VPNs
Overview
VPN provides a secure communications tunnel over a public network for remote user access and site-to-site connections (e.g. branch offices that need to collaborate and share resources).
IPsec
KorGrid supports IPsec compatibility to allow for configuration of a VPN tunnel between your tenant and a third-party IPsec peer. (Typically, an enterprise firewall)
IPsec tunneling is an advanced configuration. It's recommended to use WireguardWireGuard when possible as it provides better performance and a simpler configuration.
- Create a Phase 1 Configuration
- Create a Phase 2 Configuration
- Configure Firewall & Routing Rules
Create a VPN Network
- From the Top Menu, click Networks -> + New VPN
- Enter a Name for the network
- (Optional), enter a Description
- Layer 2 Type, select None
- Select Interface Network
- -- None -- (recommended) - to create a separate VPN network, where connections to other tenant networks is handled via Layer 3 routing.
- [Existing Network] - select an existing network to attach the VPN network directly to via Layer 2. (e.g., vlan50)
- IP Address Type, select Static
- Enter an IP Address for the network (e.g., 10.254.254.1)
- Enter a Network Address (e.g., 10.254.254.0/24)
- (Optional), enter a Hostname for the layer 3 routed interface
- Click Submit
After creating the network, you must power it on for it to become active.
- From the left menu, click Power On
Assign Public IP
A public IP address must be reserved and assigned to allow external access to your tenant. There are two ways KorGrid can assign public IPs:
- Single IP Assignment (/32)
- A network block that contains a single IP address
- Use the Network Block Method
- Multiple IP Assignment (/29, /28, etc.)
- A network block that contains multiple IP addresses
- Use the VIP Method
ℹ️ Please reach out to KorGrid Support to request public IPs for your tenant.
Determine IP Address
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu, click Network Blocks
- Determine the public IP address you wish to use from the network block
Create VIP
- From the Top Menu, click Networks -> List
- Select the External network
- From the left menu, click View
- From the left menu, click IP Addresses
- From the left menu, click New
- Type, select Virtual IP
- Enter the public IP address from the network block (e.g., 24.221.112.159)
- Owner Type, select Network
- Owner, select the newly created VPN network
- Click Submit
Apply Rules
After assigning an IP address to the VPN network you must apply the rules for the settings to take effect.
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click Apply Rules
Phase 1 Configuration
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click IPsec Tunnels
- From the left menu, click New
- Enter a Name for the phase 1 configuration
- (Optional), enter a Description
- Select Key Exchange Version
- Auto (recommended) - Uses the IKE version initiated by the remote peer.
- IKEv1 - Uses IKEv1.
- IKEv2 - Uses IKEv2.
- Enter the Remote Gateway
ℹ️ The WAN address of the IPsec remote peer.
- Configure Phase 1 (Encryption)
- Algorithm - AES-256-GCM is recommended.
- Key Length - Varies depending on algorithm selected.
- Hash - Varies depending on algorithm selected.
- DH Group - Varies depending on algorithm selected.
- Lifetime - Auto-expiration setting for SAs
- Configure Phase 1 Proposal (Authentication)
- Pre-Shared Key - Can be manually entered or you may press ⭮ to generate a pre-shared key for you.
- Negotiation Mode
- Main (recommended) - Slower negotiation, but more secure.
- Aggressive - Faster negotiation but exposes identities.
- Identifier - The identity presented to the remote peer during IKE negotiation. When left blank, the current IP is used. Typically, the tenants WAN IP address should be entered as it's the source address from the remote peer's perspective.
- Peer Identifier - The identity to expect from the remote peer; typically can be left blank to use the address currently specified as the VPN remote gateway.
- Configure Phase 1 Advanced Options
- Connection Behavior - defines the behavior to occur at IPsec startup.
- Responder Only - Loads connection but doesn't start.
- On-Demand - Loads a connection and starts it if traffic is detected between the networks.
- Start - Loads and starts the connection immediately.
