Skip to main content

VPN Customer Gateway

Not practically reviewed

Field details on this page follow CloudStack documentation and general Site-to-Site VPN practice. Not practically reviewed end-to-end in CMP — see Site-to-Site VPN.

A VPN Customer Gateway describes the customer-side site-to-site VPN endpoint — the remote VPN device and the private networks behind it. Use it only for Site-to-Site VPNnot for laptop Remote Access VPN.

Customer path (CMP): Networking → NetworksVPN Customer Gateway → create gateway

One VPN gateway per customer gateway

A VPN Customer Gateway can connect to only one CloudStack VPN gateway at a time.

Setup vs feature

Site-to-site VPN topology

Customer Network Internet / IPsec CloudStack VPC
192.168.10.0/24 VPN 10.10.0.0/16
| | |
[Palo Alto / Customer VPN Gateway] | [CloudStack VPN Gateway]
Public IP: <customer VPN gateway> =======|================== Public IP: <CloudStack VPN gateway>
^ ^ ^
Customer Gateway IPsec tunnel VPC VPN Gateway
(this page) (separate step)
SideWhat it isPublic IP example
VPN Customer GatewayCustomer's VPN device on the internetCustomer VPN gateway public IP
VPC VPN GatewayCloudStack VPN endpoint for the VPCCloudStack VPN gateway public IP
Gateway is the customer's public VPN IP

Gateway on the VPN Customer Gateway form is the customer-side VPN device's public IP addressnot a CloudStack public IP and not an IP from the customer's private LAN.

Enter the customer VPN gateway public IP in Gatewaynot the CloudStack VPN gateway public IP.

CIDR List is the customer's private network

CIDR List contains the customer's private / internal network ranges behind their VPN gateway — the remote encryption domains CloudStack should reach over the tunnel.

Enter 192.168.10.0/24 (private LAN), not the customer's public IP.


Create VPN Customer Gateway (CMP)

Screenshot: CMP — Add VPN Customer Gateway

Select Project Required. Project that owns this customer gateway.

Name Required. Display name for the gateway — for example Office-VPN-GW.

CIDR List Required. Customer private network(s) behind the VPN device. Comma-separated if multiple — for example 192.168.10.0/24 or 192.168.10.0/24,192.168.20.0/24. Must be RFC1918-compliant. Must not overlap the VPC CIDR or other guest CIDRs in use.

Gateway Required. Customer VPN device's public IP address — the routable address of the customer's firewall or VPN appliance on the internet.

IPsec Preshared Key Required. Shared secret for IPsec authentication. Must match the configuration on the customer's VPN device. Cannot contain a newline or double-quote (").

IKE Lifetime Optional. IKE SA lifetime in seconds — default 86400.

ESP Lifetime Optional. ESP SA lifetime in seconds — default 3600.

IKE Encryption Optional. IKE phase 1 encryption — for example AES 128 or aes256. Must match the customer device.

IKE Hash Optional. IKE phase 1 hash — for example SHA-1 or sha256.

IKE Version Optional. IKE version — for example IKE (IKEv1) or IKEv2 per your CloudStack / device support.

IKE DH Optional. Diffie-Hellman group for IKE — for example MODP 1024 or Group 31 (curve 25519).

Perfect Forward Secrecy Optional. PFS group for ESP — for example Group 5 (modp 1536) or None.

ESP Encryption Optional. ESP encryption — for example AES 128 or aes256.

ESP Hash Optional. ESP hash — for example SHA-1 or sha256.

Dead Peer Detection Optional. Enable DPD to detect unreachable peers.

Force Encapsulation Optional. Force UDP encapsulation of ESP packets when required by the customer firewall/NAT.

Split Connections Optional. Split connections per remote subnet when enabled.

Click Submit to create the customer gateway.


Create VPN Customer Gateway (CloudStack UI)

The same object can be created in the CloudStack admin UI for reference or troubleshooting.

