Operation Guide
Scenario
Figure 1 shows the typical networking where a VPN gateway connects to the Huawei AR router in an on-premises data center in policy-based mode.
In this scenario, the AR router has only one IP address, and the VPN gateway uses the active-active mode. A VPN connection is created between each of the two active EIPs of the VPN gateway and the IP address of the AR router.
Limitations and Constraints
VPN and AR routers support different authentication and encryption algorithms. When creating connections, ensure that the policy settings at both ends are the same.
Data Plan
Category |
Item |
Example Value for the AR Router |
Example Value for the Huawei Cloud Side |
---|---|---|---|
VPC |
Subnet |
172.16.0.0/16 |
|
VPN gateway |
Gateway IP address |
1.1.1.1 (IP address of the uplink public network interface GE0/0/8 on the AR router) |
|
Interconnection subnet |
- |
192.168.2.0/24 |
|
VPN connection |
IKE policy |
|
|
IPsec policy |
|
Operation Process
Figure 2 shows the process of using the VPN service to enable communication between the data center and VPC.
No. |
Configuration Interface |
Step |
Description |
---|---|---|---|
1 |
Management console |
Bind two EIPs to the VPN gateway. If you have purchased EIPs, you can directly bind them to the VPN gateway. |
|
2 |
Configure the AR router as the customer gateway. |
||
3 |
Create a VPN connection between the active EIP of the VPN gateway and the customer gateway. |
||
4 |
Create a VPN connection between active EIP 2 of the VPN gateway and the customer gateway. It is recommended that the connection mode, PSK, IKE policy, and IPsec policy settings of the two VPN connections be the same. |
||
5 |
CLI of the AR router |
|
|
6 |
- |
Run the ping command to verify network connectivity. |
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot