<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Henry&#039;s Points</title>
	<atom:link href="http://henrydu.com/blog/feed" rel="self" type="application/rss+xml" />
	<link>http://henrydu.com/blog</link>
	<description>Think analog, act digital</description>
	<lastBuildDate>Mon, 14 Nov 2011 18:32:20 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Some Vertical Search Engines</title>
		<link>http://henrydu.com/blog/web-application/some-vertical-search-engines-409.html</link>
		<comments>http://henrydu.com/blog/web-application/some-vertical-search-engines-409.html#comments</comments>
		<pubDate>Mon, 14 Nov 2011 18:32:20 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[Web Application]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=409</guid>
		<description><![CDATA[According to search engine wiki pedia, Google, Yahoo and Bing share almost 98% search engine market. However, there are still 2% underground search engines. They provide search in particular area, some of them may be banned by the universal search engine like Duckduckgo.com. I tried to input &#8220;Porn&#8221; and there is nothing returned. I remember [...]]]></description>
			<content:encoded><![CDATA[<p>According to search engine wiki pedia, Google, Yahoo and Bing share almost 98% search engine market. However, there are still 2% underground search engines. They provide search in particular area, some of them may be banned by the universal search engine like Duckduckgo.com. I tried to input &#8220;Porn&#8221; and there is nothing returned. I remember Matt Cutt&#8217;s first job in Google is to find porn sites, then keep them &#8220;safe&#8221;. So, Here we go.</p>
<ol>
<li>Torrent Search Engine: torrent-finder.info/</li>
<li>House Foreclosures: realestate.aol.com/blog/foreclosures/</li>
<li>Pornography: www.booble.com</li>
<li>Public Record: www.publicrecordcenter.com</li>
</ol>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p>&nbsp;</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/web-application/some-vertical-search-engines-409.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/web-application/some-vertical-search-engines-409.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>McAfee SiteAdvisor Overview</title>
		<link>http://henrydu.com/blog/web-application/mcafee-siteadvisor-overview-401.html</link>
		<comments>http://henrydu.com/blog/web-application/mcafee-siteadvisor-overview-401.html#comments</comments>
		<pubDate>Tue, 18 Oct 2011 22:29:56 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[Web Application]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=401</guid>
		<description><![CDATA[When I read some papers related classifying malicious/benign web sites, it mentioned McAfee SiteAdvisor. I went through the official website and installed plug-in to play around. I found it is a good adviser because it not only provides nuisance sore also provide how does malicious software modify our own system. The other nice feature the [...]]]></description>
			<content:encoded><![CDATA[<p>When I read some papers related classifying malicious/benign web sites, it mentioned McAfee SiteAdvisor. I went through the official website and installed plug-in to play around. I found it is a good adviser because it not only provides nuisance sore also provide how does malicious software modify our own system. The other nice feature the SiteAdvisor provided is &#8220;Are you the owner of this site? Leave a comment&#8221;. By using this, website owner may have chance to let SiteAdvisor to re-evaluate. <a href="http://user.siteadvisor.com/forums/websiteOwnerVerification.php?domain=refog.com"><br />
</a></p>
<p>We could install a McAfee SiteAdvisor plug-in to our web browser. When we search some web site by key words, the SiteAdvisor will advice us by four levels mark: green one is Safe, means very low or no risk issue; yellow one is Caution, means minor risk issue; red one is warning, means serious risk issue.</p>
<p>I input key words &#8220;kylogger&#8221;, the result is shown on below. As we can see, some websites are safe but some are risky.</p>
<p><a href="http://henrydu.com/blog/wp-content/uploads/2011/10/keylogger_search.jpg"><img class="aligncenter size-full wp-image-402" title="keylogger_search" src="http://henrydu.com/blog/wp-content/uploads/2011/10/keylogger_search.jpg" alt="" width="623" height="596" /></a></p>
<p>We can view site report by clicking on the red mark icon. One part of report is download test.</p>
