Step 1: In the top navigation bar, click Networking and click the Edge Gateways tab. Step 2: Click the edge gateway. Step 3: Under Services, click IPSec VPN. Step 4: To configure an IPSec VPN tunnel, click New. Step 5: Enter a Name and a description (optional) for the IPSec VPN tunnel. Step 6: To enable the tunnel upon creation, toggle on the Status option. For the Security Profile – we keep it as Default and configure it later once the VPN tunnel has been created. Step 7: Click NEXT to select Authentication mode. Step 8: Select a peer authentication mode and NEXT. HI GIO supported 02 option for Authentication Mode: Option Description Pre-Shared Key Choose a pre-shared key to enter. The pre-shared key must be the same on the other end of the IPSec VPN tunnel. Certificate Select site and CA certificates to be used for authentication. Step 9: On Endpoint Configuration windows, we put some parameters (follow IPSec parameters in the prepare step): IP address [Local Endpoint]: Enter public IP (HI GIO’s public IP). Networks [Local Endpoint]: Enter at least one local (HI GIO’s network) IP subnet address for the IPSec VPN tunnel. IP address [Remote Endpoint]: Enter public IP (remote site, ex: Office’s public IP). Networks [Remote Endpoint]: Enter at least one remote IP (ex: Office’s network) subnet address for the IPSec VPN tunnel. Step 10: Enter the remote ID (optional) for the peer site. In case we use a Certificate for Authentication mode The remote ID must match the SAN (Subject Alternative Name) of the remote endpoint certificate, if available. If the remote certificate does not contain a SAN, the remote ID must match the distinguished name of the certificate that is used to secure the remote endpoint, for example, C=US, ST=Massachusetts, O=VMware, OU=VCD, CN=Edge1. Step 11: Click Next. Step 12: Review your settings and click Finish. The newly created IPSec VPN tunnel is listed in the IPSec VPN view. The IPSec VPN tunnel is created with a default security profile. Step 13: To verify that the tunnel is functioning, select it and click View Statistics. If the tunnel is functioning, Tunnel Status and IKE Service Status both display Up.