Net Talk - GRE over IPsec

Поділитися
Вставка
  • Опубліковано 11 вер 2024
  • In this "Net Talk" session, we cover the theory and configuration of GRE over IPsec VPNs.

КОМЕНТАРІ • 80

  • @kenchiken6338
    @kenchiken6338 Рік тому +5

    I've been looking for an explanation like this for a while. I understand more from this 30 minute video than I ever have even in courses I paid for. Thanks for this!

  • @srb1855
    @srb1855 4 роки тому +9

    Most lucid explanation of gre-over-IPSec that I have seen! 👍

  • @edrem0777
    @edrem0777 4 роки тому +10

    This explanation of GRE over IP sec is by far the best, simple, smooth, and to the point of what GRE over internet is...Thank you for taking the time to make these videos and teaching us so much.

  • @paulmassingham550
    @paulmassingham550 5 місяців тому

    Just found this video, and I have to say this is the best explanation of how to configure GRE over IPSEC that I have seen. Thank you Kevin and keep up the great content.

  • @rlopez3188
    @rlopez3188 4 роки тому +3

    All I wanna say is thank you baby cheesus for dropping Kevin Wallace into this world!!!
    You sir are amazing!!! Your teaching style is simply awesome!!! Thanks for the videos and the knowledge transfer!!

  • @RK-ly5qj
    @RK-ly5qj 2 роки тому +1

    Im not using Cisco equipment at all but, whole theory is very needed to understand how protocols works in fact. So i'm thankful to you for your spended time to share with us your knowledge. you're doing great job !

  • @44black88
    @44black88 4 роки тому

    I just want say you do awesome work Kevin. I been following your channel for some time now. I got my CCNA before the deadline and now I'm after my CCNP. Great work!!! I always leave with little more confidence after you video instruction.

  • @AlexisRamirez-qs7qe
    @AlexisRamirez-qs7qe 2 роки тому

    Your videos helped me remember everything from my CCNA and helps apply it as well. Thank you so much for your videos.

  • @cddvdblurayful
    @cddvdblurayful 10 місяців тому

    Sir, this is a treasure. Thank you for this!

  • @mk-or8nm
    @mk-or8nm 3 роки тому

    I hit 'like' button as a 500th person. How is it possible that it is not 500k likes already? Great video Kevin as all of your videos thanks a lot for your work.

  • @Mrmagnodsb
    @Mrmagnodsb 3 роки тому

    Thank you for taking the time to make a video about this topic Kevin. Perfect explanation!!!

  • @krichklinhom5605
    @krichklinhom5605 3 роки тому

    Hello , I'm from thailand country . I have a littel bit skill in english but i try to learning from you VDO and thank you sir for all video .

  • @datedatekyal3650
    @datedatekyal3650 3 роки тому

    Great explanation, Thanks, waiting for more net talk.

  • @misterrestore7403
    @misterrestore7403 2 роки тому

    Thank you Kevin. Grate Session.. ! By the way on all your videos!

  • @luykennethcarl
    @luykennethcarl 3 роки тому

    Thanks for this kevin.. more vids to come pleasee! Very help for us students

  • @FerdsTechChannel
    @FerdsTechChannel 4 роки тому +1

    Thanks for this video, Kevin! I'm planning to make a video about this same topic.

  • @seagarts
    @seagarts 2 роки тому

    Thank you Kevin for this elaborate understanding

  • @sudiptabhar3161
    @sudiptabhar3161 3 роки тому

    Cleared my All Doubts..THANK YOU SIR

  • @joyhoo2041
    @joyhoo2041 4 роки тому

    your video is my favorite study video, simple and smooth,

  • @digew
    @digew 4 роки тому

    Many thanks for explaining it smoothly.

  • @Hypocrisy.Allergic
    @Hypocrisy.Allergic 10 місяців тому

    I swear IPsec is the most difficult subject for CCNP ENCOR for me, but great explanation as usual.

  • @howtobasicbreathe8457
    @howtobasicbreathe8457 4 роки тому

    As usual, amazingly well explained

  • @ManishKumar-zf5rh
    @ManishKumar-zf5rh 2 роки тому

    Thank you kavin. Such a lucid information

  • @mohammedosman4692
    @mohammedosman4692 4 роки тому

    Thank you sir for such an awesome explanation. I love it 👏🏽👍🏽

  • @aamm9129
    @aamm9129 2 роки тому

    CCNA 200-301 doing now thank you for this!

  • @edohkakasomado2351
    @edohkakasomado2351 4 роки тому

    Great video...It has been very helpful for me

  • @Bilal.Al-Sardar
    @Bilal.Al-Sardar 4 роки тому

    Awesome video, great explanation.

