π ~1 min read
Table of contents
Symptom & Impact
GRE interface reports up, but encapsulated traffic is dropped, impacting branch connectivity and overlay applications.
Environment & Reproduction
Reproduced after MTU changes, upstream ACL updates, or route preference changes toward underlay links.
Root Cause Analysis
Most failures are MTU/fragmentation black holes, missing protocol 47 allowance, or return-path asymmetry.
Quick Triage
Test end-to-end path and verify protocol handling along underlay firewall devices.
Step-by-Step Diagnosis
Check effective MTU and packet counters on tunnel and physical interfaces.

Solution β Primary Fix
Set consistent MTU/MSS policy, permit protocol 47, and correct return routes.
Still having issues? Our IT Solutions & Services team can diagnose and resolve this for you. Get in touch for a free consultation.

Solution β Alternative Approaches
Migrate to IPsec encapsulation or route-based VPN where transit filters cannot be adjusted.
Verification & Acceptance Criteria
Sustained bidirectional traffic with no retransmission spikes and expected throughput.
Rollback Plan
Revert tunnel MTU, restore previous static routes, and remove temporary ACL changes.
Prevention & Hardening
Apply standardized tunnel templates and pre-change path MTU validation.
Related Errors & Cross-Refs
Commonly associated with BGP flap storms and edge firewall policy drift.
Related tutorial: View the step-by-step tutorial for Windows Server 2022.
View all Windows Server 2022 tutorials on the Tutorials Hub β
Browse all common problems & solutions on the Tutorials Hub.
References & Further Reading
Microsoft Learn GRE and RRAS networking references.
Need Expert Help?
If you cannot resolve this yourself, our team offers hands-on Server Management, Managed IT Services, and flexible Support Plans. Contact us today β we respond within one business day.