IPsec-VPN is a routing-based network connection technology. After you deploy an IPsec-VPN connection, local clients can connect to services that are deployed in a Virtual Private Cloud (VPC). This topic describes how to use IPsec-VPN to connect a local client to the VPC of an Elastic Desktop Service (EDS) Enterprise office network, which allows the client to access cloud computers over a private network.
Prerequisites
Before you begin, read Overview of private connections to cloud computers and complete the following prerequisites.
Create a Cloud Enterprise Network (CEN) instance. For details, see Create a CEN instance.
Create a Virtual Private Cloud (VPC) instance and add the VPC instance to a Cloud Enterprise Network. For more information, see Create a VPC and a vSwitch or Quickly add a network instance to a CEN.
Create an office network, and add its VPC to Cloud Enterprise Network. For more information, see Create and manage an office network that uses a convenience account or Create and manage an office network that uses an enterprise AD account.
ImportantTo prevent IP address conflicts among the new office network, existing networks in Cloud Enterprise Network, and your on-premises data center, plan your IPv4 CIDR blocks before you create the office network. For details, see Plan CIDR blocks.
If you already have a convenient office network, you need to add it to the Cloud Enterprise Network.
If AD is deployed on an Elastic Compute Service (ECS) instance, you must add the VPC that contains the AD server to a Cloud Enterprise Network. If AD is deployed on an on-premises server, you must first establish a connection between your on-premises network and the cloud to successfully integrate with AD. You can first create an AD office network, and then complete the AD domain configuration after the network connection is established.
Create a cloud computer and a user account, and then assign the cloud computer to the user account.
To learn how to create a user account, see Create a convenience user or Create and manage AD users.
To learn how to create and assign a cloud computer, see Create a cloud computer and Assign a cloud computer to a user.
Obtain an Alibaba Cloud Workspace client to access the cloud computer. For details, see Use a software client.
NoteThis solution supports the Windows client, macOS client.
Sample CIDR blocks
During the preparation phase, you need to plan the CIDR blocks for your on-premises devices and cloud network instances to avoid conflicts. This topic uses the following sample CIDR blocks. In practice, use your actual values.
Item | CIDR block | Description |
Office network VPC | 172.16.0.0/12 | The PrivateLink service endpoint is in this CIDR block. |
User VPC | 192.168.0.0/16 | A VPC that you create to establish the VPN connection. |
On-premises data center | 10.0.0.0/24 | The Alibaba Cloud Workspace client connects from this CIDR block. |
On-premises data center gateway device | 115.XX.XX.154 | The public IP address of the on-premises data center gateway device. |
Your on-premises data center gateway device must support standard IKEv1 and IKEv2 protocols to connect to an Alibaba Cloud VPN gateway. Contact your gateway device vendor to confirm protocol support.
Step 1: Configure the IPsec-VPN connection
Purchase a VPN gateway and enable the IPsec-VPN feature. For details, see Create a VPN gateway.
Create a customer gateway. For details, see Create and manage a customer gateway.
Create an IPsec-VPN connection. For details, see Create an IPsec-VPN connection.
Publish the remote network CIDR block to Cloud Enterprise Network.
Log on to the VPC console.
In the left-side navigation pane, click Route Tables.
In the list of route tables, find the route table corresponding to the user VPC and click its ID.
On the Route Entry List tab, click the Custom Route tab.
Find the configured remote network CIDR block (the private CIDR block of your on-premises data center) and click Publish in the Actions column.
The route is published when its Status in CEN column changes to Published.
Step 2: Load the VPN configuration on the gateway
Log on to the VPC console.
In the left-side navigation pane, choose Interconnections > VPN > IPsec Connections.
In the top navigation bar, select the region of the IPsec-VPN connection.
On the IPsec Connections page, find the target IPsec-VPN connection and click Generate Peer Configuration in the Actions column.
Load the downloaded configuration onto your on-premises gateway device.
For details, see H3C firewall configuration example.
Step 3: Configure VPC address or cloud service routes
You can choose one of the following solutions. Solutions 1 and 2 both involve configuring an Alibaba Cloud VPC address. The difference is that Solution 1 uses a default address, which is simpler for end users as it does not require configuring a custom address.
