Access the IBM Cloud Console and open the VPC section and go to Network > VPNs.
Go to the IKE policies tab and click New IKE policy.
The New IKE policy window appears.
Enter these:
Name - Name of the policy.
Resource group
Region - Region in which the VPC is located.
Click Create IKE policy.
The system creates the IKE policy.
Click and then Edit.
Enter these:
IKE Version - 1
DH Group - 2
Authentication - sha256
Key Lifetime - 28800
Encryption - aes256
Click Save IKE policy.
Go to the IPSec Policies tab and click New IPSec Policy.
The New IPSec policy window appears.
Enter these:
Name - Name of the policy.
Resource group
Region - Region in which the VPC is located.
Click Create IPSec policy.
The system creates the IPSec policy.
Click and then Edit.
Enter these:
Authentication - sha256
Encryption - aes256
PFS - Select the checkbox.
DH Group - 2
Key Lifetime - 3600
Click Save IPSec policy.
Go to the VPN gateways tab and click New VPN gateway.
The New VPN gateway for VPC window appears.
Enter these:
Name - Name of the VPN gateway.
Virtual private cloud - Select the required cloud.
Resource group - Select the resource group.
Subnet - Select the required subnet.
Select New VPN Connection for VPC.
The New VPN connection for VPC window appears.
Enter these:
Connection name - Name of the VPN connection.
Peer gateway address - IP address of your
Preshared key - A string with at least 8 characters that contains upper-case letters and numbers.
Local subnets - Specify one or more subnets in the VPC you want to connect.
Peer subnets - 10.255.0.0/16 (Unless you have custom configurations or multiple tunnels to the same
Dead peer detection action - Restart
Interval - 10 seconds
Timeout - 30 seconds
IKE policy - Select the IKE policy created earlier.
IPSec policy - Select the IPSec policy created earlier.
In the General Settings section, enter these:
Name - Name of the tunnel.
Public IP - IP address of the VPN Gateway defined in the IBM Cloud console.
Remote ID - Identical to Remote IP.
Shared Secret - Preshared key in the IBM Cloud console.
Perimeter 81 Gateway Proposal Subnets - 10.255.0.0/16 or the value defined in the IBM Cloud console.
Remote Gateway Proposal Subnets - Subnets in the VPC that you want to connect.
In the Advanced Settings section, enter the information for your tunnel type:
Click Add Tunnel.
Access the IBM Cloud console and go to the VPN gateways tab.
Select the name of the VPN Gateway associated with the tunnel.
Scroll down and click View all connections.
Verify whether the tunnel Status as active.