Two routers protect their GRE traffic with IPsec ESP; why is transport mode allowed there, and how many bytes does it save over tunnel mode?
answer
- whose address is the source
- the router acting as a host
- a second header with the same addresses
- what policy can no longer see
basics
~20 sRFC 4301 lets a router use IPsec transport mode for packets it sources itself, and GRE packets carry the router's own address; tunnel mode would add a second IPv4 header with the same two addresses, 20 redundant bytes.
solid answer
~40 sRFC 4301 makes gateway SAs tunnel mode, but allows transport mode on an intermediate system when the outbound packet's source (or inbound packet's destination) is the system's own address. A GRE packet qualifies: the router builds the delivery header with its own address. Tunnel mode would wrap that packet in another IPv4 header naming the same two routers — **20 bytes** buying nothing. With AES-GCM and a 1,400-byte inner packet, the GRE packet is 20 + 4 + 1,400 = 1,424 bytes; transport mode makes it **1,460**, tunnel mode **1,480**. The cost RFC 4301 flags: IPsec access control can no longer see the end-to-end headers inside GRE, so per-host policy has to live elsewhere.
go deeper
Recall that RFC 4301 normally makes gateway SAs tunnel mode, and that GRE packets carry the routers' own addresses.
Explain the own-address condition for transport mode on a router and where ESP sits relative to the GRE and delivery headers.
Compute the 20-byte saving for a real packet and transform, and say where per-host filtering must move once IPsec sees only GRE.
Decide when the per-packet saving justifies losing IPsec-level access control, and where the filtering and MTU policy for an overlay should live.
## The rule that normally forbids it RFC 4301 §4.1 says that whenever either end of a security association is a **security gateway**, the SA MUST be tunnel mode. The reasons it gives are practical: packets must reach the gateway that holds the SA, and fragments need separate inner and outer headers to keep their state straight. Two exceptions follow: 1. Traffic **addressed to the gateway itself** — management traffic, for instance — where the gateway is acting as a host. 2. Transport mode **between intermediate systems**, which RFC 4301 names as a way to protect IP-in-IP, GRE or dynamic routing traffic between gateways. The second exception has a precise boundary: an intermediate system may use transport mode only for packets whose **source address (outbound) or destination address (inbound) belongs to the system itself**. It cannot use transport mode to protect a host's packet it merely forwards. ## Why GRE fits the exception GRE (RFC 2784) puts a **4-byte** base header (8 with the optional checksum) in front of the payload packet and a **delivery header** — a new IPv4 header with protocol 47 — in front of that. The router that encapsulates writes its own address as the delivery header's source and the far router's as the destination. To IPsec, that GRE packet is traffic the router originates, so a transport-mode SA between the two routers is legal. In transport mode, ESP goes after the delivery header and before the GRE header, so the GRE header and the inner packet are encrypted, the IP protocol field becomes 50, and the trailer's `Next Header` holds 47. ## The bytes, computed Take a 1,400-byte inner IPv4 packet and ESP with AES-GCM (8-byte IV, 16-byte ICV, 4-byte alignment): | Step | Transport mode | Tunnel mode | |---|---|---| | GRE packet | 20 + 4 + 1,400 = 1,424 | 20 + 4 + 1,400 = 1,424 | | Encrypted portion before padding | 4 + 1,400 + 2 = 1,406 | 1,424 + 2 = 1,426 | | Padding to a 4-byte boundary | 2 → 1,408 | 2 → 1,428 | | Header in front of ESP | 20 (the delivery header) | 20 (a new outer header) | | On the wire | 20 + 8 + 8 + 1,408 + 16 = **1,460** | 20 + 8 + 8 + 1,428 + 16 = **1,480** | Transport mode saves **20 bytes per packet**, which is exactly the redundant header: in tunnel mode the outer header and the encrypted delivery header carry the same pair of router addresses. On a 1,500-byte path the saving is also 20 bytes of inner MTU. ## What an observer sees, and what policy loses On the path, the two choices look the same: two router addresses and protocol 50. Tunnel mode adds no extra hiding — it encrypts a copy of addresses that are already visible outside. What transport mode does give up is **access control**. RFC 4301 warns that IPsec's access control functions are "significantly limited" here, because they cannot be applied to the end-to-end headers inside the GRE payload. The SA's policy sees only "GRE between router A and router B"; whatever hosts and ports ride inside the GRE tunnel pass if the GRE packet does. Any per-host or per-port filtering has to be done before encapsulation, by the routers' own filtering, rather than by the IPsec policy. ## Fragments under a transport-mode SA Transport mode cannot carry IP fragments. RFC 4301 Appendix D explains why this does not break the GRE design: the GRE encapsulation already provides an inner header, so an oversized inner packet can be fragmented **before** GRE encapsulation. Each piece gets its own GRE and delivery header and reaches IPsec as a whole datagram; IPsec never looks at the inner header and does not see a fragment. ## Summary for the operator - Transport mode is legal because the router sources and sinks the GRE packets itself. - It saves 20 bytes per packet with AES-GCM, and the same 20 bytes of MTU. - It hides nothing less than tunnel mode does. - It moves host-level filtering out of the IPsec policy and into the routers' own filters.
- Could a router use IPsec transport mode to protect a host's packets it forwards, without GRE?No. RFC 4301 permits transport mode on an intermediate system only for packets whose outbound source or inbound destination address belongs to that system. A host's forwarded packet carries the host's addresses, so protecting it at a gateway needs tunnel mode, or an encapsulation such as GRE that the router itself originates.
- If the inner packet is too big, how does GRE over an IPsec transport-mode SA avoid handing IPsec a fragment?The router fragments the inner packet before GRE encapsulation. Each fragment gets its own GRE header and delivery header, so the packet IPsec receives is a whole datagram whose outer fragment offset is zero. RFC 4301 Appendix D notes that IPsec does not examine the inner header here, so it never treats the packet as a fragment.
saying these in an interview costs you the question
- A router can never use IPsec transport mode because gateways are tunnel-only
- Transport mode lets a router protect forwarded host traffic directly, without GRE
- Tunnel mode around GRE hides more, since it encrypts an extra header
- Transport-mode GRE still lets the IPsec policy filter individual inner hosts