You are deploying OSPF over IPsec, using GRE, between an SRX Series device and a third-party device.
Which two statements are correct?
A GRE-over-IPsec design uses loopback (lo0) addresses as stable GRE tunnel endpoints. The GRE logical interface carries the OSPF adjacency and must therefore be configured under the OSPF protocol hierarchy. The OSPF packets are encapsulated within GRE and IPsec, so enabling OSPF specifically in the VPN zone is not a prerequisite.
lo0
Community Discussion