IPsec/IKE Encryption Support for VxLAN-GPE Tunnel
VxLAN-GPE tunnels between access points (APs) and RUCKUS Edge devices support IPsec/IKE-based encryption, providing secure transport for VxLAN tunnel traffic. This enhancement ensures data confidentiality and integrity, particularly in distributed deployments where APs and Edge devices operate across different subnets or geographic regions. The encryption of VxLAN‑GPE tunnel traffic can be enabled or disabled.
Feature Overview
Encryption is supported for VxLAN-GPE tunnels used in SD-LAN services on Active-Active (AA) RUCKUS Edge clusters, providing secure and reliable communication across public networks. The implementation uses IKEv2 with pre-shared key (PSK) authentication and predefined proposals to simplify configuration and ensure interoperability.
Encrypted tunnels maintain full support for high-availability operations, including AP failover and fallback, allowing seamless transitions between primary and backup Edge nodes without disrupting connectivity or requiring changes to tunnel logic.
Requirements
Following are the requirements for enabling or using this feature:
Considerations
Consider the following when configuring and using this feature:
- VxLAN-GPE tunnel encryption is based on IKE (specifically, IKEv2) and IPsec Encapsulating Security Payload (ESP) protocols operating in Transport mode. Both IKE and ESP Security Associations (SAs) support time-based rekeying with configurable lifetimes.
- Enabling or disabling tunnel encryption is a disruptive operation. Existing tunnels are deleted and re-established during the change. It is recommended to perform this action during scheduled maintenance windows to avoid service interruptions.
- When encryption is enabled, NAT-T is automatically activated to support encrypted traffic traversal across NAT devices.
- Tunnel maximum transmission unit (MTU) is reduced when encryption is enabled, due to additional ESP overhead for IPSec encryption. This may affect throughput and fragmentation behavior.
- Only one IPSec profile can be associated per tunnel profile. Multiple IPSec profiles per tunnel are not supported.
- Dead Peer Detection (DPD) is enabled by default to monitor peer availability and automatically recover from link failures. The default timeout value is 60 seconds. It is recommended to keep this option enabled.
Limitations
Note the following limitations regarding this feature:
- Encryption is not supported for the following:
- Certificate-based IKE authentication is not supported.
- Only IKEv2 protocol is supported for key exchange; IKEv1 is not supported.
- Only Encapsulating Security Payload (ESP) is supported for IPSec encryption; Authentication Header (AH) is not supported.
- IPv4 is the only supported addressing format for tunnel endpoints; IPv6 is not supported.
- L2oGRE tunnel type is not supported for encryption.
- Encryption on the AP is handled through hardware cryptographic acceleration, while RUCKUS Edge processes encryption in software.
Best Practices
Retain the default profiles AES128GCM-PRFSHA256-MODP2048 and AES128GCM-MODP2048 unless higher-grade encryption (AES128-SHA384-ECP384) is explicitly required.
Prerequisites
This feature has no prerequisites to feature enablement or usage.