...
Anchor | ||||
---|---|---|---|---|
|
Note |
---|
You must first create a workload before you can create an L2L VPN tunnel. |
- In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click L2L VPN.
- If you have virtual machines in various data centers, then click the corresponding data center.
- Click New L2L.
- In Tunnel Name, enter a descriptive name.
- In Encryption Mode, select an encryption mode. You can select between Advanced Encryption Standard or Data Encryption Standard.
- In Pre-Shared Key, click Generate or create your own key. You will use this key to securely connect to your local endpoint.
- If you create your own key, this key must contain the following requirements:
- 16 to 96 characters
- One lower-case letter
- One upper-case letter
- One number
- If you create your own key, this key must contain the following requirements:
- In Remote Peer IP Address, enter your VPN peer IP address.
- In Remote Host/Networks (CIDR), enter your LAN encryption domain, and then click the plus ( + ) sign.
- In Local Host/Networks (CIDR), enter the Armor LAN encryption domain, and then click the plus ( + ) sign.
- This information is the same as your secure cloud server IP address at Armor.
- Click Save L2L.
Excerpt | ||
---|---|---|
| ||
This has been updated; however, I am waiting for more information regarding perfect forward secrecy. Note | To create an L2L VPN tunnel, you must have an existing workload with an existing virtual machine. To learn how to create a virtual machine, see Create a virtual machine with a new workload. |
- In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click L2L VPN.
- In the top menu, in the drop-down menu, select the data center where the virtual machine lives.
- Click the plus ( + ) icon.
- If you do not have any tunnels in that data center, then click Create an L2L tunnel.
- In Tunnel Name, enter a descriptive name.
- Use the slider to enable or disable the tunnel.
- In Pre-Shared Key, enter a secure password.
- You will use this key to securely connect to your local endpoint.
- You can click Generate New Key to generate a password.
- You can also create own key. If you create your own key, the key must contain the following requirements:
- 16 to 96 characters
- One lower-case letter
- One upper-case letter
- One number
- In Encryption Mode, select an encryption mode:
- Advanced Encryption Standard (AES-128) or (AES-256)
- Data Encryption Standard (3DES)
- Mark a Diffie-Hellman Group option:
- DH-2
- MODP with a 1024-bit modulus
- DH-5
- MODP with a 1536-bit modulus
- DH-2
- Enable or disable Perfect Forward Secrecy (PFD).
- In Remote Peer IP Address, enter your VPN peer IP address.
- In Remote Host/Networks (CIDR), enter your LAN encryption domain, and then click the plus ( + ) sign.
- In Local Host/Networks (CIDR), enter the Armor LAN encryption domain, and then click the plus ( + ) sign.
- This information is the same as your secure cloud server IP address at Armor.
- Click Save Changes.
...
Anchor | ||||
---|---|---|---|---|
|
...
- In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click L2L VPN.
- If you have virtual machines in various data centers, then click the corresponding data center.
- Click the gear icon that corresponds to the desired L2L VPN tunnel, and then select Edit. Make your desired changes, and then click Save L2L.
...
hidden | true |
---|
- the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click L2L VPN.
- If you have virtual machines in various data centers, then click the corresponding data center.
- Locate and hover over the desired virtual machine.
- Click the vertical ellipses.
- Click Edit.
- Make your desired changes, and then click Save Changes.
...
Anchor | ||||
---|---|---|---|---|
|
...
L2L VPN
...
tunnel
...
- In the Armor Management Portal (AMP), in the left-side navigation, click Infrastructure.
- Click L2L VPN.
- If you have virtual machines in various data centers, then click the corresponding data center.
- Locate and hover over the desired virtual machine.
- Click the vertical ellipses.
- Click Enable, Disable, or Delete.
- Make your desired changes, and then click Save Changes.
...
Anchor | ||||
---|---|---|---|---|
|
...