How GRE Tunnels Work | VPN Tunnels Part 1

แชร์
ฝัง
  • เผยแพร่เมื่อ 19 ธ.ค. 2024

ความคิดเห็น • 107

  • @namratatiwari1588
    @namratatiwari1588 4 ปีที่แล้ว +1

    Best video on GRE ! Surfed over 5-6 videos before landing to this.

  • @DileepKumarMB
    @DileepKumarMB ปีที่แล้ว

    Overlay network using GRE Tunnel- nicely explained, Thanks

  • @Alex-gf4iu
    @Alex-gf4iu 4 หลายเดือนก่อน

    What a great video. Really useful the commands were at the bottom and you explained the difference between source and destination

  • @varunkashyap5644
    @varunkashyap5644 4 ปีที่แล้ว +1

    thanks buddy for creating this series. i read a lot but could not get through before , but today atlast i got.
    keep making such videos

    • @NetworkDirection
      @NetworkDirection  4 ปีที่แล้ว +1

      It's so good to hear that these videos are helping you

  • @oliver1121
    @oliver1121 6 ปีที่แล้ว +7

    It is so weird how perfectly timed these videos are coming out to my studying. When I was looking into learning VRF's you released an excellent video series on VRF's. Now when I want to brush up on VPN's you release this video at the perfect time. Keep up the awesome work! Hopefully the next series will be MPLS.

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +2

      That is uncanny!
      I have been thinking about basic MPLS as a series. Won’t be next, but hopefully soon

    • @GamjaField
      @GamjaField 6 ปีที่แล้ว +3

      LOL same 😂

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +1

      Nice!

  • @teamstandyteamstandy9830
    @teamstandyteamstandy9830 4 ปีที่แล้ว +1

    Very simple, high level overview of what a GRE tunnel is/does. Well done. Thank you!

  • @TheLithGH
    @TheLithGH 5 ปีที่แล้ว +4

    Thanks for creating and sharing with us!! Perfect explanation for us that are new to GRE!!! Cheers!

  • @Jderama100
    @Jderama100 6 ปีที่แล้ว +1

    Thank you, very clear and easy to understand. Please continue to make videos like this - highly appreciate it.

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      You're welcome! I'm currently working on extending this with DMVPN

  • @amitkala6382
    @amitkala6382 2 ปีที่แล้ว +2

    The way you demonstrated is simply amazing.... Would you mind to share low level stuff on ikev1 &2..... Thanks again.

    • @NetworkDirection
      @NetworkDirection  2 ปีที่แล้ว

      Thank you!
      I might revisit IKE. I'll add it to my list, thanks again

  • @PR-cn5bb
    @PR-cn5bb 6 ปีที่แล้ว +3

    Finally some quality tutorials, great work!

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      I appreciate the feedback Pawel, thanks!

  • @slamtoo11
    @slamtoo11 4 ปีที่แล้ว

    Just saw this video after I had a question in CCNA about GRE.
    This is amazing. Thank you for putting this together.

    • @Neon-nv4oy
      @Neon-nv4oy 6 หลายเดือนก่อน

      May I ask what you're doing in life now with a bit over 4 years in the field ? (if you stuck to the field ofc) I just wanna get an idea

  • @alexandercullum6632
    @alexandercullum6632 2 ปีที่แล้ว +1

    super helpful video, thank you!

  • @samsonv9332
    @samsonv9332 2 ปีที่แล้ว +1

    Awesome explanation, thanks!

  • @markusscott6696
    @markusscott6696 4 ปีที่แล้ว +3

    It is a nice explanation of packet encapsulation (starts from 6 min), but i dont understand where is the role of a tunnel - 192.168.1.0 network???

  • @steveshawcross
    @steveshawcross ปีที่แล้ว

    Good and simple explanation !!

