{"id":437,"date":"2021-01-28T15:08:26","date_gmt":"2021-01-28T14:08:26","guid":{"rendered":"https:\/\/vminded.com\/?p=437"},"modified":"2021-01-28T18:12:59","modified_gmt":"2021-01-28T17:12:59","slug":"configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final","status":"publish","type":"post","link":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/","title":{"rendered":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)"},"content":{"rendered":"\n<p>In the previous posts of this series on Configuring a VPN connection from WatchGuard TM Firebox to VMC, I have showed you how to setup the Firebox and how to establish a VPN with a native VPC.<\/p>\n\n\n\n<p>In this last post, I will attach the SDDC to the WatchGuard Firebox instance with a IPSEC route-based VPN leveraging BGP to allow for dynamic routes exchange.<\/p>\n\n\n\n<p>With this configuration, any compute and management segments created inside the SDDC will be the advertised into the BGP session established with the Firebox in the transit VPC.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\" id=\"h-firebox-to-sddc-ipsec-vpn-configuration\">Firebox to SDDC IPSec VPN configuration<\/h2>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phase-1-vpn-s-vpc-configuration\">Phase 1 &#8211; VPN&#8217;s VPC configuration<\/h3>\n\n\n\n<p>First of all I need to collect the <strong>public IP <\/strong>address of my SDDC. This is possible by logging to the VMC Console and going to the Networking and Security tab, and Selecting the Overview window:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png\" alt=\"\" class=\"wp-image-441\" width=\"552\" height=\"149\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-300x81.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-768x208.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1200x325.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12.png 1448w\" sizes=\"auto, (max-width: 552px) 85vw, 552px\" \/><figcaption>The IP of VPN is displayed as VPN Public IP. This Public IP is unique for any other VPN being established.<\/figcaption><\/figure><\/div>\n\n\n\n<p><em>N.B.: You can also request additional public IP addresses  to assign to workload VMs to allow access to these VMs from the internet.&nbsp;VMware Cloud on AWS&nbsp;provisions the IP address from AWS.<\/em><\/p>\n\n\n\n<p>Next I&#8217;ll collect the <strong>BGP<\/strong> <em>local ASN <\/em>number of the SDDC. Just like IP addresses, ASNs (Autonomous System Numbers) have to be unique on the Internet and the SDDC utilises two numbers: one for the route-based VPN and one for <strong><a href=\"https:\/\/aws.amazon.com\/directconnect\/\" target=\"_blank\" rel=\"noreferrer noopener\">Direct Connect<\/a><\/strong>.&nbsp;<\/p>\n\n\n\n<p>To do that I Click on <strong>Edit Local ASN<\/strong> option in the <strong>VPN<\/strong> window:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.20.28.png\" alt=\"\" class=\"wp-image-445\" width=\"306\" height=\"124\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.20.28.png 706w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.20.28-300x122.png 300w\" sizes=\"auto, (max-width: 306px) 85vw, 306px\" \/><\/figure><\/div>\n\n\n\n<p>Clicking <strong>EDIT LOCAL ASN<\/strong> displays the Local ASN of the SDDC as shown here:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.18.42-1024x741.png\" alt=\"\" class=\"wp-image-450\" width=\"416\" height=\"300\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.18.42-1024x741.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.18.42-300x217.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.18.42-768x556.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.18.42.png 1166w\" sizes=\"auto, (max-width: 416px) 85vw, 416px\" \/><\/figure><\/div>\n\n\n\n<p>The local ASN of any brand new SDDC is by default at <strong><em>65000<\/em><\/strong>. You can change it to a value in the range 64521 to 65535 (or 4200000000 to 4294967294). <\/p>\n\n\n\n<p><em>N.B.: Keep in mind that the remote BGP ASN number need to be different.<\/em><\/p>\n\n\n\n<p>Now it&#8217;s time to create a new Customer Gateway and map it to the SDDC settings.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-create-a-new-customer-gateway\">Create a New Customer Gateway<\/h4>\n\n\n\n<p>For that I need to go back to the AWS console and Go to the <em>VPC Dashboard<\/em> and Select <strong>Customer Gateways<\/strong> under <strong>VIRTUAL PRIVATE NETWORK<\/strong> Menu on the left.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22-1024x672.png\" alt=\"\" class=\"wp-image-453\" width=\"614\" height=\"402\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22-1024x672.