A policy-based VPN creates an IPsec tunnel and a policy that specifies how traffic uses it. When you use a policy-based VPN, you must update the routing tables on both ends of the network when new routes are added.
If you use the native VPN services of the hyperscale cloud provider, see the hyperscale cloud provider documentation for more information on creating VPNs and configuring a VPN connection between your SDDC and on-premises data center.
This topic explains how to create a policy-based VPN that connects to the SDDC's default public or private IP. If you have an SDDC with additional Tier-1 gateways (see Add a Tier-1 Gateway), you can add VPN services that terminate on those gateways. See Adding VPN Services in the NSX Data Center Administration Guide.
In VMware Cloud on Public Cloud, VPN services to a Tier-1 gateway do not support BGP or Certificate-based authentication.
If the option to create and configure additional Tier-1 gateways is not active in your SDDC, and you want to activate it, contact your account team.
Policy-based VPNs in your VMware Cloud on Public Cloud SDDC use an IPsec protocol to secure traffic. To create a policy-based VPN, you configure the local (SDDC) endpoint, then configure a matching remote (on-premises) endpoint. Because each policy-based VPN must create a new IPsec security association for each network, an administrator must update routing information on premises and in the SDDC whenever a new policy-based VPN is created. A policy-based VPN can be an appropriate choice when you have only a few networks on either end of the VPN, or if your on-premises network hardware does not support BGP (which is required for route-based VPNs).
If your SDDC includes both a policy-based VPN or a dedicated high bandwidth, low latency connection, and another connection such as a route-based VPN, connectivity over the policy-based VPN fails if any of those other connections advertises the default route (0.0.0.0/0) to the SDDC.
Procedure
Results
- Click DOWNLOAD CONFIG to download a file that contains VPN configuration details. You can use these details to configure the on-premises end of this VPN.
- Click VIEW STATISTICS to view packet traffic statistics for this VPN. See View VPN Tunnel Status and Statistics.
What to do next
Create or update firewall rules as needed. To allow traffic through the policy-based VPN, specify Internet Interface in the Applied to field.