Updated on 2023-08-01 GMT+08:00

Using TheGreenBow IPsec VPN Client to Configure On- and Off-Cloud Communication

Scenarios

This section describes how to use TheGreenBow IPsec VPN Client to establish a VPN connection between a VPC and a cloud desktop or between two VPCs.

This following describes the configuration details if TheGreenBow IPsec VPN Client is used.

  • Scenario 1: Install the client on the cloud desktop that connects to the VPN gateway of the VPC.
    1. The cloud desktop must run the Windows OS.
    2. The cloud desktop can ping the VPN gateway IP address of the VPC. (If the ping fails, the VPN connection cannot be established.)
  • Scenario 2: Install the client on the ECS in VPC1 that connects to the VPN gateway of VPC2.
    1. Windows ECS in VPC1 has EIP.
    2. The ECS in VPC1 can ping the VPN gateway IP address of VPC2. (If the ping fails, the VPN connection cannot be established.)

Prerequisites

  • Scenario 1: Cloud desktop + VPC
    • The VPC, subnet, and ECS have been configured on the cloud.
    • The VPN gateway and VPN connection on the cloud have been configured.
      Figure 1 Policy details
    • TheGreenBow IPsec VPN Client has been installed on the cloud desktop.
    • The cloud desktop can ping the IP address of the VPN gateway.
  • Scenario 2: VPC + VPC
    • The VPCs, subnets, and ECSs in two regions have been configured. The ECS in VPC2 runs the Windows OS.
    • The VPN gateway and VPN connection in VPC1 have been configured.
      Figure 2 Policy details
    • TheGreenBow IPsec VPN Client has been installed on the Windows ECS in VPC2.
    • The ECS in VPC2 can ping the VPN gateway IP address of VPC1.

      Use the default VPN configurations on HUAWEI CLOUD.

Configuration Procedure

Scenario 1: Client configuration in the "cloud desktop + VPC" scenario
  1. Configure global parameters.
  2. Configure IKE phase 1 parameters.
  3. Configure IPsec phase 2 parameters.
Scenario 2: Client configuration in the "VPC + VPC" scenario
  1. Configure global parameters.
  2. Configure IKE phase 1 parameters.
  3. Configure IPsec phase 2 parameters.

Configuration Verification

  • Scenario 1: Cloud desktop + VPC

    Check whether the cloud desktop and the ECS in the VPC can communicate with each other.

    1. Check whether the VPN connection is successfully established.
    2. Check the VPN connection status of the VPC.
    3. Check the network configurations of the cloud desktop.
    4. Ping the ECS in the VPC from the cloud desktop.
    5. Ping the cloud desktop from the ECS in the VPC.

    The cloud desktop and the ECS in the VPC can communicate with each other successfully.

  • Scenario 2: VPC + VPC

    Check whether the ECS in VPC1 and the ECS installed with the client in VPC2 can communicate with each other.

    1. Check whether the VPN connection is successfully established.
    2. Check the VPN connection status of the VPC.
    3. Check the VPC network configurations.
    4. Ping the ECS in VPC2 from the ECS in VPC1.
    5. Ping the ECS in VPC1 from the ECS in VPC2.

    The ECS in VPC1 and the ECS installed with the client in VPC2 can communicate with each other successfully.