When you add a policy-based IPSec VPN, IPSec tunnels are used to connect multiple local subnets that are behind the NSX Edge node with peer subnets on the remote VPN site.
The following steps use the IPSec Sessions tab on the NSX Manager UI to create a policy-based IPSec session. You also add information for the tunnel, IKE, and DPD profiles, and select an existing local endpoint to use with the policy-based IPSec VPN.
You can also add the IPSec VPN sessions immediately after you have successfully configured the IPSec VPN service. You click Yes when prompted to continue with the IPSec VPN service configuration and select on the Add IPsec Service panel. The first few steps in the following procedure assume you selected No to the prompt to continue with the IPSec VPN service configuration. If you selected Yes, proceed to step 3 in the following steps to guide you with the rest of the policy-based IPSec VPN session configuration.
Prerequisites
- You must have configured an IPSec VPN service before proceeding. See Add an IPSec VPN Service.
- Obtain the information for the local endpoint, IP address for the peer site, local network subnet, and remote network subnet to use with the policy-based IPSec VPN session you are adding. To create a local endpoint, see Add Local Endpoints.
- If you are using a Pre-Shared Key (PSK) for authentication, obtain the PSK value.
- If you are using a certificate for authentication, ensure that the necessary server certificates and corresponding CA-signed certificates are already imported. See Certificates.
- If you do not want to use the defaults for the IPSec tunnel, IKE, or dead peer detection (DPD) profiles provided by NSX, configure the profiles you want to use instead. See Adding Profiles for information.
Procedure
Results
What to do next
- Verify that the IPSec VPN tunnel status is Up. See Monitor and Troubleshoot VPN Sessions for information.
- If necessary, manage the IPSec VPN session information by clicking the three-dot menu (
) on the left-side of the session's row. Select one of the actions you are allowed to perform.