GRE/IPsec and DVMRP/IPsec Tunnels

In GRE/IPsec or DVMRP/IPsec connections, E Series routers can act as source and destination endpoints of the secure tunnel. Both sides of the connection run IPsec in transport mode with Encapsulating Security Payload (ESP) encryption and authentication.

In a GRE/IPsec or DVMRP/IPsec connection, the E Series router initiates an IPsec connection with a remote router. After establishing the IPsec connection, the E Series router establishes a GRE or DVMRP tunnel to the remote router. The tunnel is completely protected by the IPsec connection.

Setting Up the Secure GRE or DVMRP Connection

In Figure 29, a secure GRE/IPsec connection is set up between two E Series routers. To set up the secure connection:

  1. Set up the IPsec connection between the two routers. IKE signals a security association (SA) between the two IPsec tunnel endpoints.

    Two unidirectional SAs are established to secure data traffic.

  2. Set up a GRE tunnel between the two routers.

The GRE tunnel now runs over the SAs that IKE established.

Figure 29: GRE/IPsec Connection

GRE/IPsec Connection

Configuration Tasks

The main configuration tasks for setting up GRE or DVMRP over IPsec on E Series routers are:

Enabling IPsec Support for GRE and DVMRP Tunnels

To create GRE/IPsec and DVMRP/IPsec tunnels, use the ipsec-transport keyword with the interface tunnel command.

interface tunnel dvmrp

interface tunnel gre