I have a VPN running between a Pix525 (7.2(4)) and a 2811 router. The VPN works flawlessly except for GRE packets.
I have a tunnel running behind the PIX with a tunnel source of a.a.a.a and a tunnel destination of b.b.b.b. I have an access-list on the Pix with a match list of permit ip host a.a.a.a host b.b.b.b.
So far I have:
1. Ping a.a.a.a with a source of b.b.b.b (works)
2. Sniffed the traffic GRE is properly travelling from the 2811 to the pix but it is passing though the PIX without matching and being encapsulated
3. Changed the tunnel to IPIP mode. Now it works.
It looks like the PIX is just not able to match on GRE traffic. Has anybody seen this?