has distinct implications for security tool deployment.
Direct Attach Copper (DAC) cables are the lowest-cost option for short-reach connections, typically under 5 meters. DAC cables use twinax copper and terminate directly into QSFP-DD or OSFP ports. For intra-rack or adjacent-rack connections, DAC is often the default choice for switch-to-server links. The limitation for SecOps is that DAC links are difficult to tap without introducing active devices, and the short reach means that packet broker appliances must be co-located in the same rack or adjacent racks.
Active Optical Cables (AOC) use fiber with integrated transceivers at each end, supporting reaches from 3 to 100 meters depending on the variant. AOCs simplify deployment because they are factory-terminated and avoid the need for separate transceiver and patch cord assemblies. For SecOps, AOCs offer slightly more flexibility in physical placement of packet brokers and security tools, but the integrated transceiver design means that a cable failure requires replacing the entire assembly.
Pluggable fiber transceivers (SR, DR, FR, LR variants in QSFP-DD or OSFP form factors) provide the most flexibility. They support the longest reaches, they allow the security team to insert tap devices or packet brokers at any point in the optical path, and they enable independent troubleshooting of the transceiver, the fiber, and the connected device. For 400G, the dominant options are QSFP-DD SR8 (multi-mode, short reach), QSFP-DD DR4 (single-mode, 500m), and QSFP-DD FR4 (single-mode, 2km). At 800G, OSFP SR8 and OSFP DR8 are emerging, with OSFP-SD (short-distance) variants under development.
| Option | Reach | Form Factor | SecOps Tap Flexibility | Relative Cost |
|---|---|---|---|---|
| DAC | 1-5m | QSFP-DD, OSFP | Low | Lowest |
| AOC | 3-100m | QSFP-DD, OSFP | Medium | Moderate |
| Fiber SR | 100m (MM) | QSFP-DD, OSFP | High | Higher |
| Fiber DR/FR | 500m-2km | QSFP-DD, OSFP | High | Highest |
QSFP-DD vs OSFP: The Form Factor Decision Is a Security Decision
The QSFP-DD and OSFP form factors are both capable of 400G and 800G line rates, but they are not interchangeable. QSFP-DD (Quad Small Form Factor Pluggable Double Density) maintains backward compatibility with QSFP28 and QSFP+ cages, which means that in mixed-speed environments, a QSFP-DD switch port can accept a 100G QSFP28 transceiver. This backward compatibility matters for SecOps teams running legacy packet brokers or tap aggregation switches at 100G.
OSFP (Octal Small Form Factor Pluggable) is a larger form factor that was originally developed for 800G and above. OSFP ports can accept QSFP-DD transceivers via adapter modules, but native OSFP transceivers do not fit into QSFP-DD cages. For Australian programs planning a clean 800G build, OSFP may be the forward-looking choice. For programs that need to integrate with existing 100G or 400G security tool infrastructure, QSFP-DD offers less disruption.
The security operations implication is straightforward: if the packet broker, NDR appliance, or packet capture platform uses QSFP-DD ports, the fiber plant and transceiver selection must be coordinated from day one. Retrofitting after the fabric is built is possible but expensive and disruptive.
Australian Market Specifics: Sovereignty, Compliance, and Supply Chain
Australia’s data center market has unique characteristics that affect optical planning. The OCP Podcast episode featuring David Hirst of Macquarie Data Centres highlighted that Australian data sovereignty requirements, regulatory frameworks, and the geography of dense urban builds create planning constraints that differ from hyperscale markets in the US or Europe. Compliance is not just a checkbox; it is a market advantage for operators who can demonstrate end-to-end control of the infrastructure stack.
What SecOps Teams Should Evaluate Now
Before the 400G or 800G optics order is placed, security operations teams should confirm the following:
-
Packet broker port compatibility: What form factor and speed does the current or planned packet broker accept? If the answer is QSFP28 100G, the fabric optics plan must include a migration path.
-
Tap point placement: Where will optical taps or SPAN ports be located? DAC links cannot be easily tapped. Fiber links can be tapped with passive optical splitters, but the splitter introduces insertion loss that must be budgeted into the optical power budget.
