跳至內容

Setting-up Site-to-Site VPN connection Help

0

Hi,

I'm to new this network area. but I managed to connect my VPC with customer's Test site via DNAT through Elastic IPs.

Now I'm in a situation where I need to connect my VPC to the Customer's Production environment and customer is not agreeing to provide DNAT but they are asking me to setup a Site-to-Site VPN.

I configured my Site-to-Site VPN based on following document. https://docs.aws.amazon.com/vpn/latest/s2svpn/SetUpVPNConnections.html

but I still can see that my tunnels are down. Enter image description here

is this because that the customer does not setup connection to my site-to-site vpn from their side yet or something else? What should I do next? please advice.

已提問 3 年前檢視次數 967 次

3 個答案
1

Hello.

If you do not configure the VPN settings on the on-premises router, the status will be DOWN.
Also, if the settings on the on-premises router are incorrect, the status will be DOWN.
So, first you need to complete the router settings.

專家

已回答 3 年前

專家

已審閱 3 年前

  • So, the next step is to communicate with customer to do the setup from their end. Thank you.

1

Hello,

After you create the VPN connection, you can download the configuration file (select as per the customer's device) and share it with them to configure vpn on their end.

https://docs.aws.amazon.com/vpn/latest/s2svpn/SetUpVPNConnections.html#vpn-download-config https://docs.aws.amazon.com/vpn/latest/s2svpn/SetUpVPNConnections.html#vpn-configure-customer-gateway-device

If their end (customer gateway) is configured properly, tunnel should come UP.

If after customer has configured their end of VPN and tunnels are still not established, you must determine which phase the failure occurred:

For (IKE/Phase 1) issues, follow the steps in https://repost.aws/knowledge-center/vpn-tunnel-phase-1-ike

For (IPsec/Phase 2) issues, follow the steps in https://repost.aws/knowledge-center/vpn-tunnel-phase-2-ipsec

AWS
專家

已回答 3 年前

專家

已審閱 3 年前

0

Customer said that he has already completed the setup from their end. but still, I can see that the status is down. also, I got this email today from AWS. how this effect for my case? Enter image description here

已回答 3 年前

您尚未登入。 登入 去張貼答案。

一個好的回答可以清楚地回答問題並提供建設性的意見回饋,同時有助於提問者的專業成長。