3.2 Data Path Virtualization: VRF-Lite, GRE Tunneling, and IPsec VPN Fundamentals
Key Takeaways
VRF-Lite segments a physical router into multiple independent routing tables and forwarding instances, enabling overlapping IP subnets without requiring MPLS backbone transport.
Generic Routing Encapsulation (GRE, RFC 2784) encapsulates arbitrary passenger protocols within IP delivery headers, introducing 24 bytes of overhead and supporting dynamic routing protocols.
GRE keepalives detect a dead or one-way tunnel path, and recursive routing (learning the tunnel destination through the tunnel itself) makes IOS-XE shut the tunnel down; verify with show interfaces tunnel, show crypto ikev2 sa, and show crypto ipsec sa.
IPsec delivers confidentiality, integrity, and origin authentication through AH (integrity only) and ESP (encryption and authentication), operating in Transport Mode for host-to-host or Tunnel Mode for site-to-site topologies.
IKEv2 streamlines security associations into four initial handshake packets with native NAT traversal, while Virtual Tunnel Interfaces (VTIs) replace crypto map ACLs with routable, dynamic IPsec interfaces.
Data Path Virtualization: VRF-Lite, GRE Tunneling, and IPsec VPN Fundamentals
Enterprise data path virtualization isolates logical communication channels across shared physical network infrastructure. By virtualizing routing instances and encapsulating packets across overlay tunnels, network administrators can enforce multi-tenant segmentation, transport diverse protocols across non-contiguous networks, and secure enterprise traffic over untrusted transit networks.
Virtual Routing and Forwarding Lite (VRF-Lite)
Traditional enterprise routers maintain a single global Routing Information Base (RIB) and Forwarding Information Base (FIB). In this shared model, all interfaces and routing protocols reside in the same routing domain, prohibiting duplicate IP addresses and preventing administrative separation.
Virtual Routing and Forwarding (VRF) virtualizes the router's control and forwarding planes, enabling a single physical router to host multiple independent virtual routing instances:
- Independent Tables: Each VRF maintains a dedicated RIB, FIB, and ARP table. Routes learned in one VRF are completely isolated from all other VRFs by default.
- Overlapping Address Spaces: Multiple tenants or departments can utilize identical IP subnets (e.g.,
10.1.1.0/24) without collision, because forwarding lookups execute strictly within the tenant's private forwarding table. - VRF-Lite Architecture: When VRF is deployed without Multiprotocol BGP (MP-BGP) and MPLS label switching across the core, it is termed VRF-Lite. In VRF-Lite deployments, tenant isolation across intermediate switches is preserved by binding each VRF to dedicated 802.1Q VLAN subinterfaces.
! VRF-Lite configuration on Cisco IOS-XE
vrf definition TENANT_RED
rd 65000:10
address-family ipv4
exit-address-family
!
interface GigabitEthernet0/0/1.10
encapsulation dot1Q 10
vrf forwarding TENANT_RED
ip address 10.1.1.1 255.255.255.0
Warning
Applying vrf forwarding <name> to an interface removes any existing IP address from that interface. Always configure the vrf forwarding binding before applying the interface IP address.
Generic Routing Encapsulation (GRE) Tunneling
Generic Routing Encapsulation (GRE), defined in RFC 2784 and RFC 1701, is an unencrypted tunneling protocol that encapsulates arbitrary network-layer passenger protocols inside an IP delivery header.
Encapsulation Mechanics and Packet Format
GRE establishes a virtual point-to-point connection between two routers across an intermediate transit network:
- Passenger Protocol: The original packet being encapsulated (e.g., IPv4, IPv6, or routing protocol traffic such as OSPF hello packets).
- Carrier Protocol (GRE Header): A 4-byte header containing flags, a Protocol Type field (e.g.,
0x0800for IPv4), and optional checksum or key fields. - Delivery Protocol (Outer IP Header): A 20-byte IPv4 header using IP protocol number 47, addressed from the tunnel source IP to the tunnel destination IP.
Total GRE encapsulation overhead is 24 bytes (20 bytes outer IP + 4 bytes GRE header). Because GRE supports multicast and broadcast traffic, dynamic routing protocols (OSPF, EIGRP, BGP) can establish adjacencies directly across GRE tunnels. However, GRE provides no native data confidentiality or encryption.
! Point-to-point GRE tunnel configuration with keepalives
interface Tunnel0
ip address 172.16.1.1 255.255.255.252
tunnel source GigabitEthernet0/0/0
tunnel destination 198.51.100.2
keepalive 10 3
Keepalives and Recursive Routing Avoidance
- GRE Keepalives: A GRE interface remains up/up as long as a route to the destination exists. Configuring
keepalive [seconds] [retries]instructs the router to send periodic inner-encapsulated probes to detect dead peers or unidirectional path failures. - Recursive Routing Avoidance: A recursive routing error (
%TUN-5-RECURDOWN) occurs when the routing protocol learns a route to the tunnel destination through the tunnel interface itself. The router disables the tunnel to prevent an infinite forwarding loop. This is prevented by filtering tunnel destination advertisements or using separate underlay static routes.
