Cisco Support Community
Showing results for 
Search instead for 
Did you mean: 

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. If you'd prefer to explore, try our test area to get started. And see here for current known issues.

GRE ove IPsec


I've got my main campus and a remote site connected by an encrypted GRE tunnel. On the policing policy-map on the outgoing interface, my match statement is an ACL trying to match on ESP traffic (the hit counter doesnt increase) and I've added a line for the un-encrypted trafic IPs and this one has hits.

So, why can't I match on my permit ESP host A host B? And how is it possible to have match on the acl (permit ip any to remote site range)? The later should be encrypted when it hit the outbound policy map.

Cisco Employee

Re: GRE ove IPsec

As far as I know the policy map that you would apply to the interface is for traffic going through that interface rather than ones generated by that interface, if you want to use QoS for this vpn tunnel you need to use the Qos Preclasify feature in the crypto map settings.