policymgr allowlist gre enable

Prev Next

Enables or disables a Generic Routing Encapsulation (GRE) traffic allowlist.

GRE is a tunneling protocol that can be used to encapsulate network layer packets to transport other protocols over an IP network. GRE establishes a private point-to-to connection. Packets are analyzed and compared against a known GRE allowist to determine whether they are GRE packets. A GRE traffic allowlist allows the Network Security appliance to allowlist all GRE packets.

Note

When GRE traffic is enabled on the Network Security appliance, all GRE packets are allowlisted. When GRE traffic is disabled on the Network Security appliance, GRE packets are not allowlisted.

Important

A GRE traffic allowlist is disabled by default.

Syntax

[no] policymgr whitelist gre enable

Parameters

no

Use the no form of the command to disable the GRE traffic allowlist.

Example

The following example enables the GRE traffic allowlist on the Network Security appliance.

hostname (config) # policymgr whitelist gre enable

The following example disables the GRE traffic allowlist on the Network Security appliance.

hostname (config) # no policymgr whitelist gre enable

User role

Admin or Operator

Command mode

Config

Supported appliances

This command is supported on the following appliances running the specified releases or later:

  • Network Security: Release 8.0