IPsec VPN Architecture: Security Services, Protocols, and Modes
IPsec (IP Security) provides cryptographic protection at the network layer:
- Security Services: Confidentiality (AES encryption), Data Integrity (HMAC-SHA hashing), Origin Authentication (pre-shared keys or digital certificates), and Anti-Replay protection (sequence numbers).
- AH vs. ESP:
- Authentication Header (AH, IP Protocol 51): Provides data integrity and origin authentication, but no data confidentiality. Because AH includes the outer IP header in its hash, it fails across Network Address Translation (NAT) devices.
- Encapsulating Security Payload (ESP, IP Protocol 50): Provides confidentiality, integrity, and origin authentication. ESP supports NAT traversal (NAT-T) by encapsulating ESP inside UDP port 4500.
- Transport vs. Tunnel Mode:
- Transport Mode: Protects only the payload and Layer 4 header, preserving the original IP header. Commonly used for host-to-host communication or GRE over IPsec.
- Tunnel Mode: Encrypts the entire original IP packet and adds a new outer IP header. This is the enterprise default for site-to-site VPNs.
Tunnel Header Comparison
| Tunnel Type | Outer IP Protocol | Security Header | Encryption | Typical Overhead |
|---|---|---|---|---|
| GRE (RFC 2784) | IPv4 (Proto 47) | 4-byte GRE Header | None (Cleartext) | 24 Bytes |
| IPsec Transport (ESP) | Original IP Header | ESP Header / Trailer | Payload Encrypted | ~32–40 Bytes |
| IPsec Tunnel (ESP) | New Outer IP (Proto 50) | ESP Header / Trailer | Full Packet Encrypted | ~50–56 Bytes |
| GRE over IPsec (Transport) | New Outer IP (Proto 50) | ESP + GRE Header | Full GRE Encrypted | ~56–64 Bytes |
Internet Key Exchange: IKEv1 vs. IKEv2
Internet Key Exchange (IKE) automates mutual authentication and Security Association (SA) parameter negotiation:
- IKEv1: Splits negotiation into two phases. Phase 1 (ISAKMP SA) negotiates management tunnels using Main Mode (6 packets, identity protected) or Aggressive Mode (3 packets, cleartext identities). Phase 2 (Quick Mode, 3 packets) negotiates IPsec transform sets. Establishing an active tunnel requires 9 messages in Main Mode.
- IKEv2 (RFC 7296): Replaces IKEv1 with a streamlined 4-message exchange.
IKE_SA_INIT(2 messages) negotiates cryptographic proposals and Diffie-Hellman keys.IKE_AUTH(2 messages) authenticates identities and creates the initialCHILD_SAfor data forwarding. IKEv2 includes native NAT-T, asymmetric authentication, and anti-DoS cookies.
IKE Protocol Comparison
| Dimension | IKEv1 (RFC 2409) | IKEv2 (RFC 7296) |
|---|---|---|
| Handshake Phases | Phase 1 (ISAKMP) and Phase 2 (IPsec SA) | IKE_SA_INIT and IKE_AUTH (creates CHILD_SA) |
| Initial Message Count | 9 messages (Main Mode) / 6 messages (Aggressive) | 4 messages total |
| NAT Traversal (NAT-T) | Added by separate standards (RFC 3947 and RFC 3948) | Built into the IKEv2 specification |
| Authentication | Symmetric (both peers use PSK or Cert) | Supports asymmetric authentication |
Crypto Maps vs. Virtual Tunnel Interfaces (VTI)
Traditional policy-based IPsec VPNs used crypto maps bound to physical interfaces. Crypto maps evaluate access lists to identify interesting traffic, but they do not create a routable logical interface, preventing direct dynamic routing without GRE.
Virtual Tunnel Interfaces (VTI) provide modern route-based IPsec:
- Instantiates a routable
interface TunnelXoperating in IPsec mode (tunnel mode ipsec ipv4). - Natively transports dynamic routing protocols (OSPF, EIGRP, BGP) over IPsec without GRE overhead.
- Simplifies routing policies, firewall zone integration, and interface QoS.
