Cisco GRE over IPSEC
GRE is a tunneling protocol used to transport packets from one network through another network.
If this sounds like a virtual private network (VPN) to you, that’s because it theoretically is: Technically, a GRE tunnel is a type of a VPN—but it isn’t a secure tunneling method. However, you can encrypt GRE with an encryption protocol such as IPSec to form a secure VPN.
In fact, the point-to-point tunneling protocol (PPTP) actually uses GRE to create VPN tunnels.
For example, if you configure Microsoft VPN tunnels, by default, you use PPTP, which uses GRE
Local Network Configuration :
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
crypto isakmp key test address 2.2.2.2 no-xauth
crypto isakmp keepalive 15 5
!
!
crypto ipsec transform-set COMMTRANSIT esp-aes esp-sha-hmac
!
crypto ipsec profile COMMS
set transform-set COMMTRANSIT
!
!
interface Tunnel0
ip unnumbered GigabitEthernet0/0
keepalive 10 3
tunnel source 1.1.1.1
tunnel destination 2.2.2.2
tunnel mode ipsec ipv4
tunnel protection ipsec profile COMMS
!
!
interface GigabitEthernet0/0
description COMMS-PRIMARY
ip address 10.10.10.1 255.255.255.0
ip nat inside
ip inspect myfw in
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
ip address 1.1.1.1 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
router rip
version 2
network 10.0.0.0
!
ip route 10.10.11.0 255.255.255.0 Tunnel0
!
Remote Network Configuration :
crypto isakmp policy 10
encr aes
authentication pre-share
group 2
crypto isakmp key test address 1.1.1.1 no-xauth
crypto isakmp keepalive 15 5
!
!
crypto ipsec transform-set COMMTRANSIT esp-aes esp-sha-hmac
!
crypto ipsec profile COMMS
set transform-set COMMTRANSIT
!
!
interface Tunnel0
ip unnumbered GigabitEthernet0/0
keepalive 10 3
tunnel source 2.2.2.2
tunnel destination 1.1.1.1
tunnel mode ipsec ipv4
tunnel protection ipsec profile COMMS
!
!
interface GigabitEthernet0/0
description COMMS-SECONDARY
ip address 10.10.11.1 255.255.255.0
ip nat inside
ip inspect myfw in
ip virtual-reassembly
duplex auto
speed auto
!
!
interface GigabitEthernet0/1
ip address 2.2.2.2 255.255.255.0
ip nat outside
ip virtual-reassembly
duplex auto
speed auto
!
!
router rip
version 2
network 10.0.0.0
!
ip route 10.10.10.0 255.255.255.0 Tunnel0