A route-based VPN creates an IPsec tunnel interface and routes traffic through it as dictated by the SDDC routing table. A route-based VPN provides resilient, secure access to multiple subnets. When you use a route-based VPN, new routes are added automatically when new networks are created.
If you use the native VPN services of the hyperscale cloud provider, see the hyperscale cloud provider documentation for more information on creating VPNs and configuring a VPN connection between your SDDC and on-premises data center.
This topic explains how to create a route-based VPN that connects to the SDDC's default public or private IP. If you have an SDDC with additional Tier-1 gateways (see Add a Tier-1 Gateway), you can add VPN services that terminate on those gateways. See Adding VPN Services in the NSX Data Center Administration Guide.
In VMware Cloud on Public Cloud, VPN services to a Tier-1 gateway do not support BGP or Certificate-based authentication.
If the option to create and configure additional Tier-1 gateways is not active in your SDDC, and you want to activate it, contact your account team.
Route based VPNs in your VMware Cloud on Public Cloud SDDC use an IPsec protocol to secure traffic and the Border Gateway Protocol (BGP) to discover and propagate routes as networks are added and removed. To create a route-based VPN, you configure BGP information for the local (SDDC) and remote (on-premises) endpoints, then specify tunnel security parameters for the SDDC end of the tunnel.
Procedure
Results
- Click DOWNLOAD CONFIG to download a file that contains VPN configuration details. You can use these details to configure the on-premises end of this VPN.
- Click VIEW STATISTICS to view packet traffic statistics for this VPN. See View VPN Tunnel Status and Statistics.
- Click VIEW ROUTES to open a display of routes advertised and learned by this VPN.
- Click DOWNLOAD ROUTES to download a list of Advertised Routes or Learned Routes in CSV format.
What to do next
Create or update firewall rules as needed. To allow traffic through the route-based VPN, specify VPN Tunnel Interface in the Applied to field. The All Uplinks option does not include the routed VPN tunnel.