- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
08-29-2018 06:45 AM
Hi,
is it possible to terminate a GRE tunnel on a PaloAlto? Parhaps there is something new in 8.0
Best regrads,
Sebastian
08-29-2018 07:53 AM
Hi @sst,
Nope the firewalls don’t terminate GRE, non-encrypted IPSec, or GTP-U tunnels.
As documented here :
https://www.paloaltonetworks.com/documentation/80/pan-os/pan-os/networking/tunnel-content-inspection
Cheers !
-Kiwi.
08-30-2018 06:01 AM
Slightly off-topic, but Palo Altos can in fact terminate non-encrypted IPSec. Both AH and null-encryption ESP are supported in PAN-OS 8.0.
08-30-2018 06:38 AM
Hello All,
Just curious, why would a GRE tunnel be favored over a non-encrypted one?
Not trying to stir anything up, just asking.
Regards,
08-31-2018 04:11 AM
Maybe the far end does not have the hardware to support encryption? Just a guess at one possible reason.
I once had a tunnel to Verizon Wireless for an M2M solution and they specified GRE, would not or could not do IPSEC.
08-31-2018 09:37 AM
Hello Joe,
That makes sense.
Thanks!
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!