- Force UDP Encapsulation - When enabled, UDP encapsulation is forced, even when NAT is not detected.
- Rekey - Can be disabled to prevent local initiation of renegotiating a connection about to expire; however, it doesn't affect renegotiation requests that come from the remote peer.
- Margintime - Defines the length of time to elapse before a replacement negotiation for expired keying-channel/connection. This setting is only relevant locally (remote peer does not need to match setting).
- Dead Peer Detection - defines the default action to perform on timeout.
- Clear - Closes the connection.
- Hold - Monitors for new traffic and renegotiates connection if traffic between the networks is detected.
- Restart - Tries to renegotiate the connection immediately.
- None - Disables sending DPD messages.
- DPD Delay - Defines time internal R_U_There messages are sent to the peer. Only sent when there is no other traffic.
- DPD Failures - Defines the maximum number of failures before automatically deleting peer connections after inactivity (does not apply to IKEv2).
- Click Submit
Phase 2 Configuration
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click IPsec Tunnels
- Select the newly created Phase 1 Configuration
- From the left menu, click View P2s
- From the left menu, click New
- Enter a name for the phase 2 configuration
- Select Mode (typically Tunnel)
- Enter a Local Network, the subnet of IP addresses to include on this side of the VPN
(e.g., 192.168.100.0/24)
- Enter the Remote Network, the network of the remote peer in CIDR format
(e.g., 10.128.1.0/24)
- Select Protocol
- ESP (recommended) - Encapsulating Security Payload
- AH - Authentication Only
- Select Lifetime, the duration of the SA established during Phase 2
- Configure Phase 2 (Encryption)
- Algorithm - AES-256-GCM is recommended.
- Key Length - Varies depending on algorithm selected.
- Hash - Varies depending on algorithm selected.
- DH Group - Varies depending on algorithm selected.
- Click Submit
Firewall & Routing Rules
The following rules are automatically created on the new VPN network. Additional network configuration may be necessary for IPsec traffic beyond the default auto-created network rules, depending on your specific network and IPsec design.
Direction | Action | Protocol | Port |
|---|---|---|---|
Incoming | Allow | UDP | 500 |
Incoming | Allow | UDP | 4500 |
Incoming | Allow | ESP | - |
Incoming | Allow | AH | - |
These rules can be modified to further restrict traffic from specific source IP's, where appropriate.
Create NAT Translation
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., NAT Translation)
- (Optional), Enter a Description
- Action, select Translate
- Protocol, select ANY
- Direction, select Incoming
- Interface, select DMZ
- Pin, select Top
- Configure Source
- Type, select Any / None
- Configure Destination
- VIP Method
- Type, select My IP Addresses
- IP Address, select the desired external IP address
- Network Block Method
- Type, select Network Block
- Network Block, select the desired external IP address
- Configure Target
- Type, select My Router IP
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create Outbound Route
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., Default Route)
- Set Action to Route
- Set Protocol to ANY
- Set Direction to Outgoing
- Configure Source
- Type to Any / None
- Configure Destination
- Type to Default
- Configure Target
- Type to Other Network DMZ IP
- Target Network to External
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create Network Route(s)
Perform these steps for each internal network you wish to route across the VPN tunnel.
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., Route vlan200)
- Action, select Route
- Protocol, select ANY
- Direction, select Outgoing
- Configure Source
- Type, select Any / None
- Configure Destination
- Type, select Custom
- Custom Filter, Enter the network subnet (e.g., 192.168.200.0/24)
- Configure Target
- Type, select Other Network DMZ IP
- Target Network, select the desired network
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create NAT Exclusion(s)
Perform these steps for each internal network you wish to route across the VPN tunnel.
