Gre Tunnels - Secure Computing SG300 User Manual

Snapgear gateway
Hide thumbs Also See for SG300:
Table of Contents

Advertisement

Editing port based VLANs
Once a VLAN has been added, you may edit the settings you entered in Adding port
based VLANs by clicking its Edit icon in the main Network Setup > Connections table.
Removing port based VLANs
To remove a VLAN, click its Delete icon in the main Network Setup > Connections
table.

GRE Tunnels

The GRE configuration of the SnapGear unit allows you to build GRE tunnels to other
devices that support the Generic Routing Encapsulating protocol. You can build GRE
tunnels to other SnapGear units that support GRE, or to other devices such as Cisco
equipment.
A GRE tunnel must be created between a local IP address and a remote IP address that
can already route between each other. Typically these addresses will be LAN IP
addresses that are accessible via a VPN tunnel. It is useful to create alias addresses on
LAN interfaces for this purpose, so that the LAN IP addreses can be routed over the GRE
tunnel as well.
Warning
GRE tunnels are not secure unless they are run over another secure protocol. Using a
GRE tunnel that runs over the Internet, it is possible for an attacker to put packets onto
your network. If you want a tunneling mechanism to securely connect to networks, then
you should use IPSec, or tunnel GRE over either IPSec or PPTP tunnels.
An example setup that describes using GRE to bridge a network over an IPSec tunnel is
described in GRE over IPSec.
Packets can be sent over a GRE tunnel using either static routes or bridging.
Using static routes for a GRE tunnel over IPSec avoids having to create the many
security associations that would otherwise be needed to deal with multiple subnets at
either end.
Network Setup
101

Hide quick links:

Advertisement

Table of Contents
loading

This manual is also suitable for:

Sg530Sg570Sg575Sg580Sg550Sg560 ... Show all

Table of Contents