E-240W-A unit data sheet
38
7368 ISAM ONT E-240W-A Product Guide
3FE-46974-AAAA-TCZZA
Issue: 01
The ONT acts as the RADIUS client and sends the encapsulated EAP messages to
the AAA server via the WLAN Gateway, which acts as the RADIUS proxy server. The
interaction between the ONT and the AAA server provides subscriber management
for authenticated mobile users without adding authentication load to the 3G network.
4.2.6
Support for soft GRE tunnels
This section describes the support for soft GRE tunnels for integration with the 7750
Service Router WLAN gateway. The Nokia 7750 Service Router WLAN GW can
accept soft GRE tunnels from any IP Source Address, in a preconfigured Subnet or
Access Control List, or MPLS label.
4.2.6.1
GRE
Generic Routing Encapsulation (GRE) is a tunneling protocol that can encapsulate a
wide variety of network layer protocols inside virtual point-to-point links over an
Internet Protocol network. GRE provides a secure path for transporting packets
through a public network. In essence, GRE creates a private P2P connection, similar
to a VPN, between clients and servers. GRE is the preferred transport mechanism
between the Carrier Wi-Fi access network and the WLAN GW.
GRE works by encapsulating a payload (an inner packet that needs to be delivered
to a destination network) inside an outer IP packet. GRE tunnel endpoints send
payloads through GRE tunnels by routing encapsulated packets through intervening
IP networks. The inner packets are not parsed along the way; only the outer IP
packets are parsed as they are forwarded towards the GRE tunnel endpoint, where
the GRE encapsulation is removed, and the payload is forwarded to its final
destination.
4.2.6.2
Soft GRE
In soft GRE, only one side of the tunnel needs to be configured; the other end learns
the remote IP addresses of all remote tunnel endpoints by examining the incoming
GRE packets.
GRE tunnels can be automatically created when devices attach to the AP,
eliminating the need for each AP to be explicitly provisioned on the WLAN Gateway.
Because this soft GRE is stateless and the tunnel contexts are created based on
need, the WLAN Gateway does not need to maintain states for unused tunnels,
which improves scalability.
The operator can restrict the traffic going through the GRE tunnel based on the
SSIDs or LAN ports.
Figure
illustrates the soft GRE architecture.
Release 06.00.00h | January 2019 | Edition 08