You are viewing an old version of this page. View the current version.

Compare with Current View Page History

« Previous Version 3 Next »


1. Objectives

In SDN solutions, some services are provided by the SDN, for example

  • Source NAT
  • Static NAT
  • Load Balancer
  • Port forwarding
  • Network ACL (VPC)
  • Firewall rules (Isolated network)

However, there are still some services which are not supported by the SDN provider, for example

  • Dhcp (supported by some SDN providers)
  • Dns (supported by some SDN providers)
  • UserData (it is unsupported by SDN providers)
  • Vpn

In this case, CloudStack VR is used for provide Dhcp/Dns/Userdata services to the vm instances. It is not in the path of the traffic, it acts as a helper vm

The goal of this feature is to support VPNs in Cloudstack VR

  • Remote access VPN for SDN networks 
  • Site-to-Site VPN for SDN networks

Please note, this supports VPC only. Isolated networks is not supported

2. High Level Design

As the first step, the CloudStack VR needs a public IP (via static nat).

For Remote access vpn, the diagram is as below

For Site-to-Site VPN, the diagram is as below

In both cases, as the last step, static routes need to be create by cloudstack and configured in SDN.



3. Implementation

This described some details of the implementation

3.1 database change

a new column is added to the table user_ip_address for public ip address, which indicate if the ip is one-to-one nat to the VPC VR.


  `for_router` tinyint(1) DEFAULT '0' COMMENT 'True if the ip address is used by Domain Router to expose services',


3.2 ipsec configuration for Remote access VPN


root@r-26-VM:~# cat /etc/ipsec.d/l2tp.conf 
#ipsec remote access vpn configuration
conn L2TP-PSK
        authby=secret
        rekey=no
        keyingtries=3
        leftfirewall=yes
        type=transport
        left=172.17.1.67  (private IP of first guest NIC)
        leftid=10.0.88.10 (public IP of VPC VR)
        leftprotoport=udp/l2tp
        right=%any
        rightprotoport=udp/%any
        rightsubnetwithin=0.0.0.0/0
        auto=route

root@r-26-VM:~# cat /etc/ipsec.d/ipsec.any.secrets 
: PSK "4QCNMeE9RjDccgYgPzZZmnkc"


for xl2tpd and vpn users

root@r-26-VM:~# cat /etc/xl2tpd/xl2tpd.conf 
[lns default]
ip range = 10.1.2.2-10.1.2.8
local ip = 10.1.2.1
require chap = yes
refuse pap = yes
pppoptfile =    /etc/ppp/options.xl2tpd

root@r-26-VM:~# cat /etc/ppp/chap-secrets 
# Secrets for authentication using CHAP
# client	server	secret			IP addresses
test1 * test1 *
test2 * test2 *
test3 * test3 *



3.3 ipsec configuration for Site-to-Site VPN


root@r-26-VM:~# cat /etc/ipsec.d/ipsec.vpn-10.0.80.31.conf
#conn for vpn-10.0.80.31
conn vpn-10.0.80.31
 left=172.17.1.67    (private IP of first guest NIC)
 leftid=10.0.88.10   (public IP of VPC VR)
# leftsourceip=10.0.88.10
 leftsubnet=172.17.0.0/20
 right=10.0.80.31
 rightsubnet=172.27.0.0/20
 type=tunnel
 authby=secret
 keyexchange=ike
 ike=aes128-sha1-modp1536
 ikelifetime=1440m
 esp=aes128-sha1
 lifetime=60m
 keyingtries=2
 auto=route
 forceencaps=yes
 dpddelay=30
 dpdtimeout=120
 dpdaction=restart

root@r-26-VM:~# cat /etc/ipsec.d/ipsec.vpn-10.0.80.31.secrets 
10.0.88.10 10.0.80.31 : PSK "test2"


3.4 Static Routes for VPNs on gateway


# This is an example
# 172.17.1.67 is the private IP of first guest NIC of VPC VR

root@dummy-gateway-002:~# ip route
default via 10.0.80.1 dev ens3 
10.0.80.0/20 dev ens3 proto kernel scope link src 10.0.88.1 
10.1.2.0/24 via 172.17.1.67 dev ens8           # For Remote Access VPN, the IP range is 10.1.2.1-10.1.2.8
172.17.1.0/24 dev ens8 proto kernel scope link src 172.17.1.1 
172.17.2.0/24 dev ens9 proto kernel scope link src 172.17.2.1 
172.25.0.0/20 via 172.17.1.67 dev ens8         # For Site-to-Site VPN
172.27.0.0/20 via 172.17.1.67 dev ens8         # For Site-to-Site VPN



4. How to set up VPNs


4.1 Remote Access VPN




5. Test plan

  • No labels