Using the gre packet-filter enable command, you can enable the function for filtering IP packets encapsulated using GRE.
Using the undo gre packet-filter enable command, you can disable the function.
By default, the function for filtering IP packets encapsulated using GRE is disabled. You are advertised to disable the function. This is because the device checks IP packets encapsulated using GRE after you enable the function.
The function must be used together with security policies. Therefore, you need to configure a security policy before using the function. When an IP packet encapsulated using GRE matches a rule in the configured security policy, the packet will be permitted or blocked based on the action configured in the security policy.