I've seen customers do this with a fair amount
of regularity, it's pretty straight forward to
set this up, and the PIX and IOS should have
no problems talking to one another with IPSEC
(this sounded like it may have been a concern of
yours) - at any rate, as to whether it's "secure" -
depends on your policy. An obvious place for
attacks on the GRE tunnel are prior (or after)
the crypto endpoints - so check your other internal security.
The other thing that you might want to do to educate yourself about IPSEC is read the evauluation on
the Counterpane Systems homepage (www.counterpane.com) - it points out some of the
flaws of IPSEC (but also states that for what it does, there isn't anything better).
-Rakesh