{"id":282,"date":"2021-01-21T17:02:25","date_gmt":"2021-01-21T16:02:25","guid":{"rendered":"http:\/\/vminded.com\/?p=282"},"modified":"2021-01-28T15:09:23","modified_gmt":"2021-01-28T14:09:23","slug":"configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/","title":{"rendered":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3"},"content":{"rendered":"\n<p>In this Part, I will show you how to configure an <strong>IPsec VPN<\/strong> from the &#8220;spoke&#8221; native VPC to the Firebox instance deployed in the transit VPC. This permits to leverage the Watchguard Firewall instance in the transit VPC as a filtering device from any trafic coming outside (SDDC, spoke VPC, on-prem).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-phase-1-vpc-s-vpn-configuration\">Phase 1 \u2013 VPC&#8217;s VPN Configuration<\/h2>\n\n\n\n<p>In order to configure the VPN in the VPC, I need to do some preparation in the native VPC which consists in creating a Customer Gateway, a Virtual Private Gateway and attach them together.<\/p>\n\n\n\n<p>To do so, let&#8217;s first <strong>Connect to the <a href=\"https:\/\/console.aws.amazon.com\" target=\"_blank\" rel=\"noreferrer noopener\">AWS console<\/a><\/strong> again!<\/p>\n\n\n\n<p>Select <strong>IAM User<\/strong> and enter <strong>ID<\/strong> of your <strong><a href=\"https:\/\/aws.amazon.com\/account\/?nc1=h_ls\" target=\"_blank\" rel=\"noreferrer noopener\">AWS account<\/a><\/strong><\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\" alt=\"\" class=\"wp-image-293\" width=\"564\" height=\"333\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg 941w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in-300x177.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in-768x454.jpg 768w\" sizes=\"auto, (max-width: 564px) 85vw, 564px\" \/><\/figure><\/div>\n\n\n\n<p>Log in with the&nbsp;user account that have the administrative privileges on this account.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/AWS-User-account-.jpg\" alt=\"\" class=\"wp-image-294\" width=\"566\" height=\"337\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/AWS-User-account-.jpg 922w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/AWS-User-account--300x179.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/AWS-User-account--768x458.jpg 768w\" sizes=\"auto, (max-width: 566px) 85vw, 566px\" \/><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\">Create a Customer Gateway<\/h3>\n\n\n\n<p>NI have to go to the <strong>VPC Dashboard<\/strong> and Select <strong>Customer Gateways<\/strong> under <strong>VIRTUAL PRIVATE NETWORK<\/strong> Menu on the left.<\/p>\n\n\n\n<p>I click <strong>Create Customer Gateway <\/strong>and choose <strong>Dynamic <\/strong>as a routing option, add the public <strong>Elastic-IP<\/strong> address of the FW. Specify the <strong>BGP ASN<\/strong> to a value different from the potential peer.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"495\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway-1024x495.jpg\" alt=\"\" class=\"wp-image-313\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway-1024x495.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway-300x145.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway-768x371.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway-1200x580.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Customer-Gateway.jpg 1384w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-create-a-virtual-private-gateway\">Create a Virtual Private Gateway<\/h3>\n\n\n\n<p>I&#8217;ll now create a brand new <strong>Virtual Private Gateway<\/strong> and attach it to the <strong>spoke VPC<\/strong> created earlier.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"275\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW-1024x275.jpg\" alt=\"\" class=\"wp-image-316\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW-1024x275.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW-300x81.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW-768x206.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW-1200x323.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Create-a-VGW.jpg 1384w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>The <strong>VGW<\/strong> appears as detached:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"24\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw-1024x24.jpg\" alt=\"\" class=\"wp-image-319\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw-1024x24.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw-300x7.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw-768x18.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw-1200x29.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/detached-vgw.jpg 1384w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>I&#8217;ll select it and in the <strong>Actions<\/strong> drop-down menu, I select <strong>Attach to VPC<\/strong> option:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"330\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc-1024x330.jpg\" alt=\"\" class=\"wp-image-320\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc-1024x330.