<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Passing non-IP Traffic over IPSEC VPN using GRE over IPSEC</title>
	<atom:link href="http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/</link>
	<description>IP Networks Training and Tutorials</description>
	<lastBuildDate>Tue, 07 Feb 2012 15:03:08 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Blog Admin</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-2189</link>
		<dc:creator>Blog Admin</dc:creator>
		<pubDate>Mon, 06 Jun 2011 04:42:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-2189</guid>
		<description>Alex,

Individual IP addresses will NOT appear in the routing table. Only the whole subnet appears in the table. As long as you can reach individual IP addresses by pinging them from the other local network, this means you are ok.</description>
		<content:encoded><![CDATA[<p>Alex,</p>
<p>Individual IP addresses will NOT appear in the routing table. Only the whole subnet appears in the table. As long as you can reach individual IP addresses by pinging them from the other local network, this means you are ok.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Alex</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-2188</link>
		<dc:creator>Alex</dc:creator>
		<pubDate>Sun, 05 Jun 2011 23:04:45 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-2188</guid>
		<description>very helpful indeed. Thanx for posting. It really helped me to create gre over ipsec via internet using a cisco 887 and 877. My issue is that even though local networks (192.168.1.0 on one side and 192.168.2.0 on the other) are visible on both routing tables, nodes (all in the same workgroup) are not visible. used RIP and/or static route. I can however ping every node from one network to the other.</description>
		<content:encoded><![CDATA[<p>very helpful indeed. Thanx for posting. It really helped me to create gre over ipsec via internet using a cisco 887 and 877. My issue is that even though local networks (192.168.1.0 on one side and 192.168.2.0 on the other) are visible on both routing tables, nodes (all in the same workgroup) are not visible. used RIP and/or static route. I can however ping every node from one network to the other.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: José Dias</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1952</link>
		<dc:creator>José Dias</dc:creator>
		<pubDate>Fri, 18 Mar 2011 22:41:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1952</guid>
		<description>Hi Sunny,

You may use L2TPv3 do emulate vlan5 over a IPv4 cloud.

Regards.</description>
		<content:encoded><![CDATA[<p>Hi Sunny,</p>
<p>You may use L2TPv3 do emulate vlan5 over a IPv4 cloud.</p>
<p>Regards.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blog Admin</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1814</link>
		<dc:creator>Blog Admin</dc:creator>
		<pubDate>Thu, 24 Feb 2011 11:16:25 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1814</guid>
		<description>liaz,

Why your WAN interface is Vlan2? If its a 877 (ADSL over POTS), the WAN interface isn&#039;t an ATM / ADSL port? Check out this because the problem is on the WAN port I believe.</description>
		<content:encoded><![CDATA[<p>liaz,</p>
<p>Why your WAN interface is Vlan2? If its a 877 (ADSL over POTS), the WAN interface isn&#8217;t an ATM / ADSL port? Check out this because the problem is on the WAN port I believe.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: liaz</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1809</link>
		<dc:creator>liaz</dc:creator>
		<pubDate>Wed, 23 Feb 2011 13:16:58 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1809</guid>
		<description>Hi, i applied the configuration as mentioned on 2 cisco 877 in a lab.
I am missing something because it doesn&#039;t work.
Actually, i used 3 cisco&#039;s 877, 2 for site a and B and 1 acts as internet router.
i can ping the external ip&#039;s but no vpn or gre tunnel is up...
here are the configs:

SITE A
------

service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SITE-A
!
boot-start-marker
boot-end-marker
!
enable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
!
no aaa new-model
ip subnet-zero
!
!— This is the IPsec configuration.
!
crypto isakmp policy 10
authentication pre-share

crypto isakmp key testkey123 address 200.200.200.1
!
crypto ipsec transform-set ESPDES-TS esp-des esp-md5-hmac
!
crypto map myvpn 10 ipsec-isakmp
!
set peer 200.200.200.1
set transform-set ESPDES-TS
match address 101
!
!— This is one end of the GRE tunnel.
!
interface Tunnel0
ip address 10.0.0.1 255.255.255.0

!— Associate the tunnel with the physical outside interface.
tunnel source FastEthernet0/1
tunnel destination 200.200.200.1

!— Attach the IPSEC crypto map to the GRE tunnel.
crypto map myvpn

!— This is the internal network.

