Community discussions

MikroTik App
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

GRE over IPsec

Wed Sep 27, 2023 11:01 pm

Hi,
In IPsec configuration section under Site to Site GRE tunnel over IPsec (IKEv2) using DNS
is this configuration in GRE IPsec Tunnel Mode or GRE IPsec Transport Mode?
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1290
Joined: Tue Jun 23, 2015 2:35 pm

Re: GRE over IPsec

Thu Sep 28, 2023 3:24 am

Transport Mode
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: GRE over IPsec

Fri Sep 29, 2023 1:54 pm

But both IPSec and Gre are Layer 3 protocols?
If we want broadcast to past over vpn, we need to use L2TP over IPsec?
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1290
Joined: Tue Jun 23, 2015 2:35 pm

Re: GRE over IPsec

Sat Sep 30, 2023 5:24 am

i'm not sure if i understand u
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: GRE over IPsec

Sun Oct 01, 2023 2:35 pm

What protocols best fit to securely connect same networks over public network?
 
pe1chl
Forum Guru
Forum Guru
Posts: 10273
Joined: Mon Jun 08, 2015 12:09 pm

Re: GRE over IPsec

Sun Oct 01, 2023 2:37 pm

Transport Mode
It will be transport mode when both endpoints directly have a public IP address.
When there is NAT in front of the MikroTik router at one end, it will be tunnel mode (because IPsec transport mode does not support NAT).
 
pe1chl
Forum Guru
Forum Guru
Posts: 10273
Joined: Mon Jun 08, 2015 12:09 pm

Re: GRE over IPsec

Sun Oct 01, 2023 2:37 pm

What protocols best fit to securely connect same networks over public network?
GRE/IPsec is a good choice. That is completely unrelated to your first question.
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: GRE over IPsec

Sun Oct 01, 2023 4:49 pm

Yes, it is another question. IPsec and Gre doesn't connect same networks?
 
pe1chl
Forum Guru
Forum Guru
Posts: 10273
Joined: Mon Jun 08, 2015 12:09 pm

Re: GRE over IPsec

Sun Oct 01, 2023 10:01 pm

I don't understand you either. Maybe you are difficult to understand.
 
stalker802
newbie
Topic Author
Posts: 42
Joined: Mon Nov 22, 2010 3:50 pm

Re: GRE over IPsec

Mon Oct 02, 2023 1:28 am

Which protocols can do this?
You do not have the required permissions to view the files attached to this post.
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1290
Joined: Tue Jun 23, 2015 2:35 pm

Re: GRE over IPsec

Mon Oct 02, 2023 2:30 am

how u mean , whois protocol?

just follow the e.g.
establish the tunnel, which is the main ting.

once u do that u have two option to reach other end
1. /ip ipsec policy (more advanced)
2. /ip route (basic)
 
elbob2002
Member Candidate
Member Candidate
Posts: 256
Joined: Tue May 15, 2018 8:15 pm
Location: Ireland

Re: GRE over IPsec

Mon Oct 02, 2023 9:28 am

I think he wants to extend a single LAN across two physical locations.

For this EOIP is the only real method:

https://help.mikrotik.com/docs/display/ROS/EoIP

Performance depends on CPU though. You can have very mixed and sometimes disappointing results with EOIP.
Eoip-example.jpg
You do not have the required permissions to view the files attached to this post.
 
User avatar
nichky
Forum Guru
Forum Guru
Posts: 1290
Joined: Tue Jun 23, 2015 2:35 pm

Re: GRE over IPsec

Mon Oct 02, 2023 1:22 pm

ok, EoIP in this case will do the job.
Just one note, be careful of 42 byte overhead.

I prefer to play with BCP , but yes test it, and see how it goes.

user this ping x.x.x.x size=mtu_size do-not-fragment, if u get any issues. Good luck!!
 
elbob2002
Member Candidate
Member Candidate
Posts: 256
Joined: Tue May 15, 2018 8:15 pm
Location: Ireland

Re: GRE over IPsec

Mon Oct 02, 2023 3:30 pm

BCP has me curious - have you a quick example?

Who is online

Users browsing this forum: No registered users and 3 guests