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc-300x97.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc-768x247.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc-1200x387.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attach-to-vpc.jpg 1384w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p>It now shows as attached:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"27\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw-1024x27.jpg\" alt=\"\" class=\"wp-image-321\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw-1024x27.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw-300x8.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw-768x20.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw-1200x31.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/attached-vgw.jpg 1384w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-create-a-vpn-connection\">Create a VPN Connection<\/h3>\n\n\n\n<p>Now I will create the <strong>VPN Connection <\/strong>by associating the <strong>VGW<\/strong> to the <strong>Customer Gateway <\/strong>that I have created:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection-1024x527.jpg\" alt=\"\" class=\"wp-image-327\" width=\"534\" height=\"274\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection-1024x527.jpg 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection-300x154.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection-768x395.jpg 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection-1200x618.jpg 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/create-VPN-Connection.jpg 1234w\" sizes=\"auto, (max-width: 534px) 85vw, 534px\" \/><\/figure><\/div>\n\n\n\n<p>Once the VPN connection available, I select <strong>Download Configuration<\/strong>. This will open the following window:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Download-Configuration.jpg\" alt=\"\" class=\"wp-image-331\" width=\"527\" height=\"194\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Download-Configuration.jpg 974w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Download-Configuration-300x111.jpg 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Download-Configuration-768x284.jpg 768w\" sizes=\"auto, (max-width: 527px) 85vw, 527px\" \/><\/figure><\/div>\n\n\n\n<p>I select <strong>Watchguard, inc.<\/strong> as a Vendor and click <strong>Download<\/strong> button. A file containing all the configuration is created. I am going to use it to configure the Firebox now.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-phase-2-firebox-s-vpn-configuration\">Phase 2 \u2013 FireBox\u2019s VPN Configuration<\/h2>\n\n\n\n<p>First I need to <strong>Connect to Fireware Web UI<\/strong> by opening a web browser to the public IP address of the Firebox Cloud instance<br><strong><em>https:\/\/&lt;eth0_public_IP&gt;:8080<\/em><\/strong><\/p>\n\n\n\n<p>I log in with the&nbsp;<em>admin<\/em>&nbsp;user account and I make sure to specify the passphrase I have set in the Firebox Cloud Setup Wizard.<\/p>\n\n\n\n<p>Then I Select <strong>VPN<\/strong>, <strong>BOVPN Virtual Interfaces<\/strong> on the left and click the <strong>lock icon<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-resized is-style-default\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Watchguard-menu.jpg\" alt=\"\" class=\"wp-image-336\" width=\"178\" height=\"363\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Watchguard-menu.jpg 275w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Watchguard-menu-147x300.jpg 147w\" sizes=\"auto, (max-width: 178px) 85vw, 178px\" \/><\/figure>\n\n\n\n<p>First I started by following the instruction in the VPN configuration file downloaded earlier. <\/p>\n\n\n\n<p>So I enter the interface name and switch the <strong>Remote Endpoint Type<\/strong> to <strong>Cloud VPN or Third Party Gateway<\/strong>.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21-1024x503.png\" alt=\"\" class=\"wp-image-337\" width=\"585\" height=\"287\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21-1024x503.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21-300x147.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21-768x377.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21-1200x589.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.21.png 1238w\" sizes=\"auto, (max-width: 585px) 85vw, 585px\" \/><\/figure><\/div>\n\n\n\n<p>In the <strong>Gateway Settings<\/strong>-&gt; <strong>Credential Method<\/strong>, I have entered the <strong>Use Pre-Shared Key<\/strong> stated in the file:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54.png\" alt=\"\" class=\"wp-image-340\" width=\"460\" height=\"278\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54.png 892w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-300x182.