IPv4 Point-to-Point GRE Tunnels

This section outlines support for point-to-point Generic Routing Encapsulation (GRE) tunnels and how to configure them on a device.

GRE tunnels support includes the following:

  • IPv4 over GRE tunnels (IPv6 over GRE tunnels is not supported.)
  • Static and dynamic unicast routing over GRE tunnels
  • Multicast routing over GRE tunnels
  • Hardware forwarding of IP data traffic across a GRE tunnel
  • Path MTU Discovery (PMTUD)
Note: RUCKUS ICX 8100 devices do not support GRE tunnels.

GRE Tunnel Overview

Generic Routing Encapsulation (GRE), as described in RFC 2784, provides a method to encapsulate arbitrary packets (payload packets) within a transport protocol. These encapsulated packets are then transmitted from one tunnel endpoint to another. The payload is encapsulated within a GRE packet. The resulting GRE packet is then encapsulated in a delivery protocol, then forwarded to the tunnel destination. At the tunnel destination, the packet is decapsulated to reveal the payload. The payload is then forwarded to its final destination.

RUCKUS devices support GRE tunneling for the following protocols over an IPv4 network:

  • OSPF V2
  • BGP4
  • RIP V1 and V2

GRE Packet Structure and Header Format

The following figure displays the basic format of the GRE encapsulated packet. The payload packet is encapsulated inside a GRE packet which is carried inside a delivery protocol packet.

GRE Encapsulated Packet Structure

The GRE header, displayed in the following figure, contains a series of fields.

GRE Header Format

  • Checksum: 1 bit. This field is assumed to be zero in this version. If set to 1, this means that the Checksum (optional) and Reserved (optional) fields are present and the Checksum (optional) field contains valid information.
  • Reserved0: 12 bits. If bits 1 through 5 are non-zero, then a receiver must discard the packet unless RFC 1701 is implemented. Bits 6 through 12 are reserved for future use and must be set to zero in transmitted packets. This field is assumed to be zero in this version.
  • Ver: 3 bits. The GRE protocol version. This field must be set to zero in this version.
  • Protocol Type: 16 bits. The Ethernet protocol type of the packet, as defined in RFC 1700.
  • Checksum (optional): 16 bits. This field is optional. It contains the IP checksum of the GRE header and the payload packet.
  • Reserved (optional): 16 bits. This field is optional. It is reserved for RUCKUS internal use.

Restrictions for GRE Tunnel Configuration

When GRE is enabled on a Layer 3 switch, the following features are not supported on Virtual Ethernet (VE) ports, VE member ports (ports that have IP addresses), and GRE tunnel loopback ports:

  • ACL logging
  • ACL statistics (also called ACL accounting)
  • MAC ACLs
  • IPv6 filters
Note: The listed features are supported on VLANs that do not have VE ports.

When multiple IP addresses are configured on a tunnel source, the primary address of the tunnel is always used for forming the tunnel connections. Therefore, carefully check the configurations when configuring the tunnel destination.

When a GRE tunnel is configured, you cannot configure the same routing protocol on the tunnel through which you learn the route to the tunnel destination. For example, if the RUCKUS ICX device learns the tunnel destination route through the OSPF protocol, you cannot configure the OSPF protocol on the same tunnel and vice-versa. When a tunnel has OSPF configured, the RUCKUS ICX device cannot learn the tunnel destination route through OSPF. This could cause the system to become unstable.

The tunnel destination cannot be resolved to the tunnel itself or any other local tunnel. This is called recursive routing. This scenario would cause the tunnel interface to flap and the Syslog message TUN-RECURSIVE-DOWN to be logged. To resolve this issue, create a static route for the tunnel destination.

Note: RUCKUS ICX 8100 devices do not support GRE tunnels.

GRE MTU Configuration Considerations

When jumbo is enabled, the default Ethernet MTU size is 9216 bytes. The maximum Ethernet MTU size is 10178 bytes. The MTU of the GRE tunnel is compared with the outgoing packet before the packet is encapsulated. After encapsulation, the packet size increases by 24 bytes. Therefore, when changing the GRE tunnel MTU, set the MTU to at least 24 bytes less than the IP MTU of the outgoing interface. If the MTU is not set to at least 24 bytes less than the IP MTU, the size of the encapsulated packet will exceed the IP MTU of the outgoing interface. This will cause the packet to either be sent to the CPU for fragmentation, or the packet will be dropped if the DF (Do-Not-Fragment) bit is set in the original IP packet, and an ICMP message is sent.

Note: The fragmentation behavior depends on the mtu-exceed setting on the router.