Pages

Friday, November 4, 2016

Infoblox NetMRI 1400 Appliance with Network Automation OS Configuration Steps

The Infoblox NT 1400 network automation appliance is designed to automate network change, see the impact of changes on network health, manage network configurations and meet a variety of compliance requirements.

KEY FEATURES:
  • Network Discovery
Automatically and continually track multi-vendor infrastructure, end hosts, network constructs (routes, VLANs, virtual forwarding and routing, etc.), and topologies with current and historical information.
  • Configuration Management
Automatically detect and audit network changes and receive detailed analysis. Take advantage of configuration back up, powerful search, and correlation of network problems with time and location.
  • Change Automation
Manage network-wide change tasks with simple yet robust methods for encoding change logic with minimal scripting.
  • Policy and Compliance Enforcement
Automatically and continuously assess network changes in real time against security policies with an easy-to-use rule studio.
  • Network Analysis
Get analysis and alerts on network configuration problems, including ticking time bombs that show no fault or performance symptoms.
  • Anytime, Anywhere Mobile Access
Manage your network from your mobile device. View network inventory, find device locations, and control port and VLAN connections.
  • Hardened Appliance
Get a solution that ships on a purpose-built hardware device and includes the operating system and database, reducing your costs and maintenance requirements.

 Infoblox NT 1400 network automation appliance




Configuration Steps:

1. Connect to console port on NetMRI appliance:


NetMRIProd login:
admin
Password:
Last login: Wed May 11 16:14:55 on ttyS0


Network Automation Administrative Shell
---------------------------

Available Commands:
acl ftp md5sum register setup
autoupdate grep more remoteCopy show
cat halt netstat removedsb snmpwalk
clear help ping removemib ssh-key
configure installdsb provisiondisk repair supportbundle
debug installhelpfiles quit reset telnet
deregister installmib rdtclient restore tftpsync
diagnostic license reboot rm top
exit ls recalculate-spm route traceroute
export maintenance refreshgroups set

NetMRIProd> configure
*** Unknown Command '' ***

Usage: configure <setting> [show|reset]

Available Settings
------------------
ssh - Configures ssh client and server
http - Configures http and https server
snmp - Configures SNMP server
server - Configures system settings such as IP address, gateway, etc.
certificates - Configures SSL certificates
reset - resets all systems to factory default

NetMRIProd>
setup
This option allows you to configure system settings such as IP address,
subnet mask, default gateway, and DNS servers.

Do you want to start system setup now? (y/n) [n]:
y

Default values, when available, are given within [].
You may clear defaults by typing a SPACE and pressing Enter.

+++ Configuring Network Identification Settings
Database Name is a descriptive name for this deployment. It is used in reports titles, headers, etc.
Recommended: Begin name with uppercase letter.

Database Name [netmri]:

The Server Name identifies this system in SNMP and HTTPS server certificates.
The installed HTTPS certificate contains the following subject:
subject= /CN=NetworkAutomation-1450201401100015/O=Network Automation

Server Name [NetMRIProd]:
Do you want to generate a new HTTPS Certificate? (y/n) [n]: n

Domain Names are used to truncate device names in Network Automation tables and reports.
Recommended: specify local domain name(s).

Domain Name 1 (e.g., example.com) [gi-de.com]:
Domain Name 2 (optional) []:

Time Servers are used to synchronize time with reliable time sources.
Recommended: use a local ntp server if available.

Time Server [us.pool.ntp.org]:

Time Zone Regions
Choose your local region.

0. Africa 1. Antarctica 2. Arctic 3. Asia
4. Atlantic 5. Australia 6. Brazil 7. Canada
8. CET 9. Chile 10. EET 11. GMT
12. GMT-1 13. GMT+1 14. GMT-2 15. GMT+2
16. GMT-3 17. GMT+3 18. GMT-4 19. GMT+4
20. GMT-5 21. GMT+5 22. GMT-6 23. GMT+6
24. GMT-7 25. GMT+7 26. GMT-8 27. GMT+8
28. GMT-9 29. GMT+9 30. GMT-10 31. GMT+10
32. GMT-11 33. GMT+11 34. GMT-12 35. GMT+12
36. Europe 37. Hongkong 38. Iceland 39. Indian
40. Israel 41. Mexico 42. NZ 43. NZ-CHAT
44. Pacific 45. US 46. UTC 47. WET

Enter choice (0-47) [7]: 7

Choose a location within your time zone.

0. Atlantic 1. Central 2. East-Saskatchewan 3. Eastern
4. Mountain 5. Newfoundland 6. Pacific 7. Saskatchewan
8. Yukon

Enter choice (0-8) [3]:

+++ Configuring Management Port Settings
You must configure an IPv4 or IPv6 address/mask on the management port.
Network Automation can perform analysis from the management port or a separate scan port.

IP Address (optional) [10.9.90.42]: 10.9.12.40
Subnet Mask (optional) [255.255.255.0]:
IPv6 Address (optional):
IPv6 Prefix (optional):
You must provide either an IPv4 gateway, an IPv6 gateway, or both.

IPv4 Default Gateway (optional) [10.9.90.20]: 10.9.12.1
IPv6 Default Gateway (optional) []:

Do you want to configure the Scan Port? (y/n) [n]:

DNS Servers are used to map hostnames to IP addresses.
You may enter up to 2 name servers below.

DNS Server 1 (IP) [10.9.90.2]:
DNS Server 2 (optional) []:


Current settings:
Database Name: netmri
Server Name: NetMRIProd
Domain Name 1: gi-de.com
Domain Name 2:
Time Server: us.pool.ntp.org
Time Region: Canada
Time Location: Eastern
Mgmt Port IP Address: 10.9.12.40
Mgmt Port Subnet Mask: 255.255.255.0
Mgmt Port IPv6 Address:
Mgmt Port IPv6 Prefix:
Mgmt Port IPv4 Default Gateway: 10.9.12.1
Mgmt Port IPv6 Default Gateway:
Scan Port IP Address:
Scan Port Subnet Mask:
Scan Port IPv6 Address:
Scan Port IPv6 Prefix:
Scan Port IPv4 Default Gateway:
Scan Port IPv6 Default Gateway:
DNS Server 1: 10.9.90.2
DNS Server 2:

NOTICE: Using existing HTTPS Certificate.

Edit these settings? (y/n) [n]:

Configure the system with these settings? (y/n) [y]: y

Configuring system ...

Configuring Scan port...

OK.
Configuring Mgmt port...

OK.
+++ Restarting Network ... OK
Server name successfully configured
NTP successfully configured
Timezone successfully configured

+++ Syncing System Clock ...
+++ Trying us.pool.ntp.org ...
Error resolving us.pool.ntp.org: Name or service not known (-2)
3 Nov 16:36:52 ntpdate[20129]: Can't find host us.pool.ntp.org: Name or service not known (-2)
3 Nov 16:36:52 ntpdate[20129]: no servers can be used, exiting
+++ NTP service from us.pool.ntp.org is not available.

+++ Restarting Server ... OK
NetMRIProd>


2. WebUI Step by Step Configuration




You will need to download license from NetMRI support site.















