This is the multi-page printable view of this section. Click here to print.
VPN
- 1: Overview
- 1.1: ServiceWatch Metrics
- 2: How-to guides
- 2.1: VPN Tunnel
- 3: API Reference
- 4: CLI Reference
- 5: Release Note
1 - Overview
Service Overview
VPN (Virtual Private Network) is a service that connects the customer’s network to the Samsung Cloud Platform via an encrypted virtual private network.
Features
Prompt Service Delivery You can configure automated services through a web-based console, and after creating a service, you can use the VPN service immediately without any waiting time.
Thorough Secure Connection You can securely connect from a customer’s external network to the customer’s internal network built on the Samsung Cloud Platform via encrypted virtual tunneling using a performance‑ and reliability‑validated IPsec VPN.
Simple operating environment You can easily and quickly manage web-based deployment, capacity provisioning, and service updates without the need for a complex network environment setup.
Efficient Service Use You can manage costs efficiently because you only pay for the amount of service used, without any separate installation fees.
Provided features
VPN provides the following features.
- Provide virtual tunneling encrypted with IPsec
- Compatible VPN: Secui – Bluemax (TG360),Paloalto,Axgate,Cisco-router/ASA/Meraki, Checkpoint,AWS,Azure,Vmware NSX-T
- Create Virtual Private Gateway
- Create a gateway to connect the customer’s network to a private network that cannot be accessed from outside.
- Create VPN Tunnel
- Select IPsec VPN Gateway (maximum of 5 VPN tunnels per VPN Gateway)
- In an IPsec VPN Gateway high-availability configuration, the Standby device automatically operates when a failure occurs on the Active device.
Constraints
| Category | Default quota | Detailed description |
|---|---|---|
| VPN Gateway | 3 | Up to three can be created per account |
| VPN Tunnel | 5 | Up to 5 can be created per VPN Gateway |
Provision status by region
VPN is available in the environments below.
| Region | Provision status |
|---|---|
| Korea West (kr-west1) | Provide |
| Korea East (kr-east1) | Provide |
| South Korea South 1 (kr-south1) | Not provided |
| South Korea South 2 (kr-south2) | Not provided |
| South Korea South 3(kr-south3) | Provide |
Preliminary Service
| Service Category | service | Detailed description |
|---|---|---|
| Networking | VPC | A service that provides an isolated virtual network in a cloud environment |
1.1 - ServiceWatch Metrics
VPN sends metrics to ServiceWatch. The metrics provided by default monitoring are data collected at a 1‑minute interval.
Basic Metrics
The following are the basic metrics for the VPN namespace.
The indicators whose names are displayed in bold below are the key indicators selected from the basic indicators provided by VPN. Key metrics are used to configure service dashboards that are automatically built for each service in ServiceWatch.
Each metric indicates, via the user guide, which statistical value is meaningful when viewing that metric, and among the meaningful statistics, the values shown in bold are the primary statistics. In the service dashboard, you can view key metrics using these primary statistical values.
| Performance items | Detailed description | unit | meaningful statistics |
|---|---|---|---|
| Network In Total Bytes _vpn_tunnel | Cumulative traffic volume heading from VPN → VPC | Bytes |
|
| Network Out Total Bytes _vpn_tunnel | Cumulative traffic volume from VPC → VPN | Bytes |
|
| Network In Total Bytes _vpn_tunnel_Delta | Cumulative traffic volume over 5 minutes from VPN → VPC | Bytes |
|
| Network Out Total Bytes _vpn_tunnel_Delta | Cumulative traffic volume over 5 minutes from VPC → VPN | Bytes |
|
2 - How-to guides
Create VPN
You can create and use a VPN service from the Samsung Cloud Platform Console.
To create a VPN, follow these steps.
Click the All Services > Networking > VPN menu. You will be taken to the VPN Service Home page.
On the Service Home page, click the Create VPN button. You will be taken to the Create VPN page.
On the VPN creation page, enter the information required to create the service and select detailed options.
Enter the required information in the Service Information Input area.
Category Required statusDetailed description VPN Gateway name Required Enter VPN Gateway name - Enter using English letters and numbers, within 3 to 20 characters
Connected VPC name Required Select the VPC connected to the VPN Gateway - Click + New to create a VPC and then select it
Public IP Required Select the IP for communicating with the remote site from the VPN Gateway. Table. VPN Service Information Input ItemsEnter or select the required information in the Additional Information Input area.
Category Required statusDetailed description Explanation Selection User additional description tag Selection Add Tag - Up to 50 can be added per resource
- After clicking the Add Tag button, enter or select Key, Value values.