VPC address (default)
Obtain the private gateway address of the office network.
Log on to the Elastic Desktop Service Enterprise console.
In the left-side navigation pane, choose .
On the Office Network page, click the target office network ID.
In the Network Information section of the office network details page, copy the Private Gateway Address. You will use this address in a later step.
On your enterprise DNS service, configure a CNAME record to point
private.wuying.comto the private gateway address of the office network.The end user completes the network connection configuration on the Alibaba Cloud Workspace client.
Open the Windows client.
In the upper-right corner of the logon screen, click the icon and select Connection Configuration.
In the Connection Configuration dialog box, set the following options:
ImportantThis feature requires Windows client version 7.7 or later. Earlier versions do not support configuring an Alibaba Cloud VPC address.
Connection Type: Select Alibaba Cloud VPC.
Alibaba Cloud VPC Address: Select Default Address.
Click Confirm.
VPC address (custom)
Obtain the private gateway address of the office network and provide it to your end users.
Log on to the Elastic Desktop Service Enterprise console.
In the left-side navigation pane, choose .
On the Office Network page, click the target office network ID.
In the Network Information section of the office network details page, copy the Private Gateway Address. You will use this address in a later step.
The end user completes the network connection configuration on the Alibaba Cloud Workspace client.
Open the Windows client.
In the upper-right corner of the logon screen, click the icon and select Connection Configuration.
In the Connection Configuration dialog box, set the following options:
ImportantThis feature requires Windows client version 7.7 or later. Earlier versions do not support configuring an Alibaba Cloud VPC address.
Connection Type: Select Alibaba Cloud VPC.
Alibaba Cloud VPC Address: Select Custom Address.
Custom Address: Enter the private gateway address of the office network provided by the administrator.
Click Confirm.
Cloud routes and DNS
Configure cloud service routes.
The network segment for private cloud services on Alibaba Cloud is
100.64.0.0/10, which is a reserved network segment as specified in RFC 6598. To allow the Alibaba Cloud Workspace client to call the service APIs of Elastic Desktop Service (EDS) Enterprise, you must add the100.64.0.0/10network segment as a local address in your VPN to forward requests destined for this segment to your VPC on the cloud.NoteIf your 100.x.x.x network range has a conflict, use Solution 1 or Solution 2.
If you use cloud computers in multiple regions, you can set the
100.64.0.0/10address block as the network segment for cloud services. If you need a more granular network, you can refer to Cloud computer service port requirements to set the cloud service network segment. In this case, the IP addresses of the domain names for the private network management service are the cloud service IP addresses.
(Optional) Before you configure DNS, you can run the following command to test if the domain name can be resolved correctly.
nslookup ecd-vpc.cn-hangzhou.aliyuncs.comIf an IP address is returned, the domain name can be resolved correctly, and you can skip step 3. If no IP address is returned, you need to configure DNS as described in the next step.
(Optional) Configure DNS.
To access cloud computers over an enterprise network, DNS is required to resolve the domain names of the APIs and streaming gateways of the Elastic Desktop Service (EDS) Enterprise service within the private network. The corresponding DNS addresses are:
100.100.2.136
100.100.2.138
You can use one of the following configuration methods:
Configure the two DNS addresses on the DHCP service of your on-premises data center.
On the DNS server in your local IDC, configure zone forwarding to forward domain name resolution requests that end with
aliyuncs.comto100.100.2.136or100.100.2.138.
Step 4: Verify the private connection
The following example uses Windows client version 7.7 to verify the private connection to a cloud computer. In practice, select the appropriate client based on your situation.
Open the Windows client.
In the upper-right corner of the logon screen, click the icon and select Connection Configuration.
In the Connection Configuration dialog box, set Connection Type to Alibaba Cloud VPC.
On the logon screen, enter the credentials you received in the cloud computer assignment notification email (including the office network ID or organization ID, username, and password), and click the next icon.
In the cloud resource list on the client, find your cloud computer, and then start and connect to it.
NoteA network request timeout error indicates a network disconnection. Check your configuration. After correcting it, log on to the client and connect to the cloud computer again.