! IKEv2 Static Virtual Tunnel Interface (SVTI) configuration
crypto ikev2 proposal IKE2_PROP
encryption aes-gcm-256
prf sha256
group 19
!
crypto ikev2 policy IKE2_POL
proposal IKE2_PROP
!
crypto ikev2 keyring IKE2_KEYRING
peer BRANCH
address 198.51.100.2
pre-shared-key Str0ngSharedKey
!
crypto ikev2 profile IKE2_PROF
match identity remote address 198.51.100.2 255.255.255.255
identity local address 203.0.113.1
authentication remote pre-share
authentication local pre-share
keyring local IKE2_KEYRING
!
crypto ipsec profile VTI_IPSEC_PROFILE
set ikev2-profile IKE2_PROF
!
interface Tunnel1
ip address 10.254.1.1 255.255.255.252
tunnel source GigabitEthernet0/0/0
tunnel destination 198.51.100.2
tunnel mode ipsec ipv4
tunnel protection ipsec profile VTI_IPSEC_PROFILE
ip tcp adjust-mss 1360
MTU, Fragmentation, and TCP MSS Clamping
Encapsulating packets inside GRE (24 bytes) and IPsec ESP (50–56 bytes) expands a standard 1500-byte packet to 1574–1580 bytes. If intermediate transit networks cannot accommodate jumbo frames and packets have the Don't Fragment (DF) bit set, routers drop them and return ICMP Type 3 Code 4. If firewalls block ICMP, path MTU discovery fails, causing application drops.
To prevent fragmentation and black holes, routers enforce TCP MSS Clamping:
- The router inspects TCP SYN packets traversing the tunnel and rewrites the Maximum Segment Size using
ip tcp adjust-mss 1360. - Setting MSS to 1360 ensures that TCP segments plus IP, TCP, and IPsec/GRE headers remain under the standard 1500-byte physical MTU.
Configuring and Verifying the Data Path
Topic 2.2 says configure and verify, so you must know the commands that prove each technology works.
VRF-Lite routing and verification
A VRF needs its own routing information. With OSPF, each VRF runs its own process:
router ospf 10 vrf TENANT_RED
network 10.1.1.0 0.0.0.255 area 0
| Task | Command | What to look for |
|---|---|---|
| List VRFs and member interfaces | show vrf or show vrf brief | The interface appears under the correct VRF |
| Check the VRF routing table | show ip route vrf TENANT_RED | Tenant routes appear only in that VRF's table |
| Test reachability inside a VRF | ping vrf TENANT_RED 10.1.1.10 | A plain ping uses the global table and can fail even when the VRF works |
| Check ARP inside a VRF | show ip arp vrf TENANT_RED | Entries for neighbors on the VRF's interfaces |
GRE and IPsec verification
| Task | Command | What to look for |
|---|---|---|
| Tunnel state and encapsulation | show interfaces tunnel 0 | Tunnel up/up, the correct source and destination, and GRE/IP or IPsec transport |
| Interface summary | show ip interface brief | The tunnel interface is up/up with its overlay IP address |
| IKEv2 control channel | show crypto ikev2 sa | Status READY for the peer |
| IPsec data channel | show crypto ipsec sa | Increasing #pkts encaps and #pkts decaps counters |
| Overall session | show crypto session | Session status UP-ACTIVE |
If #pkts encaps rises but #pkts decaps stays at zero, packets are leaving but nothing is coming back. Check the peer's profile and keys, and look for a firewall blocking ESP (IP protocol 50) or UDP 500 and 4500.
What operational condition triggers a Cisco IOS-XE router to place a GRE tunnel interface into the recursive routing down state (%TUN-5-RECURDOWN)?
The router detects that GRE keepalive packets have failed three consecutive times
The physical interface acting as the tunnel source loses carrier signal
The routing table selects the tunnel interface itself as the best path to reach the tunnel destination IP address
The tunnel MTU exceeds the maximum transmission unit supported by the physical transit interface
How does the message exchange efficiency of IKEv2 compare to IKEv1 Main Mode during initial tunnel establishment?
IKEv2 needs 4 messages to build the IKE SA and first child SA, versus 9 for IKEv1 Main Mode plus Quick Mode
IKEv2 requires 6 messages for Phase 1 and 3 messages for Phase 2, exactly mirroring IKEv1 Main Mode
IKEv2 eliminates initial handshake messages entirely by exchanging encryption keys through out-of-band DNS TXT records
IKEv2 requires 12 messages because it negotiates separate security associations for IPv4 and IPv6 traffic simultaneously
Why is the IPsec Authentication Header (AH) incompatible with networks utilizing Network Address Translation (NAT)?
AH uses asymmetric encryption keys that cannot be processed by stateful NAT translation tables
AH operates exclusively at Layer 2 and therefore cannot be routed across the IP networks where NAT gateways are deployed
AH mandates a fixed MTU of 9000 bytes, which exceeds standard public internet circuit capacity
AH calculates its integrity checksum across the outer IP header, which fails verification when NAT modifies IP addresses
Sections you finish are checked off in the contents.