  • @andreslopez180
    @andreslopez180 4 роки тому +3

    Kevin this is awesome example. Can you please make a video on the same topic but with DMVPN, My employer is expanding and I'm face with the challenge of connect the sites together.

    • @kwallaceccie
      @kwallaceccie  4 роки тому +1

      Thanks for the great suggestion! I'll definitely plan on doing a DMVPN video early next year.

    • @marcovanbrenk6951
      @marcovanbrenk6951 4 роки тому

      @@kwallaceccie did you already create such great video for DMVPN? cheers

  • @barakagarama1346
    @barakagarama1346 4 місяці тому

    Am on my way for my CCNA. 🎉🎉🎉

  • @snupi12345
    @snupi12345 4 роки тому +1

    Hello Kevin. Love your videos. I have a question about the illustration of GRE over IPsec on 15:15. Shouldn't there be the other way around? That is IPsec encapsulated inside the GRE tunnel? Especially if you use, in later configuration, mode transport, opposite to mode tunnel?

  • @mudasir2168
    @mudasir2168 Рік тому

    crystal clear explanation!

  • @FerdsTechChannel
    @FerdsTechChannel 4 роки тому

    Thanks Kevin for reading my comment!

  • @donnyrap
    @donnyrap 3 роки тому

    Loved that Kevin ! Wonderful 😵

  • @bobdavislumbro4047
    @bobdavislumbro4047 6 місяців тому

    Hey kevin! quick question here @21:20 you said Routers create a layer 2 segment adjacency, why do we call it "layer two" if it also involves routing ? or is it because they are on the same subnet ?

  • @mahenooransari14
    @mahenooransari14 3 роки тому

    thanks a lot....great help in understanding the concept

  • @BG-su1lv
    @BG-su1lv 2 роки тому

    Excellent.

  • @TheRawi
    @TheRawi Рік тому

    Hi Kevin,
    Nice tutorial there!
    I have only 1 question: is the tunnel creation mandatory for the IPsec to operate?
    Can we do the exact configuration but without creating the tunnel?
    If not, how does the router use the tunnel here? I see no command to link the tunnel with the IPsec in the configuration 🤔

  • @bboymichaelyang
    @bboymichaelyang 2 роки тому

    Is this setup behind a NAT router?
    I would like to see the entire configs on the router. Thanks

  • @jessicamann684
    @jessicamann684 8 місяців тому

    GRE is configured with a destination IP address and two IP addresses for the internal tunnel (of a /30 subnet). If we configure more than one GRE tunnel on the same interface on a router, how does the router know which tunnel each incoming GRE packet belongs to?

  • @fredaguilaracosta9685
    @fredaguilaracosta9685 5 місяців тому

    Hey Kevin
    Thanks for the video. What are your recommendations for a ccna guy wanting to do the ccnp with no much industry experience

  • @robinkhn2547
    @robinkhn2547 3 роки тому

    Great video, but why did you use IKEv1? There already is a newer version of IKE, namely IKEv2, which is better than IKEv1.

  • @giftmarshallchawira241
    @giftmarshallchawira241 2 місяці тому

    Wonderful

  • @wyohman00
    @wyohman00 4 роки тому

    Great job. My only critique is using ISAKMP/IKEv1 in examples. From a security perspective, no one should be using IKEv1 when IKEv2 is available. People will refer to this video and configure their production systems with what they've seen. Always practice like you would do in production.

  • @refaiabdeen5943
    @refaiabdeen5943 2 роки тому

    Cheers Mate.

  • @zemtronix1
    @zemtronix1 4 роки тому +1

    Kevin, do you have an outline that includes your slides for your routing and switching 200-125 video. It would help with taking notes when studying when following your video. Thanks

    • @kwallaceccie
      @kwallaceccie  4 роки тому +1

      Thanks so much for your interest. However, the slides are only available to those who enroll in my live training course.

  • @saibot293
    @saibot293 4 роки тому +1

    Great video - I can actually listen to you for longer than most trainers.. question do I have to add the tunnel int to the routing protocol?

    • @kwallaceccie
      @kwallaceccie  4 роки тому +5

      Thanks! You don't have to (you could use static routes), but I did in this example. Specifically, I used the "network 0.0.0.0 255.255.255.255 area 0" command under each router's OSPF routing protocol configuration, making all active interfaces participate in the routing process.

  • @supunniwarthanarathnayake6503

    Instead of using crypto map VPN, we also can use crypto IPsec profile over the tunnel interface right?

