Forum Discussion

aamit_211382's avatar
aamit_211382
Icon for Nimbostratus rankNimbostratus
Apr 23, 2019

Does F5 Support IPSEC over GRE ?

I have worked on F5 BIGIP IPSEC configuration and GRE as well but I never worked on IPSEC over GRE. can someone help me whether F5 Supports IPSEC over GRE? If so, where can I find the required documentation?

 

1 Reply

  • There will probably be some issues here. This article describes the situation which is the opposite analogue to your position:

     

    K16093: An IP tunnel built over an IPsec tunnel interface will not work

     

    IMHO much of the issue in that respect will apply to your situation also since tunnel objects on BIG-IP act similarly to VLANs.

     

    You would potentially run into a problem with your self-IP since BIG-IP doesn't have a directly analogous concept to Linux point-to-point links.

     

    I'd be inclined to set this up in my lab to understand the reality of it since as long as your IP addresses are adjacent and the lower one's last octet is a multiple of 2 you may be able to configure a /31 subnet for the self-IP to get this to work.

     

    Whether it'd be considered supportable in production if it ran into difficulty and in the light of the above KB article would be another question entirely.