Create secure site-to-site VPN tunnels using Multicloud Defense to connect networks across locations. Connect to AWS, Azure, GCP, ASA, or FTD devices. Configure and manage encrypted connections for optimal VPN protection.
A site-to-site VPN tunnel connects networks in different geographic locations. You can create site-to-site IPsec connections between two different Multicloud Defense Gateways or between a Multicloud Defense Gateway and a cloud service provider that complies with all relevant standards. After the VPN connection is established, the hosts behind the local gateway can connect to the hosts behind the remote gateway through the secure VPN tunnel.
Typically, the dynamic peer must be the one that initiates the connection as the other peer would not know the IP address of the dynamic peer. When the remote peer attempts to establish the connection, the other peer validates the connection using the preshared key, IKE settings, and IPsec configurations.
Because the VPN connection is established only after the remote peer initiates the connection, any outbound traffic that matches access control rules that allow traffic in the VPN tunnel will be dropped until that connection is established. This ensures that data does not leave your network without the appropriate encryption and VPN protection.
At this time, Multicloud Defense supports site-to-site VPN tunnel connections with the following platforms or products:
-
AWS
-
Azure
-
GCP
-
ASA device
-
FTD device
-
Extranet or a third party firewall
Prerequisites and Limitations for Site-to-Site VPN Tunnels
Review supported endpoints, prerequisites, and limitations before creating site-to-site VPN tunnel connections with Cisco Multicloud Defense gateways.
Enable VPN Within the Gateway
Enable VPN support on a Cisco Multicloud Defense gateway and assign a BGP profile before creating a site-to-site tunnel connection.
Create a Site-to-Site VPN Connection
Create a site-to-site VPN tunnel between a Cisco Multicloud Defense gateway and a supported cloud platform, Cisco device, or third-party firewall.
Edit a Site-to-Site VPN Tunnel
Edit the endpoints, virtual interface addresses, authentication value, or IPSec profile for an existing Cisco Multicloud Defense site-to-site VPN tunnel.
Clone a Site-2-Site VPN Tunnel Connection
Clone an existing site-to-site VPN tunnel connection in Cisco Multicloud Defense and update its endpoints, IP addresses, profile, or authentication value.
Delete a VPN Tunnel Connection
Delete a site-to-site VPN tunnel connection from Cisco Multicloud Defense and remove related BGP profiles when they are no longer needed.