   



   










Saturday, October 29, 2016

Windows 10 Tips and Tricks

1. Install Telnet Client

Option 1 – From Control Panel

  1. Open “Control Panel“.
  2. Open “Programs“.
  3. Select the “Turn Windows features on or off ” option.
  4. Check the “Telnet Client” box.
  5. Click “OK“. A box will appear that says “Windows features” and “Searching for required files“.When complete, the Telnet client should be installed in Windows.

Option 2 – From Command Line

You can also install the Telnet Client by issuing a command.
  1. Hold down the Windows Key, then press “R“.
  2. The Run dialog box appears. Type:
    • pkgmgr /iu:”TelnetClient”
  3. Select “OK” and Windows will install the Telnet client.


2. Check System Uptime

Option 1 – From Task Manager

  1. Bring up the Task Manager by right-clicking the clock in the lower-right corner of the taskbar and selecting Task Manager. Alternately, you could press CTRL + ALT +Delete.
  2. Select the “Performance tab. If you cannot see tabs, select the “More details” option.
  3. You can see system uptime located toward the bottom of the window. This will provide you with a live time period on how long the system has been on.Win 8 task manager with system uptime

Option 2 – Via Command

You can also see system uptime by using the command prompt.
  1. Select “Start“.
  2. Type “cmd, then press “Enter.
  3. Type “net stats server, then press “Enter.
  4. Toward the top of the output, there is a line that says “Statistics Since…” that will show the time the computer last came online. It provides other data too, such as sessions accepted, amount of data sent, system errors, and print jobs spooled.
Stats output on command line
The “net stats server” command can also be used in many previous versions of Microsoft Windows.

3. Hiding Windows Folder
下面我教朋友一个Attrib命令,可以让文件夹彻底的

隐藏起来,就算是在文件夹选项中设置了显示隐藏文件夹,也无法显示出来的。只能通过路径访问的方式打开文件夹。如:我想把

D盘根目录下的“maopian”文件夹隐藏起来,点击【开始】-【运行】,在【运行】中输入“cmd”,回车,在弹出的在命令行窗口下

输入“attrib +s +a +h +r D:\maopian”。然后回车就可以了。

        文件夹被隐藏后,当你要打开这个文件夹的时候,可以点击【开始】-【运行】中输入“D:\maopian”打开文件夹,也可以通

过打开的任意文件夹菜单栏下的地址栏中输入“D:\maopian”打开。

        如果你想重新显示该文件夹的话,可以把attrib的“+”号替换成“-”号。文件夹就可以恢复显示了。
  
        若要隐藏成回收站的图标,只需将回收站下的desk.ini文件拷贝至该文件夹下即可

        具体attrib命令详情,可问度娘



4. 上帝模式一键开启

日常操作中,我们经常要对Windows 10进行各种设置,但是默认系统设置都是分布在不同地方,比如有的在控制面板中,有的则在某个系统程序中。这样操作起来就极为不便,不过Windows 10已经内置一个上帝模式的隐藏工具,我们只要手动开启即可将所有设置归集在一个设置窗口。

首先在桌面上右击选择“新建文件夹”,然后将该文件夹的名称重命名为“some_name.{ED7BA470-8E54-465E-825C-99712043E01C}”,这样以后只要在桌面打开上述文件夹,可以看到现在系统所有设置已经全部集中在此,大家只要按需选择所需的组件即可(图1)。

 

图1 开启系统上帝模式

实际上类似上述{ED7BA470-8E54-465E-825C-99712043E01C}名称,这个叫做类标识符,文件夹名称添加上这样的标识后就变成系统文件夹,比如“我的电脑”对应{20D04FE0-3AEA-1069-A2D8-08002B30309D} ,“我的文档”对应 {450D8FBA-AD25-11D0-98A8-0800361B1103}等。善于为普通文件夹增加类标识符可以实现一些特殊功能,比如上述上帝模式文件夹还可以用来保存私密文件,按住Shift键,右击选中上述目录选择“在新进程中打开”,这样打开的就是一个真正的文件夹,我们可以在其中保存文件,而用户默认双击打开的则是上帝模式(图2)。

 

图2 使用“在新进程中打开”可以直接打开文件夹

5. 历史问题一目了然

在系统出现问题的时候,我们经常需要在事后进行问题的查找。对于系统曾经发生的问题,Windows 10已经在后台为我们自动记录下来了。在“开始”菜单搜索框输入“可靠性监视”,在打开的程序窗口中,系统会按照时间顺序记录曾经的历史问题,点击相应的问题后不仅可以看到详细的信息,点击“检查解决方案”还可以自动解决大多数常见的系统问题(图3)。

 

图3 查看系统历史问题

如果想查询确定错误报告中涉及的问题,我们同样可以使用快捷命令来进入错误报告查询页面,右击“开始”徽标选择“运行”,接着输入“ control.exe /name Microsoft.ActionCenter /page pageSignoff”,在打开的窗口中即可看到所有问题的解决方案(图4)。

 

图4 快速查看解决方案

6. 一键锁定电脑

平时需要离开电脑一段时间时,很多朋友都会使用Win+L键或者“开始→用户图标→锁定”的方法锁定电脑。如果觉得上述方法不够快捷,现在可以在桌面新建一个快捷方式,接着在项目的地址上输入“rundll32.exe user32.dll,LockWorkStation”,即使用快捷命令快速锁定电脑(图5)。

 

图5 设置锁定快捷命令

继续点击“下一步”,然后将其名称设置为“锁定电脑”,并且将其图标替换为锁定图标。右击新建快捷方式选择属性,在打开的窗口中为其设置一个快捷键如F2,这样以后只要双击这个图标或者按F2键就可以一键锁定电脑了(图6)。

 

图6 设置快捷键

小提示:

同样的方法可以为快捷方式设定不同的命令行来实现更多快捷操作,比如将命令行更改为“shutdown /r”,这样可以快速重启电脑,更改为“rundll32.exe shell32.dll,Control_RunDLL appwiz.cpl,,1”可以快速打开“添加/卸载”组件,大家可以根据自己的需要制作更多快捷命令。

7. 常用程序快捷启动

为了快速启动系统程序,我们经常直接在“开始”菜单的运行框输入程序的对应名称即可启动。其实对于自己安装的其他程序,我们只要稍加变通即可实现类似功效。比如笔者经常需要启动安装在F盘的股票交易软件“tdxw.exe”,首先进入程序安装目录,然后右击程序选择创建快捷方式,并将快捷方式重命名为容易输入的字符如“td”,将这个快捷方式复制到“C:\windows”保存,如果有多个需要启动的程序,则依次建立多个对应快捷方式(图7)。

 

图7 复制快捷方式到系统目录

完成上述操作后,以后如果我们再需要运行安装在F盘的这个程序,只要右击“开始徽标→运行”,接着在运行框直接输入“td”即可快速启动了(图8)。

 

图8 直接输入快捷字符启动程序

小提示:

使用类似快捷方式的方法同样可以快捷启动很多系统组件,比如系统默认设置是隐藏系统保护文件夹,这样需要查看系统文件夹时我们就需要先进入文件查看设置取消系统文件夹隐藏才能打开这类文件夹。现在可以使用同样方法快速访问,只要先为隐藏系统目录创建快捷方式并命名为“yc”,以后直接输入“yc”即可快速打开指定隐藏目录了。

