GRE tunnel traffic can be protected using
IPsec
.
NOTE: The IPsec Traffic selector must be configured to capture the GRE packets without inter-
fering with the routing to the GRE tunnel. When necessary, it is possible to add other addresses
in "ARP proxy & VLAN" configuration.
■
GRE diagnostics
GRE tunnels are named after the pattern "gretunX" where "X" is the tunnel index. Tunnel index is
correspond to lines in the "GRE tunnels" starting with "0". Each line is counted including the lines
which are not "Active". Example: the first line tunnel name is "gretun0".
Monitoring
•
IP protocol number 47 is GRE.
•
To be able to monitor the traffic on the GRE tunnel interface, the GRE tunnel ID must be set
up in the ETH monittoring: Advanced parameters/User rule/-i gretun0 (as an example of the
first GRE tunnel).
•
Example of GRE packet monitoring on the Radio interface:
11:18:44.323793 [RF:phy:Tx] IP 10.10.1.41 > 10.10.1.67: IP protocol 47, length 126
•
Example of GRE packet monitoring on the ETH interface:
11:22:58.643627 [ETH] IP 192.168.1.41 > 192.168.1.1: GREv0, length 88: IP ►
10.144.1.41 > 10.144.1.2: ICMP echo request, id 319, seq 1, length 64
Troubleshooting
•
The packet forwarded to the GRE tunnel must only be routed to the corresponding IP at the
other side of the tunnel. If the IP address fits the IP address range of the tunnel, but it does
not exist, the packet is permanently looped back and forth until the TTL expires. The ICMP
message "Time exceeded: TTL expired in transit" is sent to the original sender of the packet.
•
The tunnel only accepts and extracts GRE packets with a source address which is the same
as the GRE tunnel's Peer address. If a GRE packet from another source appears, it is dis-
carded and the ICMP message "Destination unreachable: Destination port unreachable" is
sent to the original sender of the packet.
■
Buttons
Apply
- applies and saves the changes.
Cancel
- restores original values.
175
© RACOM s.r.o. – RipEX Radio modem & Router
Advanced Configuration
Содержание RipEX
Страница 2: ......
Страница 42: ... DQ Data Quality Min 180 PER Packet Error Rate Max 5 RipEX Radio modem Router RACOM s r o 42 Network planning ...
Страница 222: ...Fig 10 3 ATEX Certificate RipEX 2 3 RipEX Radio modem Router RACOM s r o 222 Safety environment licensing ...
Страница 223: ...Fig 10 4 ATEX Certificate RipEX 3 3 223 RACOM s r o RipEX Radio modem Router Safety environment licensing ...