-
Multi-vendor NOS compatibility: If the fabric runs SONiC or another open NOS, transceiver compatibility must be verified against the SAI (Switch Abstraction Interface) and the specific SONiC image. SONiC’s container-based architecture allows for modular deployment, but transceiver firmware compatibility is still a per-vendor concern.
-
Australian supply chain lead times: Optical transceiver availability in Australia may differ from global stock levels. Long-lead-time items (800G OSFP DR8, for example) should be identified and ordered early in the program.
The xSONiC Buyer Angle
xSONiC offers 400G and 800G optical transceivers across QSFP-DD and OSFP form factors, along with packet brokers designed for security tool delivery in spine-leaf and AI fabric environments. The key differentiator for Australian buyers is that xSONiC can address the optical layer and the visibility layer as a coordinated procurement, rather than leaving security teams to retrofit after the fabric is built.
For Australian enterprise and data center programs planning AI fabric or campus backbone upgrades, engaging xSONiC early in the planning cycle means that the optical power budget, the tap point design, and the packet broker integration can be validated before the cable plant is installed. This is particularly relevant for programs running SONiC-based fabrics where multi-vendor transceiver compatibility must be tested against the specific NOS build.
SecOps Optical Validation Evidence
| Evidence area | What to measure | Acceptance gate | Rework trigger |
|---|---|---|---|
| Link stability | DOM temperature, optical power, FEC errors, CRC errors, and flap history | 24 hours clean link record at 400G or 800G | Errors are dismissed as “normal burn-in” without root cause |
| Visibility path | TAP, packet broker, SPAN, filter rules, and security tool ingress capacity | 30 minutes representative traffic replay with no sustained packet loss | Tool visibility is added after cabling and optics are locked |
| Form factor fit | QSFP-DD or OSFP cage, airflow, thermal budget, reach, and spare availability | Approved optics list includes local replacement path and lead time | The optics choice works electrically but fails thermal or supply constraints |
| Incident readiness | Replacement procedure, rollback path, escalation owner, and evidence bundle | Failed optic can be isolated and replaced inside 4 hours | SecOps, network, and supplier teams disagree on fault ownership |
| Growth model | Current links, projected east-west growth, AI workload uplifts, and packet duplication ratio | 12 months visibility capacity plan covers broker and tool headroom | Fabric bandwidth grows faster than monitoring capacity |
Engineering FAQ
What should be measured before sizing a packet broker? Measure source link speed, 95th-percentile utilisation, burst peaks, replication factor, filter complexity, tunnel handling needs, and tool-port capacity. Packet broker sizing fails when it is based on average traffic rather than copied and filtered traffic.
What proves that a visibility design is production ready? The design should prove aggregation, filtering, replication, load balancing, packet slicing or deduplication if required, and tool failover under realistic traffic. Security teams should also verify that drops are reported rather than hidden.
Where do Australian buyers most often under-scope visibility projects? The common gaps are east-west data centre traffic, encrypted or tunneled flows, AI cluster bursts, retention requirements, and tool oversubscription. A procurement brief should model those before asking vendors for a bill of materials.
Related xSONiC Resources
Sources Reviewed
- Ethernet Network Adapters - ConnectX NICs | NVIDIA
- NVIDIA BlueField Data Processing Unit
- NVIDIA Spectrum-X Ethernet Platform
- ACSC Essential Eight
- OAIC Notifiable Data Breaches
- APRA CPS 234 Information Security
- NETSCOUT Network Packet Definition
- Cloudflare Network Packet Definition
- SONiC Project Documentation
- Broadcom Ethernet Switching
- Marvell Switching
- NVIDIA Ethernet Switching
- Open Compute Networking
- SONiC GitHub
- SONiC Foundation
Product fit
Where xSONiC fits
xSONiC can help validate the switch, optics, software image, telemetry, and support assumptions against the actual deployment before a production order is released.
datacenter aiXS-DC-64X800-AI-G164-port 800G AI fabric switch for large-scale GPU clusters, HPC backbones, and ultra-high-throughput data center networks.View product
datacenter aiXS-DC-32X400-SP-G232-port 400G spine/core switch for high-capacity data center fabrics and AI-ready backbones.View product


