Pure IPsec protects unicast IP traffic well, but it does not natively carry multicast or broadcast traffic across sites in the way routing protocols and some legacy services may require. GRE can encapsulate many traffic types, including multicast, inside a unicast tunnel. When GRE is combined with IPsec, GRE provides the tunnel that can carry multicast traffic and IPsec provides encryption and integrity protection for the GRE packets. This is why GRE over IPsec is a common design when encrypted site-to-site connectivity must also support routing protocol hellos or multicast-dependent control traffic. ISATAP is an IPv6 transition mechanism, not the answer for encrypted multicast between remote sites. GRE alone carries the traffic but does not encrypt it. Cisco CCNA 200-301 v1.1 Security Fundamentals expects candidates to understand the division of labor: GRE encapsulates; IPsec secures. Therefore, the mechanism that carries multicast between remote sites and supports encryption is GRE over IPsec.
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit