5.1

Table Of Contents
17 Type the shared key in if anonymous sites are to connect to the VPN service.
18 Click Display Shared Key to display the key on the peer site.
19 In Diffie-Hellman (DH) Group, select the cryptography scheme that will allow the peer site and the vShield
Edge to establish a shared secret over an insecure communications channel.
20 Edit the default MTU if required.
21 Select whether to enable or disable the Perfect Forward Secrecy (PFS) threshold. In IPsec negotiations,
Perfect Forward Secrecy (PFS) ensures that each new cryptographic key is unrelated to any previous key.
22 Click OK.
vShield Edge creates a tunnel from the local subnet to the peer subnet.
What to do next
Enable the IPSec VPN service.
Enable IPSec VPN Service
You must enable the IPSec VPN service for traffic to flow from the local subnet to the peer subnet.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge instance.
6 Click the VPN tab.
7 Ensure that you are in the IPSec VPN tab.
8 In IPSec VPN Service Status, click Enable.
What to do next
Click Enable Logging to log the traffic flow between the local subnet and peer subnet.
Edit IPSec VPN Service
You can edit an IPSec VPN service.
Procedure
1 In the vSphere Client, select Inventory > Hosts & Clusters.
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge instance.
6 Click the VPN tab.
7 Ensure that you are in the IPSec VPN tab.
8 Select the IPSec service that you want to edit.
vShield Administration Guide
82 VMware, Inc.