Nortel Switched Firewall 2.3.3 User’s Guide and Command Reference
106
Open Shortest Path First
213455-L, October 2005
GRE Tunnel support
NSF 2.3.3 supports Generic Routing Encapsulation (GRE) on all Firewalls. GRE is a point-to-
point tunneling protocol that takes packets from one network system and places them inside
frames from another network system in a peer-to-peer configuration. Typically, GRE is used to
transport legacy Layer 3 protocols over an IP backbone. In this release, NSF supports GRE
over OSPF only.
You can configure up to 5 GRE tunnels on an OSPF network. All GRE-OSPF packets are
forwarded to the Management IP address (MIP). If GRE packets are IPSec, IPSec-GRE-OSPF
encrypted packets are decrypted by Check Point software and then forwarded by GRE to the
MIP.
In this release, static GRE routes cannot be propagated in the unicast route table using the CLI.
GRE loopback interfaces are also not supported.
To configure a GRE tunnel in an OSPF network, see
Example 2: configuring GRE Tunnel on
page 109
.
OSPF features not supported in this release
Filtering OSPF routes
Stub and NSSA areas
Load balancing equal cost routes
During traffic forwarding if the first configured equal cost route is deleted, the next in line
is selected.
Using OSPF to forward multicast routes
Virtual Links
Multiple MD5 keys per OSPF interface
Route map
Summarizing routes
Host routes
OSPF connected interfaces redistribution