---
title: "Alibaba IPsec-VPN"
canonical: "https://docs.aryaka.com/space/KNOW/1295155327/Alibaba%20IPsec-VPN"
format: markdown
---
IPsec-VPN is an Alibaba service that provides a site-to-site IPsec VPN between your Aryaka sites and Alibaba’s Virtual Private Cloud (VPC). Aryaka customers can optimize their access to the Alibaba resources at any location using the nearest Aryaka POP and a route-based tunnel. This document describes the steps that Aryaka customers need to perform in the Alibaba Management console to create a tunnel to the Aryaka POP. Prerequisites Satisfy the following prerequisites before performing the IPsec configuration. You must be an administrator user on the Alibaba Management console. You must have already created a VPC. Refer to  alibabacloud.com  for instructions. You must provide the following information to Aryaka: VPC instance region Alibaba local subnets list You must have the Aryaka Public Endpoint IP that was returned to you by Aryaka support based on the information you provided to them. Configure Alibaba IPsec-VPN While we have made every effort possible to ensure accurate descriptions and screen captures at time of publication, updates to the third-party UI are beyond our control. Refer to the third-party documentation to ensure you have the most recent information. Log in to the Alibaba Management Console. Create a VPN Gateway (skip this step if you want to use an existing gateway): Click the  Options  icon >  Virtual Private Cloud  >  VPN  >  VPN Gateways . Click  Create VPN Gateway , then configure the following: Name—Enter a descriptive VPN Gateway name. Region—Select the gateway’s region (this is the same as VPC’s region) VPC—Select a VPC instance from the drop-down list that you want to connect to the Aryaka POP. vSwitch—(Optional) Select a vSwitch if multiple VPCs exists in the selected region. Peak Bandwidth—Select the agreed upon bandwidth for the IPsec connection. Traffic—Use the default value. Enable IPsec-VPN. Disable SSL-VPN. Click  Buy Now . On the page that appears, verify the details then click  Activate Now . After the gateway is activated, it is added to your VPN Gateway list: Note the VPN gateway IP Address. You must provide it in step 4 of this procedure.  Configure the Customer Gateway to provide Aryaka-side tunnel endpoint IP details: Click the  Options  icon >  Virtual Private Cloud  >  VPN  >  Customer Gateways . Click  Create Customer Gateway . Configure the following and then click  OK : Name—Provide a descriptive name to identify this Aryaka-specific gateway. IP Address—Enter the public endpoint IP provided by Aryaka support. ASN—Leave this field blank since BGP is not being configured. Description—(Optional) Enter a description of this customer gateway. Click  OK . Create the IPsec Connection: Click the  Options  icon >  Virtual Private Cloud  >  VPN  >  IPSec Connections . Click  Create IPSec Connection . Configure the following settings and then click  OK : Name—Enter a descriptive name to the VPN connection. VPN Gateway—Select the VPN gateway created in step 2 from the drop-down list. Customer Gateway—Select the customer gateway created in step 3 from the drop-down list. Route-based VPN Tunnel—Select Destination Routing Mode. Effective Immediately—Select Yes to attempt a reconnection immediately if necessary. Pre-Shared Key—Enter a random 16-bit string. Enable Advanced Configuration. The following settings are recommended for IKE: Version—IKEv1 Negotiation Mode—Aggressive Mode Encryption Algorithm—aes Authentication Algorithm—sha1 DH Group—group2 SA Life Cycle (seconds)—86400 The following settings are recommended for IPsec: Encryption Algorithm—aes Authentication Algorithm: sha1 DH Group—group 2 SA Life Cycle(seconds)—3600 DPD and NAT Traversal enabled (default) BGP Configuration disabled (default) Click  OK  when prompted to publish the route: Refer to the following sample route configuration: At this point, the IPsec connection status is still  Phase 1 Failed . Provide the following information to Aryaka support to complete configuration on the POP: In the IPsec Connections, locate the target IPsec connection and then click  Download Configuration  in the Actions column. Copy entire configuration in the download and email it to  support@aryaka.com .  After Aryaka support configures their endpoint, the IPsec connection status changes to  Phase 2 of IKE Tunnel Negotiation Succeeded . Populate the remote on-site subnets in the Alibaba route table: Navigate to the VPN Gateway page. Click  VPC Instance ID  in the Instance ID/Name column for your VPN gateway. Click the  Destination-Based Routing  tab, then click  Add Route Entry . The Add Entry page appears: Enter following information and create additional subnets as required: Destination CIDR Block—Prefix configured on the remote sites. Next Hop Type—Select the IPsec connection created in step 4. Next Hop—Select the target IPsec-VPN instance. Publish to VPC—Select Yes (recommended by Alibaba). Weight—Select 100 if this is the primary connection, or 0 (zero) if it is the backup connection. (Optional) Create a backup connection by repeating this procedure and selecting 0 in the Weight field (step 6) for all remote subnets in the route table. In this topic Related topics Alibaba Partner Express Connect alibabacloud.com