Path: Network → VPN Customer Gateway → Add VPN Customer Gateway

Screenshot: CloudStack — Add VPN Customer Gateway

CloudStack fieldCMP fieldWhat to enter
NameNameGateway label
GatewayGatewayCustomer VPN device public IP
CIDR listCIDR ListCustomer private network CIDR(s)
IPsec preshared-KeyIPsec Preshared KeyShared secret
IKE / ESP settingsSameMust match customer VPN device

Field reference — Gateway vs CIDR List

FieldQuestion it answersExampleNot this
GatewayWhere is the customer's VPN device on the internet?Customer VPN gateway public IPCloudStack VPN gateway public IP; private IP such as 192.168.10.1
CIDR ListWhat private networks are behind that device?192.168.10.0/24Public IP; CloudStack VPC CIDR 10.10.0.0/16

Multiple customer subnets behind one VPN gateway:

Customer VPN Gateway (<customer public IP>)
|
+--- 192.168.10.0/24
|
+--- 192.168.20.0/24

CIDR List: 192.168.10.0/24,192.168.20.0/24

CloudStack uses these CIDRs as remote encryption domains / traffic selectors for the VPN connection.


Supported IPsec parameters (CloudStack)

Match these on the customer firewall. If your operator has configured excluded or obsolete algorithms, some options may be hidden or shown with warnings in the UI.

PhaseParameterSupported values
IKE (phase 1)EncryptionAES128, AES192, AES256, 3DES
IKEHashSHA1, SHA256, SHA384, SHA512, MD5
IKEVersionike (autoselect — initiates IKEv2, accepts any on respond), IKEv1, IKEv2
IKEDH groupNone, Group 2, 5, 14, 15, 16, 17, 18
IKELifetimeDefault 86400 seconds (1 day)
ESP (phase 2)EncryptionAES128, AES192, AES256, 3DES
ESPHashSHA1, SHA256, SHA384, SHA512, MD5
ESPPFSSame DH groups as IKE, or None
ESPLifetimeDefault 3600 seconds (1 hour)
OtherDPDRecommended — enable on both sides
OtherForce UDP encapsulationNAT traversal for ESP when required

Defaults (CMP form): IKE lifetime 86400, ESP lifetime 3600.


Admin — excluded and obsolete parameters

CloudStack operators can enforce modern crypto by marking VPN Customer Gateway parameters as excluded (hidden from create/update forms) or obsolete (shown with warnings):

Global / domain settingPurpose
vpn.customer.gateway.excluded.encryption.algorithmsHide weak encryption (IKE and ESP)
vpn.customer.gateway.excluded.hashing.algorithmsHide weak hashes
vpn.customer.gateway.excluded.ike.versionsHide IKE versions
vpn.customer.gateway.excluded.dh.groupHide DH groups
vpn.customer.gateway.obsolete.*Same categories — shown with deprecation warnings
vpn.customer.gateway.obsolete.check.intervalHours between compliance checks (0 = disabled)

Domain-level settings override global for that domain only (no cascade to child domains).

Existing gateways using excluded/obsolete values show a warning icon in CloudStack until updated.


Update and remove

You can update a VPN Customer Gateway only when it has no VPN connection, or the related connection is in error state.

CloudStack path: Network → VPN Customer Gateway → select gateway → Edit or Delete


After creating the customer gateway

  1. Create a VPN Gateway on the VPC (CloudStack-side public IP)
  2. Create a VPN Connection linking the VPC VPN Gateway to this customer gateway
  3. Configure the customer's VPN device (Palo Alto, Fortinet, etc.) with:
    • CloudStack VPN Gateway public IP as the peer
    • Matching IPsec preshared key and IKE/ESP parameters
    • Local private subnets and remote CloudStack VPC CIDRs
Not for laptop Remote Access

For individual laptop → VPC access, use Remote Access VPN (Source NAT IP → Enable VPN + VPN User) — not VPN Customer Gateway.