Hello,
I created GRE tunnel (with IPsec Sercret) between CCR and CHR. (6.44.6)
- policy created dynamically successfully (ph2 state established)
- peer created dynamically successfully
- identities created dynamically successfully
- remote peers and installed sa created dynamically successfully
but GRE tunnel is inactive (not running).
how is this possible?
Have you specified local and remote addresses of GRE on both routers?
Do you allow proper protocols to pass firewall?
>>Have you specified local and remote addresses of GRE on both routers?
Yes
>>Do you allow proper protocols to pass firewall?
Yes, full access for these addresses (without “IPsec Secret” gre-tunnel link up successfully).
I think this is a bug in ROS…
I doubt that it is a bug. I use GRE-IPSec and IPIP-IPSec ..
You need to check your FWall rules
accept input traffic from your remote peer over proto 47(gre)
and proto 89(ospf) if you need
yeahbunin
read my previous message
Why don’t you just provide a config. export of both ends instead of whining?
What do you expect anybody to do without this BASIC information?