SoftGRE Tunneling Support
Feature Overview
- What is the name of the
feature? (What do users call the feature? If the feature is referred to by
an acronym, what is the acronym expansion? What is the formal name to be
used in documentation?)
Note: Typically, the name is used as part of the section titles, such as the overview title and the configuration section titles.
- Where does the feature fit within our taxonomy? (What are the taxonomy group and sub-group? This information is important for categorizing the feature documentation and incorporating it into the existing document sets.)
- What standard or standards govern the feature? (Sometimes needed.)
- Is the feature a new feature or an enhancement to an existing feature?
- Does the feature replace another feature?
- What does the feature do? (General description)
- How does the feature benefit the user?
- What set of terms do the writer and reader need to know to understand the feature and its use?
- How does the feature work? (Detailed description, if needed.)
This technique encapsulates the original data packets within GRE packets, creating a virtual point-to-point link over the existing network infrastructure, which adds security and enables centralized traffic distribution by establishing a tunnel from the APs to a SoftGRE gateway.
Managing and directing traffic efficiently is crucial for maintaining optimal network performance. SoftGRE tunneling plays a pivotal role in achieving this by encapsulating data packets and transmitting them over various network types.
The SoftGRE Tunneling Support feature allows you to:
- Create a SoftGRE tunnel profile
- Bind the profile to a specific venue and Wi-Fi network for tunneling AP traffic to a SoftGRE gateway
- Enable a SoftGRE tunnel profile on an Ethernet port and apply an Internet Protocol Security (IPsec) profile to the SoftGRE tunnel for added security (this configuration is supported only on Passphrase (PSK/SAE) Wi-Fi networks)
Following are the benefits:
- Enhanced flexibility: Adaptability to different network environments to work with various types of networks.
- Centralized traffic management and efficiency: Centralized control of network traffic, enabling more efficient and consistent application of network policies.
- Enhanced security: Secure encrypted communication over an Internet Protocol network.
- Improved resilience: Supports automatic gateway failover and fallback to maintain uninterrupted AP connectivity.
Requirements
This feature has no special hardware or software requirements for feature enablement or usage.
If there are no requirements, use the following default wording:
This feature has no special hardware or software requirements for feature enablement or usage.
If there are requirements, include the applicable below points (depending on product line):
- What releases support the
feature?
Note: Typically, this is not documented in the configuration guides; however, we need to know where to include the information.
- What hardware models support the feature?
- Does the feature require specific modules?
- Does the feature run only on certain ports?
- Does the feature have special memory requirements?
- In an integrated system, can the feature be managed or configured from another device? What are the related release and system requirements?
- Does the feature introduce new user requirements?
- Does the feature introduce physical or location-based requirements?
Considerations
- A maximum of 64 SoftGRE tunnel profiles can be created per RUCKUS One tenant account, but only three can be enabled per venue and only one enabled per Wi-Fi network.
- A venue supports up to three SoftGRE activated profiles without IPsec or one SoftGRE profile with IPsec.
- Each SoftGRE profile name must be unique.
- All the gateway addresses in the enabled SoftGRE profiles must be different, including primary and secondary gateway IP addresses in a single SoftGRE profile.
- SoftGRE tunneling is not supported on a Captive Portal network.
- Network Address Translation (NAT) is not supported because SoftGRE does not use
higher-layer protocols such as UDP or TCP, which typically precede GRE in the
networking stack.
ACX-71979
- SoftGRE clients cannot ping each other, regardless of being connected through different APs, if they are associated with the same SoftGRE gateway within the same VLAN.
- A SoftGRE profile cannot be deleted after it is activated in a venue.
- Client Isolation setting at the venue, network, and AP port levels works as expected when SoftGRE tunnel is configured.
- VLAN setting at the venue, AP port () and network levels ( tab) works as expected when SoftGRE tunnel is configured.
If there are no considerations, use the following default wording:
This feature has no special considerations or limitations pertaining to feature enablement or usage.
If there are considerations, include the applicable below points (depending on product line).
- Does the feature replace an existing feature?
- Does the feature work only with a certain protocol or with a limited set of protocols?
- Is the feature meant to be used in combination with another feature or a set of features?
- Is the feature incompatible with any features?
- What happens when the feature is enabled?
- What happens when the feature is disabled?
- Does enabling/disabling the feature enable/disable another feature?
- What system behavior changes, if any, does the feature introduce?
- Are performance issues associated with the feature? How can these be mitigated?
Limitations
The configuration of SoftGRE tunneling secured using IPsec is applicable only on APs in a Passphrase (PSK/SAE) Wi-Fi network.
Best Practices
This feature has no special recommendations for feature enablement or usage.
If there are no best practices (recommendations), use the following default wording:
This feature has no special recommendations for feature enablement or usage.
If there are considerations, include the applicable below points (depending on product line).
Prerequisites
To implement an IPsec-secured SoftGRE tunnel on an Ethernet port for an AP, the Ethernet port must first be enabled on the AP.
If there are no prerequisites, use the following default wording:
This feature has no prerequisites to feature enablement or usage.
If there are prerequisites, include the applicable below points (depending on product line).
The intention of this new template is to outline the information that you will need to collect from SMEs and provide to readers.
NOTE: Feature Configuration / Troubleshooting are *not* part of the Feature Concept template. These templates are likely to be part of separate task/reference templates (to be developed).