Knowledge Base  /  Lumen Edge Private Cloud  /  Security
Knowledge Base  /  Lumen Edge Private Cloud  /  Security

Enable IPSec VPN on Edge Gateway Services

Updated by Anthony Hakim on Aug 03, 2021
Article Code: kb/1158

Description

In this KB article, we walk through how to enable an IPSec VPN on Edge Gateway Services within the VMware Cloud Director (VCD) Web Console environment for Lumen Private Cloud on VMware Cloud Foundation™.

Prerequisites

You must configure at least one IPSec VPN site on the NSX Edge before enabling the IPSec VPN service.

  • Log in to your Lumen Private Cloud on VMware Cloud Foundation environment with an Org Admin Account.

    Login to Lumen Private Cloud on VMware Cloud Foundation

  • Once logged in, click Data Centers in the top menu, and then click the Virtual Data Center summary box.

Login to Lumen Private Cloud on VMware Cloud Foundation

  • Click on Edges in the panel on the left side.

  • Click your Edge Gateway. Take note of the (Public) IP Address for the Edge Gateway.

    IPSec VPN

  • Under Services, click IPSec VPN.

  • Click NEW.

    IPSec VPN

  • A new window will pop up. Follow the steps below:

  • Add IPsec VPN:

    • Enabled: Click slider to enable
    • Enable perfect forward secrecy (PFS): default
    • Name: Name your IPSec VPN
    • Local Id: Your Local Id
    • Local Endpoint: IP address of Edge Gateway
    • Local Subnets: Your Local Subnets
    • Peer Id: Your Peer Id
    • Peer Endpoint: IP address of Peer
    • Peer Subnets: Your Peer Subnets
    • Encryption Algorithm: Must match with peer
    • Authentication: Must match with peer
    • Change Shared Key:
    • Pre-Shared Key: Shared Key
    • Display Shared Key:
    • Diffie-Hellman Group: Must match with peer
    • Extension:

IPSec VPN

  • Click KEEP.
  • In the IPSec VPN Configuration page, select the Activation Status tab, and enable IPsec VPN Service Status.

IPSec VPN

  • Next, configure the Peer/Remote Site.