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22-300x197.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22-768x504.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22-1200x788.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.22.22.png 1502w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure><\/div>\n\n\n\n<p>I Click <strong>Create Customer Gateway <\/strong>and choose <strong>Dynamic <\/strong>as a routing option, and add the public <strong>Elastic-IP<\/strong> address of the SDDC public IP. <\/p>\n\n\n\n<p>I also need to specify the <strong>BGP ASN<\/strong> to the SDDC value (<em><strong>65000<\/strong><\/em> by default). Note that it has to be different from the BGP ASN of the Firebox in the transit VPC.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\" id=\"h-phase-2-firebox-s-vpn-configuration\">Phase 2 \u2013 FireBox\u2019s VPN Configuration<\/h3>\n\n\n\n<p>Now I have to setup the VPN configuration on the Firebox itself. For this, I connect back to the <strong>Fireware Web UI<\/strong>:<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<div class=\"wp-block-columns are-vertically-aligned-center is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-vertically-aligned-center is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:50%\">\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.22.43.png\" alt=\"\" class=\"wp-image-460\" width=\"215\" height=\"439\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.22.43.png 468w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.22.43-147x300.png 147w\" sizes=\"auto, (max-width: 215px) 85vw, 215px\" \/><\/figure><\/div>\n<\/div>\n\n\n\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:50%\">\n<ol class=\"wp-block-list\" type=\"1\" id=\"block-8807473f-35a6-498d-8d04-d38c1b4da4d6\"><li>Open a web browser and go to the public IP address for your instance of Firebox Cloud at: <strong><em>https:\/\/&lt;eth0_public_IP&gt;:8080<\/em><\/strong><\/li><li>Log in with the&nbsp;<em>admin<\/em>&nbsp;user account. Make sure to specify the passphrase you set in the Firebox Cloud Setup Wizard.<\/li><\/ol>\n<\/div>\n<\/div>\n<\/div>\n<\/div>\n\n\n\n<p>Select <strong>VPN<\/strong>, <strong>BOVPN Virtual Interfaces<\/strong> on the left and click the lock to open the settings window.<\/p>\n\n\n\n<p>Enter a name for the interface (eg. <em><strong>BoSddc<\/strong><\/em>) and switch the <strong>Remote Endpoint Type<\/strong> to <em><strong>Cloud VPN or Third-Party Gateway<\/strong><\/em>.<\/p>\n\n\n\n<p>In the <strong>Gateway Settings<\/strong>-&gt; <strong>Credential Method<\/strong>, Enter a <strong>Use Pre-Shared Key<\/strong> (note the key as you will have to use it in the SDDC setup):<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-1.png\" alt=\"\" class=\"wp-image-468\" width=\"450\" height=\"272\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-1.png 892w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-1-300x182.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.30.54-1-768x465.png 768w\" sizes=\"auto, (max-width: 450px) 85vw, 450px\" \/><\/figure><\/div>\n\n\n\n<p>In the Gateway Settings&#8211;&gt;Gateway Endpoint&#8211;&gt;Click <strong>ADD.<\/strong>  <\/p>\n\n\n\n<p>Select Local Gateway&#8211;&gt;Interface: Select <strong>Physical: External<\/strong><\/p>\n\n\n\n<p>Specify the <strong>gateway ID <\/strong>for tunnel authentication: Select <strong>By IP address:<\/strong> <strong><em>34.210.196.xxx<\/em><\/strong> (this is the public <strong>Elastic-IP <\/strong>of the Watchguard Firebox)<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.32.10-1-1024x985.png\" alt=\"\" class=\"wp-image-469\" width=\"521\" height=\"499\"\/><\/figure><\/div>\n\n\n\n<p>Select <strong>Remote Gateway<\/strong>&#8211;&gt;<em>Specify the remote gateway IP address for a tunnel<\/em>: a the Static IP Address has to be set to the <strong>Public IP <\/strong>address of the <strong>SDDC<\/strong>:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.29.34-1024x976.png\" alt=\"\" class=\"wp-image-472\" width=\"475\" height=\"452\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.29.34-1024x976.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.29.34-300x286.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.29.34-768x732.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.29.34.png 1110w\" sizes=\"auto, (max-width: 475px) 85vw, 475px\" \/><\/figure><\/div>\n\n\n\n<p>Next Step, Select Advanced tab and Click <strong>OK<\/strong><\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-configure-phase-1-of-ipsec-proposal\">Configure Phase 1 of IPSEC Proposal<\/h4>\n\n\n\n<p>Check &#8216;<em><strong>Start Phase1 tunnel when it is inactive<\/strong><\/em>&#8216; and Keep the &#8216;<strong><em>Add this tunnel to the BOVPN-Allow policies<\/em><\/strong>&#8216; checked.