GRE Tunneling for Remote DDoS Protection — Full Guide
REXE Technology remote protection service GRE tunneling support, L2 circuit connection, setup process, and Path.net integration — comprehensive guide.
Table of Contents
Introduction
GRE (Generic Routing Encapsulation) tunneling is a method of encapsulating traffic by creating a virtual tunnel between two network points. DDoS protection providers use GRE tunnels to offer remote protection services.
GRE Tunneling Status
REXE Technology supports GRE tunneling as part of its remote protection service.
GRE tunnels can only be set up by the REXE team via the Path panel. Customers cannot set up GRE tunnels on their own.
How Does GRE Tunneling Work?
If your server is located outside the REXE data center, the REXE team configures a GRE tunnel as part of the remote protection service:
Internet Traffic
↓
Path.net Global POP (Traffic Scrubbing)
↓
GRE Tunnel (Configured by REXE)
↓
Customer Server (External Location)
Key points:
- Setup is done by REXE: GRE tunnels are set up exclusively by the REXE team via the Path panel
- Customer setup is not possible: Customers do not have the ability to set up GRE tunnels on their own servers
- Part of remote protection: If your server is at an external location, the REXE team configures the GRE tunnel for you
- Path.net integration: All traffic is scrubbed through Path.net and then routed to your server via the GRE tunnel
Servers in the REXE Data Center
If your server is hosted in the REXE data center, GRE tunneling is not needed. Your server is directly connected to the Path.net infrastructure via an L2 (Layer 2) circuit:
Internet Traffic
↓
Path.net Global POP (Traffic Scrubbing)
↓
L2 Circuit Connection (Low Latency)
↓
REXE Data Center (Your Server)
Benefits:
- No extra latency: No GRE encapsulation/decapsulation overhead
- No MTU issues: No MTU reduction caused by GRE tunnel
- Simple configuration: No tunnel configuration needed on the server
- Full protection: All Path.net filtering features available directly
If your server is in the REXE data center, an L2 circuit connection is used. If it's at an external location, the REXE team configures a GRE tunnel for you.
GRE Tunneling Technical Details
GRE (Generic Routing Encapsulation), defined in RFC 2784, works as follows in the DDoS protection context:
Traffic Flow
- Incoming traffic: All traffic from the internet first reaches Path.net's global POP points
- Scrubbing: Path.net filters attack traffic and passes only legitimate traffic
- GRE encapsulation: Clean traffic is encapsulated with GRE protocol and passed through the tunnel
- Delivery: Encapsulated traffic reaches the customer's server and is decapsulated
MTU Considerations
When using a GRE tunnel, the MTU value decreases:
Standard Ethernet MTU: 1500 bytes
GRE Header: 24 bytes
GRE Tunnel MTU: 1476 bytes
This can cause issues with some applications. The REXE team optimizes MTU settings during GRE tunnel setup.
GRE tunnels can only be set up by the REXE team. Customers do not have the ability to set up GRE tunnels on their own servers. Contact our support team for remote protection services.
Remote Protection Service
If your server is hosted at a location other than the REXE data center:
- Remote protection via GRE tunnel: The REXE team sets up a GRE tunnel via the Path panel to provide remote DDoS protection for your server
- Move your server to REXE: For the best performance and protection, we recommend moving your server to the REXE data center
Alternative Solutions
Server Migration
By migrating your existing server to the REXE data center, you can benefit directly from Path.net protection:
- VDS or physical server options available
- Our technical team provides support during the migration process
- Your data is securely transferred
Colocation
You can host your own hardware in the REXE data center:
- Path.net DDoS protection is automatically applied
- Physical security and power redundancy provided
- 24/7 NOC support available
GRE vs L2 Circuit Comparison
| Feature | GRE Tunnel | L2 Circuit (REXE DC) |
|---|---|---|
| Latency | +1-3ms extra | Minimum latency |
| MTU | 1476 bytes | 1500 bytes |
| Setup | By REXE team | Automatic |
| Location | External servers | REXE data center |
| Cost | May require extra fee | Included in plan |
For best performance, we recommend hosting your server in the REXE data center. L2 circuit connection provides lower latency and higher MTU compared to GRE tunneling.
Remote Protection Application Process
Steps to follow to get remote protection with a GRE tunnel:
- Create a support ticket: Contact our support team via customer panel or email
- Share technical details: Provide server IP address, location, and network configuration
- REXE team evaluates: Our technical team collects the necessary information for GRE tunnel setup
- Tunnel is configured: REXE team sets up the GRE tunnel via the Path panel
- Testing and verification: Connection is tested after tunnel setup is complete
- Protection active: Your server starts receiving DDoS protection through Path.net
You do not need to make any changes on your server for GRE tunnel setup. All configuration is done by the REXE team via the Path panel.
Related Articles
Path Panel DDoS Protection Management Panel User Guide
Complete REXE Path Panel user guide: Dashboard, My IPs, TR protection status, rule management, attack history, abuse filtered, password change and API access.
Game Server DDoS Filter Selection Guide (Path.net)
Path.net DDoS protection game filters guide: Arma/DayZ, Source Engine, CS:GO, CS2, FiveM, Minecraft, Rust and more — how to apply each filter.
Application and Service DDoS Filter Guide (Path.net)
Path.net DDoS protection application filters guide: OpenVPN, Wireguard, DTLS, RTP, QUIC, SIP, TCP Symmetric and more — how to choose the right filter.