8. 快速以管理员方式启动程序

为了完成系统设置的更改,对于重要系统组件如cmd.exe、regedit.exe我们经常需要以管理员身份运行,默认情况下只能在找到指定程序后右击选择“以管理员身份”运行才能激活。对于经常需要以管理员身份运行的程序如cmd.exe,现在可以自行为其设定运行方式。首先在桌面为cmd.exe建立一个快捷方式,右击打开快捷方式后选择“快捷方式→高级”,勾选“以管理员身份运行”,这样以后启动快捷方式的身份就是系统管理员了(图9)。

 

图9 位快捷方式指定管理员方式运行

对于平时只是以标准用户使用系统的朋友,如果需要为某一程序指定的管理员账户运行,那么我们还可以通过runas命令进行指定。比如使用regedit.exe编辑系统重要键值的时候,如果需要以管理员身份运行更改。同样首先为上述程序在桌面建立快捷方式,然后在目标位置输入“C:\Windows\System32\runas.exe /savecred /user:cfan regedit.exe”,其中“cfan”是我的本机管理员账户。这样以后只要运行这个快捷方式(首次需要输入管理员账号密码,下次则会自动记住),就会自动以管理员身份启动注册表编辑器了(图10)。

 

图10 以特定管理员身份启动程序

9. 无盘符分区,保护/访问两相宜

为了保护自己保存资料的分区不被他人随意访问,一些朋友会使用删除驱动器盘符的方式对分区进行保护。但是这样自己需要访问无盘符分区时,需要先为该分区分配盘符,访问完成后又得再次删除盘符才能恢复保护,操作起来极为麻烦。现在可以通过将分区映射到特定文件夹的方法实现保护、访问两相宜。

首先在任意NTFS分区下建立一个文件夹,假设为“C:\windows\cfan”,接着进入计算机磁盘管理将需要保护分区的盘符删除,点击“新建→装入以下空白NTFS文件夹中”,点击“浏览”选择上述建立的“C:\windows\cfan”文件夹(图11)。

 

图11 将无盘符分区装入以下空白NTFS文件夹中

完成上述操作后启动命令提示符输入“attrib +h +s C:\windows\cfan”,将上述文件夹设置为系统、隐藏属性。这样一般人就无法直接访问上述分区,同时也看不到上述文件夹。以后我们需要访问该分区时,只要按Win+R键,然后在运行框中输入“cfan”即可打开上述无盘符的保护分区了(图12)。

 

图12 使用快捷命令访问无盘符分区

小提示:

使用同样方法可以将FAT32分区装入到NTFS文件夹中,这样原来FAT分区无法使用的权限保护,现在就可以借助NTFS文件夹“曲线实现”,比如可以设置指定账户才能访问上述分区(实际是访问装入的文件夹)。

另外请注意,上述删除分区盘符的操作有一定风险,建议最好先将要隐藏分区上的数据在其他地方做好安全备份,然后再尝试。

上述方法实际上是为特定分区增加一个目录链接,因此对于其他保护分区也可以使用同样方法实现。比如现在很多UEFI启动的电脑,系统中经常会有一个标示为“EFI”保护分区,默认情况下我们无法在计算机管理中加载和访问。如果现在需要对这样的保护分区进行访问那么使用 MKLINK 命令就可以挂载。以管理员身份打开 CMD,运行以下命令(图13):

 

图13 查看本机ESP分区

#启动diskpart

Diskpart

#选择当前活动硬盘

Select disk 0

#列出本机所有分区,确定EFI分区序号,标签为ESP即是

List voloume

#退出diskpart

Exit

#使用命令为指定EFI分区创建目录链接

MKLINK /J C:\ESP \\?\GLOBALROOT\Device\Harddisk0\Partition8\

上述命令运行成功之后,C:\ESP就是指向ESP的一个符号链接,以后欲访问EFI分区,直接访问 C:\ESP即可(图14)。

 

图14 通过建立目录链接方法访问EFI分区

10. 更多提效的快捷方法

双击任意窗口的最左上角都能关闭该窗口

平常使用高分Windows 10平板用户都会对关闭当前程序窗口头痛,因为默认窗口右上角的关闭按钮很小,经常点击半天无法关闭。其实在Windows 10中,我们只要双击任意窗口的最左上角都能关闭该窗口,显然对于平板用户任意双击比精确点击关闭按钮更简单。

11. Ctrl+Alt+Del=Ctrl+Shift+Esc

Ctrl+Alt+Del是我们调出任务管理器的常见快捷方式,但是在普通键盘上这三个键分散得比较远,不容易同时按下,实际上这个快捷键和Ctrl + Shift + Esc等效,这样同时按住都排列在键盘左侧的三键是不是更简单?







Cisco IOS Router Configuration: IPSec over GRE or GRE over IPSec(1)

IPSec over GRE means Outer Header is GRE. In other words, IPSec is riding over GRE.

Please refer:



The order for IPsec over GRE is IPsec first, GRE second. This order will result in these operations:

1.) Original header | Payload ! before IPsec
2.) Original header | ESP | Encrypt ( Payload ) ! after IPsec in transport mode
3.) Outer header | GRE | Original header | ESP | Encrypt ( Payload ) ! after GRE
The original header is obfuscated but not encrypted.


GRE over IPSec means Outer Header is IPSec.

Please refer:



The order for GRE GRE over IPsec is GRE first, IPsec second. The order will be:

1.) Original header | Payload ! before GRE
2.) Outer header | GRE | Original header | Payload ! after GRE
3.) Outer header | ESP | Encrypt ( GRE | Original header | Payload ) ! after IPsec transport mode
Here the original header is encrypted.

GRE over IPSec in Tunnel Mode
GRE over IPSec in transport mode



1. IPSec Over GRE

Example 1:
Router1#show run
Building configuration...

Current configuration : 2063 bytes
!
! Last configuration change at 08:26:21 UTC Thu May 12 2011 by hari
!
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router1
!
boot-start-marker
boot-end-marker
!
!
aaa new-model
!
!
aaa authentication login default local
aaa authorization exec default local
!
!
aaa session-id common
!
!
!
ip source-route
!
ip cef
no ipv6 cef
!
multilink bundle-name authenticated
license udi pid CISCO892-K9 sn FGL151325XQ
!
!
username temp privilege 15 secret 5 $1$bTf6$BoInpDJHbBC1drvgr356h0
!
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key cisco address 172.19.0.2
!
!
crypto ipsec transform-set myset esp-3des esp-sha-hmac
mode transport
!
crypto map cmap 10 ipsec-isakmp
set peer 172.19.0.2
set transform-set myset
match address 101
!
interface Loopback0
ip address 1.1.1.1 255.255.255.255
!
!
interface Tunnel0
ip address 172.25.0.1 255.255.255.252
tunnel source FastEthernet8
tunnel destination 172.19.0.2
tunnel path-mtu-discovery
crypto map cmap
!
!
interface BRI0
no ip address
encapsulation hdlc
shutdown
isdn termination multidrop
!
!
interface FastEthernet0
!
!
interface FastEthernet1
!

