# A DEFCON 33 Presentation Revisits the Security Risks of Unencrypted VXLAN Tunnels

DevFeed: [A DEFCON 33 Presentation Revisits the Security Risks of Unencrypted VXLAN Tunnels](<https://devfeed.tech/articles/omg-after-a-decade-vxlan-is-still-insecure-11336.md>)

Original publisher: [Read original article](<https://blog.ipspace.net/2026/02/worth-reading-omg-vxlan-still-insecure/>)

Published: 2026-02-04T06:22:00Z

Content type: opinion

Language: en

Sources: [ipSpace.net blog](<https://devfeed.tech/sources/ipspace-net-blog.md>)

Topics: [VXLAN](<https://devfeed.tech/topics/vxlan.md>), [Security](<https://devfeed.tech/topics/security.md>)

Tags: [defcon](<https://devfeed.tech/tags/defcon.md>), [presentation](<https://devfeed.tech/tags/presentation.md>), [security](<https://devfeed.tech/tags/security.md>), [vxlan](<https://devfeed.tech/tags/vxlan.md>), [worth-reading](<https://devfeed.tech/tags/worth-reading.md>)

## AI overview

The article revisits long-known security concerns about unencrypted VXLAN tunnels and points readers to a summary and slides from a DEFCON 33 presentation on using GRE and VXLAN.

## Source excerpt

In 2017 (over eight years ago), I was making fun of the fact that "VXLAN is insecure" was news to some people. Obviously, the message needed to be repeated, as the same author gave a very similar presentation two years later at a security conference. Unfortunately, it seems that everything old is new again (see also RFC 1925 rules 4 and 11), as proved by a "Using GRE and VXLAN for Fun and Profit" (my summary) presentation at DEFCON 33. Even if you knew that unencrypted tunnels are insecure (duh!) for decades, you might still want to read the summary of the talk (published on APNIC blog) and view the slides.