IPsec/IKE Encryption Support for VxLAN-GPE Tunnel

VxLAN-GPE tunnels between access points (APs) and RUCKUS Edge devices support IPsec/IKE-based encryption, providing secure transport for VxLAN tunnel traffic. This enhancement ensures data confidentiality and integrity, particularly in distributed deployments where APs and Edge devices operate across different subnets or geographic regions. The encryption of VxLAN‑GPE tunnel traffic can be enabled or disabled.

Feature Overview

Encryption is supported for VxLAN-GPE tunnels used in SD-LAN services on Active-Active (AA) RUCKUS Edge clusters, providing secure and reliable communication across public networks. The implementation uses IKEv2 with pre-shared key (PSK) authentication and predefined proposals to simplify configuration and ensure interoperability.

Encrypted tunnels maintain full support for high-availability operations, including AP failover and fallback, allowing seamless transitions between primary and backup Edge nodes without disrupting connectivity or requiring changes to tunnel logic.

Requirements

Following are the requirements for enabling or using this feature:

  • This feature is introduced in RUCKUS Edge firmware release 2.5.0 and supported on APs running firmware version 7.1 and later.
  • UDP ports 500 (IKE) and 4500 (NAT-T) must be open between APs and the Edge devices.

Considerations

Consider the following when configuring and using this feature:

  • VxLAN-GPE tunnel encryption is based on IKE (specifically, IKEv2) and IPsec Encapsulating Security Payload (ESP) protocols operating in Transport mode. Both IKE and ESP Security Associations (SAs) support time-based rekeying with configurable lifetimes.

    • IKE Proposals:
      • AES128GCM-PRFSHA256-MODP2048 (default)
      • AES128-SHA384-USE_INTEGRITY_ALG-ECP384
      • AES128-SHA256-USE_INTEGRITY_ALG-MODP2048
    • IPsec Proposals:
      • AES128GCM-MODP2048 (default)
      • AES128-SHA384-ECP384
      • AES128-SHA256-MODP2048

  • Enabling or disabling tunnel encryption is a disruptive operation. Existing tunnels are deleted and re-established during the change. It is recommended to perform this action during scheduled maintenance windows to avoid service interruptions.
  • When encryption is enabled, NAT-T is automatically activated to support encrypted traffic traversal across NAT devices.
  • Tunnel maximum transmission unit (MTU) is reduced when encryption is enabled, due to additional ESP overhead for IPSec encryption. This may affect throughput and fragmentation behavior.
  • Only one IPSec profile can be associated per tunnel profile. Multiple IPSec profiles per tunnel are not supported.
  • Dead Peer Detection (DPD) is enabled by default to monitor peer availability and automatically recover from link failures. The default timeout value is 60 seconds. It is recommended to keep this option enabled.

Limitations

Note the following limitations regarding this feature:

  • Encryption is not supported for the following:
    • PIN service tunnels
    • AP–Edge tunnels in Active-Backup (AB) HA mode
    • Edge–Edge tunnels in SD-LAN service
  • Certificate-based IKE authentication is not supported.
  • Only IKEv2 protocol is supported for key exchange; IKEv1 is not supported.
  • Only Encapsulating Security Payload (ESP) is supported for IPSec encryption; Authentication Header (AH) is not supported.
  • IPv4 is the only supported addressing format for tunnel endpoints; IPv6 is not supported.
  • L2oGRE tunnel type is not supported for encryption.
  • Encryption on the AP is handled through hardware cryptographic acceleration, while RUCKUS Edge processes encryption in software.

Best Practices

Retain the default profiles AES128GCM-PRFSHA256-MODP2048 and AES128GCM-MODP2048 unless higher-grade encryption (AES128-SHA384-ECP384) is explicitly required.

Prerequisites

This feature has no prerequisites to feature enablement or usage.