07-16-2017 08:57 AM - edited 03-08-2019 11:20 AM
Hi all ,
I'm reseaching about GRE and IPSEC . But i'm wondering that what is the different between GRE over IPSEC & ISEC VPN???
I'm really confused about them.
Can someone explain for me???
Thank for help :D
Solved! Go to Solution.
07-17-2017 10:48 AM
I have full articles of the configuration for both at loopedback.com as I was studying for route, essentially mGRE is much less to configure, but there are some very important details plus you need the "ipsec security profile" included in the configuration.
Generally I only see site to site, and client VPN, though Meraki is making its Cloud VPN a cheap and viable way to sort of do a DMVPN like setup with easy configuration so I don't see a whole lot of that configured on routers anymore.
IPSec is a bit heftier than GRE over IPsec for some reason to configure, but here are the exact differences:
07-17-2017 06:26 AM
GRE and IPSec, is a GRE tunnel using IPSec for encryption.
IPSec VPN is IPSec without the GRE protocol.
Generally the latter saves at least 28 bytes of overhead. The latter, however, might also have some protocol transport limitations that GRE supports.
07-17-2017 06:57 AM
Tks Joseph,
Can u explain more the differrent between them? Which is most used, the typical of each protocol, etc.. :D
07-17-2017 10:48 AM
I have full articles of the configuration for both at loopedback.com as I was studying for route, essentially mGRE is much less to configure, but there are some very important details plus you need the "ipsec security profile" included in the configuration.
Generally I only see site to site, and client VPN, though Meraki is making its Cloud VPN a cheap and viable way to sort of do a DMVPN like setup with easy configuration so I don't see a whole lot of that configured on routers anymore.
IPSec is a bit heftier than GRE over IPsec for some reason to configure, but here are the exact differences:
07-17-2017 11:20 PM
I don't know which is used more often.
At my current employer, we only use GRE/IPSec if newer VTI IPSec tunnels are not supported.
GRE/IPSec was supported longer, so those used to doing it that way (i.e. for those that go by - if it ain't broke, don't fix it), such tunnels might have not been updated as IOS features were upgraded to allow building tunnels w/o GRE.
I find the newer VTI tunnels much easier to configure than GRE/IPSec tunnels that require map classes (or the even older versions that also required configuration on the tunnel and physical interfaces.)
Again, GRE/IPSec lets you, I also believe, do anything across the VPN you might do with GRE, which is pretty flexible. For example, you might run any routing protocol across the tunnel.
"Pure" IPSec was more oriented to host-to-host encryption, but something like VTI tunnels uses IPSec in such away it functions as much as a GRE/IPSec tunnel.
07-17-2017 11:20 PM
Tks for help :p Bro :D
07-18-2017 07:57 AM
You are sure welcome if you were talking to me, there are 5 stars back at ya :)
07-18-2017 09:00 AM
My E not good, but hope u can understand what i wrote :D
07-17-2017 11:21 PM
Tks David:D
Discover and save your favorite ideas. Come back to expert answers, step-by-step guides, recent topics, and more.
New here? Get started with these tips. How to use Community New member guide