Skip to main content

 

Cisco Meraki Documentation

Cisco Campus Gateway Data Plane Encryption Configuration Guide

Overview and Purpose

While Cisco Campus Gateway (CG) supports deployment within a large campus network, some deployments place the Campus Gateway in a central location, such as a data center, to serve a large geographic area. In these deployments, the connection from the access points (APs) to the Campus Gateway may traverse untrusted links,  such as direct internet access, rather than a site-to-site VPN. Virtual Extensible LAN (VXLAN) tunnel encryption for the data plane tunnels between the Campus Gateway and APs is essential in these environments.

Starting with MCG 32.2 and MR 32.2, CG supports encryption of the VXLAN data plane tunnels between the Campus Gateway and access points. After upgrading to this firmware version or later, the Campus Gateway always encrypts the VXLAN management traffic, including Bidirectional Forwarding Detection (BFD) keepalives, RADIUS, and MR Neighbors, within the VXLAN tunnel. Client data traffic remains unencrypted by default unless you explicitly enable it.

VXLAN tunnel encryption uses Datagram Transport Layer Security (DTLS) 1.2 with AES-128-GCM. The Campus Gateway generates a pre-shared key (PSK) upon AP registration and secures the tunnel with this key. The Campus Gateway sends the PSK to the access point using the secured QUIC control plane tunnel in the Registration reply message.

When data plane encryption is enabled, the maximum packet size is 1412 bytes. Data plane encryption adds 38 bytes of overhead in addition to the 50 bytes of VXLAN overhead.

Prerequisites and Limitations

Before configuring Campus Gateway Data Plane Encryption, ensure the following requirements are met:

Licensing Requirements

License type

Required license

Co-Termination Licensing

MR Enterprise

Meraki Subscription Licensing

MR Enterprise

Cisco Networking Subscription

Cisco Wireless Essentials

Hardware Requirements

Campus Gateway data plane encryption is available on the following devices:

  • MR and CW access points: All Wi-Fi 6 or later models

  • Campus Gateway: All models

Firmware Requirements

Campus Gateway data plane encryption requires the following firmware versions:

  • MR and CW access points: MR 32.2.3 or later

  • Campus Gateway: MCG 32.2.3 or later

Limitations

  • Enabling data plane encryption requires the access points to rejoin the Campus Gateway. Wireless network operations are disrupted during this process. Enable this feature during a maintenance window.
  • When data plane encryption is enabled, maximum throughput for access points tunneling to the Campus Gateway decreases due to encryption overhead.

Configuration Steps

Enable data plane encryption

  1. Navigate to Wireless > Campus Gateway > Campus Gateways.

  2. Choose Edit to open the Edit cluster attributes dialogue box.
    VXLAN Encryption_4.png

  3. In the Data traffic encryption enabled on networks field, choose the networks to enable encryption on.
    VXLAN Encryption_3 (1).png

  4. Choose Save.

Note: The Campus Gateway and access points must reside in the same Meraki network. Only the Meraki network where the Campus Gateway resides is available for selection.

Verification

  1. To verify the networks with data plane encryption enabled, choose View network encryption on the cluster overview page.
    VXLAN Encryption_1.png
  2. To check the encryption status of each access point, navigate to the Tunneled APs tab and view the Encryption status column. An Encrypted status appears next to each access point.
    VXLAN Encryption 5.png
  • Was this article helpful?