VPN Connection の編集
暗号化パラメータや Dead Peer Detection の設定など、既存の VPN Connection の構成を変更します。
手順
- メニューで Network を選択し、VPN Site-to-Site タブを開きます。Edit VPN Connection を選択します。
-
設定情報を編集します。パラメータは 3 つのセクションに分かれています。
- General Information — 接続の基本情報
- Remote VPN Information — 暗号化とお客様側の設定
- Dead Peer Detection — 接続に問題が発生した際のリトライ設定
セクション 1: General Information
| 項目 | 説明 |
|---|---|
| VPN name | VPN Connection の名前。 |
| Description | VPN Connection の説明。 |
| Pre-shared key | 2 台の機器で共有するセキュリティキー。Refresh Key で新しいキーを生成し、Copy でコピーします。 |
| Local IP public | FPT Cloud が割り当てる public IP アドレス。 |
| Local private networks | FPT Cloud 内のリソースのプライベートネットワーク範囲。 |
セクション 2: Remote VPN Information
Customer gateway:
| 項目 | 説明 |
|---|---|
| Customer gateway | リモート側エンドポイントの設定。接続先の Customer Gateway を正しく選択します。 |
| Providers | FPT Cloud がサポートする VPN プロバイダーの一覧。 |
IKE Policy:
| 項目 | 説明 |
|---|---|
| Authorization algorithm | VPN 確立時にデータを認証するアルゴリズム。値: sha1、sha256、sha384、sha512、aes-xcbc。推奨: sha256。 |
| Encryption algorithm | キー交換を暗号化するアルゴリズム。aes-128、aes-192、aes-256 および各 GCM 派生を含みます。推奨: aes-128-gcm-12。 |
| IKE version | サポートされるバージョン: ikev1、ikev2。 |
| Lifetime units | IKE の有効期間の単位。デフォルト: second。 |
| Lifetime value | Phase 1 セッションの継続時間。 |
| DH Group | キー交換に使う Diffie-Hellman グループ。値: group_1 〜 group_21。 |
| Phase 1 negotiation mode | 値: main、aggressive。デフォルト: main。 |
IPSec Policy:
| 項目 | 説明 |
|---|---|
| Authorization algorithm | VPN 稼働時にデータを認証するアルゴリズム。値: sha1、sha256、sha384、sha512、aes-xcbc。推奨: sha256。 |
| Encapsulation mode | データを暗号化・カプセル化する方式。デフォルト: tunnel。 |
| Encryption algorithm | VPN トラフィックを暗号化するアルゴリズム。値: aes-128、aes-192、aes-256。推奨: aes-256。 |
| Lifetime units | デフォルト: second。 |
| Lifetime value | IPSec セッションが再確立されるまでの継続時間。 |
| Perfect Forward Secrecy | DH Group と組み合わせる PFS オプション。値: off、group_1 〜 group_21。推奨: group_14。 |
| Transform protocol | 暗号化と認証の protocol。値: esp、ah。 |
プロバイダー既定値:
FPT Cloud は AWS、Fortigate、Palo Alto 向けの設定を用意しています。その他のプロバイダーでは、IKE と IPSec のパラメータを手動で入力します。
| パラメータ | AWS | Fortigate | Palo Alto |
|---|---|---|---|
| IKE version | ikev2 | ikev2 | ikev2 |
| Encryption algorithm | aes-256 | aes-256 | aes-256 |
| Authorization algorithm | sha256 | sha256 | sha256 |
| DH Group | group14 | group14 – group19 | group14 – group20 |
| Lifetime value | 28800s | 28800s | 28800s |
| Phase 1 negotiation mode | main | main | main |
| IPSec Encryption algorithm | aes-256 | aes-256 | aes-256 |
| IPSec Authorization algorithm | sha256 | sha256 | sha256 |
| Perfect Forward Secrecy | group14 | group14(または group19) | group19 |
| IPSec Lifetime value | 3600s | 3600s | 3600s |
| Encapsulation mode | tunnel | tunnel | tunnel |
| Transform protocol | esp | esp | esp |
セクション 3: Dead Peer Detection
| 項目 | 説明 |
|---|---|
| Delay (s) | DPD プローブの送信間隔。デフォルト: 30s。 |
| Max failures | peer が停止していると判断して接続をリセットするまでの失敗回数の上限。デフォルト: 10。 |
- Update VPN Connection をクリックして保存します。中止する場合は Cancel をクリックします。