<p><a href="http://henrydu.com/blog/wp-content/uploads/2011/10/down_load_test.jpg"><img class="aligncenter size-full wp-image-405" title="down_load_test" src="http://henrydu.com/blog/wp-content/uploads/2011/10/down_load_test.jpg" alt="" width="660" height="232" /></a>SiteAdvisor also provides mark for each dowload files. There is a Nuisance Score related with the file. The most attractive part is How does it modify my system.</p>
<p><a href="http://henrydu.com/blog/wp-content/uploads/2011/10/nuisance_score.jpg"><img class="aligncenter size-full wp-image-406" title="nuisance_score" src="http://henrydu.com/blog/wp-content/uploads/2011/10/nuisance_score.jpg" alt="" width="721" height="430" /></a>On the report, the SiteAdvisor also provides the online affiliations for the link, which give the web user overall picture about the website and its affiliations.</p>
<p><a href="http://henrydu.com/blog/wp-content/uploads/2011/10/online-affiliations.jpg"><img class="aligncenter size-full wp-image-407" title="online affiliations" src="http://henrydu.com/blog/wp-content/uploads/2011/10/online-affiliations.jpg" alt="" width="688" height="295" /></a></p>
<p>&nbsp;</p>
<p>The backend of the SiteAdvisor maybe more interesting but I&#8217;d like to leave it for a while. Later, I may go through other similar product.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/web-application/mcafee-siteadvisor-overview-401.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/web-application/mcafee-siteadvisor-overview-401.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Steve Jobs 1955-2011</title>
		<link>http://henrydu.com/blog/travel-log/steve-jobs-1955-2011-396.html</link>
		<comments>http://henrydu.com/blog/travel-log/steve-jobs-1955-2011-396.html#comments</comments>
		<pubDate>Thu, 06 Oct 2011 04:40:29 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[So we travel]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=396</guid>
		<description><![CDATA[Share on Facebook]]></description>
			<content:encoded><![CDATA[<p><a href="http://henrydu.com/blog/wp-content/uploads/2011/10/steven_jobs.png"><img class="aligncenter size-full wp-image-397" title="Steve Jobs" src="http://henrydu.com/blog/wp-content/uploads/2011/10/steven_jobs.png" alt="" width="570" height="419" /></a></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/travel-log/steve-jobs-1955-2011-396.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/travel-log/steve-jobs-1955-2011-396.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>HandBrake for MP4</title>
		<link>http://henrydu.com/blog/cool-stuff/handbrake-for-mp4-388.html</link>
		<comments>http://henrydu.com/blog/cool-stuff/handbrake-for-mp4-388.html#comments</comments>
		<pubDate>Sun, 17 Jul 2011 22:06:12 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[Cool Stuff]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=388</guid>
		<description><![CDATA[Thanks Jeffrey Ai who told me a nice tool to convert many formats of Movies to MP4(MV4) format. Especially, it can be working on Mac OS and Linux platform. The download link and details are listed at: http://handbrake.fr/ Share on Facebook]]></description>
			<content:encoded><![CDATA[<p>Thanks Jeffrey Ai who told me a nice tool to convert many formats of Movies to MP4(MV4) format. Especially, it can be working on Mac OS and Linux platform. The download link and details are listed at: http://handbrake.fr/</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/cool-stuff/handbrake-for-mp4-388.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/cool-stuff/handbrake-for-mp4-388.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>True Nobility</title>
		<link>http://henrydu.com/blog/travel-log/true-nobility-382.html</link>
		<comments>http://henrydu.com/blog/travel-log/true-nobility-382.html#comments</comments>
		<pubDate>Fri, 18 Feb 2011 05:46:04 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[So we travel]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=382</guid>
		<description><![CDATA[by Ernest Hemingway In a calm sea every man is a pilot.But all sunshine without shade, all pleasure without pain, is not life at all. Take the lot of the happiest–it is a tangled yarn. Bereavements and blessings,one following another, make us sad and blessed by turns. Even death itself makes life more loving. Men [...]]]></description>
			<content:encoded><![CDATA[<p>by Ernest Hemingway</p>
<p>In a calm sea every man is a pilot.But all sunshine without shade, all pleasure without pain, is not life at all.</p>