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-768x465.png 768w\" sizes=\"auto, (max-width: 460px) 85vw, 460px\" \/><\/figure><\/div>\n\n\n\n<p>In the Gateway Settings&#8211;&gt;Gateway Endpoint&#8211;&gt;Click ADD:. Select Local Gateway&#8211;&gt;Interface:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10-1024x985.png\" alt=\"\" class=\"wp-image-341\" width=\"477\" height=\"459\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10-1024x985.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10-300x289.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10-768x739.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10.png 1108w\" sizes=\"auto, (max-width: 477px) 85vw, 477px\" \/><\/figure><\/div>\n\n\n\n<p>I need now to Specify the gateway ID for tunnel authentication. I select <strong>By IP address<\/strong>: here I enter the following 34.210.196.xxx (this is the public Elastic-IP of the firebox).<\/p>\n\n\n\n<p>Now I have to Select Remote Gateway&#8211;&gt;Specify the remote gateway IP address for a tunnel to <strong>Static IP<\/strong> and enter the public IP of my SDDC.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.35.54-1024x971.png\" alt=\"\" class=\"wp-image-342\" width=\"510\" height=\"483\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.35.54-1024x971.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.35.54-300x285.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.35.54-768x728.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.35.54.png 1124w\" sizes=\"auto, (max-width: 510px) 85vw, 510px\" \/><\/figure><\/div>\n\n\n\n<p>Select Advanced&#8211;&gt;Click <strong>OK<\/strong><\/p>\n\n\n\n<p>I have checked &#8216;<strong>Start Phase1 tunnel when it is inactive<\/strong>&#8216; and kept the &#8216;<strong>Add this tunnel to the BOVPN-Allow policies<\/strong>&#8216; checked.<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00.png\" alt=\"\" class=\"wp-image-345\" width=\"348\" height=\"267\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00.png 634w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00-300x231.png 300w\" sizes=\"auto, (max-width: 348px) 85vw, 348px\" \/><\/figure><\/div>\n\n\n\n<p>We need to select the following for <strong>Phase 1 Settings<\/strong>:<\/p>\n\n\n\n<p>1. <strong>Version:<\/strong> IKEv2<br>2. <strong>Mode: <\/strong>Main<br>3. Uncheck <strong>NAT Traversal<\/strong><\/p>\n\n\n\n<p><em>NAT Traversal is enabled by default but if your WatchGuard device is not behind a NAT\/PAT device, please deselect NAT Traversal.<\/em><\/p>\n\n\n\n<p>For the <strong>Dead Peer Detection<\/strong>, choose the following values:<\/p>\n\n\n\n<p>a. <strong>Traffic idle timeout<\/strong>: 10<br>b. <strong>Max retries: <\/strong>3<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.39.43-1024x730.png\" alt=\"\" class=\"wp-image-348\" width=\"428\" height=\"305\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.39.43-1024x730.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.39.43-300x214.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.39.43-768x548.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.39.43.png 1080w\" sizes=\"auto, (max-width: 428px) 85vw, 428px\" \/><\/figure><\/div>\n\n\n\n<p>Next we have to change the <strong>Transform Settings<\/strong> by clicking <strong>ADD<\/strong> et setup the following values:<\/p>\n\n\n\n<p>1. <strong>Authentication:<\/strong> SHA1<br>2. <strong>Encryption: <\/strong>AES(128-bit)<br>3. <strong>SA Life:<\/strong> 8 hours<br>4. <strong>Key Group: <\/strong>Diffie-Hellman Group 2<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1024x140.png\" alt=\"\" class=\"wp-image-350\" width=\"410\" height=\"56\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1024x140.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-300x41.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-768x105.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1200x164.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35.png 1406w\" sizes=\"auto, (max-width: 410px) 85vw, 410px\" \/><\/figure><\/div>\n\n\n\n<p>Click <strong>OK <\/strong>and Remove any pre-existing <strong>Phase 1 Transform Settings<\/strong> (eg. SHA1-3DES).<\/p>\n\n\n\n<p>Now we need to configure<strong> Phase 2<\/strong> of IPSEC <em>Proposal<\/em>.<\/p>\n\n\n\n<p>I need to Go to VPN&#8211;&gt;Phase2 Proposals&#8211;&gt;Click ADD:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>Name: AWS-ESP-AES128-SHA1<\/li><li>Description: AWS Phase 2 Proposal<\/li><li>Type: ESP<\/li><li>Authentication: SHA1<\/li><li>Encryption: AES(128-bit)<\/li><li>Force Key Expiration: Select &#8216;Time&#8217; -&gt; 1 hours<\/li><\/ul>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"676\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1024x676.png\" alt=\"\" class=\"wp-image-356\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1024x676.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-300x198.