.......
!
interface FastEthernet8
ip address 172.19.0.1 255.255.255.0
duplex auto
speed auto
!
!
interface GigabitEthernet0
no ip address
shutdown
duplex auto
speed auto
!
!
interface Vlan1
no ip address
!
!
router ospf 1
log-adjacency-changes
network 1.1.1.1 0.0.0.0 area 0
network 172.25.0.0 0.0.0.255 area 0
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
!
access-list 101 permit ip host 1.1.1.1 host 2.2.2.2
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
transport input telnet
line vty 5 193
transport input telnet
!
scheduler max-task-time 5000
end
Router2#show run
Building configuration...

Current configuration : 1958 bytes
!
! Last configuration change at 02:44:36 UTC Mon May 2 2011
!
version 15.0
service timestamps debug datetime msec
service timestamps log datetime msec
no service password-encryption
!
hostname Router2
!
boot-start-marker
boot-end-marker
!
!
no aaa new-model
!
ip source-route
!
ip cef
no ipv6 cef
!
!
multilink bundle-name authenticated
license udi pid CISCO892-K9 sn FGL151324Y0
!
!
username hari privilege 15 secret 5 $1$JARP$69Wl2bZWX4fqfnoOIIFZn/
!
crypto isakmp policy 1
encr 3des
hash md5
authentication pre-share
group 2
crypto isakmp key cisco address 172.19.0.1
!
!
crypto ipsec transform-set myset esp-3des esp-sha-hmac
mode transport
!
crypto map cmap 10 ipsec-isakmp
set peer 172.19.0.1
set transform-set myset
match address 101
!
interface Loopback0
ip address 2.2.2.2 255.255.255.255
!
!
interface Tunnel0
ip address 172.25.0.2 255.255.255.252
tunnel source FastEthernet8
tunnel destination 172.19.0.1
tunnel path-mtu-discovery
crypto map cmap
!
!
interface BRI0
no ip address
encapsulation hdlc
shutdown
isdn termination multidrop
!
!
interface FastEthernet0
!
!.....
!
interface FastEthernet7
!
!
interface FastEthernet8
ip address 172.19.0.2 255.255.255.0
duplex auto
speed auto
!
!
interface GigabitEthernet0
no ip address
shutdown
duplex auto
speed auto
!
!
interface Vlan1
no ip address
!
!
router ospf 1
log-adjacency-changes
network 2.2.2.2 0.0.0.0 area 0
network 172.25.0.0 0.0.0.255 area 0
!
ip forward-protocol nd
no ip http server
no ip http secure-server
!
!
!
access-list 101 permit ip host 2.2.2.2 host 1.1.1.1
!
control-plane
!
!
!
line con 0
line aux 0
line vty 0 4
login
transport input telnet
line vty 5 193
login
transport input telnet
!
scheduler max-task-time 5000
end


https://supportforums.cisco.com/discussion/11190806/gre-over-ipsec

Trying to establish vpn session between 2 Cisco 892/k9 routers. but when i apply the crypto map in the GRE tunnel interface this type of message apears.
  NOTE: crypto map is configured on tunnel interface.
        Currently only GDOI crypto map is supported on tunnel interface.

Suggestions:

If you are trying to configure GRE over IPSec, then you can do this with one of the 2 configuration options, 
1) using crypto map and apply the crypto map to the physical egress interface for the GRE encapsulated tunnel packets, 

2) using ipsec profiles with tunnel protection. With crypto map on the tunnel interface, the order of encapsulation is the opposite of what you are trying to do - it'll be encryption first and then tunnel encapsulation, in other words, it'll be IPSec over GRE. Currently we only support GETVPN with that, hence the warning you saw.


Solution:

If there are reasons why you can not put a crypto map on the physical interface then I agree with the original suggestion by Wen and suggested again by Tod that you use the tunnel protection profile which will allow the tunnel to do GRE protected by IPSec and does not require crypto map.


Are you configuring a Virtual Tunnel Interface with IP Security?
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
crypto isakmp key ******** address 0.0.0.0 0.0.0.0
crypto isakmp keepalive 10
!
!
crypto ipsec transform-set TSET esp-3des esp-sha-hmac
!
crypto ipsec profile VTI
set transform-set TSET
!
!
interface Tunnel0
ip address 192.168.10.2 255.255.255.0
tunnel source 10.0.149.220
tunnel destination 10.0.149.221
tunnel mode ipsec ipv4
tunnel protection ipsec profile VTI


========================================================================

Example 2:


SITE A:
Local LAN: 192.168.1.254/255.255.255.0
Tunnel64: 10.0.64.1/255.255.255.0
interface Tunnel64
description testing tunnel
ip address 10.0.64.1 255.255.255.0
ip mtu 1352
ip tcp adjust-mss 1312
tunnel source FastEthernet4
tunnel destination (SITE B Public IP)
tunnel path-mtu-discovery
tunnel protection ipsec profile (VPN-PROFILE)
ip route 0.0.0.0 0.0.0.0 (ROUTER IP ADDRESS)
ip route 192.168.64.0 255.255.255.0 10.0.64.254

SITE B:
Local LAN: 192.168.64.254/255.255.255.0
Tunnel1: 10.0.64.254/255.255.255.0

interface Tunnel1
ip address 10.0.64.254 255.255.255.0
ip mtu 1352
ip tcp adjust-mss 1312
tunnel source FastEthernet4
tunnel destination (SITE A Public IP)
tunnel path-mtu-discovery
tunnel protection ipsec profile (VPN PROFILE)
ip route 0.0.0.0 0.0.0.0 (PUBLIC IP GATEWAY)
ip route 192.168.1.0 255.255.255.0 10.0.64.1
https://supportforums.cisco.com/discussion/12345601/gre-over-ipsec-can-ping-tunnel-interface-not-remote-lan

=======================================================================

2. GRE over IPSec

Scenario 9

IPsec is deployed on top of GRE. The outgoing physical MTU is 1500, the IPsec PMTU is 1500, and the GRE IP MTU is 1476 (1500 - 24 = 1476). Because of this, TCP/IP packets will be fragmented twice, once before GRE and once after IPsec. The packet will be fragmented before GRE encapsulation and one of these GRE packets will be fragmented again after IPsec encryption.
Configuring "ip mtu 1440" (IPsec Transport mode) or "ip mtu 1420" (IPsec Tunnel mode) on the GRE tunnel would remove the possibility of double fragmentation in this scenario.
  1. The router receives a 1500-byte datagram.
  2. Before encapsulation, GRE fragments the 1500-byte packet into two pieces, 1476 (1500 - 24 = 1476) and 44 (24 data + 20 IP header) bytes.
  3. GRE encapsulates the IP fragments, which adds 24 bytes to each packet. This results in two GRE + IPsec packets of 1500 (1476 + 24 = 1500) and 68 (44 + 24) bytes each.
  4. IPsec encrypts the two packets, adding 52 byes (IPsec tunnel-mode) of encapsulation overhead to each, in order to give a 1552-byte and a 120-byte packet.
  5. The 1552-byte IPsec packet is fragmented by the router because it is larger than the outbound MTU (1500). The 1552-byte packet is split into pieces, a 1500-byte packet and a 72-byte packet (52 bytes "payload" plus an additional 20-byte IP header for the second fragment). The three packets 1500-byte, 72-byte, and 120-byte packets are forwarded to the IPsec + GRE peer.
  6. The receiving router reassembles the two IPsec fragments (1500 bytes and 72 bytes) in order to get the original 1552-byte IPsec + GRE packet. Nothing needs to be done to the 120-byte IPsec + GRE packet.
  7. IPsec decrypts both 1552-byte and 120-byte IPsec + GRE packets in order to get 1500-byte and 68-byte GRE packets.
  8. GRE decapsulates the 1500-byte and 68-byte GRE packets in order to get 1476-byte and 44-byte IP packet fragments. These IP packet fragments are forwarded to the destination host.
  9. Host 2 reassembles these IP fragments in order to get the original 1500-byte IP datagram.
Scenario 10 is similar to Scenario 8 except there is a lower MTU link in the tunnel path. This is a "worst case" scenario for the first packet sent from Host 1 to Host 2. After the last step in this scenario, Host 1 sets the correct PMTU for Host 2 and all is well for the TCP connections between Host 1 and Host 2. TCP flows between Host 1 and other hosts (reachable via the IPsec + GRE tunnel) will only have to go through the last three steps of Scenario 10.
In this scenario, the tunnel path-mtu-discovery command is configured on the GRE tunnel and the DF bit is set on TCP/IP packets that originate from Host 1.

