Cloud Edge Secure Access Getting Started Guide

IBM Cloud

This article describes how to establish a Site-To-Site IPSec VPN connection between your IBM server and the SonicWall Cloud Edge network.

  • Configuring a VPN gateway at the IBM Cloud Console
  • Making sure the tunnel is up

Please follow the steps below:

Configuring a VPN gateway at the IBM Cloud Console

  1. Open to the VPC section in the IBM Cloud Console. Go to VPNs (under the Network tab).

    360006279459ScreenShot2019-11-10at130022.png

  2. Open the IKE Policies tab, then select New IKE Policy.

    360006984460ScreenShot2019-12-05at163619.png

  3. Choose a Name, the Region in which the appropriate VPC lies, define the Resource group, then select Create IKE policy.

    360006997959ScreenShot2019-12-05at164339.png

  4. Once the policy has been created, select the three-dotted menu (...) and select Edit.
  5. Fill in the following information:

    • IKE Version: 1
    • DH Group: 2
    • Authentication: sha256
    • Key Lifetime: 28800
    • Encryption: aes256
  1. Select Save IKE policy.
  2. Open the IPSecPolicies tab, then select New IPSec Policy.
  3. Choose an indicative Name, the Region in which the appropriate VPC lies and define the Resource group, then select Create IPSec policy.

    360006997959ScreenShot2019-12-05at164339.png

  4. Once the policy has been created, select the three-dotted menu (...) and select Edit.
  5. Fill in the following information:

    • Check: PFS
    • DH Group: 2
    • Authentication: sha256
    • Key Lifetime: 3600
    • Encryption: aes256
  6. Select Save IPSec policy.

    360006989860ScreenShot2019-12-05at180156.png

  7. Open the VPN gateways tab, then select New VPN gateway.
  8. Fill in the following information:

    • Name: Enter a name of your choice
    • Virtual private cloud: Choose the desired cloud
    • Resource group: Choose the resource group
    • Subnet: Choose the appropriate subnet

      360007200619ScreenShot2019-12-12at170828.png

  9. Check New VPN Connection for VPC.
  10. Fill in the following information:

    • Connection name: Set a name
    • Peer gateway address: Insert your SonicWall Cloud Edge gateway IP
    • Preshared key: Insert an 8 character (at least) string containing upper-case letters, upper-case letters, and numbers
    • Local subnet: Specify one or more subnets in the VPC you want to connect
    • Peer subnet: Unless you have custom configurations or multiple tunnels to the same gateway insert 10.255.0.0/16

      360007201379ScreenShot2019-12-12at173114.jpg

    • Dead peer detection action: Restart
    • Interval: 10 seconds
    • Timeout: 30 seconds
    • IKE policy: Choose the policy that was earlier
    • IPSec policy: Choose the policy that was earlier

Configuring the tunnel in the Management Platform

  1. Enter the SonicWall Cloud Edge Management Platform. Under the Networks tab in the left menu, select the name of the network in which you'd like to set the tunnel.
  2. Locate the desired gateway, select the three-dotted menu (...), select Add Tunnel, and then IPSec Site-2-Site Tunnel.

  3. Fill in the General Settings:

    • Name: Specify a name
    • Public IP: Insert the IP of the VPN Gateway you have just defined
    • Remote ID: Identical to Remote IP
    • Shared Secret: Insert the same preshared key you chose before
    • SonicWall Cloud Edge Gateway Proposal Subnets: 10.255.0.0/16 or according to what you defined in the IBM Cloud portal
    • Remote Gateway Proposal Subnets: Specify one or more subnets in the VPC you want to connect
  4. Fill in the Advanced Settings:

    • IKE Version: 1
    • IKE Lifetime: 8h
    • Tunnel Lifetime: 1h
    • Dead Peer Detection Delay: 10s
    • Dead Peer Detection Timeout: 30s
    • Encryption (Phase 1): aes256
    • Encryption (Phase 2): aes256
    • Integrity (Phase 1): sha256
    • Integrity (Phase 2): sha256
    • Diffie-Hellman Groups (Phase 1): 2
    • Diffie-Hellman Groups (Phase 2): 2

Making sure the tunnel is up

  1. Under the VPN gateways tab select the name of the VPN Gateway that is associated with the tunnel.

    3600071855001.jpg

  2. Scroll down and select View all connections.
  3. You'll be able to see the status of the tunnel. If for some reason the tunnel is down please make sure you configured all the fields according to this article. At any point, our support team will be happy to assist or troubleshoot.

    360007185620ScreenShot2019-12-12at181101.jpg

Was This Article Helpful?

Help us to improve our support portal

Techdocs Article Helpful form

  • Hidden
  • Hidden

Techdocs Article NOT Helpful form

  • Still can't find what you're looking for? Try our knowledge base or ask our community for more help.
  • Hidden
  • Hidden