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-768x507.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1200x793.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27.png 1502w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Go to VPN&#8211;&gt;BOVPN Virtual Interfaces&#8211;&gt;Select vpn-054bfd003f8ac9d2d-1&#8211;&gt;Click EDIT<\/li><\/ol>\n\n\n\n<p>Phase 2 Settings&#8211;&gt;Perfect Forward Secrecy:<\/p>\n\n\n\n<p>Check <strong>&#8216;Enable Perfect Forward Secrecy&#8217;<\/strong>: Diffie-Hellman Group 2<br>IPSec Proposals&#8211;&gt;Click on existing proposal&#8211;&gt;Click <strong>REMOVE<br><\/strong>Select <strong>&#8216;AWS-ESP-AES128-SHA1&#8217;<\/strong> from the drop-down menu&#8211;&gt;Click <strong>ADD<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"1017\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-1024x1017.png\" alt=\"\" class=\"wp-image-359\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-1024x1017.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-300x298.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-150x150.png 150w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-768x762.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14-1200x1191.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.51.14.png 1374w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-phase-3-configure-bgp-routing\">Phase 3 &#8211; Configure BGP Routing<\/h2>\n\n\n\n<p>It&#8217;s now time to configure <strong><a href=\"https:\/\/www.cloudflare.com\/learning\/security\/glossary\/what-is-bgp\/\" target=\"_blank\" rel=\"noreferrer noopener\">BGP<\/a><\/strong> dynamic routing.<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>Go to VPN&#8211;&gt;BOVPN Virtual Interfaces&#8211;&gt;Select vpn-054bfd003f8ac9d2d-1&#8211;&gt;Click EDIT<\/li><li>VPN Routes:<\/li><\/ol>\n\n\n\n<p>In the<strong> Interface<\/strong> window, keep &#8216;<em>Assign virtual interface IP addresses<\/em>&#8216; option checked:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"864\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1024x864.png\" alt=\"\" class=\"wp-image-364\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1024x864.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-300x253.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-768x648.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07.png 1072w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<p>Go to Network&#8211;&gt;Dynamic Routing<\/p>\n\n\n\n<p>Check <strong>&#8216;Enable Dynamic Routing&#8217;<\/strong><\/p>\n\n\n\n<p>Click on &#8216;BGP&#8217; tab:<\/p>\n\n\n\n<figure class=\"wp-block-image size-large is-style-default\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"442\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32-1024x442.png\" alt=\"\" class=\"wp-image-368\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32-1024x442.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32-300x130.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32-768x332.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32-1200x518.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.58.32.png 1362w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Check &#8216;<strong>Enable<\/strong>&#8216;<\/p>\n\n\n\n<p>Add the BGP dynamic routing configuration commands in the box as seen above.<\/p>\n\n\n\n<p>We have to add the line: <strong>router bgp 65001&nbsp;<\/strong>&nbsp;but only once at the beginning of the BGP config.<\/p>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-phase-4-check-tunnel-is-established\">Phase 4 &#8211; Check tunnel is established<\/h2>\n\n\n\n<p>Go back to <strong>AWS Console<\/strong> to check VPN are established:<\/p>\n\n\n\n<div class=\"wp-block-image is-style-default\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"402\" src=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-1024x402.png\" alt=\"\" class=\"wp-image-369\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-1024x402.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-300x118.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-768x302.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-1536x604.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-2048x805.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.07.29-1200x472.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 1362px) 62vw, 840px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><strong><a href=\"https:\/\/aws.amazon.com\/?nc2=h_lg\" target=\"_blank\" rel=\"noreferrer noopener\">AWS<\/a><\/strong> allows the creation of a second tunnel to be established between the spoke VPC and the Firebox instance. To create the second VPN session, create a second tunnel by following the same instruction as above with the parameters described in the configuration file downloaded earlier.