<p>Take the lot of the happiest–it is a tangled yarn. Bereavements and blessings,one following another, make us sad and blessed by turns. Even death itself makes life more loving. Men come closest to their true selves in the sober moments of life,under the shadows of sorrow and loss.</p>
<p>In the affairs of life or of business, it is not intellect that tells so much as character,not brains so much as heart, not genius so much as self-control, patience, and discipline, regulated by judgment.</p>
<p>I have always believed that the man who has begun to live more seriously within begins to live more simply without. In an age of extravagance and waste, I wish I could show to the world how few the real wants of humanity are.</p>
<p>To regret one’s errors to the point of not repeating them is true repentance. There is nothing noble in being superior to some other man. The true nobility is in being superior to your previous self.</p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/travel-log/true-nobility-382.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/travel-log/true-nobility-382.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apple Think Different Ad in 1997</title>
		<link>http://henrydu.com/blog/travel-log/apple-think-different-ad-in-1997-374.html</link>
		<comments>http://henrydu.com/blog/travel-log/apple-think-different-ad-in-1997-374.html#comments</comments>
		<pubDate>Sun, 30 Jan 2011 03:28:26 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[So we travel]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=374</guid>
		<description><![CDATA[Share on Facebook]]></description>
			<content:encoded><![CDATA[<p><iframe title="YouTube video player" class="youtube-player" type="text/html" width="480" height="390" src="http://www.youtube.com/embed/WyGT2F74p_A" frameborder="0" allowFullScreen></iframe></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/travel-log/apple-think-different-ad-in-1997-374.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/travel-log/apple-think-different-ad-in-1997-374.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why Facebook</title>
		<link>http://henrydu.com/blog/business/why-facebook-378.html</link>
		<comments>http://henrydu.com/blog/business/why-facebook-378.html#comments</comments>
		<pubDate>Thu, 09 Dec 2010 23:49:48 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[Business]]></category>
		<category><![CDATA[So we travel]]></category>
		<category><![CDATA[Web Application]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=378</guid>
		<description><![CDATA[Why people like social on Fackbook? I asked my friend. Q: hey, my co-worker wants to know, why people like facebook more than others, like QQ, myspace, etc. A: cuz everyone is using them, lol Q: so, why everyone using it? more fancy? A: easier to communicate and share, i guess. and you can pick [...]]]></description>
			<content:encoded><![CDATA[<p>Why people like social on Fackbook? I asked my friend.</p>
<p>Q: hey, my co-worker wants to know, why people like facebook more than others, like QQ, myspace, etc.</p>
<p>A: cuz everyone is using them, lol</p>
<p>Q: so, why everyone using it? more fancy?</p>
<p>A: easier to communicate and share, i guess. and you can pick whatever you want to see.</p>
<p>Q: but why I don&#8217;t login so often?</p>
<p>A: cuz you are too busy, facebook is for the bored office dudes like me.</p>
<p> <img src='http://henrydu.com/blog/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/business/why-facebook-378.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/business/why-facebook-378.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>router-traffic for CBAC</title>
		<link>http://henrydu.com/blog/networks/router-traffic-for-cbac-376.html</link>
		<comments>http://henrydu.com/blog/networks/router-traffic-for-cbac-376.html#comments</comments>
		<pubDate>Tue, 07 Dec 2010 21:40:33 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[Networks]]></category>
		<category><![CDATA[Security]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=376</guid>
		<description><![CDATA[CBAC is the upgrade version of flexible access control. Since access list is not stateful control, which means, if very strict access list applied in Outside interface for inbound traffic, most of traffic initialized from Inside subnet will be blocked. CBAC help us to inspect specified outgress traffic and put state in the state table. [...]]]></description>
