5.1

Table Of Contents
Configuring IPSec VPN Service
You can set up a vShield Edge tunnel between a local subnet and a peer subnet.
1 Configure IPSec VPN Parameters on page 81
You must configure at least one external IP address on the vShield Edge to provide IPSec VPN service.
2 Enable IPSec VPN Service on page 82
You must enable the IPSec VPN service for traffic to flow from the local subnet to the peer subnet.
Configure IPSec VPN Parameters
You must configure at least one external IP address on the vShield Edge to provide IPSec VPN service.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Double-click a vShield Edge instance.
5 Click the VPN tab.
6 Ensure that you are in the IPSec VPN tab.
7
Click the Add ( ) icon.
The Add IPSec VPN dialog box opens.
8 Type a name for the IPSec VPN.
9 Type the IP address of the vShield Edge instance in Local Id. This will be the peer Id on the remote site.
10 Type the IP address of the local endpoint.
If you are adding an IP to IP tunnel using a pre-shared key, the local Id and local endpoint IP can be the
same.
11 Type the subnets to share between the sites in CIDR format. Use a comma separator to type multiple
subnets.
12 Type the Peer Id to uniquely identify the peer site. For peers using certificate authentication, this ID must
be the common name in the peer's certificate. For PSK peers, this ID can be any string. VMware
recommends that you use the public IP address of the VPN or a FQDN for the VPN service as the peer ID
13 Type the IP address of the peer site in Peer Endpoint. If you leave this blank, vShield Edge waits for the
peer device to request a connection.
14 Type the internal IP address of the peer subnet in CIDR format. Use a comma separator to type multiple
subnets.
15 Select the Encryption Algorithm.
16 In Authentication Method, select one of the following:
Option Description
PSK (Pre Shared Key)
Indicates that the secret key shared between vShield Edge and the peer site
is to be used for authentication. The secret key can be a string with a
maximum length of 128 bytes.
Certificate
Indicates that the certificate defined at the global level is to be used for
authentication.
Chapter 9 vShield Edge Management
VMware, Inc. 81