You can use the VMware Cloud Director Tenant Portal to autoconfigure a route-based IPSec VPN tunnel on a dedicated provider gateway, which automatically creates an IPSec VPN tunnel, IP space uplink, and the associated BGP prefixes, maps, and neighbor in VMware Cloud Director.

Prerequisites

Procedure

  1. From the primary left navigation panel, select Networking, and from the page top navigation bar, select Provider Gateways.
  2. Click the name of the target dedicated provider gateway.
  3. On the right of the provider gateway name, click Autoconfigure > IPSec VPN.
  4. Enter a name for the IPSec VPN tunnel.
  5. From the drop-down menu, select an IP space.
  6. Enter the IP address for the remote endpoint.
  7. From the drop-down menu, select one of the IP addresses that are available to the edge gateway for the local endpoint.
    The IP address must be either the primary IP of the edge gateway, or an IP address that is separately allocated to the edge gateway.
  8. For Local Tunnel Interface, enter a valid IPv4 CIDR, IPv6 CIDR, or one of each by separating them with a comma.
  9. For the Virtual Tunnel Interface (VTI), enter the IP address specified on the remote side.
    The IP address must be part of the locally defined VTI CIDR. Enter a valid IPv4 CIDR, IPv6 CIDR, or one of each by separating them with a comma.
  10. Enter the autonomous system (AS) number of the remote BGP neighbor with which you want to establish the connection.
  11. Enter an autonomous system (AS) ID number to use for the local AS feature of the BGP.
  12. Click Autoconfigure.