Setup an AWS Site-to-Site Virtual Private Network (VPN)

แชร์
ฝัง

ความคิดเห็น • 87

  • @dongphim
    @dongphim 6 หลายเดือนก่อน +1

    I passed Solution Architect associate exam December 29 2023, Thank for the your knowledge provider via udemy course, hope you always successfully on education major.

  • @stevecuthbertson4381
    @stevecuthbertson4381 ปีที่แล้ว

    Cracking video. Successfully hooked up my home network to my AWS VPC and could ping my home domain controller from AWS and vice-versa. Now I can play with FSx for Windows.

  • @kingslee5182
    @kingslee5182 หลายเดือนก่อน

    Thanks i have configured, step by step explanation is very helpful, thanks a lot.

  • @rahulthapa5201
    @rahulthapa5201 3 ปีที่แล้ว +2

    I passed AWS solution architect associate exam today with your course and 6 mock test series, exam look more like a mock test rather than a real exam😂 thankyou Davis sir, you are an awesome teacher ❤️🎉 will go for professional? or apply for job, I am a non technical background student.

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 ปีที่แล้ว

      Hi Rahul, congratulations on your exam success. It would be best to take another associate-level course before doing any professional level. All the best.

    • @rahulthapa5201
      @rahulthapa5201 3 ปีที่แล้ว

      @@DigitalCloudTraining can you provide some production level architect examples where I get good hands-on experience and prepare for good job opportunities.

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 ปีที่แล้ว

      @@rahulthapa5201 I recommend that you post that question to our Slack group to get several inputs.

    • @rahulthapa5201
      @rahulthapa5201 3 ปีที่แล้ว

      @@DigitalCloudTraining can you share the link of slack group

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 ปีที่แล้ว

      @@rahulthapa5201 digitalcloud.training/slack/

  • @SpongeWorthy76
    @SpongeWorthy76 ปีที่แล้ว +2

    Appears openswan isn't available to download anymore

    • @kelphils2628
      @kelphils2628 ปีที่แล้ว

      It’s still available, if you setup a dynamic routing instead of static routing in the vpn connection setup, you won’t see openswan configuration option when you try downloading a config file

  • @BasilTS
    @BasilTS ปีที่แล้ว +1

    Well that is as they say MINT, excellent video

  • @user-qp3ho8gy8q
    @user-qp3ho8gy8q 8 หลายเดือนก่อน

    I followed the video and I can ping the EC2 instance in the VPC with no issue. However I can't ping any EC2 instances inside the private subnet in the AWS VPC from the "on-prem" side. I made sure the security group and firewall allowed ICMP. Any idea?

  • @George-mk7lp
    @George-mk7lp 27 วันที่ผ่านมา

    I have a question regarding EC2 instances and on-premises servers. In the example you provided, are the EC2 instances used solely for exchanging a public IP address for establishing a tunnel connection. If they are used for tunnel connections, does it mean that if any of these instances go down, the tunnel will also go down? Since this tutorial is from three years ago, I'm curious if this approach is still commonly used today in site-to-site connection.

    • @DigitalCloudTraining
      @DigitalCloudTraining  23 วันที่ผ่านมา

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @sebastianalvarado2820
    @sebastianalvarado2820 2 ปีที่แล้ว

    Thanks for this video, is very thorough and helps a lot. If we want to access an ALB inside the VPC, what would the IP be or how would the instance inside the On Prem Data Center access the ALB?

  • @alisohailtheitkid
    @alisohailtheitkid 7 หลายเดือนก่อน

    Absolutely impressive!, Thanks Coach!

  • @gogsi02
    @gogsi02 7 หลายเดือนก่อน

    I have set up similar configuration but using gns3 on my laptop and a gns3 router. It basically works but once i start changing the tunnel options namely Local IPV4 Network CIDR and Remote IPV4 Network CIDR and change them to one of my networks behind the routers all fails and tunnels are down. So I can not explain myself how does to options work. Any ideas ?

    • @DigitalCloudTraining
      @DigitalCloudTraining  7 หลายเดือนก่อน

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @user-eh7tv4ym2x
    @user-eh7tv4ym2x 6 หลายเดือนก่อน

    Really great tutorial. However, any way to make NAT the ip so that it reaches the on prem instances as a public ip?

    • @DigitalCloudTraining
      @DigitalCloudTraining  6 หลายเดือนก่อน

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.

  • @ashermanangan
    @ashermanangan 2 ปีที่แล้ว

    Thanks Niel, I love this tutorial

  • @han8050
    @han8050 ปีที่แล้ว

    Thanks Neal, your video is great!

  • @SerbanTeodorescu
    @SerbanTeodorescu ปีที่แล้ว

    Really nice and clear video. Too bad you cant have dynamic IP for customer gateway.

    • @ffelegal
      @ffelegal ปีที่แล้ว

      You can use a private certificate and not specify the IP now.

