1 - Overview

Service Overview

VPN (Virtual Private Network) is a service that connects the customer network and Samsung Cloud Platform through an encrypted virtual private network.

Configuration Diagram
Figure. VPN Configuration Diagram

Features

  • Rapid Service Provision You can set up automated services through the web-based Console, and you can use the VPN service immediately without any waiting time after creating the service.

  • Secure Access You can safely access your internal network built on the Samsung Cloud Platform from your customer’s network outside through encrypted virtual tunneling using a performance and stability verified IPsec VPN.

  • Easy Operation Environment You can easily and quickly manage web-based deployment, capacity provisioning, and service updates without the complex network environment configuration.

  • Efficient Service Use It is possible to manage costs efficiently because you can pay only for the amount of service used without any separate installation costs.

Provided Features

VPN provides the following functions.

  • Providing virtual tunneling encrypted with IPsec
    • Compatible VPN: Secui – Bluemax (TG360),Paloalto,Axgate,Cisco-router/ASA/Meraki, Checkpoint,AWS,Azure,Vmware NSX-T
  • Create Virtual Private Gateway
    • Create a Gateway to connect the customer’s network to a private network that cannot be accessed from the outside
  • VPN Tunnel Creation
    • Select IPsec VPN Gateway (The maximum number of VPN Tunnels per VPN Gateway is 5)
    • IPsec VPN Gateway redundancy configuration, when a failure occurs in the Active device, the Standby device operates automatically

Constraints

DivisionBasic QuotaDetailed Description
VPN Gateway33 creations possible per Account
VPN Tunnel5Up to 5 can be created per VPN Gateway
Table. VPN Restrictions

Region-based provision status

VPN is available in the following environments.

RegionAvailability
Western Korea(kr-west1)Provided
South Korea, southern region1(kr-south1)Not provided
South Korea, southern region 2(kr-south2)Not provided
South Korea southern region 3(kr-south3)Provided
Table. Current Status of VPN Services by Region

Preceding Service

Service CategoryServiceDetailed Description
NetworkingVPCA service that provides an independent virtual network in a cloud environment
Fig. Preceding VPN Service

1.1 - ServiceWatch Metrics

VPN sends metrics to ServiceWatch. The metrics provided by basic monitoring are data collected at a 1‑minute interval.

Reference
How to check metrics in ServiceWatch, refer to the ServiceWatch guide.

Basic Indicators

The following are the basic metrics for the VPN namespace.

Performance ItemDetailed DescriptionUnitMeaningful Statistics
Table. VPN Basic Metrics

2 - How-to guides

Creating a VPN

You can create and use VPN services in the Samsung Cloud Platform Console.

Caution
You can create up to 3 VPNs per Account. If you exceed the creation limit, you cannot create a new VPN.

To create a VPN, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.

  2. On the Service Home page, click the Create VPN button. You will be redirected to the Create VPN page.

  3. On the Create VPN page, enter the required information for service creation and select detailed options.

    • Enter the required information in the Service Information section.

      Item
      Required
      Description
      VPN Gateway NameRequiredEnter the VPN Gateway name
      • Enter 3 to 20 characters using alphanumeric characters
      Connected VPC NameRequiredSelect the VPC connected to the VPN Gateway
      • Click + New Creation to create a VPC and then select it
      Public IPRequiredSelect the IP for the VPN Gateway to communicate with remote sites
      Table. VPN Service Information Input Items

    • Enter or select the required information in the Additional Information section.

      Item
      Required
      Description
      DescriptionOptionalUser additional description
      TagsOptionalAdd tags
      • Add up to 50 tags per resource
      • Click the Add Tag button and then enter or select Key and Value values
      Table. VPN Service Additional Information Input Items

  4. On the Summary panel, review the detailed information of creation and estimated charges, then click the Create button.

    • After creation is complete, verify the created resource on the VPN List page.

Viewing VPN Detailed Information

For VPN services, you can view and modify the entire resource list and detailed information. The VPN Detail page consists of Detailed Information, Tags, and Task History tabs.

To view the detailed information of VPN services, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.
  2. On the Service Home page, click the VPN menu. You will be redirected to the VPN List page.
  3. On the VPN List page, click the resource for which you want to view detailed information. You will be redirected to the VPN Detail page.
    • The VPC Detail page displays status information and additional feature information, and consists of Detailed Information, Tags, and Task History tabs.

Detailed Information

You can view the task history of the resource selected on the VPN List page.

