• In the previous lesson, you saw why GRE goes first and why IPsec runs in transport mode on top of it. Now you build both layers.

    As the network engineer responsible for the New York (R1) and San Francisco (R2) sites, your task will be to configure the GRE over IPsec tunnel between them.

    GRE over IPsec lab topology

    Figure 1 - GRE over IPsec lab topology

    Underlay Routing

    Before building the GRE tunnel, the underlay must be working.
    Configure static routes on ISP1 and ISP2 so they can forward traffic between the two enterprise WAN interfaces.

    ISP1# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    ISP1(config)# ip route 10.10.10.0 255.255.255.0 203.0.113.1
    ISP1(config)# ip route 10.20.20.0 255.255.255.0 203.0.113.6
    ISP1(config)# ip route 203.0.113.8 255.255.255.252 203.0.113.6
    ISP2# conf t
    Enter configuration commands, one per line.  End with CNTL/Z.
    ISP2(config)# ip route 10.10.10.0 255.255.255.0 203.0.113.5
    ISP2(config)# ip route 10.20.20.0 255.255.255.0 203.0.113.10
    ISP2(config)# ip route 203.0.113.0 255.255.255.252 203.0.113.5

    Each enterprise router also needs a default route toward its ISP.

    R1(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.2
    R2(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.9

    GRE Tunnel

    Your underlay is ready. Now build the GRE tunnel.
    The tunnel endpoints are the WAN addresses and the tunnel uses the 192.168.100.0/30 subnet.

    On R1:

    R1(config)# int tunnel0
    %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to down
    R1(config-if)# ip address 192.168.100.1 255.255.255.252
    R1(config-if)# tunnel source 203.0.113.1
    R1(config-if)# tunnel destination 203.0.113.10
    %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
    R1(config-if)# end

    On R2:

    R2(config)# int tunnel0
    %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to down
    R2(config-if)# ip address 192.168.100.2 255.255.255.252
    R2(config-if)# tunnel source 203.0.113.10
    R2(config-if)# tunnel destination 203.0.113.1
    %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up
    %OSPF-5-ADJCHG: Process 1, Nbr 1.1.1.1 on Tunnel0 from LOADING to FULL, Loading Done
    R2(config-if)# end

    OSPF over GRE

    The tunnel is up on both routers. The OSPF adjacency message on R2 confirms Hello packets are already flowing through GRE.
    Now configure OSPF across the tunnel.

    R1(config)# router ospf 1
    R1(config-router)# router-id 1.1.1.1
    R1(config-router)# network 10.10.10.0 0.0.0.255 area 0
    R1(config-router)# network 192.168.100.0 0.0.0.3 area 0
    R1(config-router)# exit
    R2(config)# router ospf 1
    R2(config-router)# router-id 2.2.2.2
    R2(config-router)# network 10.20.20.0 0.0.0.255 area 0
    R2(config-router)# network 192.168.100.0 0.0.0.3 area 0
    R2(config-router)# exit

    Your GRE tunnel is up and OSPF is running through it.
    But traffic is still in cleartext. Now add IPsec on top to encrypt it.

    Answer the question below

    What subnet is used for the GRE tunnel addresses in this lab?