In the previous lesson, you saw why GRE goes first and why IPsec runs in transport mode on top of it. Now you build both layers.
As the network engineer responsible for the New York (R1) and San Francisco (R2) sites, your task will be to configure the GRE over IPsec tunnel between them.

Figure 1 - GRE over IPsec lab topology
Underlay Routing
Before building the GRE tunnel, the underlay must be working.
Configure static routes on ISP1 and ISP2 so they can forward traffic between the two enterprise WAN interfaces.ISP1# conf t Enter configuration commands, one per line. End with CNTL/Z. ISP1(config)# ip route 10.10.10.0 255.255.255.0 203.0.113.1 ISP1(config)# ip route 10.20.20.0 255.255.255.0 203.0.113.6 ISP1(config)# ip route 203.0.113.8 255.255.255.252 203.0.113.6ISP2# conf t Enter configuration commands, one per line. End with CNTL/Z. ISP2(config)# ip route 10.10.10.0 255.255.255.0 203.0.113.5 ISP2(config)# ip route 10.20.20.0 255.255.255.0 203.0.113.10 ISP2(config)# ip route 203.0.113.0 255.255.255.252 203.0.113.5Each enterprise router also needs a default route toward its ISP.
R1(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.2R2(config)# ip route 0.0.0.0 0.0.0.0 203.0.113.9GRE Tunnel
Your underlay is ready. Now build the GRE tunnel.
The tunnel endpoints are the WAN addresses and the tunnel uses the 192.168.100.0/30 subnet.On R1:
R1(config)# int tunnel0 %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to down R1(config-if)# ip address 192.168.100.1 255.255.255.252 R1(config-if)# tunnel source 203.0.113.1 R1(config-if)# tunnel destination 203.0.113.10 %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up R1(config-if)# endOn R2:
R2(config)# int tunnel0 %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to down R2(config-if)# ip address 192.168.100.2 255.255.255.252 R2(config-if)# tunnel source 203.0.113.10 R2(config-if)# tunnel destination 203.0.113.1 %LINEPROTO-5-UPDOWN: Line protocol on Interface Tunnel0, changed state to up %OSPF-5-ADJCHG: Process 1, Nbr 1.1.1.1 on Tunnel0 from LOADING to FULL, Loading Done R2(config-if)# endOSPF over GRE
The tunnel is up on both routers. The OSPF adjacency message on R2 confirms Hello packets are already flowing through GRE.
Now configure OSPF across the tunnel.R1(config)# router ospf 1 R1(config-router)# router-id 1.1.1.1 R1(config-router)# network 10.10.10.0 0.0.0.255 area 0 R1(config-router)# network 192.168.100.0 0.0.0.3 area 0 R1(config-router)# exitR2(config)# router ospf 1 R2(config-router)# router-id 2.2.2.2 R2(config-router)# network 10.20.20.0 0.0.0.255 area 0 R2(config-router)# network 192.168.100.0 0.0.0.3 area 0 R2(config-router)# exitYour GRE tunnel is up and OSPF is running through it.
But traffic is still in cleartext. Now add IPsec on top to encrypt it.Answer the question below
What subnet is used for the GRE tunnel addresses in this lab?
IPsec secures the GRE tunnel by encrypting GRE traffic as it crosses the Internet.

Figure 2 - GRE over IPsec lab topology
The workflow follows the same five steps as the IPsec Configuration lesson, with two key differences: the ACL matches GRE protocol 47 instead of LAN subnets, and the transform set uses transport mode instead of tunnel mode.
Step 1 - Interesting Traffic
Your ACL matches GRE protocol 47 between the two WAN addresses.
This tells IPsec to encrypt everything that belongs to the GRE tunnel.R1(config)# access-list 110 permit gre host 203.0.113.1 host 203.0.113.10R2(config)# access-list 110 permit gre host 203.0.113.10 host 203.0.113.1The ACLs are mirrored.
On R1 the source is its own WAN IP; on R2 it is the opposite.40 % Complete: you’re making great progress
Ready to pass your CCNP exam?