  • @bobmbaka7681
    @bobmbaka7681 2 ปีที่แล้ว

    Good day,
    Your videos have been very helpful and I even got your course on Udemy too. I have a challenge right now I have been given an on premises Cisco server form with details of the VPN to use as guide to connect to and I am really not getting it yet

  • @robertpadilla4897
    @robertpadilla4897 ปีที่แล้ว

    Hi sir , great tutorial deserves a subscribe , I am new in aws / networking , in this setup will AWS VPC ping On-Premises Private Subnet , do i need to setup another VGW and CGW to be able to achieve 2 way routing ? or just need to adjust routing config from existing VGW and CGW?

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      You can post your technical questions on our facebook group to get more insights: facebook.com/groups/awscertificationqa

  • @somethingvlogbyabishek
    @somethingvlogbyabishek 2 ปีที่แล้ว

    Thanks for explaining, our requirements we need to configure with strongswan can pls do video on that

  • @Mr.Abd101
    @Mr.Abd101 2 ปีที่แล้ว +1

    Hey Hii This video Very helpful Thank you

    • @Mr.Abd101
      @Mr.Abd101 2 ปีที่แล้ว +1

      But I have questions how to implement site to site VPN from local Onprem to Aws

    • @Mr.Abd101
      @Mr.Abd101 2 ปีที่แล้ว +1

      Can you plz explain how to setup that

    • @Mr.Abd101
      @Mr.Abd101 2 ปีที่แล้ว

      👋👋

  • @muchaohyy
    @muchaohyy 2 ปีที่แล้ว

    This is very handy and useful. Thanks for sharing.

  • @terahnsdad
    @terahnsdad 2 ปีที่แล้ว +1

    I can ping between OpenSwan and the ec2 in the AWS VPC, but not from the On-premise ec2, even after updating the route table to point to the OpenSwan instance...I would have thought this was the easy part!

    • @terahnsdad
      @terahnsdad 2 ปีที่แล้ว +4

      Reboot of the openSwan ec2 and restart of ipsec service fixed this.

    • @garybruce
      @garybruce ปีที่แล้ว

      @@terahnsdad I have the same problem on the last part (cannot ping from on-prem EC2 to aws VPC EC2). The reboot and restart did not work for me. Any thoughts anyone. I've been bashing away at this for some time now 😞

    • @romeocorgiolu51
      @romeocorgiolu51 ปีที่แล้ว

      @@terahnsdad thank you!!

  • @mohsinnisar8567
    @mohsinnisar8567 2 ปีที่แล้ว

    Awesome explanation.

  • @juansanchez6685
    @juansanchez6685 ปีที่แล้ว

    Great video!

  • @hieunguyenofficial9497
    @hieunguyenofficial9497 2 ปีที่แล้ว

    Thank you very much!

  • @mikkohbrayoh7629
    @mikkohbrayoh7629 10 หลายเดือนก่อน

    Thank you.

  • @abdelrahmansalah8727
    @abdelrahmansalah8727 ปีที่แล้ว

    Great Video, I have setup the CGW to the Office Router IP , and installed the openswan on OpenSwan on one of the on-permise machine, what other configurations should i do on this case?

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.
      Thank you for your understanding, and we wish you all the best in your exam preparations!

  • @YasserAlhawary
    @YasserAlhawary 2 ปีที่แล้ว

    Thanks alot , the content is great

  • @oliverxu1978
    @oliverxu1978 2 ปีที่แล้ว

    high quality demo

  • @dcabib
    @dcabib 2 ปีที่แล้ว

    Amazing.... thanks for sharing

  • @andrewmcmahon2464
    @andrewmcmahon2464 2 ปีที่แล้ว

    what would be the remote ipv4 network cidr if it was going to a office network and not another vpc in aws

  • @niteshr7651
    @niteshr7651 2 ปีที่แล้ว

    Great demo! 👍👍

  • @mikoajdreger4213
    @mikoajdreger4213 ปีที่แล้ว

    Hey, I have my server at home on which I have a website - if I connect this server to the VPC via VPN site to site, will I be able to host this server (website) via VPC on the Internet? thanks for a great video!

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      Hey Mikolaj, this would be a great question to post on our facebook group: facebook.com/groups/awscertificationqa

  • @nimesis124
    @nimesis124 ปีที่แล้ว

    Created the VPN and the TUNNEL shows UP but I am able to access my Only one machine which is itself libreswan not able to connect other machines....... Don't know why

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      You can post your technical questions on our slack channel: digitalcloud.training/slack/ and our FB group: facebook.com/groups/awscertificationqa

  • @wajeehulhussain2058
    @wajeehulhussain2058 2 ปีที่แล้ว

    Hey Neal,
    Your videos have been of an immense help in understanding the flow. I have a quick question, i aim to establish a private connection between an on-prem private application server with a SFTP server hosted inside of a private subnet in a AWS VPC.
    Based on this video, what steps would differ to accomplish this task?
    I would be glad if you could reply to my comment. Much needed.

