<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRE inspection in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367973#M674216</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no inspection for GRE on ASA. The GRE packet will just be passed through the ASA.&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Sun, 04 Apr 2010 00:12:57 GMT</pubDate>
    <dc:creator>Jennifer Halim</dc:creator>
    <dc:date>2010-04-04T00:12:57Z</dc:date>
    <item>
      <title>GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367972#M674215</link>
      <description>&lt;P&gt;How is packet inspection affected (if at all) on an ASA, when the packet is encapsulated with GRE?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thank you&lt;/P&gt;</description>
      <pubDate>Mon, 11 Mar 2019 17:28:50 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367972#M674215</guid>
      <dc:creator>drehobljs</dc:creator>
      <dc:date>2019-03-11T17:28:50Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367973#M674216</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;There is no inspection for GRE on ASA. The GRE packet will just be passed through the ASA.&lt;/P&gt;&lt;P&gt;Hope that helps.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Apr 2010 00:12:57 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367973#M674216</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-04T00:12:57Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367974#M674217</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Are you talking about pptp inspection?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-external-small" href="http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721656"&gt;http://www.cisco.com/en/US/docs/security/asa/asa80/command/reference/i2.html#wp1721656&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;SPAN class="content"&gt;When enabled, PPTP application inspection inspects PPTP protocol packets and dynamically creates the GRE connections and xlates necessary to permit PPTP traffic.&lt;/SPAN&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;If you are talking about just GRE, it is IP protocol 47 and will be allowed if permitted via ACL just like any other traffic. There is no inspection specifically for it.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Apr 2010 03:20:22 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367974#M674217</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-04-04T03:20:22Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367975#M674218</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;I am talking about just GRE.&amp;nbsp; For example... If I tell the ASA that I don't want specified PTP protocols passing through, but there is ptp tunneled through http, the firewall will see that (hence application layer inspection), and will drop the packet.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So.. if I permit GRE, but block, say TFTP, will the firewall drop a packet that has a GRE encapsulated TFTP request?&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Apr 2010 16:44:15 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367975#M674218</guid>
      <dc:creator>drehobljs</dc:creator>
      <dc:date>2010-04-04T16:44:15Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367976#M674219</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Jeff&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;No it won't because the firewall has no idea of what is encapsulated with the GRE tunnel. This is one of the main reasons it is recommended not to allow GRE tunnels through your firewall.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jon&lt;/P&gt;&lt;P&gt;&lt;EM&gt;&lt;BR /&gt;&lt;/EM&gt;&lt;/P&gt;&lt;P&gt;&lt;EM&gt;Cisco are currently donating money to the Haiti earthquake appeal for every rating so please consider rating all helpful posts.&lt;/EM&gt;&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Apr 2010 21:48:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367976#M674219</guid>
      <dc:creator>Jon Marshall</dc:creator>
      <dc:date>2010-04-04T21:48:36Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367977#M674220</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Firewall will not block TFTP if you deny TFTP when it is encpsulated within the GRE packet.&amp;nbsp; Anything within the GRE packet, the firewall will not know.&lt;/P&gt;&lt;P&gt;Jon has already cofirmed that for you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;-KS&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Sun, 04 Apr 2010 23:01:36 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367977#M674220</guid>
      <dc:creator>Kureli Sankar</dc:creator>
      <dc:date>2010-04-04T23:01:36Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367978#M674221</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Thanks for the response.&amp;nbsp; Any chance this will change in the future?&amp;nbsp; Seams pretty weak to me.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Apr 2010 05:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367978#M674221</guid>
      <dc:creator>drehobljs</dc:creator>
      <dc:date>2010-04-05T05:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: GRE inspection</title>
      <link>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367979#M674222</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Don't think it will change in the near future. You might want to contact your Cisco account manager for the feature request.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Mon, 05 Apr 2010 05:57:14 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-inspection/m-p/1367979#M674222</guid>
      <dc:creator>Jennifer Halim</dc:creator>
      <dc:date>2010-04-05T05:57:14Z</dc:date>
    </item>
  </channel>
</rss>

