Networking · Comparison · 10 min read

GRE vs IPsec, and the Reason They Are Normally Used Together

Two tunneling protocols that fail in opposite directions, which is why production networks stack them rather than choose. And the modern arrangement that removes one of the layers.

Written by Marko Ristic, Editor Updated Sep 17, 2026
47The IP protocol number GRE uses, and it has no ports
24 BWhat GRE adds: a 4 byte header plus a new IP header
0Encryption GRE provides, across any network
1400The tunnel MTU that removes the whole stacked overhead problem
Short answer

GRE is encapsulation with no security; IPsec is security with limited encapsulation. GRE carries multicast and non IP protocols in the clear. Classic IPsec encrypts but carries only unicast, so routing protocols will not run over it. GRE over IPsec is the usual answer.

  • GRE is IP protocol 47 and encrypts nothing at all
  • Classic IPsec carries unicast only, so OSPF will not come up
  • GRE over IPsec gives a routable tunnel with everything encrypted
  • A route based tunnel does the same with one layer instead of two
  • Two encapsulations means the MTU has to be handled deliberately
On this page

The differenceWhat each one is for

The two tunneling protocols answer different questions, and reading them as competitors is what makes the comparison confusing.

GRE is a wrapper. It takes a packet of almost any kind, puts a small header on it and a fresh IP header in front of that, and sends it across the network to the other end of the tunnel, which unwraps it.

It does not care what data is inside: IPv4, IPv6, multicast, a routing protocol update, or a protocol that is not IP at all. There is no authentication, no encryption and no integrity check worth the name. Anybody who can see the packets can read them in full, which is the security story in one sentence.

IPsec is protection. Its encryption covers the payload and its authentication covers the whole packet, so an observer sees neither the data nor a way to modify it undetected. The encapsulation is a means to that end rather than a feature: tunnel mode exists to hide the original addresses, not to carry arbitrary protocols.

The consequence people run into is one specific limitation. A classic IPsec tunnel matches network traffic against a policy and encrypts what matches, and that machinery handles unicast IP.

It has no answer for a multicast packet, which is what OSPF and several other routing protocols use to find neighbors across a network. A routing protocol simply does not come up over a plain IPsec tunnel.

GRE has the opposite shape. It carries multicast packets without complaint and provides no security of any kind.

IPsec transport mode and tunnel mode

IPsec has two modes, and the differences matter once GRE is involved.

Tunnel mode encrypts the whole original packet and puts a new IP header in front. It is the mode for a site to site IPsec tunnel between two gateways, because it hides the private addresses of both networks from the internet.

Transport mode encrypts only the payload and keeps the original IP header. It suits traffic between two hosts, and it suits GRE over IPsec, where GRE has already added a new IP header. Using transport mode there saves the 20 bytes a second outer header would cost.

Inside either mode, ESP provides encryption, integrity and authentication. AH provides integrity and authentication without encryption, and is rare in practice. IKE negotiates the keys and the security associations on UDP port 500, moving to UDP 4500 when NAT traversal is in use.

Use casesGRE vs IPsec: when to use each

Most GRE vs IPsec questions are really a question about which networks the packets cross and what has to travel inside the tunnel.

  • GRE alone fits networks you already trust: a private WAN, an MPLS service, a lab. Typical jobs are carrying multicast, carrying IPv6 across an IPv4 network, or joining two routing domains. Never use it alone across the internet.
  • IPsec alone fits a secure connection between two sites over the internet when static routes are enough. It is also the basis of many remote access VPNs. It needs no GRE when only unicast IP packets cross the tunnel.
  • GRE over IPsec fits several sites with dynamic routing, multicast applications, or two vendors whose route based tunnels will not interoperate. Cisco's DMVPN is the large scale version: multipoint GRE tunnels protected by IPsec.
  • Route based IPsec fits the same need on current firewalls, with one layer of encapsulation. It is covered below.

The trade in each case is flexibility against security and overhead. GRE gives the most flexibility and no protection. IPsec gives protection and the least flexibility. The combinations buy both at the cost of bytes and configuration.

