- CheckMates
- :
- Products
- :
- Quantum
- :
- Security Gateways
- :
- Re: GRE Tunnel
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Mute
- Printer Friendly Page
Are you a member of CheckMates?
×- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GRE Tunnel
Hi Experts,
I believe the the GRE tunnel cannot be terminated in the Check Point firewalls (Please confirm if by any way or in any version hardware or software or any model its supported). Also this GRE is proprietary of other vendor, is that a reason CP does not support or any other technical reasons there? Please let me know, any information is highly appreciable.
Thanks in advance.
Vijay
Accepted Solutions
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The plan is to support GRE in the main-train in the first major release in 2020.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GRE is in R81 which we plan to GA soon and we're looking for EA customers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hello,
GRE tunnels are not supported on Gaia OS. Please see sk92845 for more information.
Thanks.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GRE is hardly proprietary as it is a standard Linux kernel module.
It was possible in some older versions of Gaia to enable the necessary drivers and manually configure these interfaces using standard Linux commands.
However, none of the Gaia infrastructure recognizes GRE interfaces.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Thanks for the response!!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
According to Wikipedia, Generic Routing Encapsulation (GRE) is a tunneling protocol developed by Cisco Systems. Linux and BSD can establish ad-hoc IP over GRE tunnels which are interoperable with Cisco equipment.
sk92845: Can users create a GRE tunnel on Gaia OS?
sk157893: Check Point recommendations for tunneling through IPsec instead of GRE
sk96071: Check Point 600/1100 Appliances drops GRE packets
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The plan is to support GRE in the main-train in the first major release in 2020.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Gera,
I just opened a support case with TAC to get more info on GRE support. This is the answer I received:
"I consulted with the developers and verified sk92845.
termination of GRE traffic is not supported on Check Point Gateway.
You may refer to the local office to request for Request for Enhancement.
Please let me know in case further information is needed."
Could you point me to up to date information on GRE support as it seems TAC doesn't have the right info...
Thanks,
Tom.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
The HF was developed as RFE for another customer, so that's the reason for TAC response.
Let's discuss it offline - can you please send me an email to gerad@checkpoint.com , and I will ask my team to see if and how we can help.
Thanks
Gera
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
is there any update concerning GRE support on Gaia? Is the hotfix that was available for R80.10 also available for R80.30 and R80.40?
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
GRE is in R81 which we plan to GA soon and we're looking for EA customers.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Gera,
Would you be able to advise on whether GRE tunnel support for R81 will also include GRE support in a VS?
Kind regards,
John.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
hi Gera,
Is it possable to encypt the GRe tunnel. this could bd dome by making the tunnel endpoint intresting for encrpted traffic. thanks!
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi Gera,
We are on R81, if this supports GRE can i get the implementaion guide for the same please?
Regards,
Sanjay S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Start with the product documentation: https://sc1.checkpoint.com/documents/R81/WebAdminGuides/EN/CP_R81_Gaia_AdminGuide/Topics-GAG/GRE-Int...
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
That was a customer-specific hotfix that had some limitations associated with it, including support for future jumbo hotfixes.
Those generally don’t get ported to other releases but rather integrated as part of a maintrain release, such as R81.
Best to join the R81 Early Availability program.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Hi PhoneBoy,
If it possible to create the GRE tunnel over IPSec as we do in the Cisco routers?
Regards,
Sanjay S
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
I don't believe that's supported, no.
Am curious why you'd tunnel GRE in IPSec, though.
- Mark as New
- Bookmark
- Subscribe
- Mute
- Subscribe to RSS Feed
- Permalink
- Report Inappropriate Content
Why? For exactly the reason that Sanjay mentioned. The old-school way of doing routed vpn on Cisco IOS devices uses IPSEC in GRE. Nowadays, it's not actually necessary anymore to do routed vpn this way on cisco (you have now Virtual Tunnel Interfaces).
Some companies still use that old "technology" though and we have one customer that needs to setup such a tunnel with another company that (for whatever reason) insists on using IPSEC in GRE... so indeed this feature would be appreciated 😉
Thanks,
Tom
