GRE, IP-in-IP, and SIT tunnels are not encrypted; they use a simple password-like key that is exchanged in clear text in each packet. They are not suitable for a production network unless otherwise secured. All GRE, IP-in-IP, and SIT tunnels can be protected by an IPsec tunnel. IPsec is explained in detail in Ciena Vyatta Network OS IPsec Site-to-Site VPN Configuration Guide.
Multipoint GRE (mGRE) tunnels can also be secured by using IPsec as part of a Dynamic Multipoint Virtual Private Network (DMVPN). Refer to Ciena Vyatta Network OS DMVPN Configuration Guide for more information on securing mGRE tunnels.
For information on determining which VPN solution best meets your needs, refer to Ciena Vyatta Network OS VPN Support Configuration Guide.