Configure an IPsec Connector
Set up an IPsec Network Connector in CloudConnexa — covers selecting your platform in the portal and links to setup guides for AWS, Azure, GCP, Cisco, and generic IPsec devices.
Overview
An IPsec Connector creates an IPsec tunnel between a private network and a CloudConnexa region. Use it to establish site-to-site VPN connectivity with public cloud networks, routers, gateways, and other IPsec-compatible devices.
After you configure the Connector in CloudConnexa, configure the corresponding IPsec tunnel on your remote device or cloud platform.
IPsec Connector options
Depending on your platform and configuration, CloudConnexa supports:
IKE: IKEv1 or IKEv2.
Authentication: Pre-shared key (PSK) or certificate-based authentication, when supported.
Platforms: AWS, Azure, Google Cloud (GCP), routers, VPN gateways, and generic IPsec devices.
Redundancy: Dual IPsec tunnels with control over the CloudConnexa data center used by each tunnel.
For more information about Network Connectors, refer to About Network Connectors. If you're choosing between an IPsec and OpenVPN Connector for a public cloud environment, refer to IaaS Connectors.
Choose how to configure your IPsec Connector
You can configure an IPsec Connector when you:
Create a Network: Select IPsec as the tunneling protocol during Network configuration, then select your device or cloud provider and proceed with configuration.
Add a Connector to an existing Network: Navigate to Networks → Connectors, add a new Connector, and configure it for IPsec.
Configure an existing Connector: Navigate to Networks → Connectors and select Configure for the Connector.
The available configuration values and instructions depend on the platform you select.
Configure the IPsec Connector
You can configure an IPsec Connector from the Connectors page:
Navigate to Networks → Connectors.
Select Configure for the Connector.
From Platform to Connect, select your device or platform.
Under Set Up CloudConnexa Tunnel, configure the tunnel settings displayed for your selected platform.
For CloudConnexa Public IP Address, select an available data center IP address in the Connector's CloudConnexa Region.
Configure the corresponding IPsec tunnel on your remote device or cloud platform. Refer to Choose the tutorial for your platform.
Enter the remote tunnel information requested by CloudConnexa, such as the remote public IP address and PSK.
Select Test Connection to verify connectivity.
Complete the configuration.
Tip
For a dual-tunnel configuration, you can select different CloudConnexa Public IP Address values for Tunnel 1 and Tunnel 2 to control which CloudConnexa data centers the tunnels connect to.
Advanced configuration
Expand Advanced Configuration when your remote VPN device requires IPsec settings other than the defaults.
Settings | What you can configure |
|---|---|
IKE Version | IKEv1 or IKEv2 |
Phases 1 and 2 | Encryption, integrity, and Diffie-Hellman group |
IKE Rekey | Margin time, fuzz, and packets |
Connection Initiation & Restoration | Startup and restoration actions TipStartup action determines which side initiates the IPsec tunnel. Start makes CloudConnexa initiate the connection; Attach waits for the remote peer to connect. |
Choose the tutorial for your platform
The remote side of an IPsec tunnel must also be configured with the corresponding CloudConnexa settings. Follow the tutorial for your environment:
I want to connect… | Tutorial |
|---|---|
A generic IPsec device or private network | Configure a Generic IPsec Tunnel from Your Private Network to CloudConnexa |
A Cisco router | |
One AWS VPC using a Virtual Private Gateway (VPG) | |
Multiple AWS VPCs using Transit Gateway | Connect AWS VPC to CloudConnexa with IPsec using Transit Gateway |
An Azure VNet | |
A Google Cloud VPC |
Tip
Can't find your platform? If it supports compatible IPsec settings, start with Configure a Generic IPsec Tunnel from Your Private Network to CloudConnexa.