9.4 Dynamic Segmentation, User-Based Tunneling, and Policy Enforcement

Key Takeaways

  • Aruba Dynamic Segmentation unifies policy enforcement across wired and wireless campus networks, centralizing traffic inspection and micro-segmentation on Aruba Gateways.

  • User-Based Tunneling (UBT) establishes GRE tunnels from AOS-CX access switches to Aruba Gateways, selectively encapsulating client traffic based on authenticated user roles.

  • Unlike Port-Based Tunneling (PBT) which tunnels all port traffic indiscriminately, UBT provides granular, per-user forwarding decisions on shared switch ports.

  • The centralized Policy Enforcement Firewall (PEF) delivers stateful Layer 4-7 firewalling, deep packet inspection (DPI), web filtering, and intra-VLAN micro-segmentation directly on Aruba Gateways.

  • Dynamic Segmentation eliminates hop-by-hop VLAN provisioning and complex distributed ACLs across access switches, simplifying campus network architecture while enforcing Zero Trust security.

Last updated: October 2026

Dynamic Segmentation, User-Based Tunneling, and Policy Enforcement

Quick Summary: In traditional campus networks, securing diverse endpoints requires sprawling VLAN architectures, complex spanning tree topologies, and unwieldy access control lists distributed across hundreds of edge switches. Aruba Dynamic Segmentation eliminates this operational complexity by extending the centralized security model of wireless controllers to the wired access layer. Using User-Based Tunneling (UBT), AOS-CX switches encapsulate authenticated client traffic inside Generic Routing Encapsulation (GRE) tunnels and forward it directly to Aruba Gateways. At the gateway, the centralized Policy Enforcement Firewall (PEF) applies stateful Layer 4–7 inspection, application visibility, and micro-segmentation, delivering robust Zero Trust security regardless of physical connection points.


The Limitations of Traditional Campus Segmentation

For decades, campus networks segregated traffic using physical topology and manual configuration. This legacy model has reached an architectural breaking point in the modern enterprise:

  • VLAN Sprawl: Supporting guest users, contractors, corporate laptops, VoIP phones, facilities systems, and IoT devices requires dozens of distinct VLANs. These VLANs must be manually defined and tagged across access, aggregation, and core switches, inflating spanning tree instances and operational overhead.
  • Distributed and Static ACL Management: Enforcing security at the access layer forces administrators to configure complex Access Control Lists (ACLs) switch by switch. Updating a single security rule across an enterprise campus requires touching dozens or hundreds of devices, creating configuration drift and security blind spots.
  • The IoT Coexistence Dilemma: When an IP camera or smart thermostat connects to an access switch, placing it in a shared VLAN exposes adjacent corporate workstations if that IoT device is compromised. Standard Layer 2 switches cannot restrict communication between two devices residing within the same VLAN without private VLANs or router hairpinning.
  • Wired vs. Wireless Disparity: While wireless users benefit from centralized controllers that enforce stateful firewall policies and deep packet inspection, wired switch ports remain constrained by rigid, stateless Layer 2/Layer 3 packet filters.

Aruba Dynamic Segmentation Architecture

Dynamic Segmentation solves these challenges by decoupling logical security policy from physical network topology. Instead of configuring VLANs and ACLs on every intermediate switch, the campus network is split into two distinct planes:

+---------------------------------------------------------------------------------------------------------+
|                                 ARUBA DYNAMIC SEGMENTATION ARCHITECTURE                                 |
|                                                                                                         |
|     [ Wired Endpoints ]               [ AOS-CX Access Switch ]              [ Aruba Gateway Cluster ]   |
|      - Corporate PC    ==== Auth ===>   Assigns User Role                     Runs Policy Enforcement   |
|      - IoT Camera                        Decides Forwarding:                   Firewall (PEF)           |
|      - Guest User                        - Local Switching OR                  - Stateful L4-L7 DPI     |
|                                          - UBT GRE Tunnel === Routed Core ==>  - AppRF & Web Filtering  |
|                                                                                - Micro-Segmentation     |
|                                                  ^                                       ^              |
|                                                  |                                       |              |
|                                                  +------- ClearPass Policy Manager ------+              |
|                                                            (Pushes Unified Roles)                       |
+---------------------------------------------------------------------------------------------------------+

The Three Core Architectural Components

  1. AOS-CX Access Switches: Edge switches (such as the CX 6200 and CX 6300 series) authenticate connecting devices via 802.1X, MAC-Auth, or Captive Portal. Based on the assigned user role from ClearPass, the switch acts as a Tunnel Endpoint, encapsulating client frames into GRE tunnels directed toward the gateway.
  2. Aruba Gateways (Mobility Controllers / Branch Gateways): Centralized appliances (such as the 7000 or 7200 series, or 9000/9200 series) that terminate GRE tunnels. Gateways act as the Layer 3 default gateway for tunneled clients and inspect all traffic using an integrated stateful firewall.
  3. ClearPass Policy Manager (CPPM): Acts as the centralized policy authority, evaluating endpoint context and assigning consistent user roles across both wired switch ports and wireless SSIDs.

