IntroductionForcepoint ONE SSE Cloud SWG solution enables web traffic filtering when a SmartEdge agent cannot be deployed on the end user's machine, such as for Guest users or IoT devices or when the organization does not want to deploy an agent.
GRE OverviewGeneric Routing Encapsulation (GRE) is a tunneling protocol used to encapsulate and route data via a virtual point-to-point connection.
ThroughputFor Forcepoint ONE SSE Cloud SWG, Forcepoint allocates 0.1 megabits per second (Mbps) per licensed user per virtual datacenter.
AudienceDefines the audience of this document.
Configurations in Forcepoint ONE SSEThis section details the configurations required to setup GRE tunnel in Forcepoint ONE SSE.
Creating SitesA Site represents a corporate location from which traffic will originate. While creating a Site, you can configure GRE tunnel through which traffic should be sent over to cloud and create or add subnets groups within the site.
Viewing TunnelsAfter creating tunnels, you can monitor the status of each tunnel under Analyze > Tunnels page.
Configurations on edge devicesThis section details the configurations you need to carry on edge device using the details from the Analyze > Tunnels page in Forcepoint ONE SSE portal.
Configuring GRE tunnel to primary data centerAfter creating GRE tunnels in Forcepoint ONE SSE, you should configure the tunnels on the Edge devices so that the web traffic flows between the edge device and Cloud SWG data centers. This topic describes the steps to configure GRE primary tunnel on Cisco IOS.
Configuring GRE tunnel to secondary data centerAfter creating GRE tunnels in Forcepoint ONE SSE, you should configure the tunnels on the Edge devices so that the web traffic flows between the edge device and Cloud SWG data centers. This topic describes the steps to configure GRE secondary tunnel on Cisco IOS.
Configuring ACL and route mapUse the route map to only route the web traffic on ports 80 and 443 through the GRE tunnels.
Configuring failoverBy using the IP SLA, you can configure failover when the primary tunnel is down.
Useful show commandsLists useful show commands that may be handy while configuring tunnels.
Example GRE configuration for Cisco ISRThis GRE configuration example is for Cisco ISR routers using Cisco IOS.
TroubleshootingThe following table lists some problems that may be encountered in configuring and establishing your tunnel, with some suggested actions.
Verifying high availability failoverFor each site you add, it is important to ensure that the High Availability (HA) failover capability is provisioned and configured correctly such that failover happens successfully when required.