From: Larson, Chris (CLarson@usaid.gov)
Date: Wed Jul 16 2003 - 13:43:41 GMT-3
I believe this is a play on words. I think there is only one way to do it
when you get right down to the configs.
There are also quite a few reasons to do it if you consider that IP is the
only protocol that can use IPSEC. What if you wanted to encrypt and deliver
IPX or something.
You could, by putting the IPX in a GRE and encrypting the GRE using IPSEC.
When you get right down to the config what you do is create the GRE tunnel,
and then in the IPSEC define gre as something that gets encrypted. So I
don't think it is actually IPSEC over GRE (although maybe that can be done
to??) in my experience it has been the encryption of a GRE tunnel. And the
purpose has usually been to encrypt some traffic that IPSEC does not
accomodate. ie. IPX.
> -----Original Message-----
> From: Joe Deleonardo [SMTP:joe_deleonardo@hotmail.com]
> Sent: Tuesday, July 15, 2003 1:09 PM
> To: cciesecurity@yahoogroups.com; ccielab@groupstudy.com;
> security@groupstudy.com
> Subject: IPSec over GRE -vs- GRE over IPSec
>
> IPSec over GRE -vs- GRE over IPSec.
>
> Alright is this just a play on words or what? GRE over IPSec makes sense,
> it's used to transport non unicast traffic.
>
> But why would you want to do IPSec over GRE. Does anyone have a link to a
> config example? ... if it's something?
>
> Thanks,
>
> Joe
>
>
> _______________________________________________________________________
> You are subscribed to the GroupStudy.com CCIE R&S Discussion Group.
>
> Subscription information may be found at:
> http://www.groupstudy.com/list/CCIELab.html
This archive was generated by hypermail 2.1.4 : Wed Aug 06 2003 - 06:52:41 GMT-3