Home > Wide Area Network (WAN) Tips > > GRE tunnel vs. IPsec tunnel: What is the difference?
EnterpriseWAN Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 


GRE tunnel vs. IPsec tunnel: What is the difference?


Lisa Phifer, Contributing expert
05.08.2009
Rating: --- (out of 5)


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


Generic Routing Encapsulation (GRE), defined by RFC 2784, is a simple IP packet encapsulation protocol. GRE is used when IP packets need to be sent from one network to another, without being parsed or treated like IP packets by any intervening routers.

For example, in Mobile IP, a mobile node registers with a Home Agent. When the mobile node roams to a new network, it registers with a Foreign Agent there. Whenever IP packets addressed to the mobile node are received by the Home Agent, they can be relayed over a GRE tunnel to the Foreign Agent for delivery. It does not matter how the Home Agent and Foreign Agent communicate with each other -- hops in between just pass along the GRE packet. Only the GRE tunnel endpoints -- the two Agents -- actually route the encapsulated IP packet.

The IP Security (IPsec) Encapsulating Security Payload (ESP), defined by RFC 2406, also encapsulates IP packets. However, it does so for a different reason: To secure the encapsulated payload using encryption. IPsec ESP is used when IP packets need to be exchanged between two systems while being protected against eavesdropping or modification along the way.

For example, in a site-to-site VPN, a source host in network "A" transmits an IP packet. When that packet reaches the edge of network "A" it hits a VPN gateway. VPN gateway "A" encrypts the private IP packet and relays it over an ESP tunnel to a peer VPN gateway at the edge of network "B." VPN gateway "B" then decrypts the packet and delivers it to the destination host. Like GRE, it doesn't really matter how the two VPN gateways communicate with each other -- hops in between just pass along the ESP packet. But unlike GRE, someone at those hops could not possibly look at or change the encapsulated IP packet, even if they wanted to. That's because cryptographic algorithms have been applied to scramble the IP packet and detect any modification or replay.

In summary, use GRE where IP tunneling without privacy is required -- it's simpler and thus faster. But, use IPsec ESP where IP tunneling and data privacy are required -- it provides security features that are not even attempted by GRE.

This question was asked at Ask the Experts on SearchNetworking.com.

Lisa Phifer

About the author: Lisa Phifer is president and co-owner of Core Competence, a consulting firm focused on business use of emerging network and security technologies. At Core Competence, Lisa draws upon her 27 years of network design, implementation and testing experience to provide a range of services, from vulnerability assessment and product evaluation to user education and white paper development. She has advised companies large and small regarding the use of network technologies and security best practices to manage risk and meet business needs. Lisa teaches and writes extensively about a wide range of technologies, from wireless/mobile security and intrusion prevention to virtual private networking and network access control. She is also a site expert to SearchMobileComputing.com and SearchNetworking.com.


Rate this Tip
To rate tips, you must be a member of SearchEnterpriseWAN.com.
Register now to start rating these tips. Log in if you are already a member.




Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   



RELATED CONTENT
Internet and application security
WAN engineers prepare networks as cloud computing adoption rises
A year of networking dangerously: Security breaches at the brink
Ensuring wireless connectivity with IPsec-secured access points
WAN management: Palo Alto adds traffic shaping, QoS, to firewalls
Network optimization, security convergence promise more WAN control
Changing established VPN router crypto map for new encryption traffic
Controller mixes WAN failover with SIP capabilities for VoIP
As legislation passes, enterprises need to get VPN ready
WAN spending: Bright spots for 2009
Tracking NetFlow over MPLS helps airline with compliance

VPN setup and configuration
Determining efficient VPN solutions, encryption options
VPN, remote access security best practices
Determining IPsec tunneling, bandwidth capacity
Changing established VPN router crypto map for new encryption traffic
Using NAT Traversal and IPsec Passthrough together
Broadband VPN bandwidth issues
Trouble connecting to the VPN: Static and dynamic IP address issues
VPN operating system interoperability -- Configure VPNs with Windows, Checkpoint
VPN operating system interoperability -- Configure VPNs with Linux
VPN operating system interoperability -- configure VPNs with Unix

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
Network Address Translation  (SearchEnterpriseWAN.com)
tunneling  (SearchEnterpriseWAN.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary

DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.

About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Site Map




All Rights Reserved, Copyright 2009, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts