7.2 Wireless Forwarding Modes: Bridge vs Tunnel Mode

Key Takeaways

  • Bridge mode forwards client traffic directly onto the local access switch VLAN at the AP Ethernet port, minimizing latency and eliminating the need for centralized gateway hardware.

  • Tunnel mode carries client traffic from APs to an Aruba gateway cluster; AOS 10 campus APs build IPsec tunnels (signaling) and GRE tunnels (client data) to every gateway in the cluster, enabling centralized firewalling and roaming across Layer 3 boundaries.

  • Mixed forwarding deployments allow organizations to bridge non-sensitive, high-bandwidth traffic (such as Guest or IoT) locally while tunneling corporate and voice traffic to centralized gateways for inspection.

  • In an AOS 10 gateway cluster, the cluster leader publishes a bucket map, and each tunneled client is anchored to a User Designated Gateway (UDG) with a standby UDG chosen by hashing the client MAC address.

  • In AOS 10, Gateways are dedicated purely to data-plane policy enforcement and routing, completely freed from managing AP configurations or radio RF algorithms.

Last updated: October 2026

Wireless Forwarding Modes: Bridge vs Tunnel Mode

Quick Summary: In modern enterprise WLAN architectures, the control plane (managed by Aruba Central) is fully decoupled from the data forwarding plane. Network architects can configure traffic forwarding on a per-WLAN (per-SSID) basis using two primary modes: Bridge mode and Tunnel mode. Bridge mode provides local breakout directly onto the access switch VLAN, maximizing throughput and eliminating gateway dependencies. Tunnel mode carries client traffic to Aruba gateways, unlocking centralized Policy Enforcement Firewall (PEF) inspection, micro-segmentation, and seamless roaming across complex Layer 3 campus networks.


The Data Plane Architecture: Decoupling Forwarding from Control

One of the most powerful capabilities of Aruba wireless networks is forwarding flexibility. In traditional legacy networks, all traffic was forced through centralized controllers regardless of destination. In AOS 10, because management and control reside in Aruba Central, the data plane can be tailored specifically to the security and performance requirements of each individual SSID.

An administrator deploying an enterprise campus can choose between:

  • Bridge Mode (Local Breakout): Decentralized, distributed switching at the network edge.
  • Tunnel Mode (Gateway-Centric): Centralized encapsulation, stateful inspection, and policy enforcement.
  • Mixed Mode: Simultaneously running Bridge mode on select SSIDs and Tunnel mode on others from the very same physical access points.

Bridge Mode (Local Breakout Architecture)

In Bridge mode, the access point acts as an intelligent 802.11-to-802.3 bridge. When an associated client transmits an 802.11 wireless data frame, the AP immediately strips the wireless encapsulation, converts the frame into a standard IEEE 802.3 Ethernet frame, tags it with the configured VLAN ID, and forwards it directly out its physical Ethernet uplink port onto the access switch.

[Wireless Client] --(802.11)--> [Aruba AP] --(802.3 Tagged VLAN)--> [Access Switch] --> [Local Core / Internet]

Packet Flow and Operational Characteristics

  1. Local Switching: The access switch receives the tagged Ethernet frame on its switch port. All subsequent Layer 2 switching and Layer 3 routing occur within the local wired infrastructure.
  2. Default Gateway & DHCP: The client's default gateway resides on the local wired network (typically a Virtual Switching Framework [VSF] stack or a core switch Virtual Routing and Forwarding [VRF] interface). DHCP requests are serviced by local enterprise DHCP servers or local DHCP relay agents.
  3. VLAN Configuration Requirements: Because traffic breaks out locally, every VLAN associated with a Bridge-mode SSID must be configured and tagged on the upstream switch port connecting to the AP, as well as on all inter-switch trunks up to the default gateway.

Advantages of Bridge Mode

  • Zero Gateway Dependency: Operates without requiring Aruba Mobility Gateways or gateway hardware licenses, significantly reducing capital expenditure.
  • Minimal Latency & Maximum Throughput: Traffic takes the most direct physical path to local servers, printers, or direct internet breakouts, avoiding trombone routing across WAN or campus core links.
  • Optimized WAN Bandwidth: In distributed branch or retail deployments, high-bandwidth traffic (such as video streaming or cloud SaaS applications) exits straight to the local ISP router rather than congesting enterprise WAN or VPN circuits.
  • Complete Branch Survivability: If WAN connectivity to corporate headquarters or the cloud drops, local clients continue to communicate with local servers, printers, and checkout registers without interruption.

Ideal Use Cases for Bridge Mode

  • Distributed remote branch offices and retail stores.
  • High-density student dormitories, hotel guest rooms, or public venues where traffic primarily targets the public Internet.
  • Environments with limited WAN bandwidth or where local peer-to-peer traffic (e.g., local video rendering or storage) dominates.

