Bamboozle Cloud Engine

Site to Site VPN

Encrypted tunnels connecting your on-premises network to Bamboozle Cloud securely over the public internet.

How Bamboozle site-to-site VPN connects your officeYour office router connects to the Bamboozle Cloud through an encrypted IPsec tunnel (IKEv1 or IKEv2) over the public internet, reaching VMs on the private network. Your office Router / firewall IPsec tunnel IKEv1 / IKEv2 Encrypted over the internet Bamboozle Cloud App VM DB VM Private network

Key Capabilities

What It Does

Built into Bamboozle Cloud Engine — available in all three regions, managed from Cloud Control.

  • IPsec IKEv2 Tunnels

    Industry-standard IPsec tunnels using IKEv2 for key exchange. Connect your Bamboozle virtual networks to on-premises hardware firewalls, routers, or other cloud provider VPCs — any IPsec-compatible peer.

  • Configurable IKE & IPsec Policies

    Full control over IKE phase 1 and IPsec phase 2 parameters — encryption algorithm, integrity algorithm, Diffie-Hellman group, and lifetime. Match the policy to your on-premises VPN device requirements.

  • Multi-Subnet Support

    Define multiple local and peer CIDRs in a single VPN connection. Route traffic for multiple subnets on both sides through a single encrypted tunnel.

  • Dead Peer Detection

    DPD (Dead Peer Detection) automatically detects when the remote peer is unreachable and can restart the tunnel. Configurable DPD action: hold, clear, restart, or restart-by-peer.

  • Encrypted in Transit

    All traffic through the VPN tunnel is encrypted end-to-end using AES-128 or AES-256. No data travels in plaintext between your cloud virtual networks and your on-premises infrastructure.

  • Virtual Router Integration

    VPN connections attach to your project's virtual router, giving VMs on your private networks direct routed access to on-premises resources — no additional gateways or proxy hosts required.

Supported Configurations

What We Connect

Standard IPsec — compatible with any hardware or software VPN device that supports IKEv1 or IKEv2.

  • On-premises to cloud (hybrid cloud)
  • Cloud to cloud (multi-cloud)
  • IPsec IKEv1 and IKEv2
  • AES-128 / AES-256 encryption
  • SHA-1 / SHA-256 / SHA-384 integrity
  • DH Group 2, 5, 14, 15, 16, 19, 20
  • Multiple local CIDRs per tunnel
  • Multiple peer CIDRs per tunnel
  • Dead Peer Detection (DPD)
  • Main mode / Aggressive mode (IKEv1)
  • Perfect Forward Secrecy (PFS)
  • Cisco ASA, Fortinet, pfSense, MikroTik compatible

Getting Started

How It Works

All networking features are self-service — available in Cloud Control in minutes.

  1. Define IKE Policy

    Set your IKE phase 1 parameters — authentication, encryption algorithm, DH group, and lifetime — to match your on-premises VPN device configuration.

  2. Define IPsec Policy

    Set your IPsec phase 2 parameters — encryption, integrity, PFS group, and lifetime. These must match the remote peer's IPsec configuration exactly.

  3. Create VPN Connection

    Specify the remote peer IP address, pre-shared key, local subnet(s), and remote subnet(s). The tunnel will attempt to establish immediately.

  4. Traffic Flows

    Once the tunnel is up, VMs on your local virtual network can communicate directly with resources on the remote subnet — using private IPs throughout.

Ready to Configure?

All networking features are available in Cloud Control. Talk to us or view pricing for your region.