No relevant resource is found in the selected language.

This site uses cookies. By continuing to browse the site you are agreeing to our use of cookies. Read our privacy policy>Search


To have a better experience, please upgrade your IE browser.


CLI-based Configuration Guide - VPN

AR100, AR120, AR150, AR160, AR200, AR1200, AR2200, AR3200, and AR3600 V200R010

This document describes VPN features on the device and provides configuration procedures and configuration examples.
Rate and give feedback:
Huawei uses machine translation combined with human proofreading to translate this document to different languages in order to help you better understand the content of this document. Note: Even the most advanced machine translation cannot match the quality of professional translators. Huawei shall not bear any responsibility for translation accuracy and it is recommended that you refer to the English document (a link for which has been provided).
Configuring mGRE

Configuring mGRE


To implement DSVPN, create a tunnel interface and set the interface type to Multipoint GRE (mGRE). You only need to configure the source address or source interface but not the destination address on the mGRE interface. An mGRE tunnel interface has multiple remote ends and allows multiple GRE tunnels to be established on the interface. This simplifies GRE configuration on devices.

Perform the following operations on the Hub and Spokes.


  1. Run system-view

    The system view is displayed.

  2. Run interface tunnel interface-number

    A tunnel interface is created and the tunnel interface view is displayed.

  3. Run ip address ip-address { mask | mask-length }

    The IP address of the tunnel interface is configured.

  4. Run tunnel-protocol gre p2mp

    The tunnel encapsulation mode is set to mGRE.

    Changing the encapsulation mode of a tunnel interface deletes other parameters of the tunnel interface, including the source address or source interface configured for the tunnel interface, and NHRP parameters.

  5. Run source { [ vpn-instance vpn-instance-name ] source-ip-address | interface-type interface-number }

    The source address or source interface is configured for the tunnel interface.

    Changing the source command configuration will cause the IPSec configuration on the tunnel interface to be deleted.

  6. (Optional) Run gre key { plain key-number | [ cipher ] plain-cipher-text }

    The key number of a tunnel interface is set.

    By default, no key number is set for a tunnel interface.

    When multiple mGRE tunnel interfaces are configured with the same source address or source interface, run this command to set a key number for each interface.

    If plain is selected, the password is saved in the configuration file in plain text. This brings security risks. It is recommended that you select cipher to save the password in cipher text.

Updated: 2019-08-07

Document ID: EDOC1100033725

Views: 151851

Downloads: 367

Average rating:
This Document Applies to these Products
Related Version
Related Documents
Previous Next