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00-1.png\" alt=\"\" class=\"wp-image-475\" width=\"356\" height=\"273\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00-1.png 634w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.38.00-1-300x231.png 300w\" sizes=\"auto, (max-width: 356px) 85vw, 356px\" \/><\/figure><\/div>\n\n\n\n<p>The Phase 1 Settings should be as follow:<br>1. Version: <strong>IKEv1<\/strong><br>2. Mode: Main<br>3. Uncheck NAT Traversal<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.31.34.png\" alt=\"\" class=\"wp-image-478\" width=\"475\" height=\"461\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.31.34.png 980w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.31.34-300x291.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.31.34-768x746.png 768w\" sizes=\"auto, (max-width: 475px) 85vw, 475px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p><em>N.B.: NAT Traversal is enabled by default but if your WatchGuard device is not behind a NAT\/PAT device, please deselect NAT Traversal.<\/em><\/p>\n\n\n\n<p>Dead Peer Detection:<br>a. Traffic idle timeout: 10<br>b. Max retries: 3<\/p>\n\n\n\n<p>Transform Settings&#8211;&gt;Click <strong>ADD<\/strong>:<\/p>\n\n\n\n<p>1. Authentication: SHA1<br>2. Encryption: AES(128-bit)<br>3. SA Life: 8 hours<br>4. Key Group: Diffie-Hellman Group 2<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1-1024x140.png\" alt=\"\" class=\"wp-image-481\" width=\"572\" height=\"78\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1-1024x140.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1-300x41.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1-768x105.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1-1200x164.png 1200w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.40.35-1.png 1406w\" sizes=\"auto, (max-width: 572px) 85vw, 572px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Click <strong>OK<\/strong>.<\/p>\n\n\n\n<p><em>Remove any pre-existing Phase 1 Transform Settings eg. SHA1-3DES<\/em>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-configure-phase-2-of-ipsec-proposal\">Configure Phase 2 of IPSEC Proposal<\/h4>\n\n\n\n<p>Go to <strong>VPN<\/strong>&#8211;&gt;<strong>Phase2 Proposals<\/strong>&#8211;&gt;Click <strong>ADD<\/strong><\/p>\n\n\n\n<p><strong>Name:<\/strong> AWS-ESP-AES128-SHA1<br><strong>Description:<\/strong> AWS Phase 2 Proposal<br><strong>Type: <\/strong>ESP<br><strong>Authentication:<\/strong> SHA1<br><strong>Encryption: <\/strong>AES(128-bit)<br>Force Key Expiration: Select &#8216;Time&#8217; -&gt; <em><strong>1 hours<\/strong><\/em><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1-1024x676.png\" alt=\"\" class=\"wp-image-484\" width=\"543\" height=\"357\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1-1024x676.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1-300x198.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.45.27-1-768x507.png 768w\" sizes=\"auto, (max-width: 543px) 85vw, 543px\" \/><\/figure><\/div>\n\n\n\n<p><\/p>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<p>Go to VPN&#8211;&gt;BOVPN Virtual Interfaces&#8211;&gt;Select <em><strong>BoSddc<\/strong><\/em>&#8211;&gt;Click <strong>EDIT<\/strong><\/p>\n\n\n\n<p>Phase 2 Settings&#8211;&gt;Perfect Forward Secrecy:<\/p>\n\n\n\n<p>Check <strong>&#8216;Enable Perfect Forward Secrecy&#8217;<\/strong>: Diffie-Hellman Group 2<br>IPSec Proposals&#8211;&gt;Click on existing proposal&#8211;&gt;Click <strong>REMOVE<br><\/strong>Select <strong>&#8216;AWS-ESP-AES128-SHA1&#8217;<\/strong> from the drop-down menu&#8211;&gt;Click <strong>ADD<\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.33.30-972x1024.png\" alt=\"\" class=\"wp-image-487\" width=\"517\" height=\"544\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.33.30-972x1024.png 972w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.33.30-285x300.png 285w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.33.30-768x809.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.33.30.png 1162w\" sizes=\"auto, (max-width: 517px) 85vw, 517px\" \/><\/figure><\/div>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\" id=\"h-configure-bgp-dynamic-routing\">Configure BGP dynamic routing.