Auto Light Dark
Auto Light Dark

Direct VPN Configuration

This section is only needed if the ESKM is inside a private network, if the ESKM has a public address configured this step shouldn’t be configured.

The Private Network configuration in OCI needs the stablishment of a Site-to-Site VPN in order to connect the OCI private network with the ESKM private network.

  1. In the OCI Console, go to Networking → Customer-premises equipment.

  2. Select Create CPE.

  3. Insert the Name and select the Compartment.

  4. Insert the Customer-premises public IP address.

  5. Select the CPE Vendor and Platform/Version.

  6. Create CPE.

image-20261005-115247.png


Create a CPE

  1. Go to Networking → Site-to-Site VPN.

  2. Create IPSec Connection.

  3. Define the Name and select the Compartment, CPE and Network Dynamic Route Gateway created before.

  4. Introduce <IP_ADDRESS>/32 as the static route to the on-premise network.

  5. Expand Tunnel 1 and select IKEv2 and Static Route.

image-20261005-115333.png



Create IPSec connection

  1. Expand Tunnel 2 and select IKv2 and Static Routing.

To define the algorithms used in the IKEv2 phases, expand the advanced options and the desired phase. Some companies may have restrictions with the allowed algorithms.

  1. Create IPSec Connection.

  2. In the Site-to-Site VPN panel, select the created IPSec VPN panel, select the created IPSec Connection → Tunnels → tunnel-1.

  3. Copy the Oracle VPN IP address and the Shared Secret.

  4. Use these parameters to configure the ESKM network side.

The Site-to-Site VPN tunnels are commonly managed in the gateway’s firewall. If the ESKM environment’s firewall requires the modification of the algorithms or the session key lifetime, it can be done by selecting the Edit button, Advanced Options –> Phase One/Two → Set custom configurations.