9.4 Dynamic Segmentation, User-Based Tunneling, and Policy Enforcement
Key Takeaways
Aruba Dynamic Segmentation unifies policy enforcement across wired and wireless campus networks, centralizing traffic inspection and micro-segmentation on Aruba Gateways.
User-Based Tunneling (UBT) establishes GRE tunnels from AOS-CX access switches to Aruba Gateways, selectively encapsulating client traffic based on authenticated user roles.
Unlike Port-Based Tunneling (PBT) which tunnels all port traffic indiscriminately, UBT provides granular, per-user forwarding decisions on shared switch ports.
The centralized Policy Enforcement Firewall (PEF) delivers stateful Layer 4-7 firewalling, deep packet inspection (DPI), web filtering, and intra-VLAN micro-segmentation directly on Aruba Gateways.
Dynamic Segmentation eliminates hop-by-hop VLAN provisioning and complex distributed ACLs across access switches, simplifying campus network architecture while enforcing Zero Trust security.
Dynamic Segmentation, User-Based Tunneling, and Policy Enforcement
Quick Summary: In traditional campus networks, securing diverse endpoints requires sprawling VLAN architectures, complex spanning tree topologies, and unwieldy access control lists distributed across hundreds of edge switches. Aruba Dynamic Segmentation eliminates this operational complexity by extending the centralized security model of wireless controllers to the wired access layer. Using User-Based Tunneling (UBT), AOS-CX switches encapsulate authenticated client traffic inside Generic Routing Encapsulation (GRE) tunnels and forward it directly to Aruba Gateways. At the gateway, the centralized Policy Enforcement Firewall (PEF) applies stateful Layer 4–7 inspection, application visibility, and micro-segmentation, delivering robust Zero Trust security regardless of physical connection points.
The Limitations of Traditional Campus Segmentation
For decades, campus networks segregated traffic using physical topology and manual configuration. This legacy model has reached an architectural breaking point in the modern enterprise:
- VLAN Sprawl: Supporting guest users, contractors, corporate laptops, VoIP phones, facilities systems, and IoT devices requires dozens of distinct VLANs. These VLANs must be manually defined and tagged across access, aggregation, and core switches, inflating spanning tree instances and operational overhead.
- Distributed and Static ACL Management: Enforcing security at the access layer forces administrators to configure complex Access Control Lists (ACLs) switch by switch. Updating a single security rule across an enterprise campus requires touching dozens or hundreds of devices, creating configuration drift and security blind spots.
- The IoT Coexistence Dilemma: When an IP camera or smart thermostat connects to an access switch, placing it in a shared VLAN exposes adjacent corporate workstations if that IoT device is compromised. Standard Layer 2 switches cannot restrict communication between two devices residing within the same VLAN without private VLANs or router hairpinning.
- Wired vs. Wireless Disparity: While wireless users benefit from centralized controllers that enforce stateful firewall policies and deep packet inspection, wired switch ports remain constrained by rigid, stateless Layer 2/Layer 3 packet filters.
Aruba Dynamic Segmentation Architecture
Dynamic Segmentation solves these challenges by decoupling logical security policy from physical network topology. Instead of configuring VLANs and ACLs on every intermediate switch, the campus network is split into two distinct planes:
+---------------------------------------------------------------------------------------------------------+
| ARUBA DYNAMIC SEGMENTATION ARCHITECTURE |
| |
| [ Wired Endpoints ] [ AOS-CX Access Switch ] [ Aruba Gateway Cluster ] |
| - Corporate PC ==== Auth ===> Assigns User Role Runs Policy Enforcement |
| - IoT Camera Decides Forwarding: Firewall (PEF) |
| - Guest User - Local Switching OR - Stateful L4-L7 DPI |
| - UBT GRE Tunnel === Routed Core ==> - AppRF & Web Filtering |
| - Micro-Segmentation |
| ^ ^ |
| | | |
| +------- ClearPass Policy Manager ------+ |
| (Pushes Unified Roles) |
+---------------------------------------------------------------------------------------------------------+
The Three Core Architectural Components
- AOS-CX Access Switches: Edge switches (such as the CX 6200 and CX 6300 series) authenticate connecting devices via 802.1X, MAC-Auth, or Captive Portal. Based on the assigned user role from ClearPass, the switch acts as a Tunnel Endpoint, encapsulating client frames into GRE tunnels directed toward the gateway.
