Getting started

This document shows how to establish a redundant IPsec tunnel with an Amazon Web Services (AWS) Virtual Private Cloud (VPC) using the BGP dynamic routing protocol.

It uses a sample architecture to illustrate the various configurations you need to set up. Since there are many configuration options, customize these elements to suit your architecture and needs.

Architecture presented

Requirements

  • An SNS firewall in version 5.1 or higher,

  • An Amazon Web Services (AWS) account and access to the AWS Management Console.

  • The IP address used to establish tunnels must be static and may be behind a network address translation (NAT) device. For more information on network address translation, see the Integrating NAT into IPsec technical note.

 

Date Description
August 3, 2026

New document