GRE is encapsulation with no security; IPsec is security with limited encapsulation. GRE carries multicast and non IP protocols in the clear. Classic IPsec encrypts but carries only unicast, so routing protocols will not run over it. GRE over IPsec is the usual answer.
- GRE is IP protocol 47 and encrypts nothing at all
- Classic IPsec carries unicast only, so OSPF will not come up
- GRE over IPsec gives a routable tunnel with everything encrypted
- A route based tunnel does the same with one layer instead of two
- Two encapsulations means the MTU has to be handled deliberately
On this page
The differenceWhat each one is for
The two tunneling protocols answer different questions, and reading them as competitors is what makes the comparison confusing.
GRE is a wrapper. It takes a packet of almost any kind, puts a small header on it and a fresh IP header in front of that, and sends it across the network to the other end of the tunnel, which unwraps it.
It does not care what data is inside: IPv4, IPv6, multicast, a routing protocol update, or a protocol that is not IP at all. There is no authentication, no encryption and no integrity check worth the name. Anybody who can see the packets can read them in full, which is the security story in one sentence.
IPsec is protection. Its encryption covers the payload and its authentication covers the whole packet, so an observer sees neither the data nor a way to modify it undetected. The encapsulation is a means to that end rather than a feature: tunnel mode exists to hide the original addresses, not to carry arbitrary protocols.
The consequence people run into is one specific limitation. A classic IPsec tunnel matches network traffic against a policy and encrypts what matches, and that machinery handles unicast IP.
It has no answer for a multicast packet, which is what OSPF and several other routing protocols use to find neighbors across a network. A routing protocol simply does not come up over a plain IPsec tunnel.
GRE has the opposite shape. It carries multicast packets without complaint and provides no security of any kind.
IPsec transport mode and tunnel mode
IPsec has two modes, and the differences matter once GRE is involved.
Tunnel mode encrypts the whole original packet and puts a new IP header in front. It is the mode for a site to site IPsec tunnel between two gateways, because it hides the private addresses of both networks from the internet.
Transport mode encrypts only the payload and keeps the original IP header. It suits traffic between two hosts, and it suits GRE over IPsec, where GRE has already added a new IP header. Using transport mode there saves the 20 bytes a second outer header would cost.
Inside either mode, ESP provides encryption, integrity and authentication. AH provides integrity and authentication without encryption, and is rare in practice. IKE negotiates the keys and the security associations on UDP port 500, moving to UDP 4500 when NAT traversal is in use.
Use casesGRE vs IPsec: when to use each
Most GRE vs IPsec questions are really a question about which networks the packets cross and what has to travel inside the tunnel.
- GRE alone fits networks you already trust: a private WAN, an MPLS service, a lab. Typical jobs are carrying multicast, carrying IPv6 across an IPv4 network, or joining two routing domains. Never use it alone across the internet.
- IPsec alone fits a secure connection between two sites over the internet when static routes are enough. It is also the basis of many remote access VPNs. It needs no GRE when only unicast IP packets cross the tunnel.
- GRE over IPsec fits several sites with dynamic routing, multicast applications, or two vendors whose route based tunnels will not interoperate. Cisco's DMVPN is the large scale version: multipoint GRE tunnels protected by IPsec.
- Route based IPsec fits the same need on current firewalls, with one layer of encapsulation. It is covered below.
The trade in each case is flexibility against security and overhead. GRE gives the most flexibility and no protection. IPsec gives protection and the least flexibility. The combinations buy both at the cost of bytes and configuration.
GRE over IPsecGRE over IPsec, which is what people actually deploy
The standard tunneling combination puts the GRE tunnel inside the IPsec one. The GRE tunnel is the routable interface with a routing protocol running over it, and IPsec encryption covers everything GRE produces.
original packet [ IP ][ payload ]
after GRE [ new IP ][ GRE ][ IP ][ payload ]
after IPsec [ new IP ][ ESP ][ new IP ][ GRE ][ IP ][ payload ]
Three properties follow, and they are the reason this arrangement persists.
