Cisco Support Community
cancel
Showing results for 
Search instead for 
Did you mean: 
Announcements

Welcome to Cisco Support Community. We would love to have your feedback.

For an introduction to the new site, click here. And see here for current known issues.

New Member

GRE over IPSEC tunnel mode

Hi, can GRE work over IPSEC tunnel mode? As IPSEC tunnel mode will encapsulate all the headers (GRE and IP) inside the outermost ESP IP header, then how will the GRE process know the tunnel end-points as they will be encrypted?

I was able to sucessfully configure GRE over IPSEC transport mode and everything worked fine. But i am not sure if GRE works fine with IPSEC tunnel mode?

4 REPLIES
Hall of Fame Super Silver

Re: GRE over IPSEC tunnel mode

Sandev

GRE works fine with IPSec tunnel mode. The IPSec encapsulates the GRE packet, then sends the ESP packet to the VPN peer. The VPN peer deencapsulates the ESP packet, finds that the payload is a GRE packet, and processes the GRE packet as expected.

HTH

Rick

New Member

Re: GRE over IPSEC tunnel mode

Thanks, i configured this in a lab environment. I could see that my IPSEC tunnel is up. (Was able to check this by show crypto isakmp sa and show crypto ipsec sa), but somehow i was not able to ping my GRE tunnel endpoint. Both my tunnel endpoints are in the same subnet.

When i changed the mode to transport, it started pinging. Any idea why this is happening?

New Member

Re: GRE over IPSEC tunnel mode

Could you post your config on this subject. Thanks

New Member

Re: GRE over IPSEC tunnel mode

Hi, thanks for your concern. It worked now.

461
Views
0
Helpful
4
Replies
CreatePlease login to create content