  • @dennielluissadian5026
    @dennielluissadian5026 2 ปีที่แล้ว

    Hello please give me a hint how I could also configure the tunnel2. Openswan is giving me internal error and the eroute can't be installed because something is already in use by the tunnel1.

    • @DigitalCloudTraining
      @DigitalCloudTraining  2 ปีที่แล้ว

      You must follow the steps exactly, and you'll get the same result.

  • @rha3d
    @rha3d ปีที่แล้ว

    is there any tutorial for configure Elastic Benstalk with VPN Site To Site?

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      You can purchase the full course on our website www.digitalcloud.training

  • @lesllyfashion
    @lesllyfashion ปีที่แล้ว

    would that be ideal for production environment.

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      Hi there, we recommend posting your question in our Facebook group. Our community members are always happy to share their knowledge and help each other out.
      If you're not already a member of our Facebook community, we'd love to have you join us! 

      Here's the link to sign up: facebook.com/groups/awscertificationqa
      Once you're in, you can post your question and get some helpful insights.
      Thank you for your understanding, and we wish you all the best in your exam preparations!

  • @kedarpandhare8522
    @kedarpandhare8522 2 ปีที่แล้ว

    Hey Neal, I have a quick question on the Inside IPv4 CIDR range that was created once the VPN connection was setup. Is that somewhere mentioned in the config file or AWS automatically creates it as part of VPN connection process?

  • @gdevelek
    @gdevelek 3 ปีที่แล้ว

    Great video.

  • @maheshshettigar5558
    @maheshshettigar5558 2 ปีที่แล้ว

    Hello Sir,
    your training vidoes are excellent.. Thanks for creating such videos,, i had a query regarding the traning video.. i had setup site to site vpn as per your guidlines. but i'm unable to get the ping responces from both side.. IPSEC tunnel is up.., Please advice..

    • @DigitalCloudTraining
      @DigitalCloudTraining  2 ปีที่แล้ว

      Probably routing or security groups but there are quite a few things that will cause it to fail if not setup properly. It's very important to follow my instructions very closely.

  • @EvaBaaza
    @EvaBaaza 2 ปีที่แล้ว

    How did he get to the screen at 10:12 ? Is that from the AWS a=command line ?

  • @frby6993
    @frby6993 3 ปีที่แล้ว

    Thanks!

  • @budali44
    @budali44 3 ปีที่แล้ว

    Thanks

  • @prajwalaradhyas6606
    @prajwalaradhyas6606 2 ปีที่แล้ว

    My VPN remains down, even after configuring all things correctly..

  • @YasserAlhawary
    @YasserAlhawary 2 ปีที่แล้ว

    Isn't it better and cheaper to setup site to site vpn using this AWS product And through it make admins Access from On-premises to vpc in additional to the site to site purposes for servers
    And if users needs access from home they use the entity vpn to be On-premises network and then access the vpc
    I mean it will serve both
    Site to site and client to site
    Actually I thought Aws client vpn is cheaper service than site to site and was thinking of making site to site over one AWS Client connection using nat/route but after checking prices it's ridiculous , the AWS Client vpn is way more expensive

    • @DigitalCloudTraining
      @DigitalCloudTraining  2 ปีที่แล้ว +1

      Possibly. There are pros and cons to every solution so it depends on your use case.

    • @YasserAlhawary
      @YasserAlhawary 2 ปีที่แล้ว

      @@DigitalCloudTraining I'm not talking about current production scenario.
      I am new to AWS and found both services and was check the best cost wise deployment scenario.
      For sure the problem will be user identity integration between vpn users and AWS auditing/logging
      But in general AWS pricing in AWS vpn Client is overpriced 😅

  • @snowm9534
    @snowm9534 3 ปีที่แล้ว

    Hi Neal, I wasn't able to open the zipped file as it's requiring a password. Where can I get the password for the zipped file?

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 ปีที่แล้ว

      No idea why it's asking for a password, it's just a text file.

    • @DigitalCloudTraining
      @DigitalCloudTraining  3 ปีที่แล้ว

      It's not zipped either so not sure what you're downloading

  • @naveedtokhi3791
    @naveedtokhi3791 ปีที่แล้ว

    Hey Neal,
    Nice video. I have come accross this issue, where I'm unable to download the openswan package it gives me this error,'
    [root@ip-------------- ~]# sudo yum install openswan
    Last metadata expiration check: 1:42:25 ago on Sat Mar 18 03:02:23 2023.
    No match for argument: openswan
    Error: Unable to find a match: openswan
    Suggest what should I do, as I tried downloading the libreswan and strongswan, I am unable to download them either.

    • @DigitalCloudTraining
      @DigitalCloudTraining  ปีที่แล้ว

      This would be great question to post on our fb group: facebook.com/groups/awscertificationqa