Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

New Member

VPN 3000 to router and GRE

Can the VPN 3000 support GRE over IPSEC yet ?

New Member

Re: VPN 3000 to router and GRE

Hello Tsalus,

I understand you are wondering if the VPN 3000 can provide GRE/IPSec services.  Unfortunately the VPN 3000 cannot provide GRE encapsulation services, it can only provide IPSec tunnels.  If you wish to run GRE traffic over an IPSec tunnel terminated on a VPN 3000 that is fine, except that the GRE traffic needs to be terminated on a device which supports GRE, for Cisco that would be a Router running IOS.

The VPN 3000 is an end of life product no longer receiving software development and as such will never support provided GRE services.

What you can do is have two routers and the VPN 3000 to provide GRE/IPSec.  How you would do this is to

1. Configure a Lan to Lan tunnel between the outside router and the VPN 3000.  The proxies, crypto map acl, will be permit gre between the physical source IP and the destination router.

Lan to Lan tunnel configuration example for IOS and VPN 3000

2. You will ensure the router behind the VPN 3000 is configured to accept/create a GRE tunel with the far end router over the VPN tunnel.

NOTE: It is not recommended to use GRE keepalives over an IPSec tunnel.

I hope this answers your question and provides guidance on a possible solution if you need GRE for the ability to carry Multicast traffic.

If you have further questions please let us know and explain what you are trying to accomplish.