<\/h4>\n\n\n\n<p>Go to VPN&#8211;>BOVPN Virtual Interfaces&#8211;>Select <strong><em>BoSddc<\/em><\/strong>&#8211;>Click <strong>EDIT<\/strong><\/p>\n\n\n\n<p>For the <strong><em>VPN Routes<\/em><\/strong> settings, I keep &#8216;<em><strong>Assign virtual interface IP addresses<\/strong><\/em>&#8216; option checked for the <strong>Interface<\/strong> option.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\" style=\"flex-basis:100%\">\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1-1024x864.png\" alt=\"\" class=\"wp-image-488\" width=\"497\" height=\"418\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1-1024x864.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1-300x253.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1-768x648.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-13.54.07-1.png 1072w\" sizes=\"auto, (max-width: 497px) 85vw, 497px\" \/><\/figure><\/div>\n<\/div>\n<\/div>\n\n\n\n<p>Then I setup the Local IP address to: <em><strong>169.254.85.186<\/strong><\/em> and Peer IP address or netmask to: <em><strong>255.255.255.252<\/strong><\/em><\/p>\n\n\n\n<p>then Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<p>Go to Network&#8211;>Dynamic Routing and Check &#8216;Enable Dynamic Routing&#8217;.<\/p>\n\n\n\n<p>Click on &#8216;BGP&#8217;: Check &#8216;Enable&#8217;<\/p>\n\n\n\n<p>I have to Add the below <strong>BGP dynamic routing <\/strong>configuration commands in the box: <\/p>\n\n\n\n<p><em>router bgp 65001\u00a0\u00a0\u00a0 <\/em>&#8212; <strong>N.B.: <\/strong>Use this command only once at the beginning of the BGP config as this the local ASN number that the Firebox will use for any VPNs.<\/p>\n\n\n\n<p>NOw it&#8217;s time to add the configuration  for the second BGP neighbor that we need to configure for the SDDC:<\/p>\n\n\n\n<p><em>neighbor 169.254.85.185 remote-as 65000<br>neighbor 169.254.85.185 activate<br>neighbor 169.254.85.185 timers 10 30<\/em><\/p>\n\n\n\n<p>Click <strong>SAVE<\/strong>.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Phase 3 \u2013 VMC on AWS SDDC\u2019s VPN Configuration<\/h2>\n\n\n\n<p>VMC on AWS allows to create up to 4 <strong>IPSEC route-based VPN tunnels <\/strong>to be established between Firebox\/VPC and your SDDC. To create the VPN on the SDDC side, you first have to Connect to the <strong><a href=\"https:\/\/vmc.vmware.com\/home\" target=\"_blank\" rel=\"noreferrer noopener\">SDDC console<\/a><\/strong>.<\/p>\n\n\n\n<p>Then you need to Go to the <strong>Networking &amp; Security<\/strong> tab.<\/p>\n\n\n\n<p>Select <strong>Network<\/strong> -&gt; <strong>VPN<\/strong> and Click on the <strong>Route Based<\/strong> tab.<\/p>\n\n\n\n<p>Click <strong>ADD VPN<\/strong>.<\/p>\n\n\n\n<figure class=\"wp-block-image size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"499\" height=\"240\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2021-01-28-at-17.46.07.png\" alt=\"\" class=\"wp-image-517\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2021-01-28-at-17.46.07.png 499w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2021-01-28-at-17.46.07-300x144.png 300w\" sizes=\"auto, (max-width: 499px) 85vw, 499px\" \/><\/figure>\n\n\n\n<p><\/p>\n\n\n\n<p>Next, you have to enter the following configuration settings:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li>First give a <strong>name<\/strong> to the IPSec VPN (eg. <strong><em>TOFirebo<\/em><\/strong>x).<\/li><\/ul>\n\n\n\n<p>Select <strong>Local Public IP1<\/strong> of the SDDC: this is the public IP address of the SDDC. As the <strong>Remote Public IP<\/strong>, Select the <strong>Elastic IP <\/strong>that was assigned to the public interface of the <strong>Watchguard Firebox FW<\/strong>. The Remote private IP is automatically entered.<\/p>\n\n\n\n<p>For the <strong>BGP Local IP\/Prefix Length<\/strong>, choose the following: <em><strong>169.254.85.185\/30<\/strong><\/em>.<\/p>\n\n\n\n<p>The BGP Remote IP is the Local IP configured previously in the VPN Routes of the BOVPN Virtual interfaces: <em><strong>169.254.85.186<\/strong><\/em>.<\/p>\n\n\n\n<p><strong>BGP Neighbor ASN <\/strong>has to be he remote ASN of the <strong>WatchGuard Firebox: <\/strong> <em><strong>65001<\/strong><\/em>.<\/p>\n\n\n\n<div class=\"wp-block-columns is-layout-flex wp-container-core-columns-is-layout-9d6595d7 wp-block-columns-is-layout-flex\">\n<div class=\"wp-block-column is-layout-flow wp-block-column-is-layout-flow\">\n<figure class=\"wp-block-image size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-1024x313.png\" alt=\"\" class=\"wp-image-514\" width=\"747\" height=\"228\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-1024x313.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-300x92.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-768x235.