AWS Site To Site VPN (Part 1)

แชร์
ฝัง
  • เผยแพร่เมื่อ 14 ม.ค. 2025

ความคิดเห็น • 132

  • @jasonshi6916
    @jasonshi6916 ปีที่แล้ว +2

    I LOVE this 30 mins session!! it is best tutorial about AWS site-to-site VPN so far on TH-cam.

  • @murthyavanithsa575
    @murthyavanithsa575 4 ปีที่แล้ว +1

    I think it's a very long time since I have seen our Indians going quality tutorials , it's succinct! 👌

  • @EvaBaaza
    @EvaBaaza 2 ปีที่แล้ว +6

    Chetan is changing the world

  • @tejbirsingh8104
    @tejbirsingh8104 4 ปีที่แล้ว +2

    Man u just saved my 20 marks for final exam
    u r genius

  • @vborole
    @vborole ปีที่แล้ว +1

    Thanks chetan, i have been going through all ur recordings, these are quite insightful; thanks again and good work :)

    • @chetanagrawal492
      @chetanagrawal492 ปีที่แล้ว +1

      Hey Vinod, great to see you here :-)

  • @thapasujan07
    @thapasujan07 5 หลายเดือนก่อน +1

    Thank you Sir for this. 💙

  • @thilinaba
    @thilinaba 4 ปีที่แล้ว +5

    Well explained. This saved me a lot of reading time. Thanks.

  • @gauravdalal9280
    @gauravdalal9280 4 ปีที่แล้ว +3

    Wow, no nicely explained.
    You have covered the topic thoroughly... Respect.
    Keep coming up with more stuff...🙂

  • @AroundDubai
    @AroundDubai ปีที่แล้ว +2

    Hi, Is there anyway we can use DynDns address while configuring the site to site ?

  • @ajaygupta943
    @ajaygupta943 3 ปีที่แล้ว +1

    It is really Fabulous...very nicely explained

  • @RalphQuick
    @RalphQuick ปีที่แล้ว +3

    Brilliant! Clear and concised!

  • @markjoseph8196
    @markjoseph8196 2 ปีที่แล้ว +2

    is it possible to create site to site tunnel between AWS lightsail server to an onpremise server?

  • @fikreselamelala2678
    @fikreselamelala2678 2 ปีที่แล้ว +1

    Thanks for sharing your knowledg!

  • @sanjaykattimath5946
    @sanjaykattimath5946 4 ปีที่แล้ว +1

    Awesome Demo with nice explanation ....!!!!
    Thanks Buddy keep it up

  • @markyboi01
    @markyboi01 4 ปีที่แล้ว +1

    Great Video and explanation. Well done Sir and Thank you

  • @venut4195
    @venut4195 4 ปีที่แล้ว +2

    Great session man - i really love it and will follow you on upcoming sessions.

  • @santoshmargale3047
    @santoshmargale3047 2 ปีที่แล้ว +2

    Hello, is there is same approach for the Fortinet Vendor as you did with Openswan ?

  • @amolghadigaonkar8656
    @amolghadigaonkar8656 4 ปีที่แล้ว +2

    Very Nicely explained and documented. Thank You #Respect

  • @ammabalasimha
    @ammabalasimha 4 ปีที่แล้ว +2

    wonderful Bro..nice explaination

  • @venkateshd1208
    @venkateshd1208 ปีที่แล้ว +1

    Thanks I can able to configure😍

  • @tamilpattucassette6859
    @tamilpattucassette6859 2 ปีที่แล้ว +1

    Thank you for sharing. It's valuable.

  • @annali513
    @annali513 4 ปีที่แล้ว +1

    Could you please explain AWS Solutions Architect Professional ? I like your explanation, you are the best instructor I have ever seen

  • @srikanthakella5334
    @srikanthakella5334 3 ปีที่แล้ว +4

    Hi. It was very helpful. I want to know whether VPC flow logs will capture the traffic of VPN or not. If not, request you to share steps to capture logs. Thanks in advance.
    Note: A small suggestion, many videos are available over internet but no one will talk about capturing logs, troubleshooting common problems. So request you to even include these also in your videos. Please don't think otherwise. I am sorry if I am wrong.

