- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
Enhanced Security Measures in Place: To ensure a safer experience, we’ve implemented additional, temporary security measures for all users.
11-04-2021 03:50 AM
Anybody know how to configure gre over ipsec ?
from the 9.0,pa support gre tunnel and only one word describe about this feature.
Has anyone done any specific this configuration?
Can you give me a description of the configuration? Thank you
11-06-2021 12:54 AM
Thank you for posting question @Felixcao
My interpretation of what is written in documentation is: by selecting check box: "Add GRE Encapsulation" Firewall will add GRE Header (IP Protocol 47) between ESP and traffic going to the tunnel interface. For example TCP Traffic routed to the Tunnel interface where you configured IPsec will get first encapsulated into GRE, then into ESP. This configuration is there in place for example if you have on the other side regular Cisco router running running Tunnel interface in: " tunnel mode gre" with attached: "tunnel protection ipsec profile".
Kind Regards
Pavel
11-23-2021 07:45 AM
Should the GRE interface be on the PA side or will it be sufficient on the other side, for example on the Mikrotik or Cisco side?
Has anyone configured GRE over IPSEC between PA and Mikrotik? Please share an example of a working configuration.
11-29-2021 04:52 PM
Thank you for the message @m.dmitriev
The GRE encapsulation should be enabled on both sides. Without both sides having GRE in place, the traffic that gets encapsulated by GRE on one side would not be able to get decapsulated on the other side of the tunnel. Regarding your second question, unfortunately, I do not have any hands on experience with Mikrotik.
Kind Regards
Pavel
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!