GRE tunnels do aid multicast, so a GRE tunnel can be employed to initial encapsulate the dynamic routing protocol multicast packet within a GRE IP unicast packet, that can then be encrypted by IPsec. Keep in mind that the DF little bit is copied within the interior IP header to the outer IP header when IPsec encrypts a packet. During fragmentation, yet another twenty-byte IP header is added for the 2nd fragment, causing a 1500-byte fragment plus a seventy two-byte IP fragment. GRE packets to receive 1500-byte and 68-byte GRE packets. Configuring "ip mtu 1440" (IPsec Transportation mode) or "ip mtu 1420" (IPsec Tunnel manner) to the GRE tunnel would take away the possibility of double fragmentation Within this state of affairs. The media MTU and PMTU values are saved during the IPsec Protection Affiliation (SA). You will note With this scenario how the IPsec PMTU changes into a reduce benefit as the results of the necessity for fragmentation.

Observe: You really want to stay away from fragmentation following encapsulation any time you do components encryption with IPsec. IPsec encrypts The 2 packets, introducing fifty two byes (IPsec tunnel-mode) of encapsulation overhead to every, to give a 1552-byte plus a a hundred and twenty-byte packet. The packet is going to be fragmented ahead of GRE encapsulation and 1 of such GRE packets might be fragmented all over again right after IPsec encryption. One particular attention-grabbing scenario is when an IP packet has become split into two fragments and encapsulated by GRE. IP tunnel packets Using the tunnel path-mtu-discovery command, as well as the DF little bit is copied from the first IP header for the GRE IP header. The original IP headers stay intact, besides the IP protocol discipline is improved to be ESP (fifty), and the first protocol price is saved within the IPsec trailer being restored once the packet is decrypted. 58 bytes (Encapsulating Stability Payload (ESP) and ESP authentication (ESPauth)) for every packet.

