Configure Access VPNs and VPN settings
Under VPN > Add Access VPN create a new VPN.
- Choose a name for the VPN
- Select EC-S/M/L/XL if you want to use the VPN at both EC-M/L/XL and EC-S locations or select EC-M/L/XL only to only use the VPN in these locations.
- Select a ABR traffic steering profile or QoS VPN-Cluster, if required.
- Under LAN-I you will see all LAN-I networks (cnn-id) that are assigned to you as a customer.
- You can connect such a LAN-I network to the VPN here (any-to-any).
- Under Satellite Cloud, you can connect clouds such as Azure, AWS or DCS+ directly to the VPN.
- To do this, open the VPN and select the desired cloud access connection under "Satellite Cloud".
- Please note: if you connect several clouds as a Satellite Cloud, they are not connected to each other.
note
- You can only connect an Enterprise Connect VPN with one LAN-I VPN at the most.
- You can only connect a LAN-I VPN with one Enterprise Connect VPN.
- If you connect several cloud instances with a VPN as a Spoke Network, then these clouds have no connectivity with each other.
- To connect clouds with each other, you have to execute a separate usecase, which currently can only be executed by Swisscom.
- You can configure whether the VPN should be connected to the Internet under: Configure connections of the VPNs with the Internet
- After completing the VPN configuration, you will see the additional VPN tile where you can adjust the configuration at any time.
Configure IPv6 on an Access VPN
IPv6 can be enabled directly by activating the IPv6 toggle if IPv6 is available for the customer agreement.
Prerequisites
- IPv6 on Access VPNs is supported on the following CPE models:
- Huawei AR8140 physical CPE with Advanced License
- Business Box / AR6700v-L (uCPE)
- Interworking Gateway (IWG) based on AR6700v-L
- In larger customer environments, IPv6 activation must be coordinated carefully. Before enabling IPv6, make sure that the required SD-WAN infrastructure and network domain migration have been completed.
note
To verify the prerequisites, contact Swisscom Support.
Behaviour and limitations
- Enabling IPv6 activates the IPv6 address family on the VPN.
- VLANs can then be configured as either:
- IPv4 only
- IPv4 and IPv6 dual stack. For more information, see Configure IPv6 on a VLAN.
- IPv6-only VLANs are not supported.
- IPv6 prefixes are exchanged only within the same VPN and only between EC-M/L/XL sites.
- EC-S sites do not support IPv6 within the Access VPN context shown here.