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., NAT Exclusion vlan200)
- Action, select Translate
- Protocol, select ANY
- Direction, select Outgoing
- Interface, select DMZ
- Pin, select Top
- Configure Source
- Type, select Other Network DMZ IP
- Network, select the desired network (e.g., vlan200)
- Configure Destination
- Type, select Custom
- Custom Filter, enter != followed by the IP address of the newly created VPN network. (e.g., !=10.254.254.1)
- Configure Target
- Type, select Other Router IP
- Target Network, select the desired network (e.g., vlan200)
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create Internal Network Route(s)
Perform these steps on each internal network you wish to route across the VPN tunnel.
- From the Top Menu, click Networks -> List
- Select the desired network (e.g., vlan200, vlan210, etc.)
- From the left menu, click View
- From the left menu, click Rules
- From the left menu, click New
- Enter a Name for the rule (e.g., Route to VPN)
- Action, select Route
- Protocol, select ANY
- Direction, select Outgoing
- Configure Source
- Type, select Any / None
- Configure Destination
- Type, select Custom
- Custom Filter, enter the remote VPN subnet(s) (e.g., 10.128.1.0/24) ℹ️ It's typically best practice to create separate rules for each subnet.
- Configure Target
- Type, select Other Network DMZ IP
- Target Network, select the newly created VPN network
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create Firewall Rule(s)
Firewall rules must be configured in two places to allow traffic from the remote VPN network to reach your application VMs:
- VPN Network - Controls traffic entering through the VPN and determines which internal networks it can reach.
- Internal Networks - Control access to the VMs themselves and define what application traffic is permitted.
On the VPN network, rules are typically broader, allowing traffic from the remote subnet to reach one or more internal networks using subnet-based and any-to-any policies where appropriate.
On the internal networks, rules should be more granular, restricting traffic based on specific source and destination IP addresses, ports, or protocols to match the requirements of the applications hosted on those VMs.
Because application requirements vary widely between environments, there is no single rule set that applies to every scenario. Firewall policies should always be designed around the specific traffic flows and security requirements of each deployment.
Connect To Peer
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- Scroll to the IPsec Connections section
- Click the 🔌 button to initiate the connection to the remote peer
- Click Yes to confirm
Advanced Configuration
The following settings are available for advanced IPsec configurations, but are not typically necessary. Please contact KorGrid Support for assistance with these settings.
Edit IPsec Configuration
- From the Top Menu, click Networks -> List
- Select the newly created VPN network
- From the left menu, click View
- From the left menu, click Edit IPsec
- Configuration Mode
- Normal (recommended) - This option is typically used and includes common IPsec fields.
- Advanced - Allows for extensive or out-of-the-ordinary IPsec configuration through the use of configuration (conf) files.
- Unique IDs
- Yes - Keep particular participant IDs unique. (e.g., Replace)
- Never - Will ignore INITIAL_CONTACT notify, will not replace old IKE_SAs.
- No - Will replace IKE_SAs only upon INITIAL_CONTACT notify.
- Propose IPComp Compressions - Utilizes a special protocol designed to compress the payload of IP packets. Must be supported by the remote peer.
- Exclude My Network - This setting should typically be enabled.
- Cisco Extensions - This setting should remain disabled unless specifically needed to support configuration of the remote IPsec peer.
- Unencrypted ID and HASH payloads - It's generally recommended to keep this option disabled. Transmitting ID and HASH payloads unencrypted during initial exchange introduces several security vulnerabilities.
- MSS Clamp - In some situations, MSS clamping can improve performance in IPsec tunnels. However, it's critical to thoroughly understand your network to calculate and set MSS accurately. An incorrect setting can lead to suboptimal performance and/or packet loss.
- Strict CRL Policy - A strict CRL (certificate revocation list) policy will not accept revoked certificates during authentication.
- Make Before Break - New SAs are established while old ones are still active; removing old SAs only when the new ones are ready.
- Click Submit
WireGuard
WireGuard is a modern, open-source VPN software and tunnel protocol that provides fast communication, utilizing state-of-the-art cryptography. WireGuard has been integrated directly into our platform for the implementation of secure tunnels with minimal setup effort. These secure tunnels can be used for both remote user access and site-to-site connectivity.