ItemDescription
Service StatusCurrent status
  • Active: Operating normally
  • Creating: Creation in progress
  • Editing: Configuration in progress
  • Deleting: Termination in progress
  • Error: Current status unknown
    • If this occurs continuously, contact the registered administrator
Service TerminationVPN Service Termination
Table. VPN Status Information and Additional Features
ItemDescription
ServiceService name
Resource TypeResource type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameVPN resource name
Resource IDUnique resource ID in the service
CreatorUser who created the service
Creation Date/TimeDate/Time when the service was created
ModifierUser who modified the service
Modification Date/TimeDate/Time when the service information was modified
VPN Gateway NameVPN Gateway name
Connected VPC NameVPC name connected to VPN
Public IPIP information for VPN Gateway to communicate with remote sites
DescriptionUser-written additional description
  • Click the Modify icon to modify
Table. VPN Detailed Information Items

Tags

On the VPN List page, you can view the tag information of the selected resource, and add, modify, or delete tags.

ItemDescription
Tag ListTag list
  • View tag Key, Value information
  • Add up to 50 tags per resource
  • When entering tags, search and select from previously created Key and Value lists
Table. VPN Tag Tab Items

Task History

You can view the task history of the resource selected on the VPN Detail page.

ItemDescription
Task History ListResource change history
  • View task date/time, resource name, task details, task results, and task performer information
Table. VPN Task History Tab Detailed Information Items

Terminating a VPN

You can terminate unused VPCs to reduce operating costs. However, since terminating the service can immediately stop operating services, you must fully consider the impact of service interruption before proceeding with termination.

Caution
  • You cannot terminate if there are resources connected to the VPN, such as VPN Tunnels.
  • You cannot terminate if the VPN service status is Creating or Editing.

To terminate a VPN, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.
  2. On the Service Home page, click the VPN menu. You will be redirected to the VPN List page.
  3. On the VPN List page, select the resource to terminate. You will be redirected to the VPN Detail page.
  4. On the VPN Detail page, click the Service Termination button.
  5. After termination is complete, verify that the resource has been terminated on the VPN List page.

2.1 - VPN Tunnel

Creating a VPN Tunnel

You can configure IPSec Tunneling with remote sites in the VPN service using the Samsung Cloud Platform Console.

To create a VPN Tunnel, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.

  2. On the Service Home page, click the Create VPN Tunnel button. You will be redirected to the Create VPN Tunnel page.

  3. On the Create VPN Tunnel page, enter the required information for service creation and select detailed options.

    • Enter the required information in the Service Information section.

      Item
      Required
      Description
      VPN Tunnel NameRequiredEnter the VPN Tunnel name
      • Enter 3 to 20 characters using alphanumeric characters
      VPC Gateway NameRequiredSelect the VPN Gateway to connect
      VPC NameDefaultVPC information connected to VPN Gateway is automatically entered
      Public IPDefaultIP information for VPN Gateway to communicate with remote sites is automatically entered
      Peer VPN GW IPRequiredEnter the IP information of the remote VPN
      • Example: 192.168.10.0
      Remote Subnet(CIDR)RequiredEnter the subnet address of the remote site to connect
      • After entering the IP address, click the Add button, up to 10 can be added
      • Example: 20.0.0.0/24
      Pre-shared KeyRequiredEnter the shared key (PSK) to be used for IKE mutual authentication between VPN gateways
      • Enter 8 to 64 characters
      • Recommended to use a 32-character alphanumeric combination string
      DescriptionOptionalUser additional description
      Table. VPN Tunnel Service Information Input Items

    • Enter or select the required information in the Tunnel Configuration section.

      Item
      Required
      Description
      IKE Configuration > IKE VersionRequiredSelect IKE version
      IKE Configuration > Algorithm ConfigurationRequiredSelect Encryption Algorithm and Digest Algorithm, then click the Add button
      IKE Configuration > Diffie-HellmanRequiredSelect Diffie-Hellman group
      IKE Configuration > SA LifeTimeRequiredEnter the VPN session (Security Association) validity period
      IPSec Configuration > Algorithm ConfigurationRequiredSelect Encryption Algorithm and Digest Algorithm, then click the Add button
      IPSec Configuration > Perfect Forward Secrecy(PFS)RequiredSelect whether to use PFS group
      IPSec Configuration > Diffie-HellmanRequiredSelect Diffie-Hellman group
      IPSec Configuration > SA LifeTimeRequiredEnter the VPN session (Security Association) validity period
      Table. VPN Tunnel Configuration Items

    • Enter the required information in the DPD Additional Configuration section.

      Item
      Required
      Description
      DPD Additional Configuration > DPD probe intervalRequiredEnter the DPD check interval
      • Enter a value between 1 and 3,600 seconds
      Table. VPN Tunnel DPD Additional Configuration Input Items

    • Enter or select the required information in the Additional Information section.

