- Configure the virtual network.
- Configure the virtual network gateway.
- In the Azure dashboard, click Create a resource.
- Search for Virtual network gateway and click Create.
- Enter the settings for your virtual network gateway.
- VPN type: Policy-based
- Virtual network: Select the network created on Step 1.
- Public IP address: Create a new public IP address if not available
- Click Next: Tags and enter the settings in Tags page.
- Click Next: Review + create.
- Click Create to start creating a virtual network gateway.
- In the Azure dashboard, locate and select the created Local Network Gateway.
- Under Settings, go to Connection and click Add.
- Input the settings for the new IP security (IPSec) site-to-site connection. For the following fields, select the network gateway created on the previous steps:
- Virtual Network Gateway
- Local Network Gateway
- Click Create to build the IPSec site-to-site connection.
- Login to Cloud Edge Cloud Console (CECC).
- Select the Policies tab and click IP Addresses/FQDNs.
- Click Add and create two (2) IP Address objects:
- IP address for local network protected by Cloud Edge appliance
- IP address for Azure virtual network
- Click the Gateways tab and select the registered Cloud Edge Appliance.
- Access Site-to-Site VPN.
- Go to Policies tab and click Add.
- Configure the following for the IPSec Policy:
- IKE encryption algorithm: Change from AES 128 to AES 256
- IPSec encryption algorithm: Change from AES 128 to AES 256
- Click Save.
- Go to Connections tab and click Add.
- Configure the following settings:
- Gateway: Input the Public IP address used by Azure Virtual Network Gateway
- Remote ID: Input the Public IP address used by Azure Virtual Network Gateway
- Local Networks: Select IP address object for local network protected by Cloud Edge appliance (Step 3)
- Remote Networks: Select IP address object for local network protected by Azure virtual network (Step 3)
- Key and Confirm Key: Input same shared key used by Azure Site-to-site IPSec connection.
- Policy Name: Select policy created on Step 6
Cloud Edge Cloud Console
- Access Gateways and select the registered Cloud Edge appliance.
- Go to Site-to-Site VPN and click Status.
- Check for "ESTABLISHED" and "INSTALLED" to confirm the successful tunnel.