GRE over IPsecGRE over IPsec, which is what people actually deploy

The standard tunneling combination puts the GRE tunnel inside the IPsec one. The GRE tunnel is the routable interface with a routing protocol running over it, and IPsec encryption covers everything GRE produces.

original packet          [ IP ][ payload ]
after GRE                [ new IP ][ GRE ][ IP ][ payload ]
after IPsec              [ new IP ][ ESP ][ new IP ][ GRE ][ IP ][ payload ]

Three properties follow, and they are the reason this arrangement persists.

A routing protocol can run over it. The GRE tunnel presents a network interface that routing protocols treat like any other, so OSPF or EIGRP forms a neighbor relationship across it and the two networks exchange routes normally.

Failover becomes possible. With routes learned dynamically, a second network path can take over automatically, rather than depending on the static route tracking a plain IPsec VPN would need.

All the data is encrypted. Including the routing protocol traffic, which is inside the GRE packet that IPsec wrapped, so the network topology itself is not visible on the wire.

The mirror image, IPsec over GRE, also exists and is much rarer. There the GRE tunnel is built first and IPsec encrypts selected traffic inside it, so the GRE header itself travels in the clear.

It is used when only some of the data crossing the tunnel needs security, and it is worth recognizing mostly so you do not confuse the two names.

Route based VPNThe route based tunnel, which removes the GRE layer

The reason GRE over IPsec became the standard setup is that early IPsec implementations were policy based: you defined which network traffic to encrypt and there was no interface to route over.

Route based IPsec changed that. The tunnel is presented as a virtual network interface, commonly called a VTI, and traffic is encrypted because you routed it into that interface rather than because it matched a policy. That gives the routable interface GRE was being used to provide, without the extra tunneling layer.

Where it is available, and it is available on most current firewalls, it is the simpler setup and the one worth reaching for first.

Policy based IPsecGRE over IPsecRoute based IPsec
A routable tunnel interfaceNoYesYes
Carries multicastNoYesDepends on the platform
Routing protocols across itNoYesUsually yes
Layers of encapsulationOneTwoOne
OverheadLowestHighestLow
Interoperates between vendorsUsuallyUsuallySometimes, less reliably
Configuration complexityMediumHighLow

The last row is why route based tunnels have taken over inside one vendor's equipment, and the row above it is why GRE over IPsec is still what you meet between two different vendors that could not agree on anything else.

OverheadThe overhead, which has to be handled

Tunnel overhead is the practical cost in the GRE vs IPsec decision. Every tunneling layer costs bytes out of the 1500 an Ethernet link carries, and stacking two of them is how a tunnel ends up passing small packets and hanging on large ones.

ArrangementApproximate overheadA working MTU
GRE alone24 bytes1476
IPsec tunnel mode alone50 to 75 bytes1400
GRE over IPsec, tunnel modeBoth, so 74 to 991400 or lower
GRE over IPsec, transport mode20 bytes less than tunnel mode1400
GRE over IPsec with NAT traversalAdd 8 more for UDP1376

The number to set is not really the point. The point is that MTU and MSS have to be dealt with deliberately on any of these tunnels, and doubling the encapsulation doubles the chance that nobody did.

A tunnel that comes up, passes a ping, authenticates a user and then hangs on the first file transfer is this, essentially every time.

Setting the tunnel MTU to 1400 and clamping the TCP MSS around 1350 removes the whole category without arithmetic.

PitfallsWhere people go wrong

Treating GRE as a security control. It provides no security at all. A GRE tunnel across a public network is plain text data, readable by anyone on the path, and the word tunnel does a lot of misleading work here.

Expecting a routing protocol to come up over plain IPsec. Classic policy based IPsec VPNs carry unicast only, so the multicast a protocol uses to find neighbors on the network goes nowhere and the adjacency never forms.

Reaching for GRE over IPsec when a route based tunnel would do. If both ends support it, the route based setup gives the same routable interface with one tunneling layer instead of two.

Ignoring the MTU on a doubly encapsulated tunnel. Two tunneling layers of overhead on a 1500 byte link, and the symptom is a tunnel that works for every small packet.

Trusting the tunnel interface to reflect reality. A GRE tunnel stays up as long as its destination is routable on the network, so it can be up while the far end is off. GRE keepalives exist for that and are off by default.

Confusing GRE over IPsec with IPsec over GRE. The first is secure end to end, encrypting everything including the GRE header, and is what people mean. The second leaves the GRE header exposed on the network and is rare.

