Bamboozle Cloud Engine
Site to Site VPN
Encrypted tunnels connecting your on-premises network to Bamboozle Cloud securely over the public internet.
Key Capabilities
What It Does
Built into Bamboozle Cloud Engine — available in all three regions, managed from Cloud Control.
-
IPsec IKEv2 Tunnels
Industry-standard IPsec tunnels using IKEv2 for key exchange. Connect your Bamboozle virtual networks to on-premises hardware firewalls, routers, or other cloud provider VPCs — any IPsec-compatible peer.
-
Configurable IKE & IPsec Policies
Full control over IKE phase 1 and IPsec phase 2 parameters — encryption algorithm, integrity algorithm, Diffie-Hellman group, and lifetime. Match the policy to your on-premises VPN device requirements.
-
Multi-Subnet Support
Define multiple local and peer CIDRs in a single VPN connection. Route traffic for multiple subnets on both sides through a single encrypted tunnel.
-
Dead Peer Detection
DPD (Dead Peer Detection) automatically detects when the remote peer is unreachable and can restart the tunnel. Configurable DPD action: hold, clear, restart, or restart-by-peer.
-
Encrypted in Transit
All traffic through the VPN tunnel is encrypted end-to-end using AES-128 or AES-256. No data travels in plaintext between your cloud virtual networks and your on-premises infrastructure.
-
Virtual Router Integration
VPN connections attach to your project's virtual router, giving VMs on your private networks direct routed access to on-premises resources — no additional gateways or proxy hosts required.
Supported Configurations
What We Connect
Standard IPsec — compatible with any hardware or software VPN device that supports IKEv1 or IKEv2.
- On-premises to cloud (hybrid cloud)
- Cloud to cloud (multi-cloud)
- IPsec IKEv1 and IKEv2
- AES-128 / AES-256 encryption
- SHA-1 / SHA-256 / SHA-384 integrity
- DH Group 2, 5, 14, 15, 16, 19, 20
- Multiple local CIDRs per tunnel
- Multiple peer CIDRs per tunnel
- Dead Peer Detection (DPD)
- Main mode / Aggressive mode (IKEv1)
- Perfect Forward Secrecy (PFS)
- Cisco ASA, Fortinet, pfSense, MikroTik compatible
Getting Started
How It Works
All networking features are self-service — available in Cloud Control in minutes.
-
Define IKE Policy
Set your IKE phase 1 parameters — authentication, encryption algorithm, DH group, and lifetime — to match your on-premises VPN device configuration.
-
Define IPsec Policy
Set your IPsec phase 2 parameters — encryption, integrity, PFS group, and lifetime. These must match the remote peer's IPsec configuration exactly.
-
Create VPN Connection
Specify the remote peer IP address, pre-shared key, local subnet(s), and remote subnet(s). The tunnel will attempt to establish immediately.
-
Traffic Flows
Once the tunnel is up, VMs on your local virtual network can communicate directly with resources on the remote subnet — using private IPs throughout.
Ready to Configure?
All networking features are available in Cloud Control. Talk to us or view pricing for your region.