Tunnel Mode (Centralized Gateway Forwarding)

In Tunnel mode, client traffic is not placed onto the local access switch VLAN. Instead, the access point carries the client's frames to an Aruba gateway cluster (for example 7000, 7200, 9000, 9100, or 9200 Series gateways using the Mobility persona). In AOS 10, each campus AP builds an IPsec tunnel and a GRE tunnel to every gateway in the cluster, orchestrated by Central: IPsec carries device signaling and broadcast/multicast toward clients, and GRE carries client unicast traffic (AOS 10 TechDocs, "Cluster roles").

[Wireless Client] --(802.11)--> [Aruba AP] ==(GRE Tunnel over L3 Network)==> [Aruba Gateway] --> [PEF / Core]

Packet Flow and Operational Characteristics

  1. Encapsulated Transport: The AP encapsulates client frames in GRE packets addressed to the client's anchor gateway. To the intermediate access and distribution switches, this traffic appears simply as standard unicast IP packets traversing the AP's management VLAN.
  2. Switch Port Simplicity: The access switch port connected to the AP requires only the AP management VLAN. The client VLANs (e.g., VLAN 10 for Corporate, VLAN 20 for Voice) do not exist on the access switch or distribution trunks; they exist exclusively inside the GRE tunnel and at the Gateway!
  3. Centralized Decapsulation: The Aruba Gateway decapsulates the GRE packet, recovers the inner client frame, and processes it through the Policy Enforcement Firewall (PEF).
  4. Role-Based Inspection: The Gateway inspects traffic bidirectionally at Layers 4 through 7 using stateful packet inspection, deep packet inspection (DPI) application identification, and web content filtering before forwarding the frame onto the campus core network.

Key Advantages of Tunnel Mode

  • Centralized Security Enforcement (Zero Trust): The Policy Enforcement Firewall (PEF) enforces stateful role-based access control. Unauthorized east-west traffic between clients on the same subnet is blocked at the gateway firewall level.
  • Seamless Layer 2 Mobility Across Layer 3 Boundaries: In a large campus where access switches are separated by routed Layer 3 boundaries, a wireless client can roam across dozens of buildings. Because client traffic is tunneled back to the central gateway cluster, the client retains its original IP address, default gateway, and open TCP/UDP sessions without requiring complex mobile IP protocols.
  • Dynamic Segmentation Integration: Enables uniform policy enforcement across both wired and wireless users. Wired switch ports can tunnel traffic to the same Gateway cluster using User-Based Tunneling (UBT), ensuring consistent security policies regardless of connection medium.
  • Simplified Wired Switch Configuration: Eliminates the need to prune, trunk, and manage dozens of user VLANs across hundreds of edge access switches.

Mixed-Mode Deployments: Balancing Performance and Security

AOS 10 allows network engineers to combine both forwarding models on the same physical access point simultaneously on a per-SSID basis:

                           +-----------------------------------+
                           |          Aruba Access Point       |
                           +-----------------------------------+
                                   /                   \
                                  /                     \
         [Corporate-SSID: Tunnel Mode]       [Guest-SSID: Bridge Mode]
                                /                         \
                       (GRE Tunnel)                     (Local L2)
                              /                             \
                             v                               v
                  +---------------------+          +-------------------+
                  | Aruba Gateway       |          | Access Switch     |
                  | (PEF Inspection,    |          | VLAN 500          |
                  | Micro-segmentation) |          | (Direct Internet) |
                  +---------------------+          +-------------------+

In this highly popular hybrid deployment:

  • SSID 1: "Corp-Secure" (Tunnel Mode): Employee laptops and confidential corporate devices are tunneled to the campus Gateway cluster. All traffic undergoes stateful PEF inspection, application filtering, and micro-segmentation, preserving enterprise data integrity.
  • SSID 2: "Guest-Internet" (Bridge Mode): Guest visitors and personal devices break out locally onto a dedicated guest VLAN (e.g., VLAN 500) directly at the access switch. This traffic bypasses the Gateway cluster entirely, saving gateway compute resources, reducing campus core traffic, and routing guest web browsing straight to the internet firewall.

Aruba Gateway Clustering and High Availability

When deploying Tunnel mode in enterprise environments, the Aruba Gateway must not become a single point of failure or performance bottleneck. AOS 10 solves this through Aruba Gateway Clustering.

Cluster Architecture and Operational Mechanisms

  • A cluster of one or more gateways: Even a single gateway is treated as a cluster in AOS 10. One gateway is elected cluster leader; it assigns roles and computes the bucket map.
  • Device Designated Gateway (DDG): Each AP is assigned a DDG and a standby DDG. The DDG publishes the bucket map to the AP and forwards broadcast and multicast traffic toward that AP's clients.
  • User Designated Gateway (UDG): Each tunneled client is anchored to a UDG and a standby UDG (S-UDG). The AP hashes the last three bytes of the client MAC address (an index from 0 to 255) into the bucket map to find them, so a client keeps the same anchor gateway as it roams between APs.
  • Failover: If a gateway fails or is taken down for maintenance, the standby takes over the designated role and the leader publishes a new bucket map. Assignments are event driven; AOS 10 does not periodically rebalance.
  • When gateways are needed: HPE recommends or requires gateways when a roaming domain exceeds about 500 APs or 5,000 clients, when user VLANs cannot be extended between APs, for Layer 3 mobility, for a RADIUS proxy, and for Dynamic Segmentation of wired UBT users.