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-1536x470.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-2048x626.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.47.02-1200x367.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure>\n<\/div>\n<\/div>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Tunnel Encryption: <\/strong>AES128<\/li><li><strong>Digest Algorithm: <\/strong>SHA-1<\/li><li><strong>PFS: <\/strong>Enabled<\/li><li><strong>Diffie-Hellman: <\/strong>Group 2<\/li><li><strong>IKE Encryption:<\/strong> AES128<\/li><li><strong>IKE Digest:&nbsp;<\/strong> SHA-1<\/li><li><strong>IKE Type:<\/strong> V1<\/li><\/ul>\n\n\n\n<p>After a few seconds, we can see that the VPN is up!<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-1024x35.png\" alt=\"\" class=\"wp-image-524\" width=\"774\" height=\"26\" srcset=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-1024x35.png 1024w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-300x10.png 300w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-768x26.png 768w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-1536x53.png 1536w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-2048x70.png 2048w, https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.48.11-1200x41.png 1200w\" sizes=\"auto, (max-width: 709px) 85vw, (max-width: 909px) 67vw, (max-width: 984px) 61vw, (max-width: 1362px) 45vw, 600px\" \/><\/figure><\/div>\n","protected":false},"excerpt":{"rendered":"<p>In the previous posts of this series on Configuring a VPN connection from WatchGuard TM Firebox to VMC, I have showed you how to setup the Firebox and how to establish a VPN with a native VPC. In this last post, I will attach the SDDC to the WatchGuard Firebox instance with a IPSEC route-based &hellip; <a href=\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)&#8221;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_monsterinsights_skip_tracking":false,"_monsterinsights_sitenote_active":false,"_monsterinsights_sitenote_note":"","_monsterinsights_sitenote_category":0,"footnotes":""},"categories":[3],"tags":[],"class_list":["post-437","post","type-post","status-publish","format-standard","hentry","category-vmconaws"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v24.9 - https:\/\/yoast.com\/wordpress\/plugins\/seo\/ -->\n<title>Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com\" \/>\n<meta property=\"og:description\" content=\"In the previous posts of this series on Configuring a VPN connection from WatchGuard TM Firebox to VMC, I have showed you how to setup the Firebox and how to establish a VPN with a native VPC. In this last post, I will attach the SDDC to the WatchGuard Firebox instance with a IPSEC route-based &hellip; Continue reading &quot;Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)&quot;\" \/>\n<meta property=\"og:url\" content=\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\" \/>\n<meta property=\"og:site_name\" content=\"vminded.com\" \/>\n<meta property=\"article:published_time\" content=\"2021-01-28T14:08:26+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2021-01-28T17:12:59+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png\" \/>\n<meta name=\"author\" content=\"Christophe\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Christophe\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"9 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\"},\"author\":{\"name\":\"Christophe\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"headline\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)\",\"datePublished\":\"2021-01-28T14:08:26+00:00\",\"dateModified\":\"2021-01-28T17:12:59+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\"},\"wordCount\":1180,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png\",\"articleSection\":[\"VMConAWS\"],\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\",\"url\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\",\"name\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com\",\"isPartOf\":{\"@id\":\"https:\/\/vminded.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png\",\"datePublished\":\"2021-01-28T14:08:26+00:00\",\"dateModified\":\"2021-01-28T17:12:59+00:00\",\"breadcrumb\":{\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage\",\"url\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12.png\",\"contentUrl\":\"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12.png\",\"width\":1448,\"height\":392},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/vminded.