Got it

GRE - an efficient and cost-effective way

Latest reply: Nov 17, 2021 12:01:14 971 25 11 0 0

Security is a major concern when using the Internet. VPNs are used to ensure the security of data. VPNs are used to create a private tunnel over a public network. Data can be secured by using encryption in this tunnel through the Internet and by using authentication to protect data from unauthorized access.



INTRODUCING VPNs


VPNs are used to create an end-to-end private network connection over third-party networks, such as the Internet or extranets. To implement VPNs, a VPN gateway is necessary - it could be a router, a firewall, or a specific device. 



GRE - GENERIC ROUTING ENCAPSULATION


GRE is a basic, non-secure, site-to-site VPN tunneling protocol. It encapsulates a wide variety of protocol packet types inside IP tunnels.


GRE creates a virtual point-to-point link to routers at remote points over an IP internetwork.


GRE is described in RFC 2784.

 

GRE 1

Source: Huawei documentation


            GRE was first developed to provide the transmission of protocols among networks, Later the role of GRE became more towards providing routing-based protocol tunneling.



        CHARACTERISTICS OF GRE


            1. GRE is an IETF standard, IP protocol 47 is used for identification.


            2. GRE encapsulation uses a protocol type field in the GRE header to support the encapsulation of any OSI Layer 3 protocol.


            3. GRE does not include any strong security mechanisms to protect its payload.


            4. The GRE header, together with the tunneling IP header, creates at least 24 bytes of additional overhead for tunneled packets.

 

        BENEFITS OF VPNs

  • Cost saving;

  • Security;

  • Scalability;

  • Compatibility with broadband technology.


        WHY GRE?

 

An IPsec VPN does not allow routes to be forwarded between diverse site-to-site networks, as only Static routing is allowed, whereas GRE provides a mechanism for encapsulation of packets of one protocol into packets of another protocol and enables routing between remote and disparate networks.



IPSec VPN SUPPORT FOR GRE

 

GRE has one issue of unavailability to secure packets as they are carried across a public network (Internet).

To enable the encryption, IPSec solutions are used together with GRE to enable these tunnels with IPSec tunnels to include integrity and confidentiality.


2

Source: Huawei documentation



        GRE CONFIGURATION


            The steps for configuring GRE are as follows:


  • create the tunnel Interface;


  • configure the GRE encapsulation type;


  • set the tunnel source address or source interface and set the tunnel destination address;


  • set the tunnel interface network address (for supporting routes).

        

        

            SOME KEY CONSIDERATIONS


  • Tunnel routes to be available on both ends (source and destination devices ) so that packets encapsulated with GRE can be forwarded correctly.


  • Both Static or dynamic route can be used to pass traffic through tunnel interfaces.


  •  MTU of 1476 byte is well enough, as GRE has additional 24 Bytes overhead.


GRE 3

Source: Huawei documentation




                            [RTA]display interface Tunnel 0/0/1

                            Tunnel0/0/1 current state : UP

                            Line protocol current state : UP

                            Last line protocol up time : 2019-03-21 05:37

                            Description:HUAWEI, AR Series, Tunnel0/0/1 Interface

                            Route Port, The Maximum Transmit Unit is 1476

                            Internet Address is 30.1.1.1/24

                            Encapsulation is TUNNEL, loopback not set

                            Tunnel source 30.1.1.1 (GigabitEthernet0/0/1), destination 30.1.1.2

                            Tunnel protocol/transport GRE/IP, key disabled

                            keepalive disabled

                            Checksumming of packets disabled

……


        VALIDATION OF GRE


  • An entry in the routing table verifies the tunnel establishment.


  • Routes for GRE can be static or dynamic.

 

             

            [RTA]display ip routing-table

            Route Flags: R - relay, D - download to fib

            --------------------------------------------------------------

            Routing Tables: Public  Destinations : 13       Routes : 14      

            Destination/Mask Proto  Pre Cost Flags  NextHop   Interface

            ……

            10.10.2.0/24      Static 60  0    RD      30.1.1.2  Tunnel 0/0/1


        CONCLUSION

            GRE gives a cost-effective solution to run dynamic routing between remote networks that commonly belong to a single administrative domain. The IPSec VPN is normally preferred where there is a need to provide a site-to-site private tunnel over which routing dynamic information may be transmitted, but is not capable of forwarding of routing information.

Thanks for sharing.
Easy to understand
View more
  • x
  • convention:

user_3915171
user_3915171 Created Feb 26, 2021 03:48:07 (0) (0)
 
Thanks for the information
View more
  • x
  • convention:

AndreaBri
AndreaBri Created Dec 27, 2020 00:55:34 (0) (0)
 
MahMush
MahMush Created Dec 27, 2020 08:30:21 (0) (0)
Thank u for ur support.  
Posted by Aish1234 at 2020-12-26 08:52 Thanks for sharing. Easy to understand
Thank you @aish1234
View more
  • x
  • convention:

GRE - an efficient and cost-effective way-3718465-1 thanks for sharing
View more
  • x
  • convention:

alejandrolla
alejandrolla Created Jan 3, 2021 12:34:08 (0) (0)
 
Nice overview of the concept of GRE.
View more
  • x
  • convention:

alejandrolla
alejandrolla Created Jan 3, 2021 12:34:01 (0) (0)
 
thanks for sharing
View more
  • x
  • convention:

MahMush
MahMush Created Jan 6, 2021 15:12:22 (0) (0)
Thanks  
thanks for sharing
View more
  • x
  • convention:

MahMush
MahMush Created Jan 6, 2021 15:12:14 (0) (0)
Thanks lady :)  
Nice. Thanks
View more
  • x
  • convention:

MahMush
MahMush Created Jan 18, 2021 21:54:03 (0) (0)
Thanks  
zaheernew
MVE Author Created Feb 15, 2021 08:38:28

very useful
View more
  • x
  • convention:

MahMush
MahMush Created Feb 22, 2021 02:17:46 (0) (0)
Thanks  
MahMush
MahMush Created Feb 22, 2021 21:25:10 (0) (0)
:)  
12
Back to list

Comment

You need to log in to comment to the post Login | Register
Comment

Notice: To protect the legitimate rights and interests of you, the community, and third parties, do not release content that may bring legal risks to all parties, including but are not limited to the following:
  • Politically sensitive content
  • Content concerning pornography, gambling, and drug abuse
  • Content that may disclose or infringe upon others ' commercial secrets, intellectual properties, including trade marks, copyrights, and patents, and personal privacy
Do not share your account and password with others. All operations performed using your account will be regarded as your own actions and all consequences arising therefrom will be borne by you. For details, see " User Agreement."

My Followers

Login and enjoy all the member benefits

Login

Block
Are you sure to block this user?
Users on your blacklist cannot comment on your post,cannot mention you, cannot send you private messages.
Reminder
Please bind your phone number to obtain invitation bonus.