The Role of Gateways in AOS 10

It is critical to recognize how the role of the Gateway has changed in AOS 10 compared to AOS 8:

  • In AOS 8, the Mobility Controller handled AP configurations, firmware images, and radio RF settings.
  • In AOS 10, the Gateway is dedicated purely to data-plane traffic enforcement, routing, and tunneling. It does not manage AP configurations, RF parameters, or AP firmware; those responsibilities belong entirely to Aruba Central.

Detailed Comparison: Bridge Mode vs Tunnel Mode

Feature / AttributeBridge ModeTunnel Mode
Data Forwarding PathLocal breakout directly at the AP Ethernet port onto access switchGRE (data) and IPsec (signaling) tunnels to every gateway in the cluster
Gateway Hardware RequiredNo (functions entirely with APs and switches)Yes (requires Aruba Mobility / Campus Gateways)
Firewall Inspection LocationDistributed basic ACLs at AP or upstream switch routerCentralized stateful Policy Enforcement Firewall (PEF) at Gateway
VLAN Requirements at Access SwitchClient VLANs must be created and tagged on all switch ports and trunksOnly AP management VLAN is required on access switch ports
Layer 2 Roaming ScopeLimited to contiguous Layer 2 broadcast domainsCampus-wide across routed Layer 3 boundaries
WAN / Uplink ImpactConserves WAN; local traffic remains localTransports all client traffic back to centralized gateway
Dynamic Segmentation SupportLimited to local switch ACL enforcementFull integration with ClearPass and User-Based Tunneling (UBT)
High-Availability MechanismUpstream switch redundancy (VSF / VSX / STP)Gateway cluster with designated and standby roles (UDG/S-UDG)

Common Exam Traps

  • The All-or-Nothing Trap: Believing that an access point must operate either entirely in Bridge mode or entirely in Tunnel mode. Aruba APs support mixed-mode deployments, allowing different SSIDs on the same physical radio to use different forwarding modes simultaneously.
  • Access Switch VLAN Pruning: Assuming that client VLANs must be configured on access switches for Tunnel-mode SSIDs. In Tunnel mode, the access switch only needs the AP management VLAN; client VLANs live on the gateway cluster.
  • AOS 10 Gateway Role: Thinking that an Aruba Gateway in AOS 10 configures AP radios or pushes WLAN profiles. In AOS 10, the Gateway is purely a data-plane policy and routing enforcement engine; Aruba Central handles all configuration and RF control.
Loading diagram...
Traffic Flow Comparison: Bridge Mode Local Breakout vs Tunnel Mode Gateway Inspection
Test Your Knowledge

A network engineer is designing a wireless infrastructure for a large hospital campus. Medical monitoring carts frequently roam across four separate multi-story buildings that are interconnected by a routed Layer 3 campus backbone. The carts require uninterrupted clinical application sessions, static IP persistence, and rigorous stateful Layer 4-7 firewall inspection between endpoints. Which forwarding mode should be selected for the clinical SSID?

A

Bridge mode, because local access switches can then route clinical traffic without passing through any central appliance

B

Mixed mode, with half of the APs configured in bridge mode and the other half in tunnel mode for redundancy

C

Tunnel mode to a gateway cluster, keeping client IPs and sessions across buildings with PEF firewall policy

D

Local breakout using 802.1Q sub-interfaces on each floor's access switch stack to keep client VLANs local

Test Your Knowledge

In an AOS 10 deployment with a four-gateway cluster, how is a tunneled wireless client protected against the failure of the gateway that anchors its traffic?

A

The client must re-run DHCP and 802.1X authentication on a different SSID served by another gateway

B

The access switch uses spanning tree to move the AP's management IP address to a surviving gateway

C

Each client has a UDG and a standby UDG from the cluster's bucket map; the standby takes over

D

The AP immediately switches the SSID to bridge mode until the failed gateway reboots and rejoins

Test Your Knowledge

When configuring an access switch port that connects directly to an Aruba access point providing Tunnel-mode wireless services, what is a key configuration requirement regarding VLANs on that switch port?

A

The port must run Dynamic Trunking Protocol (DTP) to negotiate VLAN membership with the AP automatically

B

Only the AP's management VLAN is needed on the port, because tunneled client traffic is carried to the gateway

C

The port must be an untagged access port in the highest-numbered client VLAN served by the SSIDs

D

All client data VLANs (such as Corporate, Voice, and IoT) must be created and tagged on the AP's switch port

Sections you finish are checked off in the contents.