DA On-Prem -> OCI Journey when UR on a Budget --aka Cheep like Me - Part 5 - Plumbing another Tunnel

 

Part 5: Da Last Tunnel


I said last time I was missing a tunnel...Ok so let’s put one there. This isn’t too bad really. A lot of the pre-work and config is there. Let’s see the stuff already there:


On the Cloud: 

 

 

 

 


So, two tunnels were constructed in OCI but onlyone configured. Note that all the ingress/egress rules still apply and do not required any modifications on the cloud.



For example:



On the PFSense router (Vbox):


WAN (outward facing):



Nothing more needed….Just have it opened from ANY machine on the OCI VCN subnet to the endpoint for the PFSense router in the outfacing subnet.


LAN (Internal Subnet):


These rules will work fine. Remember the DRG thatis attached to the VCN and also roues to the tunnels has everything it needs configured.

 

 


IPSEC:


Again...no changes:

 

 

Ok, so let’s config the other tunnel:


Use the Green Button ‘P1’ under the below to create a new P1 (Phase 1). We will also have to create a Phase 2 but not there yet….


 

This will take you to the screen below:


 

so to ensure you got it right:


Key Exchange Version: IKEv1

Internet protocol: IPV4

Interface: WAN

Remote Gateway: Tunnel 2’s ip address.

Name: give it one


a little further down: 

 


Now for the encryption algorithm:

 

Make sure it looks like this.

 

Now for PHASE 2: Hit the button to add a P2. You’ll get this: 

 


 


To ensure you got it right:


Mode : Routed VTI

Local Network: Network setting from drop-down and the IP subnet (CIDR 24) from the internal

network.

Remote Network: Network setting from drop-down and the IP subnet(CIDR 24) from The VCN Subnet.


A little further down: 

 


 

Make it look like this.



When you get done, hit SAVE at the bottom.


Hit the ‘Apply Changes’.


Go to the Status and choose IPSEC in the drop down. You should see something like this:


Voila! Both tunnels up now…


That’s it…Time to go swingin'



 

Comments

Popular posts from this blog

DA On-Prem -> OCI Journey when UR on a Budget --aka Cheep like Me - Part 4 - Config Da Oracle Vbox

DA On-Prem -> OCI Journey when UR on a Budget --aka Cheep like Me - Part 4 - The Secret Sauce: PFsense Config