      Item
      Required
      Description
      TagsOptionalAdd tags
      • Add up to 50 tags per resource
      • Click the Add Tag button and then enter or select Key and Value values
      Table. VPN Tunnel Additional Information Input Items

  4. On the Summary panel, review the detailed information of creation and estimated charges, then click the Create button.

    • After creation is complete, verify the created resource on the VPN Tunnel List page.

Viewing VPN Tunnel Detailed Information

For VPN Tunnel services, you can view and modify the entire resource list and detailed information. The VPN Tunnel Detail page consists of Detailed Information, Tags, and Task History tabs.

To view VPN detailed information, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.
  2. On the Service Home page, click the Create VPN Tunnel button. You will be redirected to the VPN Tunnel List page.
  3. On the VPN Tunnel List page, click the resource for which you want to view detailed information. You will be redirected to the VPN Tunnel Detail page.
    • The VPN Tunnel Detail page displays status information and additional feature information, and consists of Detailed Information, Tags, and Task History tabs.
ItemDescription
StatusCurrent status
  • Active: Operating normally
  • Creating: Creating
  • Editing: Changing information
  • Deleting: Deleting
  • Error: Cannot confirm current status
    • If this occurs continuously, contact the registered administrator
VPN Tunnel DeletionVPN Tunnel delete button
Table. VPN Tunnel Status Information and Additional Features

Detailed Information

On the VPN Tunnel List page, you can view the detailed information of the selected resource and modify the information if necessary.

ItemDescription
ServiceService name
Resource TypeResource type
SRNUnique resource ID in Samsung Cloud Platform
Resource NameVPN resource name
Resource IDUnique resource ID in the service
CreatorUser who created the service
Creation Date/TimeDate/Time when the service was created
ModifierUser who modified the service information
Modification Date/TimeDate/Time when the service information was modified
VPN Tunnel NameVPN Tunnel name
VPN Gateway NameVPN Gateway name
Public IPPublic IP information
Peer VPN GW IPPeer VPN GW information
  • Click the Modify icon to modify
Remote Subnet (CIDR)Remote Subnet information
  • Click the Modify icon to modify
Pre-shared KeyPre-shared Key information
  • Click the Modify icon to modify
StatusCurrent service connection status
DescriptionVPN Tunnel additional description
  • Click the Modify icon to modify
IKEClick the Modify button to modify configuration information in bulk
IKE VersionIKE Version information
Encryption Algorithm/Digest AlgorithmAlgorithm information
Diffie-HellmanDiffie-Hellman information
SA LifeTimeSA LifeTime information
IPSecClick the Modify button to modify configuration information in bulk
Encryption Algorithm/Digest AlgorithmAlgorithm information
Diffie-HellmanDiffie-Hellman information
SA LifeTimeSA LifeTime information
Perfect Forward Secrecy(PFS)PFS configuration information
DPDDPD probe interval information
  • Click the Modify icon to modify
Table. VPN Tunnel Detailed Information Items

Tags

On the VPN Tunnel List page, you can view the tag information of the selected resource, and add, modify, or delete tags.

ItemDescription
Tag ListTag list
  • View tag Key, Value information
  • Add up to 50 tags per resource
  • When entering tags, search and select from previously created Key and Value lists
Table. VPN Tunnel Tag Tab Items

Task History

You can view the task history of the resource selected on the VPN Tunnel List page.

ItemDescription
Task History ListResource change history
  • View task date/time, resource name, task details, task results, and task performer information
Table. VPN Tunnel Task History Tab Detailed Information Items

Deleting a VPN Tunnel

You can delete unused VPC Tunnels to reduce operating costs. However, since deleting a Tunnel can immediately stop operating services, you must fully consider the impact of service interruption before proceeding with deletion.

To delete a VPN, follow these steps:

  1. Click the All Services > Networking > VPN menu. You will be redirected to the VPN Service Home page.
  2. On the Service Home page, click the Create VPN Tunnel button. You will be redirected to the VPN Tunnel List page.
  3. On the VPN Tunnel List page, click the resource for which you want to view detailed information. You will be redirected to the VPN Tunnel Detail page.
  4. Click the VPN Tunnel Delete button.
  5. After deletion is complete, verify that the resource has been deleted on the VPN Tunnel List page.

3 - API Reference

API Reference

4 - CLI Reference

CLI Reference

5 - Release Note

VPN

2025.10.23
FEATURE Change in the number of additional remote site subnets for VPN Tunnel
  • You can enter up to 10 remote subnets (CIDR).
2024.02.27
NEW Official Release of VPN Service
  • A VPN service has been released that connects the customer network and Samsung Cloud Platform through an encrypted (IPSec) virtual private network.