Site 1:


Building configuration...

Current configuration : 12325 bytes
!
! Last configuration change at 21:03:48 EST Tue Nov 29 2016 by admin
version 15.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
no service dhcp
!
hostname Site1
!
boot-start-marker
boot-end-marker
!
aqm-register-fnf
!
logging buffered 16384
no logging console
enable secret 5 $1$Au7T$y0eMjqCcQuGPFAT58fiWM.
enable password 7 06360E325F1F5B4A51
!
aaa new-model
!
!
aaa authentication login default local group radius group tacacs+
aaa authentication login ciscocp_vpn_xauth_ml_1 local
aaa authentication enable default enable group radius group tacacs+
aaa authorization console
aaa authorization exec default local group radius group tacacs+
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default stop-only group tacacs+
aaa accounting commands 5 default stop-only group tacacs+
aaa accounting commands 15 default stop-only group tacacs+
aaa accounting system default start-stop group tacacs+
!
!
!
!
!
aaa session-id common
no process cpu extended history
no process cpu autoprofile hog
clock timezone EST -5 0
clock summer-time EDT recurring
errdisable recovery cause bpduguard
!
crypto pki trustpoint TP-self-signed-397309841
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-397309841
revocation-check none
rsakeypair TP-self-signed-397309841
!
!
crypto pki certificate chain TP-self-signed-397309841
certificate self-signed 01
30820229 30820192 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 33393733 30393834 31301E17 0D313630 39323430 31353634
355A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3339 37333039
38343130 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
D99CE812 CAAAEBE1 289B7967 9887E203 31E74611 9A9DFF84 696FDF93 1DEAE087
369D82D5 1434E0FE B1231C84 B619173A 9D324F18 0BF666A9 ABC72356 C5665043
699F33E2 669F3842 AB54BC4F 472E400A 3E70F33C 0EFF6374 114EAA3B FB83A3A6
1758945F D2733774 53F10849 0B4E5B92 D3C6A414 9C2AAEFE 88E1140B 8E8D9D6F
02030100 01A35330 51300F06 03551D13 0101FF04 05300301 01FF301F 0603551D
23041830 16801425 DEA3E9A9 B98BAD6C D802B2F6 DD8E82EB 734D8430 1D060355
1D0E0416 041425DE A3E9A9B9 8BAD6CD8 02B2F6DD 8E82EB73 4D84300D 06092A86
4886F70D 01010505 00038181 00D5E7B1 4E8F4902 311BF1CB 88ED6E9B 5EF20197
AFDBA6A5 EF0378B4 B93E7703 B5EC0E35 023091A8 A84EEAD3 6186847F E3A6F350
8F6FBD94 113FB5EA B630D030 035C953B 39AB1763 5AF20F38 9BEBAA4B AA6B2395
CCCFC776 7F9CE290 888A3452 FB4F9916 F86D1E4A F51727D9 47842AE6 843F5BE9
E7225CBD F70D934F 740FF234 A9
quit
no ip source-route
no ip gratuitous-arps
!
ip dhcp bootp ignore
ip dhcp excluded-address 19.16.5.1 19.16.5.35
!
ip dhcp pool local-pool-1
import all
network 19.16.5.0 255.255.255.0
default-router 192.168.5.1
dns-server 8.8.8.8 8.8.4.4
lease 0 8
!
no ip bootp server
no ip domain lookup
ip domain name test.com
ip name-server 8.8.8.8
ip name-server 8.8.4.4
ip cef
login block-for 120 attempts 3 within 60
login on-failure log
login on-success log
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid C881-K9 sn FJC1950E2C6
!
archive
log config
logging enable
logging size 200
notify syslog contenttype plaintext
hidekeys
path flash:backup-
maximum 8
write-memory
!
no spanning-tree optimize bpdu transmission
spanning-tree uplinkfast
spanning-tree backbonefast
vtp domain gd
vtp mode transparent
username admin privilege 15 secret 5 $1$4Aja$XwY/5peZXMOYH9Vs8Fqr1
username test secret 5 $1$Vlfg$Sjn.GLyoElKHLryT/ZlY1