- Aruba Gateways (Mobility Controllers / Branch Gateways): Centralized appliances (such as the 7000 or 7200 series, or 9000/9200 series) that terminate GRE tunnels. Gateways act as the Layer 3 default gateway for tunneled clients and inspect all traffic using an integrated stateful firewall.
- ClearPass Policy Manager (CPPM): Acts as the centralized policy authority, evaluating endpoint context and assigning consistent user roles across both wired switch ports and wireless SSIDs.
Decoupling the Core
In a Dynamic Segmentation deployment, intermediate distribution and core switches operate purely as a routed IP transport network. Core switches route the outer GRE transport packets between access switches and gateways; they do not need to know about client VLANs, user MAC addresses, or application firewall policies. This drastically simplifies the campus core.
User-Based Tunneling (UBT) Mechanics
User-Based Tunneling (UBT) is the foundational protocol mechanism of Dynamic Segmentation on AOS-CX switches. Client traffic is encapsulated using Generic Routing Encapsulation (GRE, IP Protocol 47).
Port-Based vs. User-Based Tunneling
It is essential to contrast UBT with legacy Port-Based Tunneling (PBT):
| Technical Dimension | Port-Based Tunneling (PBT) | User-Based Tunneling (UBT) |
|---|---|---|
| Granularity | Physical port level; all or nothing | User / client level; identity-driven |
| Authentication Trigger | None required; tunnels entire physical port immediately | Triggered by 802.1X, MAC-Auth, or Captive Portal authentication |
| Multi-Device Ports | Cannot differentiate multiple devices on a single port | Distinct devices on the same physical port receive different forwarding policies |
| Traffic Forwarding | All traffic is forced into the tunnel | Can selectively tunnel some users while locally switching others on the same port |
Real-World UBT Multi-Client Scenario
Consider an enterprise desk where an IP Phone connects to switch port 1/1/10, and a corporate laptop is daisy-chained into the secondary PC port on the back of the phone:
- The IP phone authenticates via MAC Authentication. ClearPass assigns a local voice role. The AOS-CX switch bridges phone traffic locally onto the campus voice VLAN for low-latency routing.
- The corporate laptop authenticates via 802.1X. ClearPass assigns a tunneled corporate role. The AOS-CX switch encapsulates the laptop's frames into a GRE tunnel directed to the Aruba Gateway.
- Both devices share a single physical switch interface, yet their traffic paths are completely segregated based on identity.
Gateway Clustering and High Availability
UBT supports gateway clustering for campus resiliency. An AOS-CX switch is configured with a primary controller IP and a backup controller IP. In AOS 10, the switch's initial Switch Designated Gateway (SDG) is the primary controller IP it reaches first, the cluster leader assigns a standby SDG, and each UBT client is anchored to a User Designated Gateway (UDG) with a standby UDG, so the cluster can absorb a node failure.
Centralized Policy Enforcement Firewall (PEF)
Once client frames emerge from the GRE tunnel at the Aruba Gateway, they are processed by the Policy Enforcement Firewall (PEF). PEF is a stateful Layer 4–7 deep-inspection engine built into the gateway firmware.
Key Capabilities of PEF
- Stateful Inspection: Unlike stateless switch ACLs that inspect individual packets in isolation, PEF tracks the full state of bidirectional connections (TCP sequence numbers, handshakes, timeouts), preventing spoofing and unestablished inbound connections.
- Deep Packet Inspection (DPI) & AppRF: PEF identifies thousands of applications regardless of port or protocol. For example, if a user runs BitTorrent over TCP port 443 (standard HTTPS), PEF inspects the packet payload, recognizes the BitTorrent protocol signature, and applies bandwidth restrictions or drops the session.
- Application Visibility and Control: Administrators can prioritize critical collaboration tools (such as Microsoft Teams or Zoom) using Quality of Service (QoS) tagging, while rate-limiting or blocking recreational streaming and social media.
- Web Content Classification & Reputation: The gateway leverages real-time cloud threat intelligence to categorize external URLs into security tiers (e.g., Gambling, Malware, Phishing), blocking dangerous traffic before it enters the enterprise WAN.
- Micro-Segmentation (Intra-VLAN Role Isolation): In a standard subnet, two hosts can communicate freely at Layer 2. PEF breaks this paradigm: even if two endpoints belong to the exact same IP subnet and VLAN, PEF enforces role-to-role firewall rules. A contractor laptop cannot communicate with an adjacent corporate laptop, and an IoT smart TV cannot access a nearby security camera, eliminating lateral threat traversal.
