UAP Campus Fabric Designs
Let’s now review different campus fabric designs and examine how UAP operates within EVPN fabric topologies to enable microsegmentation.
The first topology is a campus EVPN multihoming design with two collapsed core switches forming both the spine and leaf layers of the EVPN fabric. The UAP-capable access switches connect to the collapsed core using LAG, while the EVPN side uses ESI-LAG.
It is important to note that the first EVPN layer, where the access switches connect, must also consist of UAP-capable switches. This requirement is not primarily for SGT enforcement, but because these switches must recognize UAP messages and propagate the related information into the EVPN fabric.
Figure : UAP Campus Fabric EVPN Multihoming

Again, to gain a deeper understanding of the flow of messages and how information is propagated in the EVPN fabric, we show the entire workflow for a wireless client on the Access1 switch and a wired client (not shown) attached to the Access2 switch within the same VLAN:
- In Steps 3 through 12, the administrator, typically through the Juniper Mist cloud, deploys the required configuration, including:
- UAP settings, such as the shared encryption key.
- GBP tag identification, whether assigned statically or dynamically.
- SGT enforcement on UAP-capable access switches.
- In Steps 13 through 24, you can see that UAP-capable switches identify the presence of a remote switch that is also UAP-capable through Juniper LLDP messages. Once this information has been exchanged, the switches are able to communicate using unicast UAP messages between them.
- In Steps 25 through 35, you see how the wireless client gets authenticated using EAP-TLS. When the final RADIUS access-accept message is received, the dynamic GBP tag to be assigned for the wireless client gets embedded and known to the AP.
- In Steps 35 through 37, you see the AP sending the L2 multicast message with the UAP update message to the locally attached access switch.
- In Steps 38 through 41, Access1 sends a unicast update to one of the collapsed core switches. That collapsed core switch then distributes the information across the EVPN fabric using its native mechanisms. In this example, ingress replication is enabled, so the MAC-to-GBP tag mapping is propagated through BGP.
- In Steps 42 through 43, the wireless client begins using the network and may attempt to communicate with devices in the same VLAN connected to Access2. As a result, Access2 learns a new MAC address but does not yet have the associated GBP tag in its local table.
- In Steps 44 through 46, Access2 sends a UAP lookup message into the network and receives the corresponding MAC-to-GBP mapping, which it stores in its local table.
- In Steps 47 through 48, both UAP-capable access switches now have the MAC-to-GBP mapping for the wireless client and can enforce traffic policies as it enters the wired network.
Figure : Call graph UAP Campus Fabric EVPN Multihoming wireless EAP-TLS

The following section presents the complete workflow for a wired client connected to the Access1 switch and a wired client attached to the Access2 switch, both residing within the same VLAN as part of an EVPN Multihoming fabric:
- In Steps 5 through 12, the administrator, typically through the Juniper Mist cloud, deploys the required configuration, including:
- UAP settings, such as the shared encryption key.
- GBP tag identification, whether assigned statically or dynamically.
- SGT enforcement on UAP-capable access switches.
- In Steps 13 through 24, you can see that UAP-capable switches identify the presence of a remote switch that is also UAP-capable through Juniper LLDP messages. Once this information has been exchanged, the switches are able to communicate using unicast UAP messages between them.
- In Steps 25 through 33, a wired client authenticates using MAB. The process is very similar to the EAP authentication described earlier. When the final RADIUS access-accept message is received, it includes the dynamic GBP tag to be assigned to the wired client which is then learned by the UAP-capable access switch.
- In Steps 34 through 37, Access1 sends a unicast update to one of the collapsed core switches. That collapsed core switch then distributes the information across the EVPN fabric using its native mechanisms. In this example, ingress replication is enabled, so the MAC-to-GBP tag mapping is propagated through BGP.
- In Steps 38 through 39, the wired client begins using the network and may attempt to communicate with devices in the same VLAN connected to Access2. As a result, Access2 learns a new MAC address but does not yet have the associated GBP tag in its local table.
- In Steps 40 through 42, Access2 sends a UAP lookup message into the network and receives the corresponding MAC-to-GBP mapping, which it stores in its local table.
- In Steps 43 through 44, both UAP-capable access switches now have the MAC-to-GBP mapping for the client and can enforce traffic policies as it enters the wired network.
Figure : Call graph UAP Campus Fabric EVPN Multihoming wired MAB

Similar to EVPN Multihoming, the same would happen when using one of the two campus fabric designs for core-distribution:
- CRB: Centrally-routed and bridged with gateways on the core
- ERB: Edge-routed and bridged with anycast gateways on the fabric edge
Figure : UAP Campus Fabric CRB and ERB

In an existing IP Clos fabric (topology not shown here), enabling UAP provides several additional capabilities on top of the already available GBP features. These benefits are achieved simply by upgrading the access switch firmware and deploying UAP-capable APs:
- Support for SGT enforcement policies based on destination IP prefixes.
- Propagation of GBP tags from UAP-capable APs to Juniper Networks® EX4400 and Juniper Networks® EX4100 switches acting as access switches within the IP Clos fabric.
Depending on customer requirements, Juniper Mist Edge can also be used to overlay AP traffic and perform wireless client breakout at a service block function within the fabric. In this design, the UAP-capable AP encapsulates L2 multicast UAP update and lookup messages inside the L2TPv3 tunnel toward the Juniper Mist Edge. The Juniper Mist Edge, positioned northbound of the fabric and connected to the service block function, forwards these messages when wireless client traffic is remotely broken out.
The switch connected to the Juniper Mist Edge must be UAP-capable. It not only needs to learn the MAC-to-GBP tag mapping for newly connected wireless clients, but also acts as the first SGT enforcement point within the EVPN fabric from the wireless client’s perspective.
Figure : UAP Campus Fabric Mist-Edge integration
