cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
9563
Views
7
Helpful
18
Replies

How to tell if GRE traffic is encrypted or not?

mahesh18
Level 6
Level 6

                   Hi Everyone

Site A 

Device A  has VPN Tunnel to

Site B  Device B  over Wan link.

Note Here Device A and B are end device and connect to ISP and do the encryption

Site A  Device X which is internal device has simple GRE tunnel to Site Bs  internal device.

My question is how can i find that this GRE tunnel gets encrypted at Device A or not?

Currently encryption is only at Device A and B

Thanks

Mahesh

18 Replies 18

Hi Ali,

If you can please let  me know how can i do the packet capture  on 4503?

Thanks

Mahesh

Mohammad is right - use a SPAN port and connect a sniffer.

In regards to the output of show crypto ipsec sa, you will only see traffic sourced by and destined to your IPSec endpoints, not individual traffic that is encrypted.  As I mentioned above, that output would be only useful if you have a window during which you know that you should be expecting enough traffic from those endpoints that you could watch the counters on the IPSec connection and know if they were incrementing or not.

Hi Adam,

Many  thanks for answering all my qustions.

Best regards

MAhesh