Enabling GRE over IPsec for Tunnel and Mixed Modes

The Tunnel Orchestrator service establishes either IPsec Internet Protocol security. IPsec is a protocol suite for secure IP communications that authenticates and encrypts each IP packet in a communication session. tunnels or GRE Generic Routing Encapsulation. GRE is an IP encapsulation protocol that is used to transport packets over a network. tunnels between the access point (AP) and each of the Gateways present in the cluster. The IPsec tunnels provide end-to-end encryption of data traffic between the AP and the Gateway cluster. Based on the tunnel type to client's UAC, the AP can encapsulate client traffic in either GRE over IPsec or GRE without IPsec.

To configure secure data tunnels between AP and Gateway cluster, complete the following steps:

  1. In the WebUI, set the filter to a group that contains at least one AP.
    The dashboard context for the group is displayed.
  2. Under Manage, click Devices > Access Points.
  3. Click the Config icon.
    The tabs to configure APs are displayed.
  4. Click Show Advanced, and click the Security tab.
    The Security details page is displayed.
  5. Click the Data Handling accordion.
  6. To enable IPsec tunnel for data traffic, turn on the Data Encryption toggle button.
  7. Click Save Settings.

The Data Encryption toggle button is disabled by default. When this toggle button is enabled, the AP sends client traffic to Gateway through GRE over IPsec. When this toggle button is disabled, the AP sends client traffic to Gateway through GRE only.