LWIP

LTE WLAN Radio Level Integration with IPsec Tunnel

Protocol →
Introduced in Rel-13 Also in: Core Network

LWIP is a Protocol Data Unit generated for secure transmission over WLAN, representing encapsulated user data routed via an IPsec tunnel between the UE and eNB to enable LTE-controlled WLAN integration.

Category
Protocol
Introduced
Rel-13
Where
Radio Access Network › E-UTRAN (LTE)
Also touches
1 segments
Specifications
13 specs
LWIP Description Purpose Related Classification Detected Changes Specifications

Description

Within the 3GPP specification for LTE WLAN Radio Level Integration with IPsec Tunnel (often abbreviated as LWIP), the term 'LWIP' specifically denotes a Protocol Data Unit (PDU). This LWIP PDU is generated by the LWIP Encapsulation Protocol (LWIPEP) entity in the user equipment (UE) for downlink transmission, and by the eNodeB (eNB) for uplink transmission, destined for transport over a WLAN link. The core function is to securely integrate WLAN as a data radio bearer for LTE traffic. The LWIP PDU is essentially an IP packet that encapsulates the original user data (an IP packet or an Ethernet frame) and is protected by an IPsec Encapsulating Security Payload (ESP) tunnel established directly between the UE and the eNB.

The architecture involves the UE establishing an IPsec ESP tunnel with the eNB over the untrusted WLAN access network. For user data destined to use the LWIP bearer, the UE's LWIPEP entity takes the original uplink IP packet (from the applications), performs any necessary encapsulation (e.g., into an Ethernet frame if required by the WLAN), and then this becomes the payload of a new IP packet. This new outer IP packet is the one that is secured by the IPsec ESP tunnel and routed over the WLAN link to the eNB. This resulting secured packet, ready for transmission on the WLAN, is the LWIP PDU. In the downlink direction, the eNB's LWIPEP entity performs the reverse operation, creating the secured LWIP PDU for transmission to the UE over WLAN.

From a network perspective, the eNB has full control over this data path. It decides which EPS bearers are routed via the LWIP tunnel (WLAN) and which are sent over the conventional LTE-Uu interface. The eNB terminates the IPsec tunnel, decrypts the LWIP PDU, extracts the original user data, and forwards it toward the core network via the S1-U interface. This makes the WLAN link appear as a secure, integrated layer-2 transport for the LTE bearer, managed entirely by the eNB. Key components are the LWIPEP entity, the IPsec security association, and the control-plane signaling that configures the LWIP bearer. The role of the LWIP PDU is to be the standardized, secured container that enables the eNB to use WLAN radio resources as a controlled extension of the LTE radio access network.

Purpose & Motivation

LWIP technology was developed to provide an alternative, secure method for tight radio-level integration of WLAN with LTE, complementing the LWA approach. It addressed the need for a solution that could work with existing, unmodified WLAN access points (untrusted WLAN) without requiring a dedicated WLAN Termination (WT) node as defined for LWA. Prior to LWIP, using untrusted WLAN required routing user traffic through the core network (e.g., via ePDG), which introduced latency and complexity for real-time radio resource management.

The primary problem LWIP solves is enabling the eNB to directly control and securely route user plane traffic over any generic WLAN network, treating it as a virtual radio link. It solves the security concern of transmitting LTE user data over an untrusted IP network (the WLAN) by mandating a direct IPsec tunnel between the UE and eNB. This approach provides a lower-latency path compared to core-network tunneling, allows for faster switching between LTE and WLAN, and gives the eNB the ability to perform efficient traffic steering and aggregation at the radio level. The motivation was to offer operators a flexible deployment option for WLAN integration that did not necessitate upgrades to the WLAN infrastructure itself, lowering the barrier for leveraging existing Wi-Fi deployments to augment cellular capacity.

Classification

Part ofLWA
Specific typesLWALWIPEP
Related approachesIPSecEPDG

Release Timeline

Detected Changes Across Releases

from 3GPP Change Requests

Specific changes extracted from the „Change history“ tables of 3GPP specifications (1 CRs across 1 releases). Complements the general historical overview above with the evidence-based evolution of this function.

Rel-15 1 change

In Release 15, LWIP was introduced as a method for unlicensed spectrum aggregation in EPS, using a WLAN connection as a secondary RAT within a Dual Connectivity architecture. The specification integrated LWIP alongside LAA and LWA, defining it as a user plane connectivity option using an IPsec tunnel. Furthermore, Release 15 included corrections for the Secondary RAT Data Usage reporting mechanism to properly encompass LWIP operations.

  • Correction of applicability of Secondary RAT Data Usage report for LAA, LWA and LWIP TS 36.413CR1594

Explore further

Broader topics and technologies where LWIP plays a role.

Defining Specifications

3GPP specifications that define or reference LWIP, with the latest known release. Sourced from the 3GPP document catalog — see methodology.

SpecificationTitleRelease
TS 23.401 vj50 Evolved Packet System (EPS) Stage 2 Description Rel-19
TS 23.402 vj00 EPC for Non-3GPP Access (PMIP) Rel-19
TS 23.729 vf00 Unlicensed Spectrum Offloading System Enhancements Rel-15
TS 29.272 vj40 Diameter Interfaces for MME/SGSN Rel-19
TS 32.868 vf00 OAM aspects of LTE-WLAN integration (LWA/LWIP) Rel-15
TS 33.401 vj10 EPS Security Architecture Rel-19
TS 36.300 vj00 E-UTRAN Radio Interface Protocol Architecture Overview Rel-19
TS 36.331 vj00 LTE RRC Protocol Specification Rel-19
TS 36.361 vj00 LWIP Encapsulation Protocol Specification Rel-19
TS 36.413 vj10 S1 Application Protocol (S1AP) Rel-19
TS 36.463 vj00 XwAP Protocol Specification Rel-19
TS 36.464 vj00 Xw Interface User Plane Protocol Rel-19
TS 36.465 vj00 Xw User Plane Protocol Specification Rel-19
Patrick Zandl

About the author: Patrick Zandl (b. 1974)

Telecommunications specialist, technology journalist (founder of the Mobil server), and developer who has been running since 2025 — the largest Czech-language resource on AI-assisted programming. Formerly Chief Wizard Architect at Prusa3D and head of development for Turris at CZ.NIC; currently a consultant and instructor on AI implementation in companies.