!
crypto vpn anyconnect flash:/webvpn/anyconnect-win-4.3.02039-k9.pkg sequence 1
!
vlan 10
name EXT
!
vlan 20
name LAN
!
ip ftp username rooter
ip ftp password 7 03165404120A33
ip ssh time-out 10
ip ssh logging events
ip ssh version 2
!
class-map type port-filter match-any TCP23
match port tcp 23
!
policy-map type port-filter FILTERTCP23
class TCP23
drop
log
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
lifetime 3600
!
crypto isakmp policy 2
encr aes 256
authentication pre-share
group 5
crypto isakmp key S3mm3r123!@ address 19.18.76.90
!
!
crypto ipsec transform-set TRN-BUR esp-3des esp-sha-hmac
mode tunnel
crypto ipsec transform-set ASE-MD5 esp-aes esp-md5-hmac
mode tunnel
!
crypto map SDM_CMAP_1 1 ipsec-isakmp
description Tunnel to19.18.76.90
set peer 19.18.76.90
set transform-set TRN-BUR
match address 100
!
interface Loopback0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Tunnel0
ip address 10.1.1.1 255.255.255.252
ip mtu 1380
ip tcp adjust-mss 1340
keepalive 10 3
tunnel source Vlan10
tunnel destination 19.18.76.90
tunnel path-mtu-discovery
!
interface Null0
no ip unreachables
!
interface FastEthernet0
description External
switchport access vlan 10
no ip address
!
interface FastEthernet1
description internal
switchport access vlan 20
no ip address
!
interface FastEthernet2
no ip address
no cdp enable
!.....
!
interface Virtual-Template1
no ip address
!
interface Virtual-Template2
ip unnumbered Vlan10
!
interface Vlan1
no ip address
shutdown
!
interface Vlan10
description ext
ip address 19.8.241.126 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip flow ingress
ip multicast boundary 30
ip nat outside
ip virtual-reassembly in
no ip route-cache
crypto map SDM_CMAP_1
!
interface Vlan20
description LAN
ip address 19.16.5.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip flow ingress
ip multicast boundary 30
ip nat inside
ip virtual-reassembly in
no ip route-cache
!
ip local pool camvpn 10.10.10.100 10.10.10.200
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip flow-export source Loopback0
ip flow-export version 5 origin-as
ip flow-export destination 192.0.2.34 2055
!
ip nat inside source route-map INTERNET1 interface Vlan10 overload
ip nat inside source static 19.16.5.10 19.8.241.125
ip nat inside source static tcp 19.16.5.5 25 19.8.241.126 25 extendable
ip nat inside source static tcp 19.16.5.5 80 19.8.241.126 80 extendable
ip nat inside source static tcp 19.16.5.5 443 19.8.241.126 443 extendable
ip nat inside source static tcp 19.16.5.5 3389 19.8.241.126 3389 extendable
ip route 0.0.0.0 0.0.0.0 19.8.241.121
ip route 172.21.1.0 255.255.255.0 Tunnel0
!
ip access-list extended BUR-TRN-LIST
remark CCP_ACL Category=16
permit ip 19.16.5.0 0.0.0.255 172.21.1.0 0.0.0.255
ip access-list extended inside-out
permit ip 19.16.5.0 0.0.0.255 any
!
no service-routing capabilities-manager
logging trap debugging
logging facility local5
logging source-interface Loopback0
logging host 10.2.2.3
!
route-map INTERNET1 permit 10
match ip address 108
!
snmp-server group SNMPv3-RO v3 priv read ReadView-All access snmp-Allow
snmp-server group SNMPv3-RW v3 priv read ReadView-All write WriteView-All access snmp-Allow
snmp-server view ReadView-All iso included
snmp-server view ReadView-All internet included
snmp-server view ReadView-All system included
snmp-server view ReadView-All interfaces included
snmp-server view ReadView-All internet.6.3.15 excluded
snmp-server view ReadView-All internet.6.3.16 excluded
snmp-server view ReadView-All internet.6.3.18 excluded
snmp-server view ReadView-All ip.21 excluded
snmp-server view ReadView-All ip.22 excluded
snmp-server view ReadView-All chassis included
snmp-server view WriteView-All iso included
snmp-server view WriteView-All internet included
snmp-server view WriteView-All system included
snmp-server view WriteView-All interfaces included
snmp-server view WriteView-All internet.6.3.15 excluded
snmp-server view WriteView-All internet.6.3.16 excluded
snmp-server view WriteView-All internet.6.3.18 excluded
snmp-server view WriteView-All ip.21 excluded
snmp-server view WriteView-All ip.22 excluded
snmp-server view WriteView-All chassis included
snmp-server location TORONTO
snmp-server contact NetSec-OP
access-list 20 remark SNMP ACL
access-list 20 permit 192.0.2.34
access-list 20 deny any log
access-list 23 permit 172.21.1.0 0.0.0.255
access-list 23 permit 19.16.5.0 0.0.0.255
access-list 100 remark CCP_ACL Category=4
access-list 100 permit gre host 19.8.241.126 host 19.18.76.90
access-list 101 permit ip 172.21.1.0 0.0.0.255 any
access-list 101 permit ip 19.16.5.0 0.0.0.255 any
access-list 101 permit ip 19.24.116.0 0.0.0.255 any
access-list 101 permit ip 6.16.0.0 0.0.255.255 any
access-list 108 remark CCP_ACL Category=18
access-list 108 permit ip 19.16.5.0 0.0.0.255 any
!
!
!
control-plane
!
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
!
!
!
privilege exec level 7 show configuration
privilege exec level 7 show
banner motd ^C
****************************************************************
* This is a private computing facility. *
* Unauthorized use of this device is strictly prohibited. *
* Violators will be prosecuted to the maximum extent possible. * *
****************************************************************
^C
!
line con 0
exec-timeout 4 30
logging synchronous
login authentication CONAUTH
no modem enable
stopbits 1
line aux 0
line vty 0 4
access-class 101 in
exec-timeout 4 30
privilege level 15
password 7 107E080A1646405858
logging synchronous
login authentication VTYAUTH
transport input ssh
line vty 5 15
access-class 101 in
exec-timeout 4 30
privilege level 15
absolute-timeout 15
logging synchronous
login authentication VTYAUTH
transport input ssh
!
exception core-file secure-router01-core
exception protocol ftp
exception dump 10.2.2.3
scheduler allocate 20000 1000
ntp authentication-key 6767 md5 10123A3C2625373F27211375 7
ntp authenticate
ntp update-calendar
ntp server 3.ca.pool.ntp.org
ntp server 2.ca.pool.ntp.org
ntp server 0.ca.pool.ntp.org
ntp server 1.ca.pool.ntp.org
!
!
webvpn gateway gateway_1
ip address 199.87.241.126 port 4443
http-redirect port 8080
ssl trustpoint TP-self-signed-397309841
inservice
!
webvpn context camsslvpn
secondary-color white
title-color #CCCC66
text-color black
virtual-template 2
aaa authentication list ciscocp_vpn_xauth_ml_1
gateway gateway_1
max-users 5
!
ssl authenticate verify all
inservice
!
policy group policy_1
functions svc-enabled
svc address-pool "camvpn" netmask 255.255.255.255
svc keep-client-installed
svc split include 19.16.5.0 255.255.255.0
svc split include 172.21.1.0 255.255.255.0
default-group-policy policy_1
!
end






Site 2:



Building configuration...

