<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRE Over IPSEC configuration in Routing and SD-WAN</title>
    <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636000#M368987</link>
    <description>&lt;P&gt;For reachability you&lt;/P&gt;&lt;P&gt;Ip route lo tunnel x&lt;/P&gt;&lt;P&gt;In both gre tunnel&amp;nbsp; end router,&lt;/P&gt;&lt;P&gt;This make lo is reachable.&lt;/P&gt;&lt;P&gt;After that&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config ebgp update source lo&lt;/P&gt;&lt;P&gt;Config ebgp multi hop 2&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 21 Jun 2022 16:19:55 GMT</pubDate>
    <dc:creator>MHM Cisco World</dc:creator>
    <dc:date>2022-06-21T16:19:55Z</dc:date>
    <item>
      <title>GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635649#M368972</link>
      <description>&lt;P&gt;hello&lt;/P&gt;&lt;P&gt;i have configured my GRE over IPSEC Tunnel and it is UP on both routers&amp;nbsp;&lt;/P&gt;&lt;P&gt;but when i configure BGP between both routers it doesnot come UP and when i try to make a ping between both loopbacks used for BGP it is not passing, i realised the tunnel blocks the packets from those IPs&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;please i do i authorize those IPs to be used for BGP inside the tunnel&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:02:58 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635649#M368972</guid>
      <dc:creator>dacobelltacham</dc:creator>
      <dc:date>2022-06-21T10:02:58Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635655#M368973</link>
      <description>&lt;P&gt;share config please.&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 10:07:08 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635655#M368973</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T10:07:08Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635912#M368983</link>
      <description>&lt;P&gt;Hello &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/1354665"&gt;@dacobelltacham&lt;/a&gt; ,&lt;/P&gt;
&lt;P&gt;for each direction you need an host /32 static route pointing to the GRE tunnel with destination the loopback of the other node.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Without it the tunnel is not used.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In addition if using eBGP you will need to enable eBGP-multihop under router BGP for the neighbor +&lt;/P&gt;
&lt;P&gt;neighbor x.x.x.x update-source loopM&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope to help&lt;/P&gt;
&lt;P&gt;Giuseppe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 14:26:52 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635912#M368983</guid>
      <dc:creator>Giuseppe Larosa</dc:creator>
      <dc:date>2022-06-21T14:26:52Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635950#M368985</link>
      <description>when i try to ping both loopbacks which am to used for eBGP sessions it is&lt;BR /&gt;not successfull even though my tunnel is UP and reachability is ok&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jun 2022 15:06:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635950#M368985</guid>
      <dc:creator>dacobelltacham</dc:creator>
      <dc:date>2022-06-21T15:06:19Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635954#M368986</link>
      <description>&lt;P&gt;Ebgp using loopback as update source need ebgp multi hop command.&lt;/P&gt;&lt;P&gt;This what mr. &lt;a href="https://community.cisco.com/t5/user/viewprofilepage/user-id/325924"&gt;@Giuseppe Larosa&lt;/a&gt;&amp;nbsp;mention before.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 15:13:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4635954#M368986</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T15:13:27Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636000#M368987</link>
      <description>&lt;P&gt;For reachability you&lt;/P&gt;&lt;P&gt;Ip route lo tunnel x&lt;/P&gt;&lt;P&gt;In both gre tunnel&amp;nbsp; end router,&lt;/P&gt;&lt;P&gt;This make lo is reachable.&lt;/P&gt;&lt;P&gt;After that&amp;nbsp;&lt;/P&gt;&lt;P&gt;Config ebgp update source lo&lt;/P&gt;&lt;P&gt;Config ebgp multi hop 2&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:19:55 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636000#M368987</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T16:19:55Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636030#M368989</link>