A routing protocol can run over it. The GRE tunnel presents a network interface that routing protocols treat like any other, so OSPF or EIGRP forms a neighbor relationship across it and the two networks exchange routes normally.
Failover becomes possible. With routes learned dynamically, a second network path can take over automatically, rather than depending on the static route tracking a plain IPsec VPN would need.
All the data is encrypted. Including the routing protocol traffic, which is inside the GRE packet that IPsec wrapped, so the network topology itself is not visible on the wire.
The mirror image, IPsec over GRE, also exists and is much rarer. There the GRE tunnel is built first and IPsec encrypts selected traffic inside it, so the GRE header itself travels in the clear.
It is used when only some of the data crossing the tunnel needs security, and it is worth recognizing mostly so you do not confuse the two names.
Route based VPNThe route based tunnel, which removes the GRE layer
The reason GRE over IPsec became the standard setup is that early IPsec implementations were policy based: you defined which network traffic to encrypt and there was no interface to route over.
Route based IPsec changed that. The tunnel is presented as a virtual network interface, commonly called a VTI, and traffic is encrypted because you routed it into that interface rather than because it matched a policy. That gives the routable interface GRE was being used to provide, without the extra tunneling layer.
Where it is available, and it is available on most current firewalls, it is the simpler setup and the one worth reaching for first.
| Policy based IPsec | GRE over IPsec | Route based IPsec | |
|---|---|---|---|
| A routable tunnel interface | No | Yes | Yes |
| Carries multicast | No | Yes | Depends on the platform |
| Routing protocols across it | No | Yes | Usually yes |
| Layers of encapsulation | One | Two | One |
| Overhead | Lowest | Highest | Low |
| Interoperates between vendors | Usually | Usually | Sometimes, less reliably |
| Configuration complexity | Medium | High | Low |
The last row is why route based tunnels have taken over inside one vendor's equipment, and the row above it is why GRE over IPsec is still what you meet between two different vendors that could not agree on anything else.
OverheadThe overhead, which has to be handled
Tunnel overhead is the practical cost in the GRE vs IPsec decision. Every tunneling layer costs bytes out of the 1500 an Ethernet link carries, and stacking two of them is how a tunnel ends up passing small packets and hanging on large ones.
| Arrangement | Approximate overhead | A working MTU |
|---|---|---|
| GRE alone | 24 bytes | 1476 |
| IPsec tunnel mode alone | 50 to 75 bytes | 1400 |
| GRE over IPsec, tunnel mode | Both, so 74 to 99 | 1400 or lower |
| GRE over IPsec, transport mode | 20 bytes less than tunnel mode | 1400 |
| GRE over IPsec with NAT traversal | Add 8 more for UDP | 1376 |
The number to set is not really the point. The point is that MTU and MSS have to be dealt with deliberately on any of these tunnels, and doubling the encapsulation doubles the chance that nobody did.
A tunnel that comes up, passes a ping, authenticates a user and then hangs on the first file transfer is this, essentially every time.
Setting the tunnel MTU to 1400 and clamping the TCP MSS around 1350 removes the whole category without arithmetic.
PitfallsWhere people go wrong
Treating GRE as a security control. It provides no security at all. A GRE tunnel across a public network is plain text data, readable by anyone on the path, and the word tunnel does a lot of misleading work here.
Expecting a routing protocol to come up over plain IPsec. Classic policy based IPsec VPNs carry unicast only, so the multicast a protocol uses to find neighbors on the network goes nowhere and the adjacency never forms.
Reaching for GRE over IPsec when a route based tunnel would do. If both ends support it, the route based setup gives the same routable interface with one tunneling layer instead of two.
Ignoring the MTU on a doubly encapsulated tunnel. Two tunneling layers of overhead on a 1500 byte link, and the symptom is a tunnel that works for every small packet.
Trusting the tunnel interface to reflect reality. A GRE tunnel stays up as long as its destination is routable on the network, so it can be up while the far end is off. GRE keepalives exist for that and are off by default.
