All Products
Search
Document Center

VPN Gateway:Features

Last Updated:May 28, 2024

IPsec-VPN provides flexible traffic routing methods and uses the Internet Key Exchange (IKE) and IPsec protocols to encrypt data transmission. You can use IPsec-VPN to establish secure and reliable network connections between your data center and Alibaba Cloud. This topic describes the features of IPsec-VPN.

Encryption algorithms

IPsec-VPN uses commercial cryptographic algorithms that comply with international standards. The following table describes the encryption algorithms supported by IPsec-VPN in different encryption phases.

IKE encryption

IKE authentication

IPsec encryption

IPsec authentication

aes (aes128), aes192, aes256, des, and 3des

sha1, md5, sha256, sha384, and sha512

aes (aes128), aes192, aes256, des, and 3des

sha1, md5, sha256, sha384, and sha512

Network types

You can create an IPsec-VPN connection over the Internet or a private network.

Internet

You can create an IPsec-VPN connection over the Internet. In this case, a public IP address is used to create an IPsec-VPN connection between your data center and Alibaba Cloud to implement network communication.

image

Private network

You can create an IPsec-VPN connection over a private network. Before you create an IPsec-VPN connection between your data center and Alibaba Cloud over a private network, make sure that your data center is connected to Alibaba Cloud by using the private network. In this case, you can create an IPsec-VPN connection to encrypt the private connection.

Note

We recommend that you associate a transit router with an IPsec-VPN connection that is created over a private network.

Associate an IPsec-VPN connection with a VPN gateway

image

Associate an IPsec-VPN connection with a transit router

image

Routing

You must configure a route that points to your data center for the IPsec-VPN connection. This way, your data center can be connected to Alibaba Cloud. You can configure static routing or Border Gateway Protocol (BGP) dynamic routing for IPsec-VPN connections.