Cisco GRE Tunnel Over Ipsec VPN

Cisco GRE Tunnel over IPSEC VPN Configuration:

 Router 1 Configuration:crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 193.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
exit
!
interface tunnel 0
ip address 10.10.12.1 255.255.255.0
tunnel source 192.1.1.1
tunnel destination 193.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 192.1.1.1 255.255.255.0
exit
!
interface G0/0
ip address 10.10.10.1 255.255.255.0
exit
!
ip route 10.10.11.0 255.255.255.0 tunnel 0
end
!

Router 2 Configuration on Remote end:

crypto isakmp policy 10
encryption aes 128
hash sha
autentication pre-share
group 2
!
crypto isakmp key cisco address 192.1.1.1 255.255.255.255 no-xauth
crypto ipsec transform-set ciscotransit esp-aes esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set ciscotransit
!
interface tunnel 0
ip address 10.10.12.3 255.255.255.0
tunnel source 193.1.1.1
tunnel destination 192.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec VTI
!
interface G0/1
ip address 193.1.1.1 255.255.255.0
!
interface G0/0
ip address 10.10.11.1 255.255.255.0
!
ip route 10.10.10.0 255.255.255.0 tunnel 0

Notes:

tunnel mode ipsec ipv4

 “Command to notify the router that this is an IPSec-based interface rather than GRE”.

 tunnel protection ipsec

 “Command to choose the type of encryption (transform-set) for the interface”.

Note:

What I did was create the tunnel interfaces on both ends

Enable EIGRP and enable the process on the tunnel ip addresses

Then I created a loopback interface and advertised that into EIGRP

Now I can track the route so if the main interface would drop the tunnel would still show up/up  but would drop its EIGRP adjacency which would drop the route.

Show Commands:

show ip interface brief
show crypto isakmp sa
sh0w crypto ipsec sa
show crypto session