Security Basics mailing list archives

Re: GRE Tunnels without IPSEC risks.


From: Maps1 <maps1 () btinternet com>
Date: Tue, 12 Jul 2011 19:20:44 +0100 (BST)

Thanks, All.

These are Aruba APs and controllers. 

Just so I'm clear - This is a VPN connecting the remote office to the main office, so I'm assuming it would still be 
encrypted inside this over the Internet? But then the GRE encapsulation would offer no additional protection so the 
traffic would be accessible to anyone who can sniff either side of the VPN (i.e. on the inside at either office) ?

Does that sounds right, or is it worse than this?

Thanks again!

--- On Tue, 12/7/11, Mike Hale <eyeronic.design () gmail com> wrote:

From: Mike Hale <eyeronic.design () gmail com>
Subject: Re: GRE Tunnels without IPSEC risks.
To: maps1 () btinternet com
Cc: security-basics () securityfocus com
Date: Tuesday, 12 July, 2011, 17:51
GRE, by itself, doesn't encrypt
anything.  It *encapsulates* the
payload, but doesn't encrypt it.

If you want to make sure the data is encrypted, you'll need
to run
IPSec on that tunnel.

On Tue, Jul 12, 2011 at 2:10 AM, Maps1 <maps1 () btinternet com>
wrote:
Hi List,

Our network guys have been implementing wireless
access points in a remote office, which will then use a GRE
VPN link back to our main office to connect to the wireless
controller.

In other remote offices where we have full WAN links
back to the main office, we have configured the APs to use
IPSEC tunnels for this communication. Unfortunately, these
don't seem to work through the VPN GRE tunnels used in the
smaller offices.

Please could someone help me to understand the risks
(if any) involved in setting the AP communication to not use
IPSEC tunnels, but to rely on the encryption on the GRE VPN
tunnel instead?

Thanks!


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital
Certificate
In this guide we examine the importance of Apache-SSL
and who needs an SSL certificate.  We look at how SSL
works, how it benefits your company and how your customers
can tell if a site is secure. You will find out how to test,
purchase, install and use a thawte Digital Certificate on
your Apache web server. Throughout, best practices for
set-up are highlighted to help you ensure efficient ongoing
management of your encryption keys and digital
certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1

------------------------------------------------------------------------





-- 
09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0


------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: