cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
1206
Views
0
Helpful
4
Replies

GRE over IPSEC tunnel mode

sandevsingh
Level 1
Level 1

Hi, can GRE work over IPSEC tunnel mode? As IPSEC tunnel mode will encapsulate all the headers (GRE and IP) inside the outermost ESP IP header, then how will the GRE process know the tunnel end-points as they will be encrypted?

I was able to sucessfully configure GRE over IPSEC transport mode and everything worked fine. But i am not sure if GRE works fine with IPSEC tunnel mode?

4 Replies 4

Richard Burts
Hall of Fame
Hall of Fame

Sandev

GRE works fine with IPSec tunnel mode. The IPSec encapsulates the GRE packet, then sends the ESP packet to the VPN peer. The VPN peer deencapsulates the ESP packet, finds that the payload is a GRE packet, and processes the GRE packet as expected.

HTH

Rick

HTH

Rick

Thanks, i configured this in a lab environment. I could see that my IPSEC tunnel is up. (Was able to check this by show crypto isakmp sa and show crypto ipsec sa), but somehow i was not able to ping my GRE tunnel endpoint. Both my tunnel endpoints are in the same subnet.

When i changed the mode to transport, it started pinging. Any idea why this is happening?

Could you post your config on this subject. Thanks

Hi, thanks for your concern. It worked now.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community:

Review Cisco Networking products for a $25 gift card