Creating an encrypted IPsec link using Megaport
You can create an IPsec encrypted customer-to-customer, customer-to-cloud, or cloud-to-cloud connection. See your cloud or equipment vendor’s documentation for more information about creating IPsec connections. On Megaport Cloud Routers (MCR), you can enable IPsec in the Megaport Portal during creation, or edit the MCR to enable IPsec after it has gone live. For more information, see Using IPsec with MCR.Supported ciphers
The MCR will offer the following ciphers to IPsec peers. At this time, the options are not configurable. Encryption- AES128-GCM-128
- AES256-GCM-128
- HMAC SHA-1
- HMAC SHA-256
- HMAC SHA-384
- HMAC SHA-512
-
MODP
- Diffie-Hellman Group 2 (1024-bit)
- Diffie-Hellman Group 14 (2048-bit)
-
ECP
- Diffie-Hellman Group 19 (256-bit random)
- Diffie-Hellman Group 20 (384-bit random)
- Diffie-Hellman Group 21 (521-bit random)
IP MTU settings
IPsec packets include overhead due to encryption and encapsulation. We recommend that you configure your carefully to suit your network. The maximum value depends on the negotiated ciphers. If you do not configure the IP MTU setting, the MCR will use the following default values:- 96 bytes less than the parent interface IP MTU for IPv4
- 116 bytes less than the parent interface IP MTU for IPv6
Creating a customer-to-customer link using Megaport and IPsec
You can use an IPsec connection between two of your own devices using Megaport services. Prerequisites Before creating an IPsec encrypted link from customer-to-customer, you need:- An IPsec capable router at each of your locations.
- Megaport Ports in locations where you can connect physically from your IPsec capable routers to the Port for each end of your connection.
- From each IPsec capable router, create a physical link to a Megaport Port.
- Use a VXC to connect your Ports.
- Create an IPsec connection over the interfaces connected to Megaport.
Creating a customer-to-cloud link using Megaport and IPsec
Prerequisites Before creating an IPsec encrypted link from customer-to-cloud, you need:- An IPsec capable router.
- A Megaport Port in a location where you can connect physically from your IPsec capable router to the Port.
- A connection to your CSP.
- From your IPsec capable router, create a physical link to a Megaport Port.
- Use VXC to connect the Port to the CSP, AWS Direct Connect in this case.
- Create an IPsec tunnel between your device and the CSP’s VPN services.
Creating a cloud-to-cloud link using Megaport and IPsec
Prerequisites Before creating an IPsec encrypted link from cloud to cloud, you need:- A Megaport Cloud Router (MCR) with IPsec enabled.
- Connections to your CSPs VXCs
- Create a VXC to connect your Direct Connect connection to the MCR.
- Use a VXC to connect the MCR to the ExpressRoute connection.
- Create an IPsec tunnel between the AWS and Azure VPN services.
For more information, see Using IPsec with MCR.
Creating a cloud-to-cloud link using Megaport and IPsec tunnels
Prerequisites Before creating a cloud to cloud link with IPsec tunnels, you need:- A Megaport Cloud Router (MCR) with IPsec enabled.
- Connections established through VXCs to your Cloud Service Providers.
- Create a VXC to connect your Direct Connect connection to the MCR.
- Create a VXC to connect the MCR to the ExpressRoute connection.
- Create an IPsec tunnel on the VXC between the MCR and the Direct Connect connection. For more information, see Using IPsec with MCR.
- Create an IPsec tunnel on the VXC between the MCR and the ExpressRoute connection. For more information, see Using IPsec with MCR.