<\/p>\n\n\n\n<p>That concludes the <a href=\"http:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\" target=\"_blank\" rel=\"noreferrer noopener\">Part 3<\/a> of this post. In the next <strong>final Part<\/strong>, I will show you how to establish a VPN from <strong><a href=\"https:\/\/docs.vmware.com\/en\/VMware-Cloud-on-AWS\/services\/com.vmware.vmc-aws.getting-started\/GUID-BC0EC6C5-9283-4679-91F8-87AADFB9E116.html\" target=\"_blank\" rel=\"noreferrer noopener\">SDDC<\/a><\/strong> to the Firebox instance in the transit VPC.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>In this Part, I will show you how to configure an IPsec VPN from the &#8220;spoke&#8221; native VPC to the Firebox instance deployed in the transit VPC. This permits to leverage the Watchguard Firewall instance in the transit VPC as a filtering device from any trafic coming outside (SDDC, spoke VPC, on-prem). Phase 1 \u2013 &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-282","post","type-post","status-publish","format-standard","hentry","category-vmconaws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com\" \/>\n<meta property=\"og:description\" content=\"In this Part, I will show you how to configure an IPsec VPN from the &#8220;spoke&#8221; native VPC to the Firebox instance deployed in the transit VPC. This permits to leverage the Watchguard Firewall instance in the transit VPC as a filtering device from any trafic coming outside (SDDC, spoke VPC, on-prem). Phase 1 \u2013 &hellip; Continue reading &quot;Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-21T16:02:25+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-28T14:09:23+00:00\" \/>\n<meta property=\"og:image\" content=\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3\",\"datePublished\":\"2021-01-21T16:02:25+00:00\",\"dateModified\":\"2021-01-28T14:09:23+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\"},\"wordCount\":922,\"commentCount\":1,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\",\"articleSection\":[\"VMConAWS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\",\"name\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage\"},\"thumbnailUrl\":\"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\",\"datePublished\":\"2021-01-21T16:02:25+00:00\",\"dateModified\":\"2021-01-28T14:09:23+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage\",\"url\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\",\"contentUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg\",\"width\":941,\"height\":556},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/","og_locale":"en_US","og_type":"article","og_title":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com","og_description":"In this Part, I will show you how to configure an IPsec VPN from the &#8220;spoke&#8221; native VPC to the Firebox instance deployed in the transit VPC. This permits to leverage the Watchguard Firewall instance in the transit VPC as a filtering device from any trafic coming outside (SDDC, spoke VPC, on-prem). Phase 1 \u2013 &hellip; Continue reading \"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3\"","og_url":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/","og_site_name":"vminded.com","article_published_time":"2021-01-21T16:02:25+00:00","article_modified_time":"2021-01-28T14:09:23+00:00","og_image":[{"url":"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3","datePublished":"2021-01-21T16:02:25+00:00","dateModified":"2021-01-28T14:09:23+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/"},"wordCount":922,"commentCount":1,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage"},"thumbnailUrl":"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg","articleSection":["VMConAWS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/","url":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/","name":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 3 - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage"},"thumbnailUrl":"http:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg","datePublished":"2021-01-21T16:02:25+00:00","dateModified":"2021-01-28T14:09:23+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#primaryimage","url":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg","contentUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/aws-sign-in.jpg","width":941,"height":556},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/21\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-3\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 3"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/282","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=282"}],"version-history":[{"count":45,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/282\/revisions"}],"predecessor-version":[{"id":439,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/282\/revisions\/439"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=282"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=282"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=282"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}