Decoupling the Core

In a Dynamic Segmentation deployment, intermediate distribution and core switches operate purely as a routed IP transport network. Core switches route the outer GRE transport packets between access switches and gateways; they do not need to know about client VLANs, user MAC addresses, or application firewall policies. This drastically simplifies the campus core.


User-Based Tunneling (UBT) Mechanics

User-Based Tunneling (UBT) is the foundational protocol mechanism of Dynamic Segmentation on AOS-CX switches. Client traffic is encapsulated using Generic Routing Encapsulation (GRE, IP Protocol 47).

Port-Based vs. User-Based Tunneling

It is essential to contrast UBT with legacy Port-Based Tunneling (PBT):

Technical DimensionPort-Based Tunneling (PBT)User-Based Tunneling (UBT)
GranularityPhysical port level; all or nothingUser / client level; identity-driven
Authentication TriggerNone required; tunnels entire physical port immediatelyTriggered by 802.1X, MAC-Auth, or Captive Portal authentication
Multi-Device PortsCannot differentiate multiple devices on a single portDistinct devices on the same physical port receive different forwarding policies
Traffic ForwardingAll traffic is forced into the tunnelCan selectively tunnel some users while locally switching others on the same port

Real-World UBT Multi-Client Scenario

Consider an enterprise desk where an IP Phone connects to switch port 1/1/10, and a corporate laptop is daisy-chained into the secondary PC port on the back of the phone:

  1. The IP phone authenticates via MAC Authentication. ClearPass assigns a local voice role. The AOS-CX switch bridges phone traffic locally onto the campus voice VLAN for low-latency routing.
  2. The corporate laptop authenticates via 802.1X. ClearPass assigns a tunneled corporate role. The AOS-CX switch encapsulates the laptop's frames into a GRE tunnel directed to the Aruba Gateway.
  3. Both devices share a single physical switch interface, yet their traffic paths are completely segregated based on identity.

Gateway Clustering and High Availability

UBT supports gateway clustering for campus resiliency. An AOS-CX switch is configured with a primary controller IP and a backup controller IP. In AOS 10, the switch's initial Switch Designated Gateway (SDG) is the primary controller IP it reaches first, the cluster leader assigns a standby SDG, and each UBT client is anchored to a User Designated Gateway (UDG) with a standby UDG, so the cluster can absorb a node failure.


Centralized Policy Enforcement Firewall (PEF)

Once client frames emerge from the GRE tunnel at the Aruba Gateway, they are processed by the Policy Enforcement Firewall (PEF). PEF is a stateful Layer 4–7 deep-inspection engine built into the gateway firmware.

Key Capabilities of PEF

  1. Stateful Inspection: Unlike stateless switch ACLs that inspect individual packets in isolation, PEF tracks the full state of bidirectional connections (TCP sequence numbers, handshakes, timeouts), preventing spoofing and unestablished inbound connections.
  2. Deep Packet Inspection (DPI) & AppRF: PEF identifies thousands of applications regardless of port or protocol. For example, if a user runs BitTorrent over TCP port 443 (standard HTTPS), PEF inspects the packet payload, recognizes the BitTorrent protocol signature, and applies bandwidth restrictions or drops the session.
  3. Application Visibility and Control: Administrators can prioritize critical collaboration tools (such as Microsoft Teams or Zoom) using Quality of Service (QoS) tagging, while rate-limiting or blocking recreational streaming and social media.
  4. Web Content Classification & Reputation: The gateway leverages real-time cloud threat intelligence to categorize external URLs into security tiers (e.g., Gambling, Malware, Phishing), blocking dangerous traffic before it enters the enterprise WAN.
  5. Micro-Segmentation (Intra-VLAN Role Isolation): In a standard subnet, two hosts can communicate freely at Layer 2. PEF breaks this paradigm: even if two endpoints belong to the exact same IP subnet and VLAN, PEF enforces role-to-role firewall rules. A contractor laptop cannot communicate with an adjacent corporate laptop, and an IoT smart TV cannot access a nearby security camera, eliminating lateral threat traversal.

