<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: GRE on ASA 5510 in Network Security</title>
    <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841035#M958079</link>
    <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure site to site IPSEC VPN between the security devices and ensure that the server traffic is part of the interesting traffic that initiates the tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Narayan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
    <pubDate>Wed, 02 Jan 2008 15:40:46 GMT</pubDate>
    <dc:creator>royalblues</dc:creator>
    <dc:date>2008-01-02T15:40:46Z</dc:date>
    <item>
      <title>GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841029#M958073</link>
      <description>&lt;P&gt;Hi Hi to all,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I am trying to create GRE tunnels over IPSec using ASA 5510. Before our company purchased the appliance, we were told that 5510 does supports GRE and configurations can be done to it to create the tunnel. I had been searching around the net for information on how to create the tunnels but so far, not much information had been gathered. Does anyone know about whether 5510 does indeed support GRE/IPSEC tunnels and any resources are available on how to configure them?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks a lot in advance and Happy Holidays!!&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tan&lt;/P&gt;</description>
      <pubDate>Wed, 13 Mar 2019 00:54:32 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841029#M958073</guid>
      <dc:creator>tanziweigca</dc:creator>
      <dc:date>2019-03-13T00:54:32Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841030#M958074</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tan,  PIX/ASA does support GRE but as a pass through, today I am not aware you can terminate GRE tunnel on PIX/ASA .  The solution would probably be to terminate the tunnel on another cisco device other than the ASA but let GRE pass through, you could also consider L2L vpn.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 25 Dec 2007 17:28:13 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841030#M958074</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-25T17:28:13Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841031#M958075</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Jorge,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the information.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;So I presumed that ASA 5510 cannot support GRE exactly as a termination endpoint. Rather, it can only allow pass through, NOT creating/generating tunnels from the device directly?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 12:55:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841031#M958075</guid>
      <dc:creator>tanziweigca</dc:creator>
      <dc:date>2007-12-27T12:55:34Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841032#M958076</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Tan that is correct, you cannot terminate a GRE tunnel neither in PIX nor in ASA.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Rgds&lt;/P&gt;&lt;P&gt;Jorge&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 27 Dec 2007 13:32:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841032#M958076</guid>
      <dc:creator>JORGE RODRIGUEZ</dc:creator>
      <dc:date>2007-12-27T13:32:38Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841033#M958077</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Jorge is right. ASA can't terminated a GRE tunnel.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Here's an example of configuration to make your ASA GRE tunnel passthrough in the case of you have an ISR router (or other...) which sits behind an ASA:&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;access-list outside_access_in line 13 extended permit gre 0.0.0.0 0.0.0.0 0.0.0.0 0.0.0.0&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Replace 0.0.0.0 with things more specific of your network if you are concerned with this issue.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Happy new year&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Tue, 01 Jan 2008 12:43:30 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841033#M958077</guid>
      <dc:creator>fropert</dc:creator>
      <dc:date>2008-01-01T12:43:30Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841034#M958078</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hello Fropert,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for the reply. I am still not sure on how to configure it and perhaps you can provide some insight to it. &lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;3800 Router &amp;lt;---&amp;gt; ASA 5510 &amp;lt;---&amp;gt; DMZ server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;The setup of the infrastructure is as above and IPSEC/GRE tunnel need to be established in order for the DMZ server to communicate with other machines on the Internet. I do not know how to configure the tunnel at all and I had all along presume that the ASA will be the termination point for the tunnel. Can you provide some insight on how to get the tunnel up and running with such a design?&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Many thanks for your help and Happy New Year to you.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2008 02:08:38 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841034#M958078</guid>
      <dc:creator>tanziweigca</dc:creator>
      <dc:date>2008-01-02T02:08:38Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841035#M958079</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;You can configure site to site IPSEC VPN between the security devices and ensure that the server traffic is part of the interesting traffic that initiates the tunnel&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;&lt;A class="jive-link-custom" href="http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml" target="_blank"&gt;http://www.cisco.com/en/US/products/hw/vpndevc/ps2030/products_configuration_example09186a00805a87f7.shtml&lt;/A&gt;&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;HTH&lt;/P&gt;&lt;P&gt;Narayan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Wed, 02 Jan 2008 15:40:46 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841035#M958079</guid>
      <dc:creator>royalblues</dc:creator>
      <dc:date>2008-01-02T15:40:46Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841036#M958080</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;Hi,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks for all the reply so far. So far, trying to use ASA to initiate the tunnel DOES NOT work at all. Therefore, I think I will have to change the setup. Currently had changed to the followings.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;ISP &amp;lt;--&amp;gt; Cisco 3800 router &amp;lt;--&amp;gt; ASA 5510 &amp;lt;--&amp;gt; Switch &amp;lt;--&amp;gt; Server&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;I think the portion on the switch and server should not be an issue at all. However, if I initiated the GRE tunnel from the 3800 router, will it flow through ASA 5510 to the server itself? I am still very blurred on this and some other areas and any help on the matter is greatly appreciated.&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Thanks,&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;Tan&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Thu, 03 Jan 2008 12:08:34 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841036#M958080</guid>
      <dc:creator>tanziweigca</dc:creator>
      <dc:date>2008-01-03T12:08:34Z</dc:date>
    </item>
    <item>
      <title>Re: GRE on ASA 5510</title>
      <link>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841037#M958081</link>
      <description>&lt;HTML&gt;&lt;HEAD&gt;&lt;/HEAD&gt;&lt;BODY&gt;&lt;P&gt;you might want to look into L2TP&lt;/P&gt;&lt;P&gt;&lt;/P&gt;&lt;P&gt;This might do what you need.  It can be built outside of the PIX and ASA.  It can be a little tricky to understand but once you get it you will like it.  We use it for high availabilty in our Email.  We have 2 front end servers, one in our corporate office and one in our data center, no matter which server is being used we always have connectivity and it is done through the psuedowire in the L2TP config set-up, little more complex than the generic routing, GRE, but still might provide what you are looking for.&lt;/P&gt;&lt;/BODY&gt;&lt;/HTML&gt;</description>
      <pubDate>Fri, 04 Jan 2008 16:24:26 GMT</pubDate>
      <guid>https://community.cisco.com/t5/network-security/gre-on-asa-5510/m-p/841037#M958081</guid>
      <dc:creator>Rick Morris</dc:creator>
      <dc:date>2008-01-04T16:24:26Z</dc:date>
    </item>
  </channel>
</rss>