  • @ms-learner7908
    @ms-learner7908 4 ปีที่แล้ว +1

    Excellent , Much appreciated... clear explanation. Thanks bro

  • @bada-t9s
    @bada-t9s 3 ปีที่แล้ว +1

    Well explained :) you save my project!

  • @murageshmurali5838
    @murageshmurali5838 4 ปีที่แล้ว +1

    Great Video ,Really you made easy to understand this .

  • @Tolulope374
    @Tolulope374 4 ปีที่แล้ว +1

    Very helpful video ✅💯

  • @KIRIKTECH
    @KIRIKTECH 3 ปีที่แล้ว +2

    Informative video but I have one doubt when I configure both tunnnels then it is not working

    • @vishalprasadgupta714
      @vishalprasadgupta714 2 ปีที่แล้ว

      It is already mentioned in video that openswan does not work with two tunnels

  • @harimohan8644
    @harimohan8644 2 ปีที่แล้ว +1

    can you please tell me where can i get the documents that you have mentioned

  • @s.m.ehsanulamin7235
    @s.m.ehsanulamin7235 4 ปีที่แล้ว +1

    in the lecture 28:56 we have to add the route with VPW. But what will be the route in this case? will it be 10.200.0.0/16 or 0.0.0.0/0?

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว

      Typically you would want to add the destination cidr of other side of the network that means only 10.200.0.0/16 in this case. However if you want that all the traffic should be routed to other network you can also put 0.0.0.0/0. However you need to then make sure that the internet traffic is routed further to internet via that network router.

  • @juansam4134
    @juansam4134 ปีที่แล้ว +1

    On a cisco router you have to configure encryption type, hash, authentication type and diffie helman grop. Don´t you have to do that on AWS ? Thanks

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว

      Yes, you should match it as per your router configuration. When you download VPN configuration you can select your router type.

  • @senthilkumar5129
    @senthilkumar5129 3 ปีที่แล้ว

    Good clear explanation thank you so much

  • @raoufguirguis14
    @raoufguirguis14 4 ปีที่แล้ว +2

    Wonderful session, Thanks

  • @gnadha123
    @gnadha123 3 ปีที่แล้ว +1

    Hi, To remove one VPN connection what are the actions / steps do we need follow

  • @shubhamgautam3376
    @shubhamgautam3376 2 ปีที่แล้ว +1

    please update setup guide docs link.... currently no-one accessable

  • @davystrain7217
    @davystrain7217 3 ปีที่แล้ว

    An excellent example many thanks.

  • @WarCreed
    @WarCreed 2 ปีที่แล้ว +1

    I am using Transit gateway in place of VPG after setting up S2S VPN what will be the Route setup

    • @AWSwithChetan
      @AWSwithChetan  2 ปีที่แล้ว

      Yeah you can propagate the routes via TGW route tables and attachments

  • @arnoldsalvador804
    @arnoldsalvador804 3 ปีที่แล้ว +2

    There two segments in the Create VPN connection which is not in your presentation. After the Tunnel Inside Ip version.. there are these Local Ipv4 Network CIDR (Customer Gateway CIDR range) and Remote IPv4 Network CIDR range. Are these 10.200.0.0/16 and 10.100.0.0/16?

  • @philipho
    @philipho 3 ปีที่แล้ว +1

    Well explained

  • @anushavengsarkar6299
    @anushavengsarkar6299 4 ปีที่แล้ว +1

    thanks a lot. nice explanation

  • @dhananjay3974
    @dhananjay3974 3 ปีที่แล้ว +1

    Thank you very much you explain it very well...
    Does public IP change every time like EC2 instance or it is fixed for ipse c tunnel?

