Enable VPN support on a Cisco Multicloud Defense gateway and assign a BGP profile before creating a site-to-site tunnel connection.
Use this procedure to enable the VPN for a gateway in the Multicloud Defense Controller dashboard:
Before you begin
Before you can establish a VPN connection between two devices using Multicloud Defense, you must enable the gateway to utilize a BGP profile. See Prerequisites and Limitations for Site-to-Site VPN Tunnels for the complete list of prerequisites for creating and deploying a gateway.
If you opt to use a BGP profile, the BGP profile is run over the IPSEC tunnel with the remote peer.
Procedure
| 1. | Navigate to . |
|
| 2. | Click Add Gateway to create a new gateway or select an existing gateway. Choose Edit it in the Actions drop-down menu. To configure a gateway, see Configure Your Gateway. For Azure VPN, we recommend that you use a Dsv3-Series V3 instance type instead of a Dsv5-Series V5 instance type, as the V5 instance type may not be compatible. |
|
| 3. | When you create or edit the gateway, scroll to the bottom of the window and select a BGP profile from the drop-down menu when prompted. |
|
| 4. | Locate the VPN Connection options under Advanced Settings. Check the Enable VPN option to opt into VPN tunnel connection. |
|
| 5. | Expand the BGP Profile drop-down menu and select a profile that has already been created. |