			<content:encoded><![CDATA[<p>CBAC is the upgrade version of flexible access control. Since access list is not stateful control, which means, if very strict access list applied in Outside interface for inbound traffic, most of traffic initialized from Inside subnet will be blocked. CBAC help us to inspect specified outgress traffic and put state in the state table. When the traffic comes back, the Outside interface won&#8217;t block them out.</p>
<p>However, the interesting problem is, if the traffic initilized from local router, the inspection won&#8217;t take effect. Like we want to capture transit package by issue &#8220;no ip route-cache&#8221;, we need to add &#8220;router-traffic&#8221; option when define CBAC.</p>
<blockquote><p>ip inspect name INSIDE_OUT tcp router-traffic</p></blockquote>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/networks/router-traffic-for-cbac-376.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/networks/router-traffic-for-cbac-376.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Sand Artist</title>
		<link>http://henrydu.com/blog/travel-log/sand-artist-372.html</link>
		<comments>http://henrydu.com/blog/travel-log/sand-artist-372.html#comments</comments>
		<pubDate>Thu, 02 Dec 2010 06:29:27 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[So we travel]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=372</guid>
		<description><![CDATA[First time I realize it is the most beautiful art in the world. It&#8217;s really touched. Share on Facebook]]></description>
			<content:encoded><![CDATA[<p>First time I realize it is the most beautiful art in the world. It&#8217;s really touched.</p>
<p><object classid="clsid:d27cdb6e-ae6d-11cf-96b8-444553540000" width="480" height="400" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"><param name="align" value="9" /><param name="src" value="http://player.youku.com/player.php/sid/XMTE5Njc2MDg0/v.swf" /><param name="quality" value="high" /><embed type="application/x-shockwave-flash" width="480" height="400" src="http://player.youku.com/player.php/sid/XMTE5Njc2MDg0/v.swf" quality="high" align="9"></embed></object></p>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/travel-log/sand-artist-372.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/travel-log/sand-artist-372.html/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>IPSec over GRE and IPSec VTI</title>
		<link>http://henrydu.com/blog/networks/vpn/ipsec-over-gre-and-ipsec-vti-368.html</link>
		<comments>http://henrydu.com/blog/networks/vpn/ipsec-over-gre-and-ipsec-vti-368.html#comments</comments>
		<pubDate>Wed, 03 Nov 2010 01:07:35 +0000</pubDate>
		<dc:creator>hengdu</dc:creator>
				<category><![CDATA[VPN]]></category>

		<guid isPermaLink="false">http://henrydu.com/blog/?p=368</guid>
		<description><![CDATA[When reviewing the topic of IPSEC over GRE Tunnel, I have observed that we have several ways to implement it. However, some posts are confusing people. For example, this post is named IPSEC over GRE Tunnel, the actual configuration is IPSec static VTI (Virtual Tunnel Interface), because the configuration under tunnel interface has one line, [...]]]></description>
			<content:encoded><![CDATA[<p>When reviewing the topic of IPSEC over GRE Tunnel, I have observed that we have several ways to implement it. However, some posts are confusing people. For example, <a title="IPSec over GRE" href="https://learningnetwork.cisco.com/docs/DOC-2457" target="_blank">this post</a> is named IPSEC over GRE Tunnel, the actual configuration is IPSec static VTI (Virtual Tunnel Interface), because the configuration under tunnel interface has one line, which indicated that the tunnel mode is changed.</p>
<blockquote><p>tunnel mode ipsec ipv4</p></blockquote>
<p>So, in this post, I would like to clarify some misunderstanding.</p>
<h2>GRE as IPSec interested traffic</h2>
<p>This is the first, and probably less-used solution for IPSec over GRE. We setup Lan-to-Lan IPSec between two physical interface of two routers. Under the crypto map, we set the interested traffic as</p>
<blockquote><p>access-list 105 permit gre &lt;tunnel_source_ip&gt; &lt;tunnel_source_mask&gt; &lt;tunnel_des_ip&gt; &lt;tunnel_des_mask&gt;</p></blockquote>
<p>After ping traffic between each end of the tunnel, the IPSec tunnel is setup. The following are the basic configuration of two routers.</p>
<p>R1</p>
<blockquote><p>!<br />
crypto isakmp policy 10<br />
encr 3des<br />
hash md5<br />
authentication pre-share<br />
group 5<br />
crypto isakmp key CISCO address 150.1.12.2<br />
!<br />
!<br />
crypto ipsec transform-set R1_TO_R2 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R1_TO_R2<br />
!<br />
!<br />
crypto map CRYPTO_MAP 10 ipsec-isakmp<br />
set peer 150.1.12.2<br />
set transform-set R1_TO_R2<br />
match address 105<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.1 255.255.255.0<br />
tunnel source 150.1.12.1<br />
tunnel destination 150.1.12.2<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.1 255.255.255.0<br />
crypto map CRYPTO_MAP<br />
!<br />
access-list 105 permit gre 150.1.12.0 0.0.0.255 150.1.12.0 0.0.0.255<br />
!</p></blockquote>
<p>R2</p>
<blockquote><p>!<br />
crypto isakmp policy 10<br />
encr 3des<br />
hash md5<br />
authentication pre-share<br />
group 5<br />
crypto isakmp key CISCO address 150.1.12.1<br />
!<br />
!<br />
crypto ipsec transform-set R2_TO_R1 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R2_TO_R1<br />
!<br />
!<br />
crypto map CRYPTO_MAP 10 ipsec-isakmp<br />
set peer 150.1.12.1<br />
set transform-set R2_TO_R1<br />
match address 105<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.2 255.255.255.0<br />
tunnel source 150.1.12.2<br />
tunnel destination 150.1.12.1<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.2 255.255.255.0<br />
crypto map CRYPTO_MAP<br />
!<br />
access-list 105 permit gre 150.1.12.0 0.0.0.255 150.1.12.0 0.0.0.255<br />
!</p></blockquote>
<h2>GRE Tunnel Protection</h2>
<p>Since we use <strong>tunnel protection</strong> command under tunnel interface, we don&#8217;t need to define <strong>crypto map</strong>, instead, we need to define ipsec profile. Then, we need apply ipsec protection profile to the tunnel interface. The following are the basic configuration. Please note that, there is no &#8220;<strong>tunnel mode ipsec ipv4</strong>&#8221; command, which means, the tunnel mode is still GRE.</p>
<p>R1</p>
<blockquote><p>!<br />
crypto ipsec transform-set R1_TO_R2 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R1_TO_R2<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.1 255.255.255.0<br />
tunnel source 150.1.12.1<br />
tunnel destination 150.1.12.2<br />
tunnel protection ipsec profile TEST<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.1 255.255.255.0<br />
!</p></blockquote>
<p>R2</p>
<blockquote><p>!<br />
crypto ipsec transform-set R2_TO_R1 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R2_TO_R1<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.2 255.255.255.0<br />
tunnel source 150.1.12.2<br />
tunnel destination 150.1.12.1<br />
tunnel protection ipsec profile TEST<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.2 255.255.255.0<br />
!</p></blockquote>
<h2>Removing 4-Bytes GRE header ???</h2>
<p>Cisco brought us <a title="IPSec VTI" href="http://www.cisco.com/en/US/docs/ios/12_3t/12_3t14/feature/guide/gtIPSctm.html" target="_blank">IPSec VTI</a> (virtual tunnel interface) in IOS 12.3T. The purpose of that is to have a new tunnel mode to reduce 4 bytes GRE header in the traffic. However, different tunnel mode can apply different application. Here are some considerations for IPSec VTI. The IPsec VTI is limited to IP unicast and multicast traffic only, as opposed to GRE tunnels, which have a wider application for IPsec implementation. Thus, for some non-IP traffic, we still need IPSec over GRE.</p>
<p>R1</p>
<blockquote><p>!<br />
crypto ipsec transform-set R1_TO_R2 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R1_TO_R2<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.1 255.255.255.0<br />
tunnel source 150.1.12.1<br />
tunnel destination 150.1.12.2<br />
tunnel protection ipsec profile TEST<br />
tunnel mode ipsec ipv4<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.1 255.255.255.0<br />
!</p></blockquote>
<p>R2</p>
<blockquote><p>!<br />
crypto ipsec transform-set R2_TO_R1 esp-aes 192 esp-sha-hmac<br />
!<br />
crypto ipsec profile TEST<br />
set transform-set R2_TO_R1<br />
!<br />
interface Tunnel0<br />
ip address 150.1.121.2 255.255.255.0<br />
tunnel source 150.1.12.2<br />
tunnel destination 150.1.12.1<br />
tunnel protection ipsec profile TEST<br />
tunnel mode ipsec ipv4<br />
!<br />
interface Serial1/0<br />
ip address 150.1.12.2 255.255.255.0<br />
!</p></blockquote>
<p class="facebook"><a href="http://www.facebook.com/share.php?u=http://henrydu.com/blog/networks/vpn/ipsec-over-gre-and-ipsec-vti-368.html" target="_blank" title="Share on Facebook">Share on Facebook</a></p>]]></content:encoded>
			<wfw:commentRss>http://henrydu.com/blog/networks/vpn/ipsec-over-gre-and-ipsec-vti-368.html/feed</wfw:commentRss>
		<slash:comments>7</slash:comments>
		</item>
	</channel>
</rss>

