When you add a route-based IPSec VPN, tunneling is provided on traffic that is based on routes that were learned dynamically over a virtual tunnel interface (VTI) using a preferred protocol, such as BGP. IPSec secures all the traffic flowing through the VTI.
The steps described in this topic use the IPSec Sessions tab to create a route-based IPSec session. You also add information for the tunnel, IKE, and DPD profiles, and select an existing local endpoint to use with the route-based IPSec VPN.
You can also add the IPSec VPN sessions immediately after the IPSec VPN service is successfully configured. Click Yes when prompted to continue with the IPSec VPN service configuration and select on the Add IPSec Service panel. The first few steps in the following procedure assume you selected No to the prompt to continue with the IPSec VPN service configuration. If you selected Yes, proceed to step 3 to guide you with the rest of the route-based IPSec VPN session configuration.
Prerequisites
- You must have configured an IPSec VPN service before proceeding. See Add an IPSec VPN Service.
- Obtain the information for the local endpoint, IP address for the peer site, and tunnel service IP subnet address to use with the route-based IPSec session you are adding. To create a local endpoint, see Add Local Endpoints.
- If you are using a Pre-Shared Key (PSK) for authentication, obtain the PSK value.
- If you are using a certificate for authentication, ensure that the necessary server certificates and corresponding CA-signed certificates are already imported. See Certificates.
- If you do not want to use the default values for the IPSec tunnel, IKE, or dead peer detection (DPD) profiles provided by NSX, configure the profiles you want to use instead. See Adding Profiles for information.
Procedure
Results
What to do next
- Verify that the IPSec VPN tunnel status is Up. See Monitor and Troubleshoot VPN Sessions for information.
- Configure routing using either a static route or BGP. See Configure a Static Route or Configure BGP.
- If necessary, manage the IPSec VPN session information by clicking the three-dot menu (
) on the left-side of the session's row. Select one of the actions you can perform.