Interface Configuration
WireGuard is attached to one network. This should be a network that has access to all networks which the WireGuard VPN should reach.
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click WireGuard (VPN)
- From the left menu, click New Interface
- Enter a Name for the VPN interface
- (Optional), enter a Description
- Enter an IP Address - defines the IP/network address for the interface.
ℹ️ This should be a unique address space that has been specifically set aside for the VPN and will not conflict with addressing on participating networks within the tenant or VPN peers.
- (Optional), specify a Listen Port, can typically be left to the default 51820
- Enter a Private Key, can typically be left blank to allow the key pair to auto-generate, however, a specific private key can be entered if desired
⚠️ WireGuard requires base64-encoded public and private keys. Any manually entered private key must be a complete base64 key. Random Base64 Generator.
- (Optional), enter an Endpoint IP - the external address to which a peer will connect
- (Optional), toggle Configure Firewall (recommended) - automatically configure PAT rules on the External Network
- (Optional), toggle Auto-Apply Firewall Rules (recommended) - automatically apply new firewall rules on the WireGuard network and the External Network
- Click Submit
Create Peer Definition(s)
A peer definition must be created for each entity that will connect to your WireGuard instance. For example, to create a site-to-site VPN implementation, each side would have a WireGuard interface and configure the other as a peer using the public key from the other side in the peer record. To create a remote access system for users, a peer record is created for each user that will connect, each with a different public key.
- From the Top Menu, click Networks -> List
- Select the desired network
- From the left menu, click View
- From the left menu, click WireGuard (VPN)
- From the left menu, click New Peer
- Enter a Name for the peer
- (Optional), enter a Description
- Toggle Auto-Generate Peer Configuration (recommended) - creates a configuration file to be used by the remote access users
- Enter an Endpoint - the external-facing IP or hostname of the peer; the address from which this system would access the peer
- (Optional), specify a Listen Port, can typically be left to the default 51820
- Enter a Peer IP - the IP address that routes the traffic here; typically, this is the internal address assigned to the local interface on this peer
- Enter a Public Key - the base64 public key from the peer
- (Optional), Enter a Preshared Key - can be entered to provide an extra layer of security
- Select Configure Firewall
- Site-to-Site - creates firewall rules for a site peer
- Remote User - creates firewall rules for a remote user peer
- Don't Create Rules - doesn't auto-generate any firewall rules; rules must be configured manually
- Set Keepalive - by default this is set to 0, which means keepalives are disabled. It's not generally necessary to change this value.
- Configure Allowed IPs - one or more IP address segments, in CIDR format
(e.g., 10.1.2.0/24)
- Click Submit
⚠️ Click Apply Rules to apply the changes.
Create Cluster-to-Cluster Tunnel
- On Cluster 1
- Create an Interface Configuration
- Copy the generated Public Key (for the interface) for later use
- On Cluster 2
- Create an Interface Configuration
- Set Public Key to the generated public key you copied from cluster 1
- Set Allowed IPs to include the address of the WireGuard Interface from cluster 1
- Copy the generated Public Key for later use
- On Cluster 1
- Set Public Key to the generated public key you copied from cluster 2
- Set Allowed IPs to include the address of the WireGuard Interface from cluster 2
- On Cluster 1 & Cluster 2
- ⚠️ Click Apply Rules to apply the changes.
Create Remote User Access Tunnel
- Create an Interface Configuration
- From the left menu, click New Peer
- Enter a Name for the peer, such as the remote user's name
- (Optional), enter a Description
- Toggle Auto-Generate Peer Configuration
- Enter the Endpoint for the peer, the external-facing IP address, hostname, or URL this tunnel will use to communicate with the peer
- Set Configure Firewall to Remote User
- Click Submit
Configure Client
- On the peer record, download the configuration file by clicking the ⭳ Download button
- Install WireGuard software on the client machine
- After installation, launch WireGuard client
- Click Add Tunnel
- Open the configuration file you downloaded earlier
- Click Activate