After 18 months of migration work, the final GRE-over-IPSec spoke is gone from my infrastructure. No more:
- MTU issues on every other path
- Kernel crypto overhead eating 40% CPU on small HostHatch instances
- Double encapsulation virtualization tax when crossing my own KVM hosts
- IPSec SAs expiring during maintenance windows
- Fragmentation black holes through consumer-grade transit
Replaced with WireGuard on all nodes. Native in kernel 5.6+, no userland daemon dancing, cgroup limits actually work for bandwidth shaping, and the virtualization tax dropped to near zero.
The old GRE headers were 24 bytes of pure overhead per packet. With WireGuard you pay 16 bytes and get actual security, not "whatever the Cisco default was in 2012."
Feels good. Modern tools for modern networks.