  • @NetworkDirection
    @NetworkDirection  6 ปีที่แล้ว +2

    Read more here: networkdirection.net/GRE+Tunnels
    Try the lab here: networkdirection.net/labsandquizzes/labs/lab-gre-tunnels/

  • @EpisonicProject
    @EpisonicProject 7 หลายเดือนก่อน

    Amazing video I understand gre now

  • @peterruppert7856
    @peterruppert7856 2 ปีที่แล้ว

    Thank you so much!!! Great video!!

  • @Amsj1166
    @Amsj1166 5 ปีที่แล้ว +1

    Wow very nicely explained

  • @user-qo8js3qk5z
    @user-qo8js3qk5z 3 ปีที่แล้ว

    Excellent video thank you so much for the breakdown.

  • @TheMaro57
    @TheMaro57 ปีที่แล้ว

    I have no idea what you're talking about but you're better than a college professor definitely...

  • @TheVillageShow
    @TheVillageShow 8 หลายเดือนก่อน

    Very beautiful. Thankyou so much 🎉🎉

  • @mdsameer2774
    @mdsameer2774 6 หลายเดือนก่อน

    very good. Keep going,

  • @p4pryk
    @p4pryk 6 ปีที่แล้ว +15

    There is a mistake with address on topology and set for tunnel src/dst addr. 20.20.20.20 and 10.20.20.20.
    Anyway, great series :) thx for that.

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +6

      You're absolutely right! Sorry everyone, the topology says 20.20.20.20 when it should say 10.20.20.20
      Thanks for noticing this

    • @jnev9046
      @jnev9046 5 ปีที่แล้ว

      @@NetworkDirection would this type of mis-configuration show a tunnel up/down or a reset/up? BTW, Great Explanation!

    • @NetworkDirection
      @NetworkDirection  5 ปีที่แล้ว +1

      @@jnev9046 Do you mean if we put in the wrong destination IP?
      I think this would mark the tunnel as up, but it wouldn't work

    • @ithereos9554
      @ithereos9554 4 ปีที่แล้ว +1

      @@NetworkDirection But, if the router did have reachability to 20.20.20.20 (and 20.20.20.20 was the correct destination IP), the GRE tunnel will go up without issues no?

    • @ivanarteaga3282
      @ivanarteaga3282 ปีที่แล้ว

      pin this comment! :P

  • @noelgriffiths7561
    @noelgriffiths7561 4 ปีที่แล้ว +1

    I am currently learning CCNP Enterprise Encor and found this video series on 'GRE' along with the 'VXLan' and 'VRF' videos very informative with clear explanations. Thank you for posting these videos, will you be posting any others that will be helpful with the CCNP Enterprise course?

  • @yusefskaff47
    @yusefskaff47 4 ปีที่แล้ว

    Excellent explanation!! I appreciate that 👍🏼

  • @mahendrakumarsahu4395
    @mahendrakumarsahu4395 4 ปีที่แล้ว

    Awesome !!!
    I like very much the animated explanation ♥️
    Thank you Sir

  • @AeroAngle
    @AeroAngle ปีที่แล้ว

    enabling jumbo frames help with GRE and why or why not?

  • @Null-Null1
    @Null-Null1 6 ปีที่แล้ว +3

    Another great explaination!

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +1

      Thanks Daniel! So happy that it makes sense.
      Looking forward to seeing GRE tunnels with IPSec?

    • @Null-Null1
      @Null-Null1 6 ปีที่แล้ว +3

      @@NetworkDirection Definitely! Always enjoy your well presented and explained videos

  • @YeshwanthSimhadri
    @YeshwanthSimhadri 6 ปีที่แล้ว +1

    very nice explanation - may be a LAB would have been an icing on the cake

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      Thanks, that's a good suggestion.
      I'm working on a couple of GRE labs now

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      Here's the lab: networkdirection.net/labsandquizzes/labs/lab-gre-tunnels/

  • @DillyDogSays
    @DillyDogSays 2 ปีที่แล้ว +1

    Does GRE tunnels work with Virtual Networks also? So two virtual networks could communicate on a SD-WAN via GRE Tunneling?

    • @NetworkDirection
      @NetworkDirection  2 ปีที่แล้ว

      SD-WAN uses a lot of technologies 'under the hood', including tunnels (possibly GRE), MPLS, VXLAN, and thinkg like these. Each provider implements it differently though

  • @weaselfeet
    @weaselfeet 6 ปีที่แล้ว +1

    This was fantastic, looking forward the the encryption component,

  • @pin-fatsh9553
    @pin-fatsh9553 6 ปีที่แล้ว +1

    Thanks for this well-explained nuggets :)

  • @jaronprovidence9484
    @jaronprovidence9484 5 ปีที่แล้ว +1

    Awesome video, thanks!

  • @ahmedareem9599
    @ahmedareem9599 3 ปีที่แล้ว

    man, that's a fantastic video!

  • @exmundi
    @exmundi 3 ปีที่แล้ว

    Those virtual interfaces build an ARP cache?
    If yes, how do they seem?

    • @NetworkDirection
      @NetworkDirection  3 ปีที่แล้ว

      The ARP cache will build for anything with L2 adjacency

  • @Mike-ci5io
    @Mike-ci5io 2 ปีที่แล้ว

    How does lowering mtu avoid fragmentation infact it will increase it so you want highest mtu interface can support

  • @raadhoque
    @raadhoque หลายเดือนก่อน

    very good😇

  • @MohanKumar-wp8kc
    @MohanKumar-wp8kc 3 ปีที่แล้ว

    good series

  • @sarvesh81s
    @sarvesh81s 4 ปีที่แล้ว

    Thanks for Very good Explanation , how did you put IP address in tunnel source command ?? it should be interface

    • @NetworkDirection
      @NetworkDirection  4 ปีที่แล้ว +1

      You can use either, but using the IP allows the router to choose the best interface based on the address.
      In some cases this will improve stability (covered in the following videos)

  • @babakvelamkon
    @babakvelamkon 6 ปีที่แล้ว +1

    Thanks. Plz emphasis more on vpn vs gre application, similarity and differences

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      I'm not sure I understand correct...
      GRE is a type of VPN. It's different to the app that you install on your computer to connect into the office from home.
      GRE is different, as you're not connecting a single device to the network virtually. Instead, you're creating a virtual link between entire networks.
      Does that help?

    • @babakvelamkon
      @babakvelamkon 6 ปีที่แล้ว +1

      Network Direction Thanks. The confusion I have is why to go for site-2-site Vpn and not gre/ipsec. Is there any reason that most people deploy the vpn and not secure gre?

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +1

      Ah, I understand now.
      Not everything supports GRE. GRE is kind of a routing technology. So, you'll commonly find it on routers.
      An IPSec VPN was developed from the security point of view, so it is mor common on firewalls. ASA's for example, support IPSec VPN's, not GRE + IPSec.
      As to why vendors decide to support one technology but not another... I'm not sure.

    • @babakvelamkon
      @babakvelamkon 6 ปีที่แล้ว +1

      Network Direction Thanks alot

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว

      You’re welcome

  • @tommclaughlin7179
    @tommclaughlin7179 4 ปีที่แล้ว

    Thank you for simplifying gre!

  • @narendrajayram1317
    @narendrajayram1317 5 ปีที่แล้ว +1

    great explanation!

  • @jordantaylor3788
    @jordantaylor3788 ปีที่แล้ว

    Is this still true? I didn't think you could advertise OSPF over GRE as the interfaces would be flapping when trying to send ospf packets to the endpoint?

    • @NetworkDirection
      @NetworkDirection  ปีที่แล้ว +1

      Hi Jordan
      Thanks for your comment! What you are describing is route recursion. This can happen if you do it wrong, but OSPF over GRE is just fine if you do it right. I believe the next video in this series discusses this further. 😃
      Have a great day!

  • @Zbenesch
    @Zbenesch 5 ปีที่แล้ว

    Nicely done!

  • @Robertorossell
    @Robertorossell 4 ปีที่แล้ว

    Thanks great material

  • @GamjaField
    @GamjaField 6 ปีที่แล้ว +1

    Thank you. Great explanation as always​. Will you cover the IPSec tunnel in this series?