  • @The_Son_of_Oden
    @The_Son_of_Oden 3 роки тому

    Thank you Kevin I wish you could write all cisco books

  • @perryuploads776
    @perryuploads776 Рік тому

    Hi Kevin, love your videos but the mic volume was too low on this one. 😛 Edit: At 2:06 your sound was oke

  • @apollosolutions9961
    @apollosolutions9961 3 роки тому

    Nice video !

  • @ashishlahunde4479
    @ashishlahunde4479 2 роки тому

    Thank you sir.🤗

  • @nolmanbarroso8894
    @nolmanbarroso8894 3 роки тому

    In releases before Cisco IOS 12.2(13)T, the crypto maps must be applied to both the physical interface and the logical interface (tunnel).

  • @alvaroidrugo5346
    @alvaroidrugo5346 4 роки тому

    Hello Kevin, This a great and simple explanation. I glad of that. I got a question. First you created a GRE tunnel which is the ovelay network.
    Then came in the IPSEC to provide protection to the information. But I can't realize on the configuration or what step is the join between the GRE tunnel 0 and the IPSEC config. Could you please point it out in which line command configuration that tie happens?

    • @Yooper_eh
      @Yooper_eh 4 роки тому

      If I understand your question (and the theory) correctly, the *crypto ipsec transform-set* statement creates the IPSec portion, the ACL named *GRE-IN-IPSEC* specifies the traffic and they are brought together by the *crypto map* policy named *VPN.* Looked at another way, it is the ACL that diverts the "interesting" GRE traffic through the IPSec tunnel. I hope that helps to answer your question (and that it's technically correct).

  • @MrSauske98
    @MrSauske98 2 роки тому

    That's great

  • @mariembuenaventura1278
    @mariembuenaventura1278 3 роки тому

    Thank you !

  • @GadgetRobb
    @GadgetRobb 3 роки тому

    Could you have also used tunnel protection mode instead of the crypto map?

  • @marcovanbrenk6951
    @marcovanbrenk6951 4 роки тому

    Hi Kevin is tunnel protection ipsec profile not a better solution then crypto map?

  • @pascaldufour9275
    @pascaldufour9275 3 роки тому

    If GRE is established first. Doesn't that make it IPSEC over GRE ?
    I am confused

  • @claytonsmith6092
    @claytonsmith6092 Рік тому

    Currently have a CCNA and want to get my CCNP.

  • @resres6596
    @resres6596 3 роки тому

    Perfect 👍

  • @twrkmx
    @twrkmx 3 роки тому

    GOAT

  • @mohamedelfatihelamin2698
    @mohamedelfatihelamin2698 Рік тому

    It’s not the number of keys, its the long of the key of encryption.

  • @RahulVishwakarma-uq5np
    @RahulVishwakarma-uq5np 4 роки тому

    Great Sir

  • @fredaguilaracosta9685
    @fredaguilaracosta9685 5 місяців тому

    More please

  • @techevangelist8373
    @techevangelist8373 4 роки тому

    Great presentation. One question, i see some call this IPsec over gre and some say gre over IPsec. Which one is correct 😀

    • @kwallaceccie
      @kwallaceccie  4 роки тому +2

      You can do either one. However, this video covers taking the GRE unicast packets and sending them over IPsec.

    • @mitpatel4268
      @mitpatel4268 4 роки тому +1

      @@kwallaceccie Would you please inform me how would the vice versa (IPSec over GRE) be of any advantage at all? Is it really?

  • @bobdavislumbro4047
    @bobdavislumbro4047 3 роки тому

    So then, what is the benefit of data encapsulation if it does not provide security? thanks

    • @kwallaceccie
      @kwallaceccie  3 роки тому +1

      It can provide tunnels to create a virtual overlay network.

    • @bobdavislumbro4047
      @bobdavislumbro4047 3 роки тому

      @@kwallaceccie thanks but then again... Does the tunnel provide any sort of security or anyone can see what's inside the tunnel payload etc

  • @SandeepKumar-bv6wl
    @SandeepKumar-bv6wl 2 роки тому

    GRE established before ipswc and one can communicate over GRE how ipsec controlling traffic and GRE tunnel

  • @joyhoo2041
    @joyhoo2041 4 роки тому

    I have just passed my CCNP EI cert

  • @MrBrainy33
    @MrBrainy33 4 роки тому

    this is what i call timimg..just before the CCNA =)

  • @Bobby-zg5fp
    @Bobby-zg5fp 4 роки тому

    imagine being this one dude that keeps disliking free training courses for seemingly no reason