In this KB article, we walk through how to enable an IPSec VPN on Edge Gateway Services within the vCloud Director (vCD) Web Console environment for CenturyLink Private Cloud on VMware Cloud Foundation™.
You must configure at least one IPSec VPN site on the NSX Edge before enabling the IPSec VPN service.
Login to your CenturyLink Private Cloud on VMware Cloud Foundation environment with an Org Admin Account
Once logged in, click Datacenters in the ,menu at the top and then select your Datacenter.
Click on Edges in the panel on the left side.
Select your Edge Gateway, and take note of the (Public) IP Address for the Edge Gateway. Click Configure Services at the top of the screen.
Select the VPN tab, then IPsecVPN Sites. Click the + icon to add IPsec VPN Sites (this is a prerequisite to enable IPsec VPN Services).
A new window will pop up. Follow the steps below:
Add IPsec VPN:
- Enabled: Click slider to enable
- Enable perfect forward secrecy (PFS): default
- Name: Name your IPSec VPN
- Local Id: Your Local Id
- Local Endpoint: IP address of Edge Gateway
- Local Subnets: Your Local Subnets
- Peer Id: Your Peer Id
- Peer Endpoint: IP address of Peer
- Peer Subnets: Your Peer Subnets
- Encryption Algorithm: Must match with peer
- Authentication: Must match with peer
- Change Shared Key:
- Pre-Shared Key: Shared Key
- Display Shared Key:
- Diffie-Hellman Group: Must match with peer
- Click Keep
- In the IPSec VPN Configuration page, select the Activation Status tab, and enable IPsec VPN Service Status
- Configure the Peer/Remote Site.