Gre And Ipip Tunneling Fundamentals; Gre And Ipip Tunneling For Ipv4 - Nortel Secure 4134 Configuration

Security — configuration and management
Hide thumbs Also See for Secure 4134:
Table of Contents

Advertisement

GRE and IPIP tunneling fundamentals

A tunnel is a logical interface that provides a framework for encapsulating
passenger packets inside a transport protocol. GRE and IPIP are
standards-based (RFC2784) (RFC1853) tunneling protocols that can
encapsulate packets inside an IP tunnel, creating a virtual point-to-point link
between routers at remote points over an IP network.
The advantage of using tunnels is that, while IPsec VPNs only function with
IP unicast frames, GRE and IPIP are capable of handling the transportation
of IP multicast traffic between two sites that only have IP unicast connectivity.
If encryption is required for a tunnel, you can enable IPsec transport
mode over GRE/IPIP tunneling. This allows for the encryption and the
transportation of multi-protocol traffic across the tunnel because both
unicast and multicast IP packets appear to the IPsec protocol as IP unicast
frame after GRE/IPIP tunneling.
The SR4134 also supports a tunneling feature set for transitioning to IPv6,
including IPv6 over manually-configured IPv4 tunnels, IPv6 over IPv4 GRE
tunnels, and automatic 6to4 tunnels. These tunneling features provide a
basic way for IPv6 hosts or islands to reach other IPv6 entities using IPv4
routing domains as the transport layer.
Multicast routing and unicast routing are supported on all tunnels, except
automatic 6to4 tunnels.

GRE and IPIP tunneling for IPv4

GRE and IPIP tunnels support the following features:
Copyright © 2007, Nortel Networks
.
tunnel protection: associates a tunnel interface with an IPsec profile. All
traffic through the tunnel is encapsulated before it is encrypted.
path MTU (PMTU) discovery: supported in order to avoid IP
fragmentation. The DF bit from the inner IP header is copied to the outer
IP header, allowing intermediate routers to fragment or not depending
on the value of the DF bit. IP Fragmentation is supported for IP packets
that exceed the MTU after insertion of the GRE/IPIP header.
Nortel Secure Router 4134
Security — Configuration and Management
NN47263-600 01.02 Standard
10.0 3 August 2007
65

Advertisement

Table of Contents
loading

Table of Contents