Assuming the overhead is fixed. IPsec overhead moves with the cipher, the mode and whether NAT traversal wrapped it in UDP, which is why the practical advice is a safe number rather than a calculation.

ONE PACKET, TWO ENCAPSULATIONS, AND WHY BOTH ARE THERETHE ORIGINAL PACKETIPpayloadAFTER GRE: carries anything, protects nothingnew IPGREIPpayload24 bytes added. Multicast and non IP protocols travel fine, in the clear.AFTER IPsec: everything above is now encryptednew IPESPnew IPGREIPpayload50 to 75 more bytes. The routing protocol inside is encrypted with everything else.GRE carries what IPsec cannot. IPsec protects what GRE cannot. That is the whole answer.And the two stacked are why the tunnel MTU is 1400 and the TCP MSS is clamped to 1350.
The headers accumulating is both the explanation and the warning. Each layer answers what the other cannot do, and together they are where the MTU went.

ComparisonEach one lacks exactly what the other has

CriterionGREIPsec
EncryptsNoYes
AuthenticatesNoYes
Carries multicastYesNo, in classic form
Carries non IP protocolsYesNo
Presents a routable interfaceYesOnly route based
Overhead24 bytes50 to 75 bytes
IP protocol number4750 for ESP, 51 for AH
Secure enough to use alone on the internetNoYes

Read the first row against the third and the whole comparison resolves. Each protocol lacks exactly what the other has, which is why GRE vs IPsec is answered by stacking them rather than by choosing.

FAQFrequently asked questions

What is the difference between GRE and IPsec?

GRE encapsulates without encryption; IPsec encrypts and authenticates but classically carries only unicast IP. The two tunneling protocols fail in opposite directions, which is why they are usually combined.

Is GRE encrypted?

No, not at all. A GRE tunnel across a public network carries its data in plain text, and anybody on the path can read it.

Why would I use GRE at all then?

Because it carries what IPsec cannot: multicast, broadcast and non IP protocols. That is what lets a routing protocol run across a secure tunnel.

What is GRE over IPsec?

A GRE tunnel whose packets are then encrypted by IPsec. It is the standard combination in site to site VPNs, giving a routable tunnel that carries routing protocols with all the data secure.

What is the difference between GRE over IPsec and IPsec over GRE?

GRE over IPsec encrypts the whole GRE packet including its header, which is what people normally want. IPsec over GRE encrypts selected traffic inside a GRE tunnel, leaving the GRE header visible.

Why will OSPF not run over my IPsec tunnel?

Because it finds neighbors on the network using multicast, and a classic policy based IPsec tunnel carries unicast only. GRE inside the tunnel, or a route based VPN, solves it.

What is a route based VPN?

An IPsec tunnel presented as a virtual interface, so traffic is encrypted because it was routed into that interface. It gives the routable interface GRE was providing, with one layer instead of two.

What is the GRE protocol number?

47. It has no ports, which is why a firewall rule permitting GRE names a protocol number rather than a port.

How much overhead does GRE add?

24 bytes: a 4 byte GRE header plus a new 20 byte IP header. Stacked with IPsec the total commonly reaches 74 bytes or more.

What MTU should I set on a GRE over IPsec tunnel?

1400 on the tunnel interface with a TCP MSS clamp around 1350 is the safe answer that avoids calculating an overhead that moves with the cipher.

Does a GRE tunnel know when the far end is down?

Not by default. The tunnel interface stays up as long as its destination is routable, so it can be up while the far router is off. Keepalives address this and are not enabled by default.

Can I use GRE without IPsec?

Across networks you fully control and trust, yes. Across the internet it means sending your data in the clear with no security, which is almost never the intention.

Which should a small business use?

A route based IPsec tunnel if both firewalls support it, which most current ones do. That setup is simpler, secure by default and has one layer of tunneling. GRE over IPsec when they do not, or when you need multicast across the link.

Read next · Remote access What Is an IPsec VPN? The protocol doing the protecting here, and the one whose route based form removes the need for GRE. Open this next11 min
Also worth reading
One packet a weekA short, illustrated explainer every Tuesday. No vendor pitches, unsubscribe in one click.