5.1

Table Of Contents
2 Select a datacenter resource from the inventory panel.
3 Click the Network Virtualization tab.
4 Click the Edges link.
5 Double-click a vShield Edge instance.
6 Click the VPN tab.
7 Ensure that you are in the IPSec VPN tab.
8 Select the IPSec service that you want to disable.
9
Click the Disable (
) icon.
The selected service is disabled.
vShield Edge VPN Configuration Examples
This scenario contains configuration examples for a basic point-to-point IPSEC VPN connection between a
vShield Edge and a Cisco or WatchGuard VPN on the other end.
For this scenario, vShield Edge connects the internal network 192.168.5.0/24 to the internet. The vShield Edge
interfaces are configured as follows:
n
Uplink interface: 10.115.199.103
n
Internal interface: 192.168.5.1
The remote gateway connects the 172.16.0.0/16 internal network to the internet. The remote gateway interfaces
are configured as follows:
n
Uplink interface: 10.24.120.90/24
n
Internal interface: 172.16.0.1/16
Figure 9-4. vShield Edge connecting to a remote VPN gateway
Internet
192.168.5.1
192.168.5.0/24
10.115.199.103 10.24.120.90 172.16.0.1
172.15.0.0/16
vShield Edge
NOTE For vShield Edge to vShield Edge IPSEC tunnels, you can use the same scenario by setting up the second
vShield Edge as the remote gateway.
Terminology
IPSec is a framework of open standards. There are many technical terms in the logs of the vShield Edge and
other VPN appliances that you can use to troubleshoot the IPSEC VPN.
These are some of the standards you may encounter:
n
ISAKMP (Internet Security Association and Key Management Protocol) is a protocol defined by RFC 2408
for establishing Security Associations (SA) and cryptographic keys in an Internet environment. ISAKMP
only provides a framework for authentication and key exchange and is designed to be key exchange
independent.
n
Oakley is a key-agreement protocol that allows authenticated parties to exchange keying material across
an insecure connection using the Diffie-Hellman key exchange algorithm.
n
IKE (Internet Key Exchange) is a combination of ISAKMP framework and Oakley. vShield Edge provides
IKEv2.
vShield Administration Guide
84 VMware, Inc.