Home > Ask the Networking Experts > Wireless networking with Lisa Phifer Questions & Answers > What is the difference between a GRE tunnel and IPsec tunnel?
Ask The Networking Expert: Questions & Answers
EMAIL THIS

What is the difference between a GRE tunnel and IPsec tunnel?

Lisa Phifer EXPERT RESPONSE FROM: Lisa Phifer

Pose a Question
Other Networking Categories
Meet all Networking Experts
Become an Expert for this site


Routing and switching news, advice and technical information
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


>
QUESTION POSED ON: 01 January 2008

What is the difference between a GRE tunnel and IPsec tunnel?


>
EXPERT RESPONSE

Generic Routing Encapsulation (GRE), defined by RFC 2784, is a simple IP packet encapsulation protocol. GRE is used when IP packets need to be sent from one network to another, without being parsed or treated like IP packets by any intervening routers.

For example, in Mobile IP, a mobile node registers with a Home Agent. When the mobile node roams to a new network, it registers with a Foreign Agent there. Whenever IP packets addressed to the mobile node are received by the Home Agent, they can be relayed over a GRE tunnel to the Foreign Agent for delivery. It does not matter how the Home Agent and Foreign Agent communicate with each other -- hops in between just pass along the GRE packet. Only the GRE tunnel endpoints -- the two Agents -- actually route the encapsulated IP packet.

The IP Security (IPsec) Encapsulating Security Payload (ESP), defined by RFC 2406, also encapsulates IP packets. However, it does so for a different reason: to secure the encapsulated payload using encryption. IPsec ESP is used when IP packets need to be exchanged between two systems while being protected against eavesdropping or modification along the way.

For example, in a site-to-site VPN, a source host in network "A" transmits an IP packet. When that packet reaches the edge of network "A" it hits a VPN gateway. VPN gateway "A" encrypts the private IP packet and relays it over an ESP tunnel to a peer VPN gateway at the edge of network "B." VPN gateway "B" then decrypts the packet and delivers it to the destination host. Like GRE, it doesn't really matter how the two VPN gateways communicate with each other -- hops in between just pass along the ESP packet. But unlike GRE, someone at those hops could not possibly look at or change the encapsulated IP packet, even if they wanted to. That's because cryptographic algorithms have been applied to scramble the IP packet and detect any modification or replay.

In summary, use GRE where IP tunneling without privacy is required -- it's simpler and thus faster. But use IPsec ESP where IP tunneling and data privacy are required -- it provides security features that are not even attempted by GRE.


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


RELATED CONTENT
Wireless networking with Lisa Phifer
How can I implement VLANs across WLAN links?
Extending Wi-Fi range indoors or outside with 802.11n and WDS
How does WiMAX compare to other wireless broadband services?
How many more users will 802.11n wireless access points support?
Accessing printers on a LAN while connected to a WLAN.
How to maintain corporate VPN connection while printing to a private network.
How to connect wireless networks for printing capabilities
What is the Free Public WiFi network I keep seeing in public places?
Will different wireless card link speeds cause network latency?
Open source authenticator implementation for LANs: How is open1x an 802.1X supplicant?

Network Routing Protocols
What makes a WAN different from a LAN and MAN?
Does each routing protocol have a different routing table?
How can I load balance between DSLs and LLs?
How to configure ISDN and backup leases on routers
Types of link-state advertisements (LSAs) used in Open Shortest Path First (OSPF)
How do I configure two leased lines in one router?
Why IPv4 and IPv6 don't do fragment reassembly in routers
How can I check connectivity and ping between sites?
How does asynchronous transfer mode differ from existing network technologies?
Routing with NAT traversal and UPnP
Network Routing Protocols Research

TCP/IP
Is time-to-live (TTL) thrown out in IPv6?
How are TCP/IP and HTTP related?
How do you check if TCP/IP is installed on the system?
Assessing WAN connectivity, identifying latency for centralized application access
What protocol works on all layers of OSI?
TCP/IP troubleshooting: A structured approach -- Using Netdiag.exe
Which routers won't assign IP addresses to other subnets?
How can I define the layered approach to protocols?
What are the routing differences between IPv4 and IPv6?
In IP, could we eliminate the need for ARP?

RELATED GLOSSARY TERMS
Terms from Whatis.com − the technology online dictionary
10-Gigabit Ethernet  (SearchNetworking.com)
Asynchronous Pulsed Radiated Incident Light  (SearchNetworking.com)
BOOTP  (SearchNetworking.com)
CSMA/CA  (SearchNetworking.com)
Dynamic Source Routing  (SearchNetworking.com)
edge device  (SearchNetworking.com)
Link Quality Source Routing  (SearchNetworking.com)
MOSPF (Multicast Open Shortest Path First)  (SearchNetworking.com)
Next Steps in Signaling  (SearchNetworking.com)
STUN  (SearchNetworking.com)

RELATED RESOURCES
2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
Search Bitpipe.com for the latest white papers and business webcasts
Whatis.com, the online computer dictionary



Search and Browse the Expert Answer Center
Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
Browse our Expert Advice



Expert networking advice and tips for IT professionals
Visit KnowledgeStorm's comprehensive and easy to use business white paper directory.
HomeNewsTopicsITKnowledge ExchangeTipsAsk the ExpertsMultimediaWhite PapersNetworking Product Trials
About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
SEARCH 
TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

TechTarget Corporate Web Site  |  Media Kits  |  Reprints  |  Site Map




All Rights Reserved, Copyright 2000 - 2008, TechTarget | Read our Privacy Policy
  TechTarget - The IT Media ROI Experts