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      VPN is not directly linked to EC2 IPs if you are talking about VGW side. In this video I also showed customer side using another EC2 with Public IP. Now this IP in this setup will change if you restart customer gateway side EC2. However in ideal world you should have router on customer side with fixed public IP.

    • @dhananjay3974
      @dhananjay3974 3 ปีที่แล้ว

      @AWS Training Center
      Thanks
      I want to know based on example you given.. right side public ip (VPG) will not change and it is constant?
      I know left side ip will change if ec2 restart.

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว +1

      Thats right VPG IPs are static

  • @Karthik_kkk
    @Karthik_kkk 4 ปีที่แล้ว +1

    Can you please put hybrid dns resolution on top of this? may be create private hosted zone per vpc, add inbound and outbound endpoint resolvers and try resolving dns from other vpc?

  • @s.m.ehsanulamin7235
    @s.m.ehsanulamin7235 4 ปีที่แล้ว +1

    If I want to Virtual isolation of network from customers using the web application then is it possible to do with VPC peering or I have to use VPN connectivity?

  • @sharmanick1
    @sharmanick1 3 ปีที่แล้ว +1

    Well explained, thank you :)

  • @patrafransiskus1306
    @patrafransiskus1306 4 ปีที่แล้ว +1

    Thank you very much sir, I really need this.
    One question sir, is it possible to other servers/clients on Corporate Network (Virginia Reg.) to communicate with Mumbai Reg. through the tunnel?

  • @UdayShivamurthy
    @UdayShivamurthy 3 ปีที่แล้ว +2

    As always, brilliant material Chetan. Can you pl point me to a video that explains src and destination of routing tables?

  • @romaingirardot6434
    @romaingirardot6434 2 ปีที่แล้ว +2

    Hello Sir !
    Thank you for the very helpful video. I am trying to do a AWS site to site VPN between my VPC and a distant instance wich is an open vpn server. The goal is that the VPC resources can reach my openvpn clients. Thank to your video I am able to connect my distant instance to my VPC and connexion links are up. In order to test the connexion I created an aws instance in the VPC subnet and I try to send pings from my distant instance to the aws instance (EC2-A in your video).
    But I guess I missanterstand a step, do you have any suggestion about the architecture I am trying to build ?
    A warm thank you in advance !

  • @CreaTeach98
    @CreaTeach98 3 ปีที่แล้ว +1

    Hi I have a one query , we want to make tunnel between aws to aws but issue is that both side private ip is matched so is it possible to use Nat technology. On firewall i am able to perform this..pleas help I need urgent support

    • @sibgathassan6281
      @sibgathassan6281 8 หลายเดือนก่อน

      it seems complex, even may be not possible.

  • @lifeisbeautiful7882
    @lifeisbeautiful7882 2 ปีที่แล้ว +1

    Great video

  • @acdii
    @acdii 3 ปีที่แล้ว +1

    AWS to Cisco IKEv2 would be nice considering the configuration DOWNLOAD is IKEv1 using deprecated and unsecure protocols. Thought it might be in this video, but guess not.

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      Yeah I agree. Actually at the time this video was recorded aws was supporting only IKEv1. But yes now it supports v2 as well so always good to use latest protocol version.

    • @acdii
      @acdii 3 ปีที่แล้ว

      @@AWSwithChetan Discovered why it isn't working for me. The IKEv1 two tunnel from AWS to ASA is active standby, but for IKEv2, two peer is not supported, at least not in the 9.1 version, possibly in 9.7 version. I will have to tear the entire configuration out and create one VPN tunnel. I don't think it will allow me to create 2 tunnels though.

  • @MaheshTripathi-l2t
    @MaheshTripathi-l2t ปีที่แล้ว +1

    Hi brother is it possible to access a website from this structure of vpn.

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว

      Yes, just open port 80 or 443 for the EC2 instance on which website is running and then you can access it with Private IP of EC2 over VPN connection. For using DNS either you can have your onprem DNS server resolve to this private IP or you can configure AWS route53 inbound resolver to handle the DNS.