Table. VPN service additional information input fields
Summary Check the detailed information and estimated billing amount generated in the panel, and click the Create button.
- After creation is complete, check the created resources on the VPN List page.
Check VPN detailed information
The VPN service allows you to view and edit the full resource list and detailed information. VPN Details page consists of Details, Tags, Activity Log tabs.
To view detailed information about the VPN service, follow these steps.
- Click the All Services > Networking > VPN menu. You will be taken to the VPN’s Service Home page.
- On the Service Home page, click the VPN menu. You will be taken to the VPN List page.
- On the VPN List page, click the resource to view detailed information. You will be taken to the VPN Details page.
- VPC Details page displays status information and additional feature information, and consists of Details, Tags, Activity History tabs.
Detailed Information
On the VPN List page, you can view the operation history of the selected resource.
| Category | Detailed description |
|---|---|
| Service status | Current status
|
| Service termination | Cancel VPN service |
| Category | Detailed description |
|---|---|
| Service | Service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource name | VPN resource name |
| Resource ID | Unique resource ID in the service |
| constructor | User who created the service |
| Creation timestamp | Service creation timestamp |
| Editor | User who modified the service |
| Modification date and time | Date and time the service information was modified |
| VPN Gateway name | VPN Gateway name |
| Connected VPC name | VPC name connected to VPN |
| Public IP | IP information for communicating with remote sites from the VPN Gateway |
| Explanation | Additional description written by the user
|
tag
On the VPN List page, you can view the tag information of the selected resource, and you can add, modify, or delete it.
| Category | Detailed description |
|---|---|
| Tag list | Tag list
|
Job History
On the VPN Details page, you can view the operation history of the selected resource.
| Category | Detailed description |
|---|---|
| Task History List | Resource Change History
|
Terminate VPN
You can terminate unused VPCs to reduce operating costs. However, terminating a service may cause the running service to stop immediately, so you should thoroughly consider the impact of service interruption before proceeding with the termination.
- If there are resources connected to a VPN, such as a VPN Tunnel, they cannot be terminated.
- The VPN service cannot be canceled when its status is Creating or Editing.
To cancel the VPN, follow these steps.
- Click the All Services > Networking > VPN menu. Go to the VPN Service Home page.
- From the Service Home page, click the VPN menu. You will be taken to the VPN List page.
- On the VPN List page, select the resource to cancel. Navigate to the VPN Details page.
- On the VPN Details page, click the Cancel Service button.
- Once the termination is complete, check on the VPN List page whether the resource has been terminated.
2.1 - VPN Tunnel
Create VPN Tunnel
In the Samsung Cloud Platform Console, you can configure IPSec Tunning with remote sites in the VPN service.
To create a VPN tunnel, follow these steps.
Click the All Services > Networking > VPN menu. Navigate to the VPN Service Home page.
On the Service Home page, click the Create VPN Tunnel button. You will be taken to the Create VPN Tunnel page.
On the VPN Tunnel creation page, enter the information required to create the service, and select detailed options.
Enter the required information in the Service Information Input area.
Category Required statusDetailed description VPN Tunnel name Required Enter VPN Tunnel name - Enter using English letters and numbers, within 3 - 20 characters
VPC Gateway name Required Select the VPN Gateway to connect VPC name Basic Automatically input VPC information connected to the VPN Gateway Public IP Basic Automatic entry of IP information for communicating with remote sites from the VPN Gateway Peer VPN GW IP Required Enter the IP information of the remote VPN - Example: 192.168.10.0
Romote Subnet(CIDR) Required Enter the subnet address of the remote site to connect - After entering the IP address, click the Add button; you can add up to 10 entries
- Example: 20.0.0.0/24
Pre-shared Key Required Enter the shared key (PSK) to be used for IKE mutual authentication between VPN gateways - Enter between 8 and 64 characters
- It is recommended to use a 32-character alphanumeric string
Explanation Select User additional description Table. VPN Tunnel Service Information Input ItemsEnter or select the required information in the Tunnel Settings area.
Category RequiredDetailed description IKE Settings > IKE Version Required Select IKE version IKE Settings > Algorithm Settings Required Select Encryption Algorithm and Digest Algorithm, then click the Add button. IKE configuration > Diffie-Hellman Required Diffie-Hellman Group Selection IKE configuration > SA Lifetime Required Enter the VPN session (Security Association) lifetime IPSec Settings > Algorithm Settings Required Select Encryption Algorithm and Digest Algorithm, then click the Add button. IPSec Settings > Perfect Forward Secrecy (PFS) Required Select whether to use the PFS group IPSec Settings > Diffie-Hellman Required Diffie-Hellman group selection IPSec Settings > SA Lifetime Required Enter the VPN session (Security Association) lifetime Table. VPN Tunnel configuration itemsEnter the required information in the DPD additional settings area.