      <description>i have done that but no reachability , and when i try to creat a policy to&lt;BR /&gt;permit my Loopbacks communicate inside the tunnel i noticed that the tunnel&lt;BR /&gt;goes down&lt;BR /&gt;</description>
      <pubDate>Tue, 21 Jun 2022 16:58:19 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636030#M368989</guid>
      <dc:creator>dacobelltacham</dc:creator>
      <dc:date>2022-06-21T16:58:19Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636034#M368990</link>
      <description>&lt;P&gt;&lt;SPAN&gt;ip access-list extended IPSEC_ACL&lt;/SPAN&gt;&lt;BR /&gt;&lt;SPAN&gt;permit gre&amp;nbsp;&lt;/SPAN&gt;&lt;STRONG&gt;host x.x.x.x host x.x.x.x&lt;/STRONG&gt;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&lt;STRONG&gt;Only this need for acl of ipsec.&lt;/STRONG&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 17:10:02 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636034#M368990</guid>
      <dc:creator>MHM Cisco World</dc:creator>
      <dc:date>2022-06-21T17:10:02Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636122#M368995</link>
      <description>&lt;P&gt;Hello ,&lt;/P&gt;
&lt;P&gt;&amp;gt;&amp;gt; when i try to creat a policy to&lt;BR /&gt;permit my Loopbacks communicate inside the tunnel i noticed that the tunnel&lt;BR /&gt;goes down&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;you cannot use the loopback address as external IP addresses and to route them inside the tunnel at the same time this error is called recursive routing.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;it would be easier if you would share in txt attachment file your configuraition of the two routers.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Hope to help&lt;/P&gt;
&lt;P&gt;Giuseppe&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 19:43:11 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636122#M368995</guid>
      <dc:creator>Giuseppe Larosa</dc:creator>
      <dc:date>2022-06-21T19:43:11Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636158#M368997</link>
      <description>&lt;P&gt;Hello&lt;BR /&gt;You need reachabilty to the loopbacks if you wish to establish an bgp peer.on them, So as suggested can you attach the output of the following into a file and attach it to your OP.&lt;BR /&gt;&lt;BR /&gt;&lt;EM&gt;sh run | sect router&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh ip route&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh ip protocols&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh ip int brief | in up&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh ip bgp sum&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh run | in crypto&lt;BR /&gt;sh crypto isakmp sa&lt;/EM&gt;&lt;BR /&gt;&lt;EM&gt;sh crypto ipsec sa&lt;/EM&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 20:50:20 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636158#M368997</guid>
      <dc:creator>paul driver</dc:creator>
      <dc:date>2022-06-21T20:50:20Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636180#M369000</link>
      <description>&lt;P&gt;BTW, on many Cisco devices, an "UP" tunnel doesn't always imply the tunnel is really UP.&lt;/P&gt;
&lt;P&gt;From one tunnel device, can you ping the other side's internal IP?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 21 Jun 2022 21:38:27 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4636180#M369000</guid>
      <dc:creator>Joseph W. Doherty</dc:creator>
      <dc:date>2022-06-21T21:38:27Z</dc:date>
    </item>
    <item>
      <title>Re: GRE Over IPSEC configuration</title>
      <link>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4637128#M369058</link>
      <description>&lt;P&gt;- are both end point of the tunnel reachable?&amp;nbsp;&lt;/P&gt;&lt;P&gt;- check your vrf configuration if used&lt;/P&gt;&lt;P&gt;-create a route to your loopback&amp;nbsp;&amp;nbsp;&lt;/P&gt;&lt;P&gt;- check if BGP configuration is pointing to correct neighbor and&amp;nbsp;&lt;/P&gt;&lt;P&gt;- add in BGP the correct sourcing&lt;/P&gt;&lt;P&gt;- run the above 'show commands'&lt;/P&gt;&lt;P&gt;- as a side test, create dynamic routing between if you administer both end points&lt;/P&gt;</description>
      <pubDate>Thu, 23 Jun 2022 05:50:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/routing-and-sd-wan/gre-over-ipsec-configuration/m-p/4637128#M369058</guid>
      <dc:creator>_|brt.drml|_</dc:creator>
      <dc:date>2022-06-23T05:50:26Z</dc:date>
    </item>
  </channel>
</rss>