Integration with SD-Branch and Aruba Central
Dynamic Segmentation scales from corporate headquarters to distributed branch offices:
- SD-Branch Gateways: Aruba Branch Gateways (BGWs) deployed at remote retail stores or medical clinics terminate UBT tunnels locally. Branch access switches tunnel point-of-sale terminals and guest Wi-Fi to the local branch gateway, enforcing consistent corporate security policies at remote sites.
- Aruba Central Cloud Orchestration: Using Aruba Central, network engineers manage the entire Dynamic Segmentation fabric from a single pane of glass. Administrators configure UBT zones, push global user roles, monitor real-time client sessions, and review AI-driven application telemetry across wired and wireless infrastructure.
AOS-CX UBT Configuration Commands and Verification
The following configuration session demonstrates configuring a UBT zone to an Aruba Gateway cluster, creating a tunneled user role, and applying it to an edge interface:
switch# configure terminal
! Step 1: UBT client VLAN and UBT zone (shown as it appears in show running-config ubt)
ubt-client-vlan 3000
ubt zone CAMPUS-ZONE vrf default
primary-controller ip 10.200.1.100
backup-controller ip 10.200.1.101
enable
! Step 2: Configure a Tunneled User Role matching the Gateway Role
switch(config)# port-access role Tunneled-Employee-Role
switch(config-pa-role)# gateway-zone zone CAMPUS-ZONE gateway-role Corp-User-Policy
switch(config-pa-role)# exit
! Step 3: Configure a Locally Switched Role for Comparison
switch(config)# port-access role Local-Printer-Role
switch(config-pa-role)# vlan access 30
switch(config-pa-role)# exit
! Step 4: Configure an Edge Interface for Authenticated Access
switch(config)# interface 1/1/20
switch(config-if)# description Desk-Workstation
switch(config-if)# no routing
switch(config-if)# aaa authentication port-access dot1x authenticator enable
switch(config-if)# exit
Essential Verification Commands
| Command | Output and Operational Purpose |
|---|---|
show ubt | Displays the UBT configuration and zone settings. |
show ubt state | Displays the state of the UBT zone and its connection to the primary and backup gateways. |
show ubt users | Lists clients currently tunneled with UBT and their gateway roles. |
show ubt statistics | Displays UBT packet and tunnel counters. |
Common Exam Traps
- UBT vs. PBT Distinction: The exam frequently tests the difference between tunneling an entire physical switch port indiscriminately (Port-Based Tunneling) versus tunneling traffic conditionally based on authenticated user identity (User-Based Tunneling).
- Encapsulation Protocol: Remember that UBT utilizes Generic Routing Encapsulation (GRE, IP protocol 47) between the AOS-CX switch and the Aruba Gateway, not VXLAN or IPsec.
- Core Network Agnosticism: Core and aggregation switches do not need to support UBT, GRE termination, or special firewall software. They simply route standard IP packets between the access switch IP and the gateway IP.
- Policy Enforcement Locus: In a UBT deployment, while the access switch initiates the GRE tunnel, the stateful Layer 4–7 firewall policies (
gateway-role) are enforced centrally on the Aruba Gateway, not in access switch ASICs.
What is the key architectural difference between User-Based Tunneling (UBT) and Port-Based Tunneling (PBT) on Aruba AOS-CX switches?
UBT tunnels traffic per authenticated user role, whereas PBT tunnels everything arriving on a port
PBT encrypts tunneled traffic with IPsec, whereas UBT forwards everything over unencrypted Layer 2 trunks
UBT is supported only on wireless access points, whereas PBT is supported only on modular chassis switches
PBT requires ClearPass Policy Manager, whereas UBT works only with local switch user accounts and roles
Which encapsulation protocol is established between an Aruba AOS-CX access switch and an Aruba Gateway to carry client traffic in a User-Based Tunneling (UBT) deployment?
Layer 2 Tunneling Protocol Version 3 (L2TPv3) using IP protocol 115
Virtual Extensible LAN (VXLAN) using UDP port 4789
Point-to-Point Protocol over Ethernet (PPPoE) using EtherType 0x8864
Generic Routing Encapsulation (GRE) using IP protocol 47
How does the Policy Enforcement Firewall (PEF) on an Aruba Gateway enforce micro-segmentation for clients connected via Dynamic Segmentation?
By physically disabling access switch ports whenever two endpoints attempt to communicate at once
By applying stateful role-based firewall policy between user roles, even within the same subnet
By requiring all endpoints to configure static IP routes pointing to external cloud proxy servers
By converting all IPv4 client packets into IPv6 link-local addresses before evaluating routing headers
Sections you finish are checked off in the contents.