interface VLAN 1
ip address 192.168.1.1 255.255.255.0
ip nat inside

!— This is the external interface and one end of the GRE tunnel.

interface VLAN 2
ip address 100.100.100.1 255.255.255.0
ip nat outside
crypto map myvpn

!— Define the NAT pool.

ip nat pool NATPOOL 100.100.100.2 100.100.100.20 netmask 255.255.255.0
ip nat inside source route-map nonat pool NATPOOL overload
ip classless

ip route 0.0.0.0 0.0.0.0 100.100.100.254

!— Force the private network traffic into the tunnel.

ip route 192.168.2.0 255.255.255.0 10.0.0.2

!— All traffic that enters the GRE tunnel is encrypted by IPsec.
access-list 101 permit gre host 100.100.100.1 host 200.200.200.1

!— Use access list in route-map to address what to NAT.

access-list 175 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255
access-list 175 permit ip 192.168.1.0 0.0.0.255 any

route-map nonat permit 10
match ip address 175

end

Site B:
-------

service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname SITE-B
!
boot-start-marker
boot-end-marker
!
enable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
!
no aaa new-model
ip subnet-zero
!
!— This is the IPsec configuration.
!
crypto isakmp policy 10
authentication pre-share

crypto isakmp key testkey123 address 100.100.100.1
!
crypto ipsec transform-set ESPDES-TS esp-des esp-md5-hmac
!
crypto map myvpn 10 ipsec-isakmp
!
set peer 100.100.100.1
set transform-set ESPDES-TS
match address 101
!
!— This is one end of the GRE tunnel.
!
interface Tunnel0
ip address 10.0.0.2 255.255.255.0

!— Associate the tunnel with the physical outside interface.
tunnel source FastEthernet0/1
tunnel destination 100.100.100.1

!— Attach the IPSEC crypto map to the GRE tunnel.
crypto map myvpn

!— This is the internal network.

interface vlan 1
ip address 192.168.2.1 255.255.255.0
ip nat inside

!— This is the external interface and one end of the GRE tunnel.

interface vlan 25
ip address 200.200.200.1 255.255.255.0
ip nat outside
crypto map myvpn

!— Define the NAT pool.

ip nat pool NATPOOL 200.200.200.2 200.200.200.20 netmask 255.255.255.0
ip nat inside source route-map nonat pool NATPOOL overload
ip classless

ip route 0.0.0.0 0.0.0.0 200.200.200.254

!— Force the private network traffic into the tunnel.

ip route 192.168.1.0 255.255.255.0 10.0.0.1

!— All traffic that enters the GRE tunnel is encrypted by IPsec.
access-list 101 permit gre host 200.200.200.1 host 100.100.100.1

!— Use access list in route-map to address what to NAT.

access-list 175 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255
access-list 175 permit ip 192.168.2.0 0.0.0.255 any

