ScreenOS Firewalls (NOT SRX)
Reply
Trusted Contributor
michael.saw
Posts: 1,048
Registered: ‎09-26-2011
0

IPSec over GRE?

Hi all,

 

Can Juniper Firewall support IPSec over GRE?

Are there kb links on this?

 

Couldn't find much information here...

Thanks!

Michael
JNCIA-JUNOS, JNCIS-ENT/SEC, JNCIP-ENT
(CCNA, ACMP, ACFE, CISE)
"http://www.thechampioncommunity.com/"
CONNECT EVERYTHING. EMPOWER EVERYONE.
Share & Learn. Knowledge is Power.

"If there's a will, there's a way!"
Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: IPSec over GRE?

Hi,

 

KB3256 How to configure a GRE tunnel over IPSEC between Juniper Firewall devices

KB6126 Can a GRE tunnel be established between a Juniper Firewall and a Cisco Router?

Kind regards,
Edouard
Trusted Contributor
michael.saw
Posts: 1,048
Registered: ‎09-26-2011
0

Re: IPSec over GRE?

Hi echidov,

Thanks for that.
How about IPSec over GRE?
Thanks!

Michael
JNCIA-JUNOS, JNCIS-ENT/SEC, JNCIP-ENT
(CCNA, ACMP, ACFE, CISE)
"http://www.thechampioncommunity.com/"
CONNECT EVERYTHING. EMPOWER EVERYONE.
Share & Learn. Knowledge is Power.

"If there's a will, there's a way!"
Distinguished Expert
echidov
Posts: 858
Registered: ‎11-02-2009
0

Re: IPSec over GRE?

Hi,

 

I have never tried this but it should be possible. You can configure a GRE tunnel as described in the KB but without IPSec. As there are no VPN SAs the tunnel interface will not come up. But routing through the tunnel interface may be forced if the routes are configured as permanent. The IPs of the VPN endpoints should be routed across the GRE tunnel.

As I suppose you want to terminate the VPN IPSec on a third party device(s). If both devices are SSGs this does not make sense to use IPSec over GRE.

Kind regards,
Edouard
Trusted Contributor
michael.saw
Posts: 1,048
Registered: ‎09-26-2011
0

Re: IPSec over GRE?

Hi echidov,

Thanks for sharing.

Anyone have any links to share on this?
Thanks!

Michael
JNCIA-JUNOS, JNCIS-ENT/SEC, JNCIP-ENT
(CCNA, ACMP, ACFE, CISE)
"http://www.thechampioncommunity.com/"
CONNECT EVERYTHING. EMPOWER EVERYONE.
Share & Learn. Knowledge is Power.

"If there's a will, there's a way!"
Copyright© 1999-2013 Juniper Networks, Inc. All rights reserved.