Available in VPC
You can easily create and operate VPN Gateways and tunnels in NAVER Cloud Platform's IPsec VPN. While you can explore the service in detail with our Getting Started and Using IPsec VPN guides, we recommend starting with this quickstart overview to understand the complete workflow. Here's the entire process for using IPsec VPN:
1. Set user permissions
2. Preparations
3. Create IPsec VPN Gateway
4. Create IPsec VPN tunnel
5. Follow-ups
6. Set user network VPN
7. Ping test
8. Check connection
1. Set user permissions
Set the user permissions for using IPsec VPN. IPsec VPN user permissions are defined by mapping roles to sub accounts issued by NAVER Cloud Platform's Sub Account. Thus, you first need to create sub accounts other than your main account through Sub Account.
Sub Account is a free service with no additional charges. For more information about Sub Account and pricing plan, see Services > Management & Governance > Sub Account on the NAVER Cloud Platform portal.
You can use sub accounts provided by Sub Account to configure admin permissions and user permissions of IPsec VPN. For detailed instructions, see:
2. Preparations
To use IPsec VPN, the following environment is required: For detailed instructions, see:
- VPC and Private Subnet should exist. (Create VPC and subnet)
- Virtual Private Gateway (VGW) and Virtual Private Gateway Group (VGWG) should exist. (Create VGW and VGWG)
3. Create IPsec VPN gateway
Create a VPN gateway from the NAVER Cloud Platform console. For detailed instructions, see:
4. Create IPsec VPN tunnel
Create a VPN tunnel to connect to the gateway you created. For detailed instructions, see:
5. Follow-ups
After creating the VPN tunnel, the following steps are required: For detailed instructions, see:
- Configure routing for Private Subnet
- Create server (skip if there is a server already created)
6. Set user network VPN
Check your network configuration and create VPN gateways and tunnels.
- Check network configuration
- It must not overlap with NAVER Cloud Platform's Private Subnet range.
- Customer networks in use that overlap with 100.64.0.0/10 cannot be connected with IPsec VPN and Cloud Connect.
- Check VPN gateway
- The public IP of the customer's VPN Gateway must be the same as the Peer IP entered when setting up the NAVER Cloud Platform's IPsec VPN Tunnel.
- Create VPN tunnel
- The local network becomes the customer network, and the remote network becomes NAVER Cloud Platform's Private Subnet.
- Peer IP becomes the public IP of NAVER Cloud Platform's IPsec VPN Gateway.
- The set values for IKE should be the same as those of NAVER Cloud Platform's IPsec VPN Tunnel.
7. Ping test
Sends a ping or ssh command from the NAVER Cloud Platform server to a host in the customer's network to test whether they are connected to each other.
8. Check connection
Access the console and verify that the IPsec VPN Tunnel is displayed as Active. For detailed instructions, see: