Description: This guide explains how to add another IPsec tunnel using another Region or Gateway IP for an existing GCP IPsec tunnel.
Sign in to the CloudConnexa Administration Portal and go to Networks.
Select your network, navigate to Connectors tab, and select Add Connector.
Select the target CloudConnexa region. Below example uses Tokyo.
After you create the connector, select Configure to open the Configure Connector page
Select GCP as the platform and copy the CloudConnexa public IP address. You’ll use this IP address to create a new IPsec tunnel in GCP.
Note: Click the down arrow to view the list of CloudConnexa IP addresses for this region that you can use to establish an IPsec session.Sign in to the GCP portal and go to Networking > Network Connectivity > VPN. Select Cloud VPN Gateway.
Select Create VPN Gateway and choose “Classic” Setup.
Google Computer Engine VPN Gateway
Name: Enter a name for the GCP VPN gateway.
Description (optional): Enter a short description of the VPN gateway.
Network: Select the network that the VPN gateway connects to.
Region: Select the region where the gateway for your resource network is located.
IP address: Create a public IP address to use as the peer IP address for CloudConnexa.
Tunnels
Name: Enter a name for the tunnel.
Description (optional): Enter a short description of the tunnel.
Remote peer IP address: Enter the CloudConnexa public IP address copied in Step 5.
IKE version: Select IKEv1 or IKEv2. Use the same IKE version configured in CloudConnexa.
IKE pre-shared key: Enter the pre-shared key for the tunnel. Use the same pre-shared key configured in CloudConnexa.
Routing option: Select Policy-Based.
Remote network IP ranges: Enter the CloudConnexa WPC and domain routing subnets, including any other CloudConnexa networks that need access to the GCP network. You can also find this network and subnet information under “Remote Network IP Ranges" on the CloudConnexa Connector IPsec setup page.
Local subnetworks: Select the networks or subnets that remote resources can access.
Select Create.
Note: Ensure that the new VPN Gateway and Tunnel replicates the same configuration and settings as the current active IPsec tunnel.
Return to the CloudConnexa setup process and continue with Step 2, entering the required details from the new GCP tunnel.
Google Compute Engine VPN Gateway IP: Enter the GCP public IP address created in Step 7 under Google Compute Engine VPN Gateway.
Pre-Shared Key: Enter the pre-shared key created in Step 7 under Tunnels.
Select Finish.
Verify that the tunnel status is Online in both the CloudConnexa Administration Portal and GCP Portal.
Comments
0 comments
Article is closed for comments.