---
title: "Oracle IPsec configuration"
canonical: "https://docs.aryaka.com/space/KNOW/1294696505/Oracle%20IPsec%20configuration"
format: markdown
---
VPN Connect is an Oracle service that provides a site-to-site IPSec VPN between your Aryaka sites (Oracle refers to them as  branch offices ) and Oracle’s virtual cloud network (VCN) over a secure encrypted VPN. Aryaka customers can optimize their access to the Oracle resources at any location using the nearest Aryaka POP using a route-based tunnel. This document describes the steps that Aryaka customers need to perform in the Oracle Cloud console to create a VPN tunnel with Aryaka POP. Prerequisites Satisfy the following prerequisites before performing the IPSec configuration. You must be an administrator user on the Oracle Cloud console. You must provide the following information to Aryaka before connecting an Oracle instance to Aryaka using VPN: Oracle location Oracle local subnets (if you are using static routing) Tunnel type (route-based and policy-based tunnels are supported, though Oracle suggests using route-based tunnels because there are some issues with policy-based tunnels as described in the Caveats and Limitations section of  this document  at cloud.oracle.com) Based on the prerequisite information provided to Aryaka Support, Aryaka returns the following information to you for completing the Oracle Cloud configuration: CPE public IP to be used as the VPN CPE peer for Oracle VPN CPE vendor and platform BGP session IPs VLAN Aryaka ASN (if you are using BGP routing) IKE version for the tunnel Configure Oracle VPN Complete the following steps to configure an IPsec connection with an Aryaka POP. While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Log in to the Oracle Cloud console. Create the VCN: Click  Networking  >  Virtual Cloud Networks  in the left navigation pane. The Create a Virtual Cloud Network page appears: Enter a name for the VCN in the Name field. Enter the compartment for the VCN in the Create In Compartment field. Enter a single, contiguous CIDR block in the CIDR Block field for this VCN. Note that after you create the VCN, this CIDR cannot be changed. (Optional) Click the  DNS Resolution  checkbox to enable VCN-DNS. When enabled, a domain name is automatically created for this VCN that cannot be changed. Click  Create VCN . The VCN is created using your entries. Create a dynamic routing gateway (DRG): Click  Networking  >  Dynamic Routing Gateways  in the left navigation pane. The Dynamic Routing Gateways page appears. Click the  Create a Compartment  drop-down list, then select the compartment you created in step 2. Enter the name of the dynamic routing gateway in the Name field. (Optional) Create one or more metadata tags by specifying a tag name and a corresponding key/value pair. Tags can be added or modified later. Click  Create Dynamic Routing Gateway . The DRG is created and appears in the Dynamic Routing Gateway table. Associate the DRG to the VCN: In the Dynamic Routing Gateway table, click the  DRG  created in step 3. The DRG’s details page appears. It includes the Attach to Virtual Cloud Network pane. Click  Virtual Cloud Networks  in the left Resources pane. Click  Attach to Virtual Cloud Networks . Click the  Virtual Cloud Network  drop-down list and select the VCN that you created in step 2. Click  Attach to Virtual Cloud Networks . An association of the DRG and the selected VCN is created. The Virtual Cloud Network table shows the status as Attached: Create a static routing rule for the DRG: Note:  Each VCN includes a default route table that can be used to create routing rules. These routing rules helps route traffic to the on-premises network and then to the DRG attached to the VCN. In the left navigation pane, click  Networking  >  Virtual Cloud Networks  then click the VCN that you created in step 2. The VCN’s details page appears. Click  Route Tables  >  Default Route Table . The Default Route Table for  <VCN_name>  page appears. Click  Add Route Rules  in the Route Rules table. In the Add Route Rules pane, click the  Target Type  drop-down list and select  Dynamic Routing Gateway . The DRG and compartment associated with this VCN in step 4 appear in the read-only Name and Compartment fields respectively. Enter the local prefix of one of your Aryaka sites (Oracle refers to them as  branch offices ) in the Destination CIDR Block field. (Optional) Enter a description of the rule in the Description field. Click  + Additional Route  to add more route rules for each prefix. Note that you must reserve one prefix to use when configuring the IPsec tunnel in step 7. Click  Add Route Rules . The rule is created and appears in the Route Rules table. Create a Customer-Premises Equipment (CPE) object: In the left navigation pane, click  Networking  >  Customer-Premises Equipment . Click  Create Customer-Premises Equipment . The Create Customer-PremisesEquipment page appears. Enter the name of the Aryaka POP in the Name field. Select the compartment used by this VCN from the  Create in Compartment  drop-down list. Enter the IP address provided to you by Aryaka in the Public IP Address field as described in Prerequisites. Enter the equipment vendor provided to you by Aryaka in the Vendor field as described in Prerequisites. Enter the platform or model and the version number provided to you by Aryaka in the Platform/Version field as described in Prerequisites. Click  Create CPE . The CPE object is created. Create an IPSec connection to the CPE object: In the left navigation pane, click  Networking  >  IPSec Connections  >  Create IPSec Connection . The Create IPSec Connection page appears. Select the VCN’s compartment from the  Create in Compartment  drop-down list. Enter a name for the IPSec connection in the Name field. We recommended using the VCN name for the connection. Select the VCN’s compartment from the  Customer-Premises Equipment Compartment  drop-down list. Select the CPE created in step 6 from the  Customer-Premises Equipment  drop-down list. Select the VCN’s compartment from the  Dynamic Routing Gateway Compartment  drop-down list. Select the DRG created in step 3 from the  Dynamic Routing Gateway  drop-down list. Do one of the following depending on your routing type: Static routing— Enter the one on-premise subnet not configured previously in step 5. BGP dynamic routing—Leave this field blank. Click the  Show Advanced Options  link. The CPE IKE Identifier tab appears and, by default, displays the public IP address of the CPE. Click the  Tunnel 1  tab. Enter the following in the corresponding Tunnel 1 tab field: A name for the tunnel. (Optional) A custom shared secret. By default, Oracle Cloud creates the shared secret for the tunnel. If you want to provide it instead, click the  Provide Custom Shared Secret  checkbox and enter the shared secret. The IKE version provided by Aryaka as described in Prerequisites. Click either  Static Routing  or  BGP Dynamic Routing . If you select BGP Dynamic Routing, enter the BGP ASN, Inside Tunnel Interface – CPE, and Inside Tunnel Interface – Oracle provided by Aryaka as described in Prerequisites. Click  Create IPSec Connection . Oracle Cloud sets the status of the newly created IPSec to Provisioning and Oracle begins the actual provisioning. When it is complete, the status is updated to Available. Ensure the status of your IPSec is Available, then locate the following information on the IPSec page (at  Networking  >  IPSec Connections  >    IPSec_name   ): Copy the Oracle VPN IP Address from the Tunnels table. Click the  Options  icon (three vertical dots) at the end of the Tunnels table row, then select  View Details . The tunnel’s details page appears: Click  Show  in the Shared Secret field. Copy the Shared Secret. Contact  Aryaka Customer Support  and share the Oracle VPN IP Address and the Shared Secret with them. After the support team completes the configuration, the tunnel and BGP peering are available. In this topic Related topics Oracle FastConnect