Integration with SD-Branch and Aruba Central

Dynamic Segmentation scales from corporate headquarters to distributed branch offices:

  • SD-Branch Gateways: Aruba Branch Gateways (BGWs) deployed at remote retail stores or medical clinics terminate UBT tunnels locally. Branch access switches tunnel point-of-sale terminals and guest Wi-Fi to the local branch gateway, enforcing consistent corporate security policies at remote sites.
  • Aruba Central Cloud Orchestration: Using Aruba Central, network engineers manage the entire Dynamic Segmentation fabric from a single pane of glass. Administrators configure UBT zones, push global user roles, monitor real-time client sessions, and review AI-driven application telemetry across wired and wireless infrastructure.

AOS-CX UBT Configuration Commands and Verification

The following configuration session demonstrates configuring a UBT zone to an Aruba Gateway cluster, creating a tunneled user role, and applying it to an edge interface:

switch# configure terminal

! Step 1: UBT client VLAN and UBT zone (shown as it appears in show running-config ubt)
ubt-client-vlan 3000
ubt zone CAMPUS-ZONE vrf default
    primary-controller ip 10.200.1.100
    backup-controller ip 10.200.1.101
    enable

! Step 2: Configure a Tunneled User Role matching the Gateway Role
switch(config)# port-access role Tunneled-Employee-Role
switch(config-pa-role)# gateway-zone zone CAMPUS-ZONE gateway-role Corp-User-Policy
switch(config-pa-role)# exit

! Step 3: Configure a Locally Switched Role for Comparison
switch(config)# port-access role Local-Printer-Role
switch(config-pa-role)# vlan access 30
switch(config-pa-role)# exit

! Step 4: Configure an Edge Interface for Authenticated Access
switch(config)# interface 1/1/20
switch(config-if)# description Desk-Workstation
switch(config-if)# no routing
switch(config-if)# aaa authentication port-access dot1x authenticator enable
switch(config-if)# exit

Essential Verification Commands

CommandOutput and Operational Purpose
show ubtDisplays the UBT configuration and zone settings.
show ubt stateDisplays the state of the UBT zone and its connection to the primary and backup gateways.
show ubt usersLists clients currently tunneled with UBT and their gateway roles.
show ubt statisticsDisplays UBT packet and tunnel counters.

Common Exam Traps

  • UBT vs. PBT Distinction: The exam frequently tests the difference between tunneling an entire physical switch port indiscriminately (Port-Based Tunneling) versus tunneling traffic conditionally based on authenticated user identity (User-Based Tunneling).
  • Encapsulation Protocol: Remember that UBT utilizes Generic Routing Encapsulation (GRE, IP protocol 47) between the AOS-CX switch and the Aruba Gateway, not VXLAN or IPsec.
  • Core Network Agnosticism: Core and aggregation switches do not need to support UBT, GRE termination, or special firewall software. They simply route standard IP packets between the access switch IP and the gateway IP.
  • Policy Enforcement Locus: In a UBT deployment, while the access switch initiates the GRE tunnel, the stateful Layer 4–7 firewall policies (gateway-role) are enforced centrally on the Aruba Gateway, not in access switch ASICs.
Loading diagram...
User-Based Tunneling (UBT) and Policy Enforcement Firewall Architecture
Test Your Knowledge

What is the key architectural difference between User-Based Tunneling (UBT) and Port-Based Tunneling (PBT) on Aruba AOS-CX switches?

A

UBT tunnels traffic per authenticated user role, whereas PBT tunnels everything arriving on a port

B

PBT encrypts tunneled traffic with IPsec, whereas UBT forwards everything over unencrypted Layer 2 trunks

C

UBT is supported only on wireless access points, whereas PBT is supported only on modular chassis switches

D

PBT requires ClearPass Policy Manager, whereas UBT works only with local switch user accounts and roles

Test Your Knowledge

Which encapsulation protocol is established between an Aruba AOS-CX access switch and an Aruba Gateway to carry client traffic in a User-Based Tunneling (UBT) deployment?

A

Layer 2 Tunneling Protocol Version 3 (L2TPv3) using IP protocol 115

B

Virtual Extensible LAN (VXLAN) using UDP port 4789

C

Point-to-Point Protocol over Ethernet (PPPoE) using EtherType 0x8864

D

Generic Routing Encapsulation (GRE) using IP protocol 47

Test Your Knowledge

How does the Policy Enforcement Firewall (PEF) on an Aruba Gateway enforce micro-segmentation for clients connected via Dynamic Segmentation?

A

By physically disabling access switch ports whenever two endpoints attempt to communicate at once

B

By applying stateful role-based firewall policy between user roles, even within the same subnet

C

By requiring all endpoints to configure static IP routes pointing to external cloud proxy servers

D

By converting all IPv4 client packets into IPv6 link-local addresses before evaluating routing headers

Sections you finish are checked off in the contents.