Skip to main content
Back to Category

GRE Tunneling for Remote DDoS Protection — Full Guide

REXE Technology remote protection service GRE tunneling support, L2 circuit connection, setup process, and Path.net integration — comprehensive guide.

Read time: 4 min DDoS Protection & Security
gretunnelingvpnddospath.netprotectionnetworkremote protection

Table of Contents

Introduction

GRE (Generic Routing Encapsulation) tunneling is a method of encapsulating traffic by creating a virtual tunnel between two network points. DDoS protection providers use GRE tunnels to offer remote protection services.

GRE Tunneling Status

REXE Technology supports GRE tunneling as part of its remote protection service.

GRE tunnels can only be set up by the REXE team via the Path panel. Customers cannot set up GRE tunnels on their own.

How Does GRE Tunneling Work?

If your server is located outside the REXE data center, the REXE team configures a GRE tunnel as part of the remote protection service:

Internet Traffic
    ↓
Path.net Global POP (Traffic Scrubbing)
    ↓
GRE Tunnel (Configured by REXE)
    ↓
Customer Server (External Location)

Key points:

  • Setup is done by REXE: GRE tunnels are set up exclusively by the REXE team via the Path panel
  • Customer setup is not possible: Customers do not have the ability to set up GRE tunnels on their own servers
  • Part of remote protection: If your server is at an external location, the REXE team configures the GRE tunnel for you
  • Path.net integration: All traffic is scrubbed through Path.net and then routed to your server via the GRE tunnel

Servers in the REXE Data Center

If your server is hosted in the REXE data center, GRE tunneling is not needed. Your server is directly connected to the Path.net infrastructure via an L2 (Layer 2) circuit:

Internet Traffic
    ↓
Path.net Global POP (Traffic Scrubbing)
    ↓
L2 Circuit Connection (Low Latency)
    ↓
REXE Data Center (Your Server)

Benefits:

  • No extra latency: No GRE encapsulation/decapsulation overhead
  • No MTU issues: No MTU reduction caused by GRE tunnel
  • Simple configuration: No tunnel configuration needed on the server
  • Full protection: All Path.net filtering features available directly

If your server is in the REXE data center, an L2 circuit connection is used. If it's at an external location, the REXE team configures a GRE tunnel for you.

GRE Tunneling Technical Details

GRE (Generic Routing Encapsulation), defined in RFC 2784, works as follows in the DDoS protection context:

Traffic Flow

  1. Incoming traffic: All traffic from the internet first reaches Path.net's global POP points
  2. Scrubbing: Path.net filters attack traffic and passes only legitimate traffic
  3. GRE encapsulation: Clean traffic is encapsulated with GRE protocol and passed through the tunnel
  4. Delivery: Encapsulated traffic reaches the customer's server and is decapsulated

MTU Considerations

When using a GRE tunnel, the MTU value decreases:

Standard Ethernet MTU: 1500 bytes
GRE Header: 24 bytes
GRE Tunnel MTU: 1476 bytes

This can cause issues with some applications. The REXE team optimizes MTU settings during GRE tunnel setup.

GRE tunnels can only be set up by the REXE team. Customers do not have the ability to set up GRE tunnels on their own servers. Contact our support team for remote protection services.

Remote Protection Service

If your server is hosted at a location other than the REXE data center:

  1. Remote protection via GRE tunnel: The REXE team sets up a GRE tunnel via the Path panel to provide remote DDoS protection for your server
  2. Move your server to REXE: For the best performance and protection, we recommend moving your server to the REXE data center

Alternative Solutions

Server Migration

By migrating your existing server to the REXE data center, you can benefit directly from Path.net protection:

  • VDS or physical server options available
  • Our technical team provides support during the migration process
  • Your data is securely transferred

Colocation

You can host your own hardware in the REXE data center:

  • Path.net DDoS protection is automatically applied
  • Physical security and power redundancy provided
  • 24/7 NOC support available

GRE vs L2 Circuit Comparison

FeatureGRE TunnelL2 Circuit (REXE DC)
Latency+1-3ms extraMinimum latency
MTU1476 bytes1500 bytes
SetupBy REXE teamAutomatic
LocationExternal serversREXE data center
CostMay require extra feeIncluded in plan

For best performance, we recommend hosting your server in the REXE data center. L2 circuit connection provides lower latency and higher MTU compared to GRE tunneling.

Remote Protection Application Process

Steps to follow to get remote protection with a GRE tunnel:

  1. Create a support ticket: Contact our support team via customer panel or email
  2. Share technical details: Provide server IP address, location, and network configuration
  3. REXE team evaluates: Our technical team collects the necessary information for GRE tunnel setup
  4. Tunnel is configured: REXE team sets up the GRE tunnel via the Path panel
  5. Testing and verification: Connection is tested after tunnel setup is complete
  6. Protection active: Your server starts receiving DDoS protection through Path.net

You do not need to make any changes on your server for GRE tunnel setup. All configuration is done by the REXE team via the Path panel.