Use the Global Configuration screen in the vCloud Director tenant portal to configure IPsec VPN authentication settings at an edge gateway level. On this screen, you can set a global pre-shared key and enable certification authentication.

About this task

A global pre-shared key is used for those sites whose peer endpoint is set to any.


If you intend to enable certificate authentication, verify you have at least one service certificate and corresponding CA-signed certificates in the tenant portal's Certificates screen. Self-signed certificates cannot be used for IPsec VPNs. See Add a Service Certificate to the Edge Gateway.

For the ability to use the vCloud Director tenant portal to work with an edge gateway's settings, the edge gateway must have already been converted to an advanced edge gateway using the Convert to Advanced Gateway action on the edge gateway in the vCloud Director Web console. See the vCloud Director Administrator's Guide for details.


  1. Launch the tenant portal using the following steps.
    1. Log in to the vCloud Director Web console and navigate to the edge gateway.
    2. Right-click the name of the edge gateway and click Edge Gateway Services in the context menu.

      The tenant portal opens in a new browser tab and displays the Edge Gateway screen for that edge gateway.

  2. Navigate to VPN > IPsec VPN > Global Configuration
  3. (Optional) Set a global pre-shared key:
    1. Turn on the Change Shared Key toggle.
    2. Type a pre-shared key.
    3. (Optional) Optionally turn on the Display Shared Key toggle to make the pre-shared key visible.
    4. Click Save changes.
  4. Configure certification authentication:
    1. Turn on the Enable Certification Authentication toggle.
    2. Select the appropriate service certificate, CA certificates, and CRLs.
    3. Click Save changes.

What to do next

You can optionally enable logging for the edge gateway's IPsec VPN service. See Statistics and Logs in the vCloud Director Tenant Portal.