Only 4 tunnel interfaces possible
Accepted Solution
-
Hi @Line2,
The request is already moved to ideas section.
It is also in our feature queue for evaluation.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community5
All Replies
-
Hi @Line2,There is no technical reason for the specification about the current supported tunnel interface number.The new IPSec virtual tunnel interface(VTI) is introduced since firmware 4.20, so we suggest you use VTI interface instead of Tunnel interface.Compared to GRE with extra GRE header overhead, it is better to use VTI instead of GRE over IPSec.If you still think it is necessary to increase the number of Tunnel interface, please feel free to let us know and we will evaluate the enhancement on this feature.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
Hi @Zyxel_EmilyI know VTI, I set up a lot of VTI/IPSec, between ZyWALLs only, I use most of time VTI and OSPF for dynamic routing. I know the overhead of GRE (24bytes). But there are different restrictions where you can't use VTI (3.party firewalls without VTI or no VTI with dynamic IPs there, general antipathy for VTI at a lot of firewall admins because of leak difficulty...).
Thats the same reason why I made a feature request to support OSPF on GRE interfaces. By the way a loopback interface on ZyWALLs would be handy for such things too ;-)
0 -
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community0 -
ok, if it helps :-)
0 -
Hi @Line2,
The request is already moved to ideas section.
It is also in our feature queue for evaluation.
See how you've made an impact in Zyxel Community this year!
https://bit.ly/Your2024Moments_Community5 -
thank you
0 -
One feature that I would like to add is to have the ability to encrypt the GRE tunnel with IPsec to make it secure for routing packet between site.0
-
Hi.
We want to start using GRE over ipsec on our sites with old USG1000, that don't support VTI for autodisables routes, and 4 GREs are too small for ours needs.
Will you realize more GRE in the future and will beta FW availble for test?
0 -
USG1000 does not support GRE over IPSec.
You can consider for USG1100 or VPN300 which support GRE over IPSec function.
0
Categories
- All Categories
- 415 Beta Program
- 2.4K Nebula
- 147 Nebula Ideas
- 96 Nebula Status and Incidents
- 5.7K Security
- 262 USG FLEX H Series
- 271 Security Ideas
- 1.4K Switch
- 74 Switch Ideas
- 1.1K Wireless
- 40 Wireless Ideas
- 6.4K Consumer Product
- 249 Service & License
- 387 News and Release
- 84 Security Advisories
- 29 Education Center
- 10 [Campaign] Zyxel Network Detective
- 3.5K FAQ
- 34 Documents
- 34 Nebula Monthly Express
- 85 About Community
- 73 Security Highlight