Knowledge Base  /  CenturyLink Private Cloud on VMware Cloud Foundation  /  Security
Knowledge Base  /  CenturyLink Private Cloud on VMware Cloud Foundation  /  Security

Enable IPSec VPN on Edge Gateway Services

Updated by Anthony Hakim on Sep 11, 2018
Article Code: kb/1158

Description

In this KB article, we walk through how to enable an IPSec VPN on Edge Gateway Services within the vCloud Director (vCD) Web Console environment for CenturyLink Private Cloud on VMware Cloud Foundation™.

Prerequisites

You must configure at least one IPSec VPN site on the NSX Edge before enabling the IPSec VPN service.

  • Login to your CenturyLink Private Cloud on VMware Cloud Foundation environment with an Org Admin Account

    Login to CenturyLink Private Cloud on VMware Cloud Foundation

  • Once logged in, click Datacenters in the ,menu at the top and then select your Datacenter.

    IPSec VPN

  • Click on Edges in the panel on the left side.

    IPSec VPN

  • Select your Edge Gateway, and take note of the (Public) IP Address for the Edge Gateway. Click Configure Services at the top of the screen.

    IPSec VPN

  • Select the VPN tab, then IPsecVPN Sites. Click the + icon to add IPsec VPN Sites (this is a prerequisite to enable IPsec VPN Services).

    IPSec VPN

  • A new window will pop up. Follow the steps below:

  • Add IPsec VPN:

    • Enabled: Click slider to enable
    • Enable perfect forward secrecy (PFS): default
    • Name: Name your IPSec VPN
    • Local Id: Your Local Id
    • Local Endpoint: IP address of Edge Gateway
    • Local Subnets: Your Local Subnets
    • Peer Id: Your Peer Id
    • Peer Endpoint: IP address of Peer
    • Peer Subnets: Your Peer Subnets
    • Encryption Algorithm: Must match with peer
    • Authentication: Must match with peer
    • Change Shared Key:
    • Pre-Shared Key: Shared Key
    • Display Shared Key:
    • Diffie-Hellman Group: Must match with peer
    • Extension:

IPSec VPN

  • Click Keep
  • In the IPSec VPN Configuration page, select the Activation Status tab, and enable IPsec VPN Service Status

IPSec VPN

  • Configure the Peer/Remote Site.