AWS-VPN Connection

 By Default, VPC launched in AWS can't communicate with your own VPN.VPN site-to-site connection helps you to enable the communication ...

 By Default, VPC launched in AWS can't communicate with your own VPN.VPN site-to-site connection helps you to enable the communication between AWS VPC and your own premise VPN.

Below are the important terms which we need to know about the site-to-site VPN perspective. 

VPN Connection:- A secure connection between your own premise equipment and your AWS VPC.

VPN Tunnel:- An encrypted link where data can pass from your network to or from AWS VPC. Each VPN connection includes 2 VPN tunnels that can be used for high availability.

Customer Gateway:- An AWS resource that provides information to AWS about your customer gateway device.

Customer Gateway Device:- A physical device or a software application on the customer side.


I am creating VPC in North Virginia Region and Singapore Region.

1. Create a VPC in North Virginia Region with the following configurations

    VPC CIDR : -

    Public Subnet:-

2.  Create a VPC in Singapore Region with the following configurations

    VPC CIDR : -

    Public Subnet:-

3. Create a public EC2 instance in the Singapore region within the same VPC and subnet.

4. Configure below in North Virginia Region.

    VPN---> VPNGateway ---> Create VPN Gateway ( AWS VPN Gateway)

    Attach to AWS VPC

5. Create a Customer Gateway (CGW-1) and in the IP address copy the IP address of the Singapore region's EC2 instance public IP.

6. Select Site-to-site VPN connection in N Virginia Region and Click on Create VPN VPN Connection

     Select the VPGateway and CGW-1

     Routing Options--> Static and provide the CIDR range of Singapore VPC (

    Create the VPN Connection

7. Select the RouteTable of N Virginia Region and in the Route Propagation tab select the VPN Gateway and Enable it.

8. Select VPN site-site connection and Download the Configuration with Generic Vendor.

9. Select EC2 instance of the Singapore region and connect it.

Run below commands on this instance

1. Commands for Installation of Openswan i. Change to root user: $ sudo su ii. Install openswan: $ yum install openswan -y iii. In /etc/ipsec.conf uncomment following line if not already uncommented: include /etc/ipsec.d/*.conf iv. Update /etc/sysctl.conf to have following net.ipv4.ip_forward = 1 net.ipv4.conf.all.accept_redirects = 0 net.ipv4.conf.all.send_redirects = 0 v. Restart network service: $ service network restart 2. Command for /etc/ipsec.d/aws-vpn.conf conn Tunnel1 authby=secret auto=start left=%defaultroute leftid=Customer end Gateway VPN public IP right=AWS Virtual private gateway ID- public IP type=tunnel ikelifetime=8h keylife=1h phase2alg=aes128-sha1;modp1024 ike=aes128-sha1;modp1024 keyingtries=%forever keyexchange=ike leftsubnet= rightsubnet= dpddelay=10 dpdtimeout=30 dpdaction=restart_by_peer 3. Contents for /etc/ipsec.d/aws-vpn.secrets customer_public_ip aws_vgw_public_ip: PSK "shared secret" 4. Commands to enable/start ipsec service $ chkconfig ipsec on $ service ipsec start $ service ipsec status



Ansible,6,AWS,1,Azure DevOps,1,Containerization with docker,2,DevOps,2,Docker Quiz,1,Docker Swarm,1,DockerCompose,1,ELK,2,git,2,Jira,1,Kubernetes,1,Kubernetes Quiz,5,SAST DAST Security Testing,1,SonarQube,3,Splunk,2,vagrant kubernetes,1,YAML Basics,1,
DevOpsWorld: AWS-VPN Connection
AWS-VPN Connection
Loaded All Posts Not found any posts VIEW ALL Readmore Reply Cancel reply Delete By Home PAGES POSTS View All RECOMMENDED FOR YOU LABEL ARCHIVE SEARCH ALL POSTS Not found any post match with your request Back Home Sunday Monday Tuesday Wednesday Thursday Friday Saturday Sun Mon Tue Wed Thu Fri Sat January February March April May June July August September October November December Jan Feb Mar Apr May Jun Jul Aug Sep Oct Nov Dec just now 1 minute ago $$1$$ minutes ago 1 hour ago $$1$$ hours ago Yesterday $$1$$ days ago $$1$$ weeks ago more than 5 weeks ago Followers Follow THIS PREMIUM CONTENT IS LOCKED STEP 1: Share to a social network STEP 2: Click the link on your social network Copy All Code Select All Code All codes were copied to your clipboard Can not copy the codes / texts, please press [CTRL]+[C] (or CMD+C with Mac) to copy Table of Content