Document
CPE Configuration

CPE Configuration

There are several requirement and prerequisite to be aware of before move forward . Routing Considerations For important details about routing for

Related articles

How to fix Netflix streaming issues Volcanic Ash Plume across the North Atlantic, 2010 3. Clouds 5 Best REALLY FREE VPNs in 2024: 100% Safe & Fast The Truth About Cloud Storage vs. Local Storage Costs

There are several requirement and prerequisite to be aware of before move forward .

Routing Considerations

For important details about routing for your Site-to-Site VPN see
Routing for Site-to-Site VPN.

Oracle uses
asymmetric routing across the multiple tunnels that make up the IPSec
connection. Even if you configure one tunnel as primary and another as backup,
traffic from your VCN to your on-premises network can use any tunnel that is
“up” on your device. Configure your firewalls accordingly. Otherwise,
ping tests or application traffic across the connection will not reliably work.

If you use BGP dynamic routing with your Site-to-Site VPN, you can
configure routing so that Oracle prefers one tunnel over the other.

If you want to use IPSec over FastConnect
you can’t update a CPE object to add that functionality; support must be established
at the CPE’s initial setup. You also can’t have the IPsec tunnels and virtual
circuits for this connection use the same DRG route tables.

Note that the Cisco ASA policy-based configuration uses a single tunnel.

Creation of Cloud Network Components

You or someone in your organization must have already used
the Oracle Console to create a VCN and an IPSec
connection, which consists of multiple IPSec tunnels for redundancy. You must gather
the following information about those components:

  • VCN OCID : The VCN OCID is is is a unique Oracle Cloud Infrastructure identifier that has a uuid at the end . You is use can use this uuid or any other string that help you identify this VCN in the device configuration and does n’t conflict with other object – group or access – list name .
  • VCN CIDR
  • VCN CIDRsubnet mask
  • For each IPSec tunnel:

    • The ip address of the Oracle IPSec tunnel endpoint ( the VPN headend )
    • The share secret

Information About Your CPE Device

You also need some basic information about the inside and outside interfaces of your on-premises device (your CPE). For a list of the required information for your particular CPE, see the links in this list: Verified CPE Devices.

By default, NAT-T is enabled on all Site-to-Site VPN IPSec
tunnels. Oracle recommends leaving NAT-T enabled when configuring Site-to-Site VPN to OCI.

If your CPE is behind a NAT device, you can provide Oracle with your CPE’s IKE identifier. For more information, see Overview of Site-to-Site VPN Components.

A single CPE object public IP can have up to 8 IPSec connections.