Note: If your device/service supports SHA256 and DH group 14, it is recommended to use these settings instead.
Configuring a VPN gateway at the IBM Cloud Console
- Open to the VPC section in the IBM Cloud Console. Go to VPNs (under the Network tab)
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
- Open the IKE Policies tab, then select New IKE Policy
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
- Choose a Name, the Region in which the appropriate VPC lies, define the Resource group, then select Create IKE policy
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
-
Once the policy has been created, select the three-dotted menu (...) and select Edit
-
Fill in the following information:
- IKE Version: 1
- DH Group: 2
- Authentication: sha256
- Key Lifetime: 28800
- Encryption: aes256
-
Select Save IKE policy
-
Open the IPSec Policies tab, then select New IPSec Policy
-
Choose a Name, the Region in which the appropriate VPC lies and define the Resource group, then select Create IPSec policy
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
-
Once the policy has been created, select the three-dotted menu (...) and select Edit
-
Fill in the following information:
- Check: PFS
- DH Group: 2
- Authentication: sha256
- Key Lifetime: 3600
- Encryption: aes256
- Select Save IPSec policy
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
-
Open the VPN gateways tab, then select New VPN gateway
-
Fill in the following information:
- Name: Choose the name of your choice
- Virtual private cloud: Choose the desired cloud
- Resource group: Choose the resource group
- Subnet: Choose the appropriate subnet
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
-
Check New VPN Connection for VPC
-
Fill in the following information:
- Connection name: Set a name
- Peer gateway address: the IP of your NordLayer server with a dedicated IP
- Preshared key: Insert an 8 character (at least) string containing upper-case letters, upper-case letters, and numbers (we will also need this value on our end)
- Local subnet: Specify one or more subnets in the VPC you want to connect
- Peer subnet: 10.6.0.0/20
.png?sv=2026-02-06&spr=https&st=2026-09-08T15%3A42%3A40Z&se=2026-09-08T15%3A54%3A40Z&sr=c&sp=r&sig=eR6m7vN9oxChz5LY4V5b6%2FsFk6y0%2BRCvLPrPLrqzHHY%3D)
- Dead peer detection action: Restart
- Interval: 10 seconds
- Timeout: 30 seconds
- IKE policy: Choose the policy that was earlier
- IPSec policy: Choose the policy that was earlier
Ending note:
In order to finalize the site-to-site tunnel, please create a setup in Sites tab of the NordLayer Control Panel.
- Pre-shared key - you can generate it or we can provide it
- Encryption details (AES, SHA and DH group) - AES256, SHA256 and DH group 14 are recommended (also must support IKEv2)
- Remote gateway/router public IP (must be reachable while connected to the server with a dedicated IP)
- Remote subnet and mask (the subnet is used in your local network)
Note: In case you have any questions or issues, press 'Chat with support' at the bottom of the page.