Create a Post
cancel
Showing results for 
Search instead for 
Did you mean: 
Rafal_Oracz
Explorer

GRE over IPSEC

Hi,

Has anyone managed to build GRE through an IPSEC tunnel?

I tried both: domain and route based IPSEC.

All I can achive is GRE traffic seen within vpnt interface, but it seems to blackhole traffic since I cant see any IPSEC traffic going out the gateway.

 

If it is possible, I prefer domain based IPSEC but it seems that gateway has problem with redirecting its own GRE traffic to IPSEC tunnel.

0 Kudos
6 Replies
the_rock
Legend
Legend

Last time I got it working was back in R76, have not tried it after that. Not sure if things changed drastically since then when it comes to GRE, but what is the drop if you see any? Is there specific log?

Its 100% supported, so I would certainly check things I mentioned.

Andy

https://community.checkpoint.com/t5/Security-Gateways/GRE-Tunnel/td-p/64838

0 Kudos
Lesley
Leader Leader
Leader

https://support.checkpoint.com/results/sk/sk90060

-------
If you like this post please give a thumbs up(kudo)! 🙂
0 Kudos
CheckPointerXL
Advisor
Advisor

i had to configure a new FW, one to perform GRE, the other one IPSEC

spent lot of weeks but it seems not possible with one FW to perform both operations

0 Kudos
PhoneBoy
Admin
Admin

It should be noted that GRE traffic, especially originating from the gateway itself, is not SecureXL friendly.
It will always go slowpath/F2F. 

0 Kudos
Chris_Atkinson
Employee Employee
Employee

Why would you want GRE+IPSec if you have native route based VPN, is it some use case involving multicast?

CCSM R77/R80/ELITE
0 Kudos
Rafal_Oracz
Explorer

Thanks all of you for answers.

Suddenly it started to work when I tried to swtich to route based VPN, but finnaly it works on default domain based VPN.
This configuration is needed to connect to mobile Private APN.

0 Kudos

Leaderboard

Epsum factorial non deposit quid pro quo hic escorol.

Upcoming Events

    CheckMates Events