route-map nonat permit 10
match ip address 175

end</description>
		<content:encoded><![CDATA[<p>Hi, i applied the configuration as mentioned on 2 cisco 877 in a lab.<br />
I am missing something because it doesn&#8217;t work.<br />
Actually, i used 3 cisco&#8217;s 877, 2 for site a and B and 1 acts as internet router.<br />
i can ping the external ip&#8217;s but no vpn or gre tunnel is up&#8230;<br />
here are the configs:</p>
<p>SITE A<br />
&#8212;&#8212;</p>
<p>service timestamps debug datetime msec<br />
service timestamps log datetime msec<br />
no service password-encryption<br />
!<br />
hostname SITE-A<br />
!<br />
boot-start-marker<br />
boot-end-marker<br />
!<br />
enable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx<br />
!<br />
no aaa new-model<br />
ip subnet-zero<br />
!<br />
!— This is the IPsec configuration.<br />
!<br />
crypto isakmp policy 10<br />
authentication pre-share</p>
<p>crypto isakmp key testkey123 address 200.200.200.1<br />
!<br />
crypto ipsec transform-set ESPDES-TS esp-des esp-md5-hmac<br />
!<br />
crypto map myvpn 10 ipsec-isakmp<br />
!<br />
set peer 200.200.200.1<br />
set transform-set ESPDES-TS<br />
match address 101<br />
!<br />
!— This is one end of the GRE tunnel.<br />
!<br />
interface Tunnel0<br />
ip address 10.0.0.1 255.255.255.0</p>
<p>!— Associate the tunnel with the physical outside interface.<br />
tunnel source FastEthernet0/1<br />
tunnel destination 200.200.200.1</p>
<p>!— Attach the IPSEC crypto map to the GRE tunnel.<br />
crypto map myvpn</p>
<p>!— This is the internal network.</p>
<p>interface VLAN 1<br />
ip address 192.168.1.1 255.255.255.0<br />
ip nat inside</p>
<p>!— This is the external interface and one end of the GRE tunnel.</p>
<p>interface VLAN 2<br />
ip address 100.100.100.1 255.255.255.0<br />
ip nat outside<br />
crypto map myvpn</p>
<p>!— Define the NAT pool.</p>
<p>ip nat pool NATPOOL 100.100.100.2 100.100.100.20 netmask 255.255.255.0<br />
ip nat inside source route-map nonat pool NATPOOL overload<br />
ip classless</p>
<p>ip route 0.0.0.0 0.0.0.0 100.100.100.254</p>
<p>!— Force the private network traffic into the tunnel.</p>
<p>ip route 192.168.2.0 255.255.255.0 10.0.0.2</p>
<p>!— All traffic that enters the GRE tunnel is encrypted by IPsec.<br />
access-list 101 permit gre host 100.100.100.1 host 200.200.200.1</p>
<p>!— Use access list in route-map to address what to NAT.</p>
<p>access-list 175 deny ip 192.168.1.0 0.0.0.255 192.168.2.0 0.0.0.255<br />
access-list 175 permit ip 192.168.1.0 0.0.0.255 any</p>
<p>route-map nonat permit 10<br />
match ip address 175</p>
<p>end</p>
<p>Site B:<br />
&#8212;&#8212;-</p>
<p>service timestamps debug datetime msec<br />
service timestamps log datetime msec<br />
no service password-encryption<br />
!<br />
hostname SITE-B<br />
!<br />
boot-start-marker<br />
boot-end-marker<br />
!<br />
enable secret 5 xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx<br />
!<br />
no aaa new-model<br />
ip subnet-zero<br />
!<br />
!— This is the IPsec configuration.<br />
!<br />
crypto isakmp policy 10<br />
authentication pre-share</p>
<p>crypto isakmp key testkey123 address 100.100.100.1<br />
!<br />
crypto ipsec transform-set ESPDES-TS esp-des esp-md5-hmac<br />
!<br />
crypto map myvpn 10 ipsec-isakmp<br />
!<br />
set peer 100.100.100.1<br />
set transform-set ESPDES-TS<br />
match address 101<br />
!<br />
!— This is one end of the GRE tunnel.<br />
!<br />
interface Tunnel0<br />
ip address 10.0.0.2 255.255.255.0</p>
<p>!— Associate the tunnel with the physical outside interface.<br />
tunnel source FastEthernet0/1<br />
tunnel destination 100.100.100.1</p>
<p>!— Attach the IPSEC crypto map to the GRE tunnel.<br />
crypto map myvpn</p>
<p>!— This is the internal network.</p>
<p>interface vlan 1<br />
ip address 192.168.2.1 255.255.255.0<br />
ip nat inside</p>
<p>!— This is the external interface and one end of the GRE tunnel.</p>
<p>interface vlan 25<br />
ip address 200.200.200.1 255.255.255.0<br />
ip nat outside<br />
crypto map myvpn</p>
<p>!— Define the NAT pool.</p>
<p>ip nat pool NATPOOL 200.200.200.2 200.200.200.20 netmask 255.255.255.0<br />
ip nat inside source route-map nonat pool NATPOOL overload<br />
ip classless</p>
<p>ip route 0.0.0.0 0.0.0.0 200.200.200.254</p>
<p>!— Force the private network traffic into the tunnel.</p>
<p>ip route 192.168.1.0 255.255.255.0 10.0.0.1</p>
<p>!— All traffic that enters the GRE tunnel is encrypted by IPsec.<br />
access-list 101 permit gre host 200.200.200.1 host 100.100.100.1</p>
<p>!— Use access list in route-map to address what to NAT.</p>
<p>access-list 175 deny ip 192.168.2.0 0.0.0.255 192.168.1.0 0.0.0.255<br />
access-list 175 permit ip 192.168.2.0 0.0.0.255 any</p>
<p>route-map nonat permit 10<br />
match ip address 175</p>
<p>end</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blog Admin</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1647</link>
		<dc:creator>Blog Admin</dc:creator>
		<pubDate>Wed, 12 Jan 2011 19:52:01 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1647</guid>
		<description>GRE packets are visible but the carried traffic within the GRE tunnel is encrypted by ipsec.</description>
		<content:encoded><![CDATA[<p>GRE packets are visible but the carried traffic within the GRE tunnel is encrypted by ipsec.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hiraman</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1633</link>
		<dc:creator>Hiraman</dc:creator>
		<pubDate>Sun, 09 Jan 2011 03:20:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1633</guid>
		<description>I enabled ip cache flow command on the Internet router.
I saw GRE packets passing through.
My question is that are GRE packets visible to ISP.

Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)
--------         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow
GRE                  8      0.0         7   108      0.0       3.4      15.4
Total:               8      0.0         7   108      0.0       3.4      15.4

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts

SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts
Se1           200.200.200.1   Se0           100.100.100.1   2F 0000 0000     5
Se0           100.100.100.1   Se1           200.200.200.1   2F 0000 0000     5
R3#</description>
		<content:encoded><![CDATA[<p>I enabled ip cache flow command on the Internet router.<br />
I saw GRE packets passing through.<br />
My question is that are GRE packets visible to ISP.</p>
<p>Protocol         Total    Flows   Packets Bytes  Packets Active(Sec) Idle(Sec)<br />
&#8212;&#8212;&#8211;         Flows     /Sec     /Flow  /Pkt     /Sec     /Flow     /Flow<br />
GRE                  8      0.0         7   108      0.0       3.4      15.4<br />
Total:               8      0.0         7   108      0.0       3.4      15.4</p>
<p>SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts</p>
<p>SrcIf         SrcIPaddress    DstIf         DstIPaddress    Pr SrcP DstP  Pkts<br />
Se1           200.200.200.1   Se0           100.100.100.1   2F 0000 0000     5<br />
Se0           100.100.100.1   Se1           200.200.200.1   2F 0000 0000     5<br />
R3#</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Hiraman</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-1632</link>
		<dc:creator>Hiraman</dc:creator>
		<pubDate>Sun, 09 Jan 2011 03:02:54 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-1632</guid>
		<description>I have set this up on my LAB without NAT.
Both network can reach each other other the tunnel.
But my question is how can we verify whether encryption is happening or not.
I used &quot;sh crypto iskamp sa&quot; and &quot;sh crypto ipsec sa&quot;
They didn&#039;t show any output.</description>
		<content:encoded><![CDATA[<p>I have set this up on my LAB without NAT.<br />
Both network can reach each other other the tunnel.<br />
But my question is how can we verify whether encryption is happening or not.<br />
I used &#8220;sh crypto iskamp sa&#8221; and &#8220;sh crypto ipsec sa&#8221;<br />
They didn&#8217;t show any output.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Blog Admin</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-810</link>
		<dc:creator>Blog Admin</dc:creator>
		<pubDate>Thu, 04 Nov 2010 19:05:19 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-810</guid>
		<description>GRE has problems with NAT (especially PAT). No it will not work.</description>
		<content:encoded><![CDATA[<p>GRE has problems with NAT (especially PAT). No it will not work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Enzo</title>
		<link>http://www.networkstraining.com/passing-non-ip-traffic-over-ipsec-vpn-using-gre-over-ipsec/comment-page-1/#comment-809</link>
		<dc:creator>Enzo</dc:creator>
		<pubDate>Thu, 04 Nov 2010 15:35:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.networkstraining.com/?p=255#comment-809</guid>
		<description>Hi;

 Is possible enable GRE with adsl connection, i need work with dynamic IP using PAT (Port address translation), I try with port asignation, but no work</description>
		<content:encoded><![CDATA[<p>Hi;</p>
<p> Is possible enable GRE with adsl connection, i need work with dynamic IP using PAT (Port address translation), I try with port asignation, but no work</p>
]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Page Caching using disk: enhanced

Served from: www.networkstraining.com @ 2012-02-07 19:10:43 -->
