Skip to main content

ip_sec_connection_tunnels

Creates, updates, deletes, gets or lists an ip_sec_connection_tunnels resource.

Overview​

Nameip_sec_connection_tunnels
TypeResource
Idoci.network.ip_sec_connection_tunnels

Fields​

The following fields are returned by SELECT queries:

The information was retrieved.

NameDatatypeDescription
idstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the tunnel.
associatedVirtualCircuitsarrayThe list of virtual circuit [OCID](/iaas/Content/General/Concepts/identifiers.htm)s over which your network can reach this tunnel.
bgpSessionInfoobjectInformation for establishing a BGP session for the IPSec tunnel.
compartmentIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the tunnel.
cpeIpstringThe IP address of the CPE device's VPN headend. Example: 203.0.113.22
displayNamestringA user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information.
dpdModestringDead peer detection (DPD) mode set on the Oracle side of the connection. This mode sets whether Oracle can only respond to a request from the CPE device to start DPD, or both respond to and initiate requests. (INITIATE_AND_RESPOND, RESPOND_ONLY)
dpdTimeoutInSecintegerDPD timeout in seconds.
encryptionDomainConfigobjectConfiguration information used by the encryption domain policy.
lifecycleStatestringThe tunnel's lifecycle state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED)
natTranslationEnabledstringBy default (the AUTO setting), IKE sends packets with a source and destination port set to 500, and when it detects that the port used to forward packets has changed (most likely because a NAT device is between the CPE device and the Oracle VPN headend) it will try to negotiate the use of NAT-T. The ENABLED option sets the IKE protocol to use port 4500 instead of 500 and forces encapsulating traffic with the ESP protocol inside UDP packets. The DISABLED option directs IKE to completely refuse to negotiate NAT-T even if it senses there may be a NAT device in use. . (ENABLED, DISABLED, AUTO)
oracleCanInitiatestringIndicates whether Oracle can only respond to a request to start an IPSec tunnel from the CPE device, or both respond to and initiate requests. (INITIATOR_OR_RESPONDER, RESPONDER_ONLY)
phaseOneDetailsobjectIPSec tunnel details specific to ISAKMP phase one.
phaseTwoDetailsobjectIPsec tunnel detail information specific to phase two.
routingstringThe type of routing used for this tunnel (BGP dynamic routing, static routing, or policy-based routing). (BGP, STATIC, POLICY)
statusstringThe status of the tunnel based on IPSec protocol characteristics. (UP, DOWN, DOWN_FOR_MAINTENANCE, PARTIAL_UP)
timeCreatedstring (date-time)The date and time the IPSec tunnel was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z
timeStatusUpdatedstring (date-time)When the status of the IPSec tunnel last changed, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z
vpnIpstringThe IP address of the Oracle VPN headend for the connection. Example: 203.0.113.21

Methods​

The following methods are available for this resource:

NameAccessible byRequired ParamsOptional ParamsDescription
getselectipscId, tunnelId, regionGets the specified tunnel's information. The resulting object does not include the tunnel's<br />shared secret (pre-shared key). To retrieve that, use<br />[GetIPSecConnectionTunnelSharedSecret](#/en/iaas/latest/IPSecConnectionTunnelSharedSecret/GetIPSecConnectionTunnelSharedSecret).<br />
listselectipscId, regionlimit, pageLists the tunnel information for the specified IPSec connection.<br />
updateupdateipscId, tunnelId, regionif-match, opc-request-idUpdates the specified tunnel. This operation lets you change tunnel attributes such as the<br />routing type (BGP dynamic routing or static routing). Here are some important notes:<br /><br /> * If you change the tunnel's routing type or BGP session configuration, the tunnel will go<br /> down while it's reprovisioned.<br /><br /> * If you want to switch the tunnel's routing from STATIC to BGP, make sure the tunnel's<br /> BGP session configuration attributes have been set ([bgpSessionConfig](#/en/iaas/latest/datatypes/BgpSessionInfo)).<br /><br /> * If you want to switch the tunnel's routing from BGP to STATIC, make sure the<br /> [IPSecConnection](#/en/iaas/latest/IPSecConnection/) already has at least one valid CIDR<br /> static route.<br />

Parameters​

Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.

NameDatatypeDescription
ipscIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the IPSec connection.
regionstringOCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION)
tunnelIdstringThe [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the tunnel.
if-matchstringFor optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value.
limitintegerFor list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50
opc-request-idstringUnique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID.
pagestringFor list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine).

SELECT examples​

Gets the specified tunnel's information. The resulting object does not include the tunnel's<br />shared secret (pre-shared key). To retrieve that, use<br />[GetIPSecConnectionTunnelSharedSecret](#/en/iaas/latest/IPSecConnectionTunnelSharedSecret/GetIPSecConnectionTunnelSharedSecret).<br />

SELECT
id,
associatedVirtualCircuits,
bgpSessionInfo,
compartmentId,
cpeIp,
displayName,
dpdMode,
dpdTimeoutInSec,
encryptionDomainConfig,
lifecycleState,
natTranslationEnabled,
oracleCanInitiate,
phaseOneDetails,
phaseTwoDetails,
routing,
status,
timeCreated,
timeStatusUpdated,
vpnIp
FROM oci.network.ip_sec_connection_tunnels
WHERE ipscId = '{{ ipscId }}' -- required
AND tunnelId = '{{ tunnelId }}' -- required
AND region = '{{ region }}' -- required
;

UPDATE examples​

Updates the specified tunnel. This operation lets you change tunnel attributes such as the<br />routing type (BGP dynamic routing or static routing). Here are some important notes:<br /><br /> * If you change the tunnel's routing type or BGP session configuration, the tunnel will go<br /> down while it's reprovisioned.<br /><br /> * If you want to switch the tunnel's routing from STATIC to BGP, make sure the tunnel's<br /> BGP session configuration attributes have been set ([bgpSessionConfig](#/en/iaas/latest/datatypes/BgpSessionInfo)).<br /><br /> * If you want to switch the tunnel's routing from BGP to STATIC, make sure the<br /> [IPSecConnection](#/en/iaas/latest/IPSecConnection/) already has at least one valid CIDR<br /> static route.<br />

UPDATE oci.network.ip_sec_connection_tunnels
SET
bgpSessionConfig = '{{ bgpSessionConfig }}',
displayName = '{{ displayName }}',
dpdConfig = '{{ dpdConfig }}',
encryptionDomainConfig = '{{ encryptionDomainConfig }}',
natTranslationEnabled = '{{ natTranslationEnabled }}',
oracleInitiation = '{{ oracleInitiation }}',
phaseOneConfig = '{{ phaseOneConfig }}',
phaseTwoConfig = '{{ phaseTwoConfig }}',
routing = '{{ routing }}'
WHERE
ipscId = '{{ ipscId }}' --required
AND tunnelId = '{{ tunnelId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}'
RETURNING
id,
associatedVirtualCircuits,
bgpSessionInfo,
compartmentId,
cpeIp,
displayName,
dpdMode,
dpdTimeoutInSec,
encryptionDomainConfig,
lifecycleState,
natTranslationEnabled,
oracleCanInitiate,
phaseOneDetails,
phaseTwoDetails,
routing,
status,
timeCreated,
timeStatusUpdated,
vpnIp;