[strongSwan] GRE encapsulation within IPSec

Noel Kuntze noel at familie-kuntze.de
Tue May 5 22:32:40 CEST 2015


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA256

Hello Florin,

Yes, just create a GRE tunnel device using "ip link"  or "ip tunnel".

Mit freundlichen Grüßen/Kind Regards,
Noel Kuntze

GPG Key ID: 0x63EC6658
Fingerprint: 23CA BB60 2146 05E7 7278 6592 3839 298F 63EC 6658

Am 05.05.2015 um 22:31 schrieb Florin Andrei:
> Running strongSwan on Linux, connecting with various IPSec appliances at the other end - Cisco ISR, VPN concentrators, etc.
>
> In some cases, it would help if I could create a GRE tunnel inside IPSec, terminated on a virtual interface on my end. If the tunnel was Cisco / Cisco, this would be trivial. But it's Linux (strongSwan) / Cisco.
>
> Is there a way to terminate GRE tunnels with Linux, assuming GRE is within the IPSec tunnel?
>

-----BEGIN PGP SIGNATURE-----
Version: GnuPG v2

iQIcBAEBCAAGBQJVSSjlAAoJEDg5KY9j7GZYCXAP/0Yk9uc4D2HmfOzC8rYIVzz8
uhey0A2mOthgOCvOX43yZMZ2Y/57sjt4B8qyplpbdSrLnQWAIyGjAXMGh2Xd2/P3
NkHrZjXueqnorIF+wgGBvUXBd+6HJlzUOnAmG4jC68U223PTKJV53tOLLUI1ipzn
ZafVl8n2KE3bGK1CrZPGM7pPFdceZJDHClTCVvxAgjIASGVU/6uPBYzYekGEvsQk
Ac8hnsHFEUHcAetQM5diJnkJe9bH5DJOy4NqSGWIwrqHYJsbw9yH3w3CaFf59Cot
zoBZDlWCY9nVxcoBTbbLCqt8ac6/KdiGNRYs1V/KUAqjbyRt/zVb/hJsCMHuJMZN
jSnIlmXMpaSX8UEE4/VGwoAbxoOOVX2nNNPkcNwk7zoUnU57vMOUN/OVhIUZDH6v
7wCXzPJ7lg/v11CzSrfMB/PUaUkVzHZf5uQe50Qahw/Gq9GRgwP5lGLoQ5PyojE4
RS0XliR7oEXe/009RoRPAvdQ0H294tonsSHLvkcxmySo/bTgS/J1mYo92bfJURTP
huBjexEJDuYAPJ4QiaAXrZkZAzYL5+ZVx5dQCIHml0V1hMyMI0fqNSJhc5EZSS/B
d+Z1eGxyahO2+qTMbAe5josQ7HrJnslADo3BpjVc3L9/ncUbdNGHGG43cOXDDUhw
BIaxPVEWmKSa0b5KtUcz
=I8Eg
-----END PGP SIGNATURE-----



More information about the Users mailing list