    • @NetworkDirection
      @NetworkDirection  6 ปีที่แล้ว +1

      Absolutely! Give me two weeks, and you’ll have a video on adding IPSec to the GRE tunnel, including the basics of how IPSec works

    • @GamjaField
      @GamjaField 6 ปีที่แล้ว +1

      Network Direction Awesome! :)

  • @muhammadsiddique5892
    @muhammadsiddique5892 5 ปีที่แล้ว

    Great Explanation.. Thanks.

  • @allien5329
    @allien5329 5 ปีที่แล้ว +2

    best explained !!!

  • @daveycrockett9447
    @daveycrockett9447 2 ปีที่แล้ว

    only problem with this description - is you have a RFC 1911 on the left that will NOT route across the Internet. Would have been nice if the example was more realistic in such a way that it would work in a real world scenario.

  • @mmobini1803
    @mmobini1803 ปีที่แล้ว

    Thank you!

  • @eksadiss
    @eksadiss 5 ปีที่แล้ว +1

    5:28 you said 1436 when I think you meant to say 1476

  • @jairusan
    @jairusan 4 ปีที่แล้ว

    I appreciate the effort and time spent to make this video, however, there are just too many mistakes in the content for this specific demonstration, which is dangerous and frustrating for those who really took the time to understand the configuration and even emulate the exercise. I think there are mistakes in the destination IP address: 20.20.20.20/24 > 10.20.20.20/24. In the explanation of how the packets travel through the OVERLAY VTI's or GRE tunnel, NOT UNDERLAY as you mentioned in the video, and also I am not sure if you meant 172.16.1.1 and 172.16.1.2 and forgot to specify the CIDR here...as well. Again, not trying to troll or anything but I think this video should be removed, corrected, and re-posted for the sake of all members subscribed. There are a lot of people commenting on things like, great work, awesome video, great explanation, and we know that they definitely didn't understand what they just watched. Thank you for all you do, as I am subscribed and love some of the other videos you have put together, but, unfortunately, after checking this GRE one very carefully, I will have to be very careful going forward when following the videos you post. Hope this feedback is helpful.

  • @ahmed786tutu
    @ahmed786tutu 3 ปีที่แล้ว

    i think you missed the static route explanation thats needed here

    • @NetworkDirection
      @NetworkDirection  3 ปีที่แล้ว

      Do you mean explaining what static routes are, or how they're used for this application?

    • @ahmed786tutu
      @ahmed786tutu 3 ปีที่แล้ว

      @@NetworkDirection yeah i meant for this application, ie how do the two edges know how to get to each other and how do we force traffic over the tunnel. also how not to cause recursive routing issues. but the video was information nonetheless.

  • @jahedbenbarka9008
    @jahedbenbarka9008 5 ปีที่แล้ว

    Thank u man.....

  • @leonelsimoes2616
    @leonelsimoes2616 2 ปีที่แล้ว +1

    Destination address should be 192.168.2.1 instead of 192.168.1.2

    • @NetworkDirection
      @NetworkDirection  2 ปีที่แล้ว

      Thank you! Unfortunately, I can't go back and change it

  • @digiground7613
    @digiground7613 3 ปีที่แล้ว

    nice...

  • @arunrkrishnan9833
    @arunrkrishnan9833 3 ปีที่แล้ว

    perfect

  • @rohanofelvenpower5566
    @rohanofelvenpower5566 4 ปีที่แล้ว

    aha so very very simple. Basically it adds what is called "Outer IP" header which has the ISPs routers IPs which are PUBLIC IPs so the routers over the Internet (/WAN) KNOW where they are. And there is also the small gre header that says what the original IP version is being used by the private hosts with private, non-routable IP addresses.
    So you stick public IPs on top of the packet and route it as normal. By the time it arrives at the destination and it is de-encapsulated the private host will see it's private ip (non-routable) that it knows. So easy it's a joke haha