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/vminded.com\/#website\",\"url\":\"https:\/\/vminded.com\/\",\"name\":\"vminded.com\",\"description\":\"feed your mind with virtual thoughts\",\"publisher\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/vminded.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":[\"Person\",\"Organization\"],\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a\",\"name\":\"Christophe\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g\",\"caption\":\"Christophe\"},\"logo\":{\"@id\":\"https:\/\/vminded.com\/#\/schema\/person\/image\/\"},\"sameAs\":[\"http:\/\/vminded.com\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/","og_locale":"en_US","og_type":"article","og_title":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com","og_description":"In the previous posts of this series on Configuring a VPN connection from WatchGuard TM Firebox to VMC, I have showed you how to setup the Firebox and how to establish a VPN with a native VPC. In this last post, I will attach the SDDC to the WatchGuard Firebox instance with a IPSEC route-based &hellip; Continue reading \"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)\"","og_url":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/","og_site_name":"vminded.com","article_published_time":"2021-01-28T14:08:26+00:00","article_modified_time":"2021-01-28T17:12:59+00:00","og_image":[{"url":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png","type":"","width":"","height":""}],"author":"Christophe","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Christophe","Est. reading time":"9 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#article","isPartOf":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/"},"author":{"name":"Christophe","@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"headline":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)","datePublished":"2021-01-28T14:08:26+00:00","dateModified":"2021-01-28T17:12:59+00:00","mainEntityOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/"},"wordCount":1180,"commentCount":0,"publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png","articleSection":["VMConAWS"],"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/","url":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/","name":"Configure VPN from VMC to WatchGuardTM Firebox Cloud - Part 4 (Final) - vminded.com","isPartOf":{"@id":"https:\/\/vminded.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage"},"image":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage"},"thumbnailUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12-1024x277.png","datePublished":"2021-01-28T14:08:26+00:00","dateModified":"2021-01-28T17:12:59+00:00","breadcrumb":{"@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#primaryimage","url":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12.png","contentUrl":"https:\/\/vminded.com\/wp-content\/uploads\/2021\/01\/Screenshot-2020-12-24-at-14.16.12.png","width":1448,"height":392},{"@type":"BreadcrumbList","@id":"https:\/\/vminded.com\/index.php\/2021\/01\/28\/configure-vpn-from-vmc-to-watchguardtm-firebox-cloud-part-4-final\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/vminded.com\/"},{"@type":"ListItem","position":2,"name":"Configure VPN from VMC to WatchGuardTM Firebox Cloud &#8211; Part 4 (Final)"}]},{"@type":"WebSite","@id":"https:\/\/vminded.com\/#website","url":"https:\/\/vminded.com\/","name":"vminded.com","description":"feed your mind with virtual thoughts","publisher":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/vminded.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":["Person","Organization"],"@id":"https:\/\/vminded.com\/#\/schema\/person\/1800a04c708828d9b5c7b64f8eab3b3a","name":"Christophe","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/8a35247a893da5c4bd4e7b117047b93859d3def341ac950cf2285f9d9b9220bf?s=96&d=mm&r=g","caption":"Christophe"},"logo":{"@id":"https:\/\/vminded.com\/#\/schema\/person\/image\/"},"sameAs":["http:\/\/vminded.com"]}]}},"_links":{"self":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/437","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/comments?post=437"}],"version-history":[{"count":53,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/437\/revisions"}],"predecessor-version":[{"id":545,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/posts\/437\/revisions\/545"}],"wp:attachment":[{"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/media?parent=437"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/categories?post=437"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/vminded.com\/index.php\/wp-json\/wp\/v2\/tags?post=437"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}