If you have an MCR with Megaport Internet in Mexico or the Netherlands, you must keep IPsec enabled. You cannot disable IPsec in these markets. For more information, see Megaport Internet Overview.
Supported ciphers
The MCR will offer the following ciphers to IPsec peers. At this time, the options are not configurable. Encryption- AES128-GCM-128
- AES256-GCM-128
- HMAC SHA-1
- HMAC SHA-256
- HMAC SHA-384
- HMAC SHA-512
-
MODP
- Diffie-Hellman Group 2 (1024-bit)
- Diffie-Hellman Group 14 (2048-bit)
-
ECP
- Diffie-Hellman Group 19 (256-bit random)
- Diffie-Hellman Group 20 (384-bit random)
- Diffie-Hellman Group 21 (521-bit random)
IP MTU settings
IPsec packets include overhead due to encryption and encapsulation. We recommend that you configure your carefully to suit your network. The maximum value depends on the negotiated ciphers. If you do not configure the IP MTU setting, the MCR will use the following default values:- 96 bytes less than the parent interface IP MTU for IPv4
- 116 bytes less than the parent interface IP MTU for IPv6
Enabling and configuring IPsec on an MCR
Enabling IPsec on an MCR
To enable IPsec when you are creating an MCR, click + Add IPsec on the Connection Details page. For more information, see Creating an MCR. You configure the IPsec connection details on the MCR VXC, as described below.Configuring IPsec on an MCR
Prerequisites To configure IPsec for an MCR connection, you will need:- A configured interface — For each VXC connected to an MCR, you can configure one or more interfaces. The IPsec tunnel details are dependent on having an IP address on the interface tab. Each MCR VXC will have one interface by default, but you can add more. For more information, see the A-End interface section of Creating an MCR VXC.
-
Pre-shared key — This is a value that you provide. It is used as part of establishing the tunnel on both ends.
- The length must be between 8 and 100 characters.
- This is a required field.
- Destination IP Address — The IP address of the destination endpoint in IPv4/6 format. For example, 192.168.1.2.
-
Create your connection, such as a cloud or private VXC.
For more information, see Creating an MCR VXC. - Wait for the connection to be live, then click the gear icon next to the VXC to edit the details.
- Click Next or click A-End on the header.
-
Add a description to the Interface presented on the page, if required.
This is the default interface. -
Click + Add IPsec Tunnel Interface.
Add the IPsec tunnel details:- Description — Enter a description of the IPsec tunnel for your reference.
- Source IP Address — Click the box and select the address from the drop-down list.
This is a list of interface IP addresses defined on this VXC. - Destination IP Address — Add the destination IP address.
The destination IP address of the tunnel must not be an IP address configured on the same MCR. - Pre-shared key — Add a key that is common to both the IKE2 (Internet Key Exchange version 2) initiator and responder. The length must be between 8 and 100 characters.
- Local Identifier (optional) — Enter the identifier used for IKE authentication. This allows you to override the default source IP address with a non-IP address, which is required for some configurations. By default, the source IP address is used. Valid values include IPv4/IPv6 addresses, domain names, and email addresses (lowercase, 5-100 characters). For example,
megaport.comoruser@example.com. - Remote Identifier (optional) — Enter the identifier used for IKE authentication. This allows you to override the default destination IP address with a non-IP address, which is required for some configurations. By default, the destination IP address is used. Valid values include IPv4/IPv6 addresses, domain names, and email addresses (lowercase, 5-100 characters). For example,
megaport.comoruser@example.com. - Start Action — Select either active or passive. Passive indicates that the local MCR is an IPsec responder waiting for the remote to perform IKE2 initiation.
- Phase 1 Lifetime — Enter a value between 300 and 604800 seconds. This is the lifetime of IKE2 session in seconds. The default value is 28800 seconds (8 hours). When it expires, rekeying will occur.
- Phase 2 Lifetime — Enter a value between 300 and 86400 seconds. This is the lifetime in seconds of the IPsec Security Association (SA). The value must be less than the Phase 1 Lifetime. The default value is 3600 seconds (1 hour). When it expires, rekeying will occur.
- Scroll down the page and click Save.