Connecting an On‑Premises Network to IBM Cloud VPC with a Site‑to‑Site IPsec VPN Gateway
Step‑by‑step guide to provision an IBM Cloud VPC VPN Gateway, configure a policy‑based IPsec tunnel to an on‑premises network, and validate connectivity with ping and console checks.
07 May 2026, 22:25 UTC

Problem: extending your data center into IBM Cloud securely
You have workloads running in an IBM Cloud VPC that need to reach services behind your corporate firewall. Opening public IPs or using public‑internet VPN appliances adds complexity and security risk. A native, managed site‑to‑site IPsec tunnel lets you treat the remote network as an extension of your VPC while keeping traffic encrypted.
Thesis
By provisioning an IBM Cloud VPC VPN Gateway, configuring a policy‑based IPsec tunnel, and validating connectivity with simple ping tests, you can establish a reliable, high‑availability link between your on‑premises network and IBM Cloud VPC without managing your own VPN appliances.
Planning the VPN Gateway
- Bandwidth tier: choose 100 Mbps, 500 Mbps, or 1 Gbps based on expected throughput; exceeding the tier causes packet loss.
- High availability: deploy the gateway in a multi‑zone VPC so IBM Cloud automatically fails over to a healthy zone if one zone becomes unavailable.
- Routing mode: for simple static subnet pairs use policy‑based tunnels; for dynamic routing with BGP, ensure your on‑prem firewall supports BGP and that ASNs and timers match.
Worked example: creating a policy‑based tunnel with the IBM Cloud CLI
Run the following commands in a terminal where you have the IBM Cloud CLI installed and are logged in with an Administrator or Editor role on the VPC infrastructure.
# 1. Set target region and resource group (adjust as needed)
ibmcloud target -r us-south -g Default
# 2. Create a VPC (if you don’t already have one)
ibmcloud is vpc create my-vpc --cidr 10.10.0.0/16
# 3. Create a subnet for the VPN Gateway (must be in a zone that supports VPN Gateway)
ibmcloud is subnet create my-vpn-subnet my-vpc 10.10.0.0/24 --zone us-south-1
# 4. Provision the VPN Gateway (choose bandwidth tier)
ibmcloud is vpn-gateway-create my-vpn-gateway my-vpc --subnet my-vpn-subnet --bgp-disabled --bundle 100
# 5. Define the connection to your on‑prem firewall (replace placeholders)
ibmcloud is vpn-connection-create my-vpn-connection \
--gateway my-vpn-gateway \
--peer-address 203.0.113.45 \
--peer-id 203.0.113.45 \
--local-cidrs 10.10.0.0/16 \
--remote-cidrs 192.168.10.0/24 \
--ike-version v2 \
--ike-policy aes256-sha256-dh14 \
--ipsec-policy aes256-sha256-pfs2 \
--preshared-key your‑shared‑secret
# 6. Enable the connection
ibmcloud is vpn-connection-update my-vpn-connection --state active
Replace your‑shared‑secret with a strong pre‑shared key known to both ends. The --bgp-disabled flag selects a policy‑based tunnel; omit it and add BGP parameters if you need route‑based connectivity.
Verifying connectivity
- From a compute instance in the VPC (same zone as the gateway or any zone with routing to it), ping an IP inside the remote network:
ping 192.168.10.10 - Check the tunnel state in the IBM Cloud console under **VPC Infrastructure → VPN Gateway → Connections**; it should show
Established. - Optional: view encrypted traffic counters via IBM Cloud Monitoring (look for
vpn.encrypted.packets.inandvpn.encrypted.packets.outmetrics).
Trade‑offs and limitations
- Throughput ceiling: the selected bandwidth tier caps the tunnel; sustained traffic above it will be dropped, increasing latency. Monitor with
ibmcloud is vpn-gateway-getand adjust the tier if needed. - BGP compatibility: route‑based tunnels require matching ASN, timers, and route advertisements. Mismatched BGP settings can cause tunnel flapping or black‑hole routes.
- Overlapping CIDRs: ensure the VPC subnet ranges do not overlap with any remote network ranges; otherwise traffic will be misrouted.
Actionable closing
Start with a small‑scale test: create a VPC, a single‑zone VPN Gateway, and a policy‑based tunnel to a lab firewall. Verify ping and tunnel status, then scale up by adding zones for HA or switching to BGP if you need dynamic routing. Remember to review the bandwidth tier regularly and to delete the gateway (ibmcloud is vpn-gateway-delete my-vpn-gateway) when the connection is no longer needed to avoid unnecessary charges.
0 replies
A thoughtful contribution can make all the difference. Be the first to share one.