  • @ramv8453
    @ramv8453 4 ปีที่แล้ว +1

    Excellent ! Thank you buddy :)

  • @khawarbhatti8436
    @khawarbhatti8436 4 ปีที่แล้ว +2

    good job

  • @wqdasdf7169
    @wqdasdf7169 4 ปีที่แล้ว +1

    Thank you wery much!
    It works OK if VPC-A and VPC-B both in AWS, but I had a problem with connection other cloud provider to AWS. In my case Ipsec connection was OK, but ping didn't worked until I added public IP of my openswan VM into Routing table and VPN Static route.
    Also there is not exist openswan for centos-8 and ubuntu-18+ it replaced by libreswan. Usage of libreswan the same as openswan.

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว +1

      Thats right because your openswan instance is acting as router for other side of the network. Watch my other video on site to site vpn (new video) which explains this.

  • @NarkoChamp
    @NarkoChamp 2 ปีที่แล้ว

    Failed to start Internet Key Exchange (IKE) Protocol Daemon for IPsec. getting error in the end how to fix it ?

    • @AWSwithChetan
      @AWSwithChetan  2 ปีที่แล้ว +1

      Difficult to comment without looking at error. Just try again and make sure you don’t miss the configuration.

    • @NarkoChamp
      @NarkoChamp 2 ปีที่แล้ว +1

      yes i did follow all step exactly but I get this error _faild to start internet key exchange IKE protocol daemon for IPsec"

  • @rathore354
    @rathore354 4 ปีที่แล้ว +2

    i can say only love you bro

  • @ThanhNguyenVan-ss7yy
    @ThanhNguyenVan-ss7yy 3 ปีที่แล้ว

    Do you think we can perform all these steps by using Terraform configuration file

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      On AWS side configuration.. yes ofcourse

  • @vvmanyam1
    @vvmanyam1 4 ปีที่แล้ว +1

    This is awesome, Thanks.

  • @cunninghamb505
    @cunninghamb505 4 ปีที่แล้ว

    Can you add other clients and how to prevent cross talk

  • @kevinfitzgerald3928
    @kevinfitzgerald3928 3 ปีที่แล้ว

    When trying to create the Customer gateway I am told I need a valid Public IP address despite coping the one from the EC2-B router
    I can not proceed further

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      Sorry did not get your question completely

  • @riyazpatnam3200
    @riyazpatnam3200 3 ปีที่แล้ว

    worthy explanation!!

  • @apsgren4948
    @apsgren4948 4 ปีที่แล้ว

    HI,
    I am able to ping to AWS instance from only one instance which is installed Openswan on on-premises side, I am unable to ping from different instance, And only linux to linux machine able to ping, linux to windows unable to ping.

  • @networkinsights
    @networkinsights 2 ปีที่แล้ว +1

    The service status is active but the Tunnel status is down. Tried multiple times without any success. Any solution?

    • @AWSwithChetan
      @AWSwithChetan  2 ปีที่แล้ว

      With latest version of openswan, you may have to change few tunnel parameters, especially:
      1. Remove auth=esp
      2. phase2alg=aes_gcm
      3. ike=aes256-sha1;modp1024
      Try this

    • @networkinsights
      @networkinsights 2 ปีที่แล้ว

      @@AWSwithChetan Thanks for the reply Chetan. Much appreciated. Tried your solution but did not work. Status is still down. Also can't ping the private IP. Can't figure out what is the issue. Anyway thanks.

    • @sibgathassan6281
      @sibgathassan6281 8 หลายเดือนก่อน

      @@AWSwithChetan in document 2024 you have menioned below
      ▪ Remove auth=esp
      ▪ phase2alg=aes_gcm
      ▪ ike=aes256-sha1
      i am confused which one is currently working.

