Creating IPSec Site-to-Site VPN Tunnel between a Organization vdc vshield Edge and Remote Network In this document you will find the manual for configuring the Network, creating firewall rules and test the connection. Version 1.0 1. Create a VPN Tunnel from an Organization vdc Network Backed by an Edge Gateway to a Remote Network... 2 Procedure: Create a VPN Rule from the vcloud Network&Security Edge 3 Procedure: Create a VPN Rule from the Microsoft ISA Server 5 2. Create Firewall Rules for the IPSec VPN Tunnel communication between an Organization vdc Network Backed by an Edge Gateway to a Remote Network... 12 Procedure: vcloud Networking&Security Edge Firewall Rules 12
1. Create a VPN Tunnel from an Organization vdc Network Backed by an Edge Gateway to a Remote Network You can create VPN tunnels between an organization vdc network and your internal Enterprise Network (Remote Network). Organization administrators can create VPN tunnels. If a firewall is between the tunnel endpoints, you must configure it to allow the following IP protocols and UDP ports: IP Protocol ID 50 (ESP) IP Protocol ID 51 (AH) UDP Port 500 (IKE) UDP Port 4500 Prerequisites Verify that you have a routed remote network that uses IPSec and an organization vdc network backed by an edge gateway. Example: VPN Tunnel Example Internet vcloud Network & Security Edge Device: BetaEdge_Internet Sub-Allocate IP Pools: 62.148.163.31-62.148.163.38 vcloud External Network Ext-Network-Vlan210 62.148.163.0/24 Ext:62.148.163.30 Int:192.168.11.1 Ipsec VPN Tunnel Microsoft ISA Server Device Remote Network 213.208.238.184/29 Ext:213.208.238.186 Int:10.208.238.10 Beta_OrgvDC_Internet Enterprise Internal Network 192.168.11.0/24 10.208.238.0/24 BetaSrv01 BetaSrv02
Procedure: Create a VPN Rule from the vcloud Network&Security Edge A. Click the Administration tab and click the vdc BetaOrgvDC in the left pane. B. Double-click the organization vdc name to open the organization vdc. C. Click the Edge Gateways tab, right-click the edge gateway name and select Edge Gateway Services. D. Click the VPN tab, Select the option Enable VPN and click Add. E. Type a name and optional description. (See screenshot on the next page) F. Select a remote network from the drop-down menu. (See screenshot on the next page) G. Select the local organization vdc network. (See screenshot on the next page) H. Type the peer settings. (See screenshot on the next page) I. Review the tunnel settings and click OK. (See screenshot on the next page)
Procedure: Create a VPN Rule from the Microsoft ISA Server A. From the Forefront TMG click the Remote Access Policy (VPN) tab and click the vdc BetaOrgvDC in the right pane Create VPN Site-to-Site Connection. B. Give a Site-to-Site network name and Click Next
C. Select the option IP Security Protocol (IPSec) tunnel mode and Click Next D. Specify the tunnel endpoints on the remote and local VPN Servers and Click Next
E. Enter a pre-shared key for IPsec Authentication
F. Specify the IP address ranges of the vcloud remote site internal network
G. Create a Site-to-Site Network rule between the internal Network 10.208.238.0/24 and the vcloud Organization Network 192.168.11.0/24
H. Create a Site-to-Site Network Access rule between the internal Network 10.208.238.0/24 and the vcloud Organization Network 192.168.11.0/24
I. Click Finish to complete the Site-to-Site Network configuration
2. Create Firewall Rules for the IPSec VPN Tunnel communication between an Organization vdc Network Backed by an Edge Gateway to a Remote Network Procedure: vcloud Networking&Security Edge Firewall Rules A. Click the Administration tab and click the vdc BetaOrgvDC in the left pane. B. Double-click the organization vdc name to open the organization vdc. C. Click the Edge Gateways tab, right-click the edge gateway name and select Edge Gateway Services. D. Click the Firewall tab, Select the option Enable Firewall and click Add.
E. Select the Enabled option F. Type a name for the rule. G. Type the traffic Source from the Remote Network H. Select the Source port ANY to apply this rule on from the drop-down menu. I. Type the traffic Destination to the Beta_OrgvDC_Internet vcloud Organization Network J. Select the Destination port ANYto apply this rule on from the drop-down menu. K. Select the Protocol ANY to apply this rule on from the drop-down menu. L. Select the action Allow. M. Click OK and click OK again.
Repeat steps Step D through Step M to add a Firewall Rul2 from the Beta_OrgvDC_Internet vcloud Organization Network to the Remote Network