I just have a couple of questions with GRE over IPSEC.
1. When a clear text packet enters the router does it access the crypto map first or the out bound access-list?
2. When configuring GRE over transport IPSEC where does the AH header get placed. Is it in-between the original IP header and data like this stack?
New IP header
GRE Header
Original IP header
AH Header
Encrypted Payload
Or is it placed in between the new ip header and the GRE header like this stack?
New IP header
AH Header
Encrypted Payload
Thanks in advance for any guidance.
Brad