  • @sibgathassan6281
    @sibgathassan6281 8 หลายเดือนก่อน

    i followed all steps when checking status of tunnel i am getting below error
    initiating all conns with alias='Tunnel1'
    no connection named "Tunnel1"

    • @sibgathassan6281
      @sibgathassan6281 8 หลายเดือนก่อน

      resolved after following the method available in document, method in video is not working,

    • @sibgathassan6281
      @sibgathassan6281 8 หลายเดือนก่อน +1

      but IKEV2 is working, if i disable ikv2 from aws side, then tunnel is showing down from aws side, and from DC side error is "Tunnel1" #1: dropping unexpected IKE_SA_INIT message containing NO_PROPOSAL_CHOSEN notification; message payloads: N; miss"
      any solution so that i can use ikev1?

  • @maheshshettigar5558
    @maheshshettigar5558 3 ปีที่แล้ว +1

    Hello Chetan,
    Thanks for making such excellent video. as per the guidlines i had configured VPC-A & VPC-B and conncetion has been established but i'm unable to ping.. i had check the secuirty groups but not able to identify where is the issue.. Please help...
    Thanks in advance..
    Rgds,
    Mahesh

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      Do you see tunnel up and In SG I hope ICMP Ipv4 is allowed.

  • @vishalk2798
    @vishalk2798 3 ปีที่แล้ว

    should both networks be \16 as remote andlocal or one can be \24 and one \16

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว +1

      Can be anything, doesn’t matter. Depends on how big or small networks you want to have.

    • @vishalk2798
      @vishalk2798 3 ปีที่แล้ว

      @@AWSwithChetan Thanks

  • @bodebolade977
    @bodebolade977 3 ปีที่แล้ว

    how would i configure this if the customer network is requesting for public IP instead of typical private IP in such VPN setup? How is the natting suppose to be done? Thank you

    • @AWSwithChetan
      @AWSwithChetan  3 ปีที่แล้ว

      Customer gateway router should have Public IP and it should do the NATing for all internal machines.

  • @abdulismail8150
    @abdulismail8150 4 ปีที่แล้ว

    Great chaytan , i hope i got the spelling right. great demo, do u have complete course? for associate architect?

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว

      Thanks man..you spelled it almost correct. Its Chetan :-).
      I don’t have associate architect course. I just have hands on course on AWS Networking on Udemy.

  • @Ravi-my1cl
    @Ravi-my1cl 2 ปีที่แล้ว

    After starting ipsec service still tunnel status is down. Can you please help me on this?

    • @AWSwithChetan
      @AWSwithChetan  2 ปีที่แล้ว

      With latest version of openswan, you may have to change few tunnel parameters, especially:
      1. Remove auth=esp
      2. phase2alg=aes_gcm
      3. ike=aes256-sha1;modp1024
      Try this

    • @ebenezerferguson3756
      @ebenezerferguson3756 2 ปีที่แล้ว

      @@AWSwithChetan This was very helpful. Thank you very much

  • @muralib1267
    @muralib1267 4 ปีที่แล้ว

    Your approach was really wonderful..! and one doubt I have, Can we replace that customer gateway with With Azure Cloud .. I mean I want to establish connection between AWS to Azure Cloud ?? Is it possible..? Quick reply is appriciated.. ! Thanks In Advance.

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว +1

      Yes you can connect to Azure or GCP. My Udemy course has hands-on where I have shown how to do that however unfortunately I can’t publish same video here.

    • @muralib1267
      @muralib1267 4 ปีที่แล้ว

      @@AWSwithChetan No Problem. can you share the tutorial name ??

  • @ramkumar-th1yd
    @ramkumar-th1yd 4 ปีที่แล้ว +1

    Super

  • @adsingh1644
    @adsingh1644 4 ปีที่แล้ว

    Great video.
    Tried to follow all the steps one by one, without mistake 5-6 times. but @30:02 when start IPSEC services, it refuses and gives an error" [root@ip-10-2-0-250 ec2-user]# systemctl start ipsec
    Job for ipsec.service failed because the control process exited with error code. See "systemctl status ipsec.service" and "journalctl -xe" for details.
    Please if someone can assist to resolve this issue, As I followed some more videos but still getting the same error in this lab, Even from Google, couldn't find any solution. Pls assist 🙏

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว +1

      Whats the output of journalctl -xe command?