Confusing GRE over IPsec with IPsec over GRE. The first is secure end to end, encrypting everything including the GRE header, and is what people mean. The second leaves the GRE header exposed on the network and is rare.
Assuming the overhead is fixed. IPsec overhead moves with the cipher, the mode and whether NAT traversal wrapped it in UDP, which is why the practical advice is a safe number rather than a calculation.
ComparisonEach one lacks exactly what the other has
| Criterion | GRE | IPsec |
|---|---|---|
| Encrypts | No | Yes |
| Authenticates | No | Yes |
| Carries multicast | Yes | No, in classic form |
| Carries non IP protocols | Yes | No |
| Presents a routable interface | Yes | Only route based |
| Overhead | 24 bytes | 50 to 75 bytes |
| IP protocol number | 47 | 50 for ESP, 51 for AH |
| Secure enough to use alone on the internet | No | Yes |
Read the first row against the third and the whole comparison resolves. Each protocol lacks exactly what the other has, which is why GRE vs IPsec is answered by stacking them rather than by choosing.
FAQFrequently asked questions
What is the difference between GRE and IPsec?
GRE encapsulates without encryption; IPsec encrypts and authenticates but classically carries only unicast IP. The two tunneling protocols fail in opposite directions, which is why they are usually combined.
Is GRE encrypted?
No, not at all. A GRE tunnel across a public network carries its data in plain text, and anybody on the path can read it.
Why would I use GRE at all then?
Because it carries what IPsec cannot: multicast, broadcast and non IP protocols. That is what lets a routing protocol run across a secure tunnel.
What is GRE over IPsec?
A GRE tunnel whose packets are then encrypted by IPsec. It is the standard combination in site to site VPNs, giving a routable tunnel that carries routing protocols with all the data secure.
What is the difference between GRE over IPsec and IPsec over GRE?
GRE over IPsec encrypts the whole GRE packet including its header, which is what people normally want. IPsec over GRE encrypts selected traffic inside a GRE tunnel, leaving the GRE header visible.
Why will OSPF not run over my IPsec tunnel?
Because it finds neighbors on the network using multicast, and a classic policy based IPsec tunnel carries unicast only. GRE inside the tunnel, or a route based VPN, solves it.
What is a route based VPN?
An IPsec tunnel presented as a virtual interface, so traffic is encrypted because it was routed into that interface. It gives the routable interface GRE was providing, with one layer instead of two.
What is the GRE protocol number?
47. It has no ports, which is why a firewall rule permitting GRE names a protocol number rather than a port.
How much overhead does GRE add?
24 bytes: a 4 byte GRE header plus a new 20 byte IP header. Stacked with IPsec the total commonly reaches 74 bytes or more.
What MTU should I set on a GRE over IPsec tunnel?
1400 on the tunnel interface with a TCP MSS clamp around 1350 is the safe answer that avoids calculating an overhead that moves with the cipher.
Does a GRE tunnel know when the far end is down?
Not by default. The tunnel interface stays up as long as its destination is routable, so it can be up while the far router is off. Keepalives address this and are not enabled by default.
Can I use GRE without IPsec?
Across networks you fully control and trust, yes. Across the internet it means sending your data in the clear with no security, which is almost never the intention.
Which should a small business use?
A route based IPsec tunnel if both firewalls support it, which most current ones do. That setup is simpler, secure by default and has one layer of tunneling. GRE over IPsec when they do not, or when you need multicast across the link.
Keep readingRelated concepts
Read next · Remote access What Is an IPsec VPN? The protocol doing the protecting here, and the one whose route based form removes the need for GRE. Open this next11 min- Routing · 12 min OSPF Explained The multicast this protocol uses to find neighbors is exactly what a plain IPsec tunnel will not carry.
- Diagnostics · 12 min MTU and Fragmentation, and the Numbers Worth Memorizing Two encapsulations on a 1500 byte link is the clearest way to produce a tunnel that hangs on real data.