Category RequiredDetailed description DPD additional settings > DPD probe interval Required Enter DPD test interval - Enter a value between 1 and 3,600 seconds
Table. VPN Tunnel DPD Additional Settings Input ItemsIn the Additional Information Input area, enter or select the required information.
Category RequiredDetailed description tag Select Add Tag - Up to 50 can be added per resource
- After clicking the Add Tag button, enter or select Key and Value values
Table. VPN Tunnel additional information input fields
Summary Check the detailed information and estimated billing amount generated in the panel, and click the Create button.
- When creation is complete, check the created resource on the VPN Tunnel List page.
Check VPN Tunnel detailed information
VPN Tunnel service allows you to view and edit the full resource list and detailed information. VPN Tunnel Details page consists of Details, Tags, Activity Log tabs.
To view detailed VPN information, follow these steps.
- Click the All Services > Networking > VPN menu. Navigate to the VPN Service Home page.
- On the Service Home page, click the Create VPN Tunnel button. You will be taken to the VPN Tunnel List page.
- On the VPN Tunnel List page, click the resource to view detailed information. You will be taken to the VPN Tunnel Details page.
- VPN Tunnel Details page displays status information and additional feature information, and consists of Details, Tags, Activity Log tabs.
| Category | Detailed description |
|---|---|
| Status | Current status
|
| Delete VPN Tunnel | VPN Tunnel delete button |
Detailed Information
On the VPN Tunnel List page, you can view detailed information of the selected resource and, if necessary, edit the information.
| Category | Detailed description |
|---|---|
| Service | Service name |
| Resource Type | Resource Type |
| SRN | Unique resource ID in Samsung Cloud Platform |
| Resource name | VPN resource name |
| Resource ID | Unique resource ID in the service |
| constructor | User who created the service |
| Creation date | Service creation timestamp |
| Editor | User who edited the service information |
| Modification date | Date and time the service information was modified |
| VPN Tunnel name | VPN Tunnel name |
| VPN Gateway name | VPN Gateway name |
| Public IP | Public IP information |
| Peer VPN GW IP | Peer VPN GW Information
|
| Remote Subnet (CIDR) | Remote Sunet information
|
| Pre-shared Key | Pre-shared Key information
|
| status | Current service connection status |
| description | VPN Tunnel additional description
|
| IKE | Click the Edit button to bulk edit configuration information. |
| IKE Version | IKE Version information |
| Encryption Algorithm/Digest Algorithm | Algorithm information |
| Diffie-Hellman | Diffie-Hellman information |
| SA LifeTime | SA LifeTime information |
| IPSec | Click the Edit button to bulk edit the configuration information. |
| Encryption Algorithm/Digest Algorithm | Algorithm information |
| Diffie-Hellman | Diffie-Hellman information |
| SA LifeTime | SA LifeTime information |
| Perfect Forward Secrecy(PFS) | PFS configuration information |
| DPD | DPD probe interval information
|
tag
On the VPN Tunnel List page, you can view the tag information of the selected resource, and you can add, modify, or delete it.
| Category | Detailed description |
|---|---|
| Tag list | Tag list
|
Job History
VPN Tunnel List page allows you to view the operation history of the selected resource.
| Category | Detailed description |
|---|---|
| Task History List | Resource Change History
|
Delete VPN Tunnel
You can reduce operational costs by deleting unused VPC tunnels. However, deleting a tunnel may cause the running service to stop immediately, so you should carefully consider the impact of service interruption before proceeding with the deletion.
To cancel the VPN, follow these steps.
- Click the All Services > Networking > VPN menu. You will be taken to the VPN Service Home page.
- On the Service Home page, click the Create VPN Tunnel button. You will be taken to the VPN Tunnel List page.
- On the VPN Tunnel List page, click the resource to view detailed information. You will be taken to the VPN Tunnel Details page.
- VPN Tunnel Delete Click the button.
- After termination is complete, check the VPN Tunnel List page to see if the resource has been deleted.
3 - API Reference
4 - CLI Reference
5 - Release Note
VPN
- You can input up to 10 Romote Subnet (CIDR).
- A VPN service that connects the customer network to the Samsung Cloud Platform via an encrypted (IPSec) virtual private network has been launched.