Current configuration : 10365 bytes
!
! Last configuration change at 21:11:11 EST Tue Nov 29 2016 by admin
version 15.3
no service pad
service tcp-keepalives-in
service tcp-keepalives-out
service timestamps debug datetime msec localtime show-timezone
service timestamps log datetime msec localtime show-timezone
service password-encryption
service sequence-numbers
!
hostname Site2
!
boot-start-marker
boot-end-marker
!
aqm-register-fnf
!
logging buffered 16384
no logging console
enable secret 5 $1$Au7T$y0eMjqCcQuGPFAT58fiWM.
!
aaa new-model
!
aaa authentication login default local group radius group tacacs+
aaa authentication enable default enable group radius group tacacs+
aaa authorization console
aaa authorization exec default local group radius group tacacs+
aaa accounting exec default start-stop group tacacs+
aaa accounting commands 1 default stop-only group tacacs+
aaa accounting commands 5 default stop-only group tacacs+
aaa accounting commands 15 default stop-only group tacacs+
aaa accounting system default start-stop group tacacs+
!
aaa session-id common
clock timezone EST -5 0
clock summer-time EDT recurring
errdisable recovery cause bpduguard
!
crypto pki trustpoint TP-self-signed-103227904
enrollment selfsigned
subject-name cn=IOS-Self-Signed-Certificate-103227904
revocation-check none
rsakeypair TP-self-signed-103227904
!
crypto pki certificate chain TP-self-signed-103227904
certificate self-signed 01
30820229 30820192 A0030201 02020101 300D0609 2A864886 F70D0101 05050030
30312E30 2C060355 04031325 494F532D 53656C66 2D536967 6E65642D 43657274
69666963 6174652D 31303332 32373930 34301E17 0D313630 39323430 31353634
375A170D 32303031 30313030 30303030 5A303031 2E302C06 03550403 1325494F
532D5365 6C662D53 69676E65 642D4365 72746966 69636174 652D3130 33323237
39303430 819F300D 06092A86 4886F70D 01010105 0003818D 00308189 02818100
9C48F515 D36758BD 77CF74D5 4F2C3FB6 A687CF45 825AAE0B 367CC4F1 F2630CBC
80E185FB E9CB948A 15A0B637 0E625245 A9B4DE3C 80B63CBB E5049B08 3104C167
D7062F27 12045C11 7EED8340 69F8C49D DA6C9338 34EEEF28 B361CBED E8F2173E
3023AE81 B75683D6 02CD6600 AD5A7181 220DADEC 841743A8 50931AAE 1AE95039
02030100 01A35330 51300F06 03551D13 0101FF04 05300301 01FF301F 0603551D
23041830 16801431 5ADB9FC3 3B3505C1 BB7FF656 712C5341 BD436E30 1D060355
1D0E0416 0414315A DB9FC33B 3505C1BB 7FF65671 2C5341BD 436E300D 06092A86
4886F70D 01010505 00038181 002226E8 F788CD21 E6F33781 C1146D4B A2F506F7
7FEAEB7B B55967B4 967FED0E 8312E2D5 DFE28921 8B941BA1 60B3AAC9 B78E10A2
4EAF7793 8A55354A 4475DBFF 922CA2C1 F97455E6 AA895A4A 00665990 2C4D667B
3C84CA0E 54437C2E F80E48B3 16ABB5AC 81EC2BAC 5C0CB465 22ABB1F2 122514E5
9A2900C6 AADA9B96 41339D1B 58
quit
no ip source-route
no ip gratuitous-arps
!
ip dhcp bootp ignore
ip dhcp excluded-address 172.21.1.1 172.21.1.99
!
ip dhcp pool local-pool-1
import all
network 172.21.1.0 255.255.255.0
default-router 172.21.1.1
dns-server 8.8.8.8 8.8.4.4
lease 0 8
!
no ip bootp server
no ip domain lookup
ip domain name test.com
ip name-server 8.8.8.8
ip name-server 8.8.4.4
ip cef
login block-for 120 attempts 3 within 60
login on-failure log
login on-success log
no ipv6 cef
!
multilink bundle-name authenticated
!
license udi pid C881-K9 sn FJC1950E2C7
!
archive
log config
logging enable
logging size 200
notify syslog contenttype plaintext
hidekeys
path flash:backup-
maximum 8
write-memory
!
no spanning-tree optimize bpdu transmission
spanning-tree uplinkfast
spanning-tree backbonefast
vtp domain gd
vtp mode transparent
username admin privilege 15 secret 5 $1$4Aja$XwY/5peZXMOYH9Vs8Fqr1
username temp secret 5 $1$Vlfg$Sjn.GLyoEKHKLryT/ZlY1
!
vlan 10
name EXT
!
vlan 20
name LAN
!
ip ftp username rooter
ip ftp password 7 03165404120A33
ip ssh time-out 10
ip ssh logging events
ip ssh version 2
!
class-map type port-filter match-any TCP23
match port tcp 23
!
policy-map type port-filter FILTERTCP23
class TCP23
drop
log
!
crypto isakmp policy 1
encr 3des
authentication pre-share
group 2
lifetime 3600
!
crypto isakmp policy 2
encr aes 256
authentication pre-share
group 5
crypto isakmp key S3mm3r123!@ address 19.8.241.126
!
!
crypto ipsec transform-set TRN-BUR esp-3des esp-sha-hmac
mode tunnel
!
crypto map SDM_CMAP_1 1 ipsec-isakmp
description Apply the crypto map on the peer router's interface having IP address 19.18.76.90 that connects to this router.
set peer 19.8.241.126
set transform-set TRN-BUR
match address SDM_1
!
interface Loopback0
no ip address
no ip redirects
no ip unreachables
no ip proxy-arp
!
interface Tunnel0
ip address 10.1.1.2 255.255.255.252
ip mtu 1380
ip tcp adjust-mss 1340
keepalive 10 3
tunnel source Vlan10
tunnel destination 199.87.241.126
tunnel path-mtu-discovery
!
interface Null0
no ip unreachables
!
interface FastEthernet0
description External
switchport access vlan 10
no ip address
!
interface FastEthernet1
description Internal
switchport access vlan 20
no ip address
!......
!
interface Virtual-Template1
ip unnumbered Vlan10
!
interface Vlan1
no ip address
!
interface Vlan10
description EXT
ip address 19.18.76.90 255.255.255.248
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip flow ingress
ip multicast boundary 30
ip nat outside
ip virtual-reassembly in
no ip route-cache
crypto map SDM_CMAP_1
!
interface Vlan20
description LAN
ip address 172.21.1.1 255.255.255.0
no ip redirects
no ip unreachables
no ip proxy-arp
ip accounting access-violations
ip flow ingress
ip multicast boundary 30
ip nat inside
ip virtual-reassembly in
no ip route-cache
!
ip forward-protocol nd
ip http server
ip http access-class 23
ip http authentication local
ip http secure-server
ip http timeout-policy idle 60 life 86400 requests 10000
!
ip flow-export source Loopback0
ip flow-export version 5 origin-as
ip flow-export destination 192.0.2.34 2055
!
ip nat inside source route-map INTERNET1 interface Vlan10 overload
ip nat inside source static tcp 172.21.1.4 3389 192.186.76.90 3389 extendable
ip route 0.0.0.0 0.0.0.0 192.186.76.89
ip route 10.10.10.0 255.255.255.0 Tunnel0
ip route 19.16.5.0 255.255.255.0 Tunnel0
!
ip access-list extended BUR-TRN-LIST
permit ip 172.21.1.0 0.0.0.255 192.168.5.0 0.0.0.255
ip access-list extended SDM_1
remark CCP_ACL Category=4
permit gre host 19.18.76.90 host 199.87.241.126
!
logging trap debugging
logging facility local5
logging source-interface Loopback0
logging host 10.2.2.3
!
route-map INTERNET1 permit 10
match ip address 108
!
snmp-server group SNMPv3-RO v3 priv read ReadView-All access snmp-Allow
snmp-server group SNMPv3-RW v3 priv read ReadView-All write WriteView-All access snmp-Allow
snmp-server view ReadView-All iso included
snmp-server view ReadView-All internet included
snmp-server view ReadView-All system included
snmp-server view ReadView-All interfaces included
snmp-server view ReadView-All internet.6.3.15 excluded
snmp-server view ReadView-All internet.6.3.16 excluded
snmp-server view ReadView-All internet.6.3.18 excluded
snmp-server view ReadView-All ip.21 excluded
snmp-server view ReadView-All ip.22 excluded
snmp-server view ReadView-All chassis included
snmp-server view WriteView-All iso included
snmp-server view WriteView-All internet included
snmp-server view WriteView-All system included
snmp-server view WriteView-All interfaces included
snmp-server view WriteView-All internet.6.3.15 excluded
snmp-server view WriteView-All internet.6.3.16 excluded
snmp-server view WriteView-All internet.6.3.18 excluded
snmp-server view WriteView-All ip.21 excluded
snmp-server view WriteView-All ip.22 excluded
snmp-server view WriteView-All chassis included
snmp-server location Markham
snmp-server contact NetSec-OP
access-list 20 remark SNMP ACL
access-list 20 permit 192.0.2.34
access-list 20 deny any log
access-list 23 permit 172.21.1.0 0.0.0.255
access-list 23 permit 19.16.5.0 0.0.0.255
access-list 101 permit ip 172.21.1.0 0.0.0.255 any
access-list 101 permit ip 19.16.5.0 0.0.0.255 any
access-list 101 permit ip 19.24.116.0 0.0.0.255 any
access-list 108 deny ip 172.21.1.0 0.0.0.255 19.16.5.0 0.0.0.255
access-list 108 permit ip 172.21.1.0 0.0.0.255 any
!
!
!
control-plane
!
!
!
mgcp behavior rsip-range tgcp-only
mgcp behavior comedia-role none
mgcp behavior comedia-check-media-src disable
mgcp behavior comedia-sdp-force disable
!
mgcp profile default
!
privilege exec level 7 show configuration
privilege exec level 7 show
banner motd ^CC
****************************************************************
* This is a private computing facility. *
* Unauthorized use of this device is strictly prohibited. *
* Violators will be prosecuted to the maximum extent possible. *
* *
* TACACS+/RADIUS Authentication and Authorization are in place.*
* All actions/commands are monitored and recorded. *
* By using the network you expressly consent to such *
* monitoring and recording. *
****************************************************************
^C
!
line con 0
exec-timeout 4 30
logging synchronous
login authentication CONAUTH
no modem enable
stopbits 1
line aux 0
line vty 0 4
access-class 101 in
exec-timeout 4 30
privilege level 15
logging synchronous
login authentication VTYAUTH
transport input ssh
line vty 5 15
access-class 101 in
exec-timeout 4 30
privilege level 15
absolute-timeout 15
logging synchronous
login authentication VTYAUTH
transport input ssh
!
exception core-file secure-router01-core
exception protocol ftp
exception dump 10.2.2.3
scheduler allocate 20000 1000
ntp authentication-key 6767 md5 10123A3C2625373F27211375 7
ntp authenticate
ntp update-calendar
ntp server 3.ca.pool.ntp.org
ntp server 2.ca.pool.ntp.org
ntp server 0.ca.pool.ntp.org
ntp server 1.ca.pool.ntp.org
!
end




