How to configure IPSec VPN connections to endpoints outside mCloud

This article provides a general guide for establishing functional IPSec VPN connections to endpoints outside of mCloud. Please note that specific endpoints, such as routers or other cloud providers, may have additional requirements or unique configurations not covered in this guide.

Prerequisites:

This article assumes the following is already configured and functional within your mCloud Dashboard:

  • mCloud project

  • mCloud internal subnet

  • mCloud router

  • Remote endpoint capable of IPSec tunnels

Method:

  1. Log into mCloud at https://mcloud.micron21.com/

  2. Go to Project > Network > VPN

    1. ips1.png

  3. Click on "+Add IKE Policy"

    1. ips2.png

  4. Fill out the desired settings and click Add

    1. This policy can roughly be described as "Phase 1" on other network devices. Keep this in mind when setting up IPSec connections, any mismatch in these settings between endpoints will cause errors.

    2. ips3.png

  5. Click on the "IPsec Policies" tab and click "+Add IPsec Policy".

    1. ips4.png

  6. Fill out the desired settings and click Add

    1. This policy is roughly equivalent to "Phase 2" on other network devices.

    2. ips5.png

  7. Click on the "VPN Services" tab

  8. Click on "+Add VPN Service"

    1. ips6.png

  9. Enter a name, and select a router. Don't select a subnet at this time, then Click Add

    1. ips7.png

  10. Click on the "Endpoint Groups" Tab. We’ll need to add two endpoint groups here, for internal and remote.

    1. Click "+Add Endpoint Group" and add a local subnet for our internal network

      1. ips8.png

    2. Click "+Add Endpoint Group" and add an external subnet for our remote network

      1. ips9.png

  11. Click on the "IPsec Site Connections" tab and click "+Add IPsec Site Connection".

  12. Enter the required details for the configuration we have done to this point, the remote peer details, and a pre-shared key.

    1. ips10.png

  13. Configure the remote site VPN, matching the settings added above, and confirm both sides are connected. From here you can test traversing the firewall between sites.



Can't find what you're looking for?

Create or manage support tickets directly with Micron21

You will need to register a new account if this is the first time lodging a ticket.

If you have previous lodged a ticket either online, email or over the phone you will already have an account. Please reset your password, if you have not logged into the support portal before.

Lodge a ticket Manage existing tickets

Need to send us information securely? Use our Escrow service here

Need more advanced support?

Micron21 provides a comprehensive approach to customer care that starts with a base 24/7 support that is included free with every service we offer - there are no charges to enjoy a basic level of support with Micron21 and you are not restricted in how you contact us to receive assistance any time of day or night.

For those who require more advanced support though, our Customer Care plans and Ad-Hoc support are designed to completely remove the complexity of IT management - from taking full responsibility for your entire infrastructure or tailoring a custom approach, we have the capability and know-how.

 

If you've organised remote assistance from Micron21, click here to connect

Sign up for the Micron21 Newsletter