No results found
We couldn't find anything using that term, please try searching for something else.
There are several requirement and prerequisite to be aware of before move forward . Routing Considerations For important details about routing for
There are several requirement and prerequisite to be aware of before move forward .
For important details about routing for your Site-to-Site VPN see
Routing for Site-to-Site VPN.
Oracle uses
asymmetric routing across the multiple tunnels that make up the IPSec
connection. Even if you configure one tunnel as primary and another as backup,
traffic from your VCN to your on-premises network can use any tunnel that is
“up” on your device. Configure your firewalls accordingly. Otherwise,
ping tests or application traffic across the connection will not reliably work.
If you use BGP dynamic routing with your Site-to-Site VPN, you can
configure routing so that Oracle prefers one tunnel over the other.
If you want to use IPSec over FastConnect
you can’t update a CPE object to add that functionality; support must be established
at the CPE’s initial setup. You also can’t have the IPsec tunnels and virtual
circuits for this connection use the same DRG route tables.
Note that the Cisco ASA policy-based configuration uses a single tunnel.
You or someone in your organization must have already used
the Oracle Console to create a VCN and an IPSec
connection, which consists of multiple IPSec tunnels for redundancy. You must gather
the following information about those components:
For each IPSec tunnel:
You also need some basic information about the inside and outside interfaces of your on-premises device (your CPE). For a list of the required information for your particular CPE, see the links in this list: Verified CPE Devices.
By default, NAT-T is enabled on all Site-to-Site VPN IPSec
tunnels. Oracle recommends leaving NAT-T enabled when configuring Site-to-Site VPN to OCI.
If your CPE is behind a NAT device, you can provide Oracle with your CPE’s IKE identifier. For more information, see Overview of Site-to-Site VPN Components.
A single CPE object public IP can have up to 8 IPSec connections.