    • @adsingh1644
      @adsingh1644 4 ปีที่แล้ว

      @@AWSwithChetan Thanks for your swift response. I followed all the steps again n found that always /etc/ipsec.d/aws.secrets file was creating an issue. I deleted this file and created new. Entered the line from downloaded configuration file. started serices n status was showing ACTIVE.
      [root@ip-10-2-0-95 ipsec.d]# systemctl status ipsec
      â ipsec.service - Internet Key Exchange (IKE) Protocol Daemon for IPsec
      Loaded: loaded (/usr/lib/systemd/system/ipsec.service; enabled; vendor preset: disabled)
      Active: active (running) since Thu 2020-06-25 20:25:56 UTC; 9min ago
      But now when I checked the status of tunnel, whoich should be UP, after Route Propagation. Tunnel is still DOWN.
      Would u assist with this now. That what could be the reason for showing Tunnel Down, however ipsec service is ACTIVE.
      Waiting for your kind response. Thanks

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว +1

      Tunnel would start when you send some request (ping) to aws from your openswan instance. Also I hope you have configured only one tunnel in openswan. Don’t add both in your configs as it causes problem.

    • @adsingh1644
      @adsingh1644 4 ปีที่แล้ว

      @@AWSwithChetan Yes, I have configured only one tunnel. IPSEC service is active n running. But even while pinging (passing traffic) from OPENSWAN Instance side, not pinging as well. no error even.

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว

      The Security group on aws side of ec2 instance allows ICMP, right? Also try the other way around traffic
      -Chetan

  • @vineshpandey7276
    @vineshpandey7276 3 ปีที่แล้ว +1

    Thanks buddy !!!

  • @josephattabenninjr7317
    @josephattabenninjr7317 4 ปีที่แล้ว +1

    terrific!!!! good job

  • @kayoutube690
    @kayoutube690 4 ปีที่แล้ว

    how about the NACL configuration?

  • @SUPRIYADASsupu
    @SUPRIYADASsupu 4 ปีที่แล้ว

    Is it possible that you upload the document. it will be easier for us to practice.

    • @AWSwithChetan
      @AWSwithChetan  4 ปีที่แล้ว

      Document download link is there in the description

  • @linuxusers1255
    @linuxusers1255 3 ปีที่แล้ว

    Failed to start Internet Key Exchange (IKE) Protocol Daemon for IPsec.
    --------------------------- i am getting this error

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว

      Kindly refer to latest guide added to video description.

  • @꺄르륵-j2y
    @꺄르륵-j2y 3 ปีที่แล้ว

    He is hero

  • @RoadToDevOps
    @RoadToDevOps ปีที่แล้ว

    Hello Sir, I'm not able to install "Openswan", can you please help?

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว +1

      May be you are using Amazon Linux 3 (2023) AMI. Can you try with Amazon Linux 2 AMI for launching EC2 instance?

    • @RoadToDevOps
      @RoadToDevOps ปีที่แล้ว

      @@AWSwithChetan sure sir, Thanks a lot for your quick response; and one more thing can you please update the course on udemy as well as i'm getting error while Uploading the certificate and keys to ACM; its showing "Unable to locate credentials. You can configure credentials by running "aws configure"."
      Can you please guide me on this case? As the interviewer will ask questions from the latest ami

  • @0N369
    @0N369 3 ปีที่แล้ว

    Why my openswan is not able to start its throws error

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว

      There had been new cipher suites that you have to use due to security issues in the older openswan.
      I will see if I can provide the link to pdf for latest version deployment. Otherwise if you want you can get the video and pdf in my networking course at www.awswithchetan.com

  • @sujendrakumar4852
    @sujendrakumar4852 3 ปีที่แล้ว

    it did not worked .

    • @AWSwithChetan
      @AWSwithChetan  ปีที่แล้ว

      @ajaygupta943 I have made a latest guide available in the video description.