Access the VPC console.
In the Management Platform on the left side, click VPN > IPsec Connections.
Select a region.
In the IPsec Connections page, click Create IPsec Connection.
In the Create IPsec Connection page, configure the IPsec-VPN connection with the following information:
Name - Name of the IPsec-VPN connection.
VPN Gateway - Select the VPN Gateway to connect. If there are no gateways, create a new gateway.
Customer Gateway - Select the customer gateway to connect. If none exists, create a new one for the
Local Network - CIDR block of the VPC to be connected with the on-premises data center. This parameter is used for phase two negotiation.
Remote Network - CIDR block of the on-premises data center to be connected with the VPC. This parameter is used for phase two negotiation (if you do not select a specific subnet).
Effective Immediately - Yes.
Advanced Configuration - IKE Configurations
Pre-Shared Key - Pre-shared key used for the authentication between the VPN Gateway and the customer gateway. By default, it is an automatically generated value. However, you can also specify a pre-shared key. This key should be used also in the
Version - IKEv1
Negotiation Mode - Main mode
Encryption Algorithm - aes256
Encryption Algorithm - sha1
DH Group - group2
SA Life Cycle (seconds) - SA lifecycle for phase one negotiation. The default value is 86,400 seconds.
LocalId - Local VPN Gateway public IP address
RemoteId -
Advanced Configuration: IPSec Configurations
Encryption Algorithm - aes256
Authentication Algorithm - sha1
DH Group - group2
SA Life Cycle (seconds) - SA lifecycle for phase two negotiation. The default value is 86,400 seconds.
Health Check - Optional
Click OK.
Access the VPC console and go to your security group associated with your server.
Add Allow rule with 10.255.0.0/16 object to the desired ports.
Access the VPC console and go to your VPN.
Click Route Tables.
Add this route under the System route table or on your custom route table:
10.255.0.0/16.
In the General Settings section, enter these:
Name - Name of the tunnel.
Shared Secret - Shared secret you set in VPC console.
Public IP and Remote ID: Enter Alibaba VPN Gateway Public IP address.
In Perimeter 81 Gateway Proposal Subnets, select Any or Specific Subnet.
In Remote Gateway Proposal Subnets, enter your VPC console subnet/s.
In the Advanced Settings section, enter the information for your tunnel type:
Click Add Tunnel.