3. MTU vs MSS

The MTU is the Maximum IP packet size for a given link. Packets bigger than the MTU is fragmented at the point where the lower MTU is found and reassembled further down the chain. MTU is always layer 1 and represents capacity of a physical link . But there are situations where protocols/software need to define MTU manually , eg IP MTU or MPLS MTU .

MSS is Maximum TCP segment Size. Unlike MTU, packet exceeding MSS aren't fragmented, they're simply discarded. MSS is normally decided in the TCP three-way handshake, but some setup might yield path where the decided upon MSS is still too big, leading to dropped packets. The MSS isn't negociated packet per packet, but for a complete TCP session, nor does it take into account TCP/IP headers.MSS is always calculated from MTU to avoid any further fragmentation. In case no MTU value is found MSS with minimum size ( 576 ) will be send ( as you know MSS = MTU - layer3 header + layer 2 header ) . and MTU is maximum packet size an interface can support .

The TCP Maximum Segment Size (MSS) defines the maximum amount of data that a host is willing to accept in a single TCP/IP datagram. This TCP/IP datagram might be fragmented at the IP layer. The MSS value is sent as a TCP header option only in TCP SYN segments. Each side of a TCP connection reports its MSS value to the other side. Contrary to popular belief, the MSS value is not negotiated between hosts. The sending host is required to limit the size of data in a single TCP segment to a value less than or equal to the MSS reported by the receiving host.
Originally, MSS meant how big a buffer (greater than or equal to 65496K) was allocated on a receiving station to be able to store the TCP data contained within a single IP datagram. MSS was the maximum segment (chunk) of data that the TCP receiver was willing to accept. This TCP segment could be as large as 64K (the maximum IP datagram size) and it could be fragmented at the IP layer in order to be transmitted across the network to the receiving host. The receiving host would reassemble the IP datagram before it handed the complete TCP segment to the TCP layer.

For example, when using PPPoE, all the overhead means you needs to reduce the MSS on the way, normally by specifying it on the router where the chokepoint is found, which will then replace the MSS of passing threeway handshake by the correct lower value if it's higher. PPPoE is simply adding 8 bytes (6 bytes PPPoE + 2 bytes PPP) on top of everything (IP+TCP) and is meant to be run over Ethernet at 1500 bytes MTU, hence the 1492 MSS normally configured to make it go through.

Your IP stack will chop off data to be sent up to the MSS, put it in a TCP segment, then put it in one or more IP packets (depending if it's bigger than local MTU settings) before sending it. Intermediate router could chop it down further if they have lower MTU, but they're only affecting the IP Packet itself, not playing into the TCP segment/header.

Configuration for MTU and MSS:


Tunnel xxxx
ip mtu 1372
ip tpc adjust-mss 1332


Cisco recommends a GRE MTU of 1400, that's cool. A GRE tunnel encapsulation requires 24/28 Bytes - as you have stated ( I always go with 28, includes some fudge). So the MTU that the GRE can send is 1400 - 28 = MTU 1372 - not including GRE encapsulation. Don't forget that the Maximum Segment Size is the largest transmissible amount of data that can be sent un-fragmented. So the IP header requires 20 bytes. The TCP header requires 20 bytes = 40 bytes.
Great - so now we have:-
28 Bytes - GRE
20 Bytes - IP
20 Bytes - TCP
Total of 68 Bytes, 1400 - 68 = 1332 this is the MSS, that clients and upstream devices should be setting there to MSS in the TCP handshake.

Here is an example from Cisco TechNotes: 

Resolve IP Fragmentation, MTU, MSS, and PMTUD Issues with GRE and IPSEC

  1. Host A compares its MSS buffer (16K) and its MTU (1500 - 40 = 1460) and uses the lower value as the MSS (1460) to send to Host B.
  2. Host B receives Host A's send MSS (1460) and compares it to the value of its outbound interface MTU - 40 (4422).
  3. Host B sets the lower value (1460) as the MSS for sending IP datagrams to Host A.
  4. Host B compares its MSS buffer (8K) and its MTU (4462-40 = 4422) and uses 4422 as the MSS to send to Host A.
  5. Host A receives Host B's send MSS (4422) and compares it to the value of its outbound interface MTU -40 (1460).
  6. Host A sets the lower value (1460) as the MSS for sending IP datagrams to Host B.
1460 is the value chosen by both hosts as the send MSS for each other. Often the send MSS value will be the same on each end of a TCP connection.
In Scenario 2, fragmentation does not occur at the endpoints of a TCP connection because both outgoing interface MTUs are taken into account by the hosts. Packets can still become fragmented in the network between Router A and Router B if they encounter a link with a lower MTU than that of either hosts' outbound interface.




Reference: