ip_sec_connection_tunnels
Creates, updates, deletes, gets or lists an ip_sec_connection_tunnels resource.
Overview​
| Name | ip_sec_connection_tunnels |
| Type | Resource |
| Id | oci.network.ip_sec_connection_tunnels |
Fields​
The following fields are returned by SELECT queries:
- get
- list
The information was retrieved.
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the tunnel. |
associatedVirtualCircuits | array | The list of virtual circuit [OCID](/iaas/Content/General/Concepts/identifiers.htm)s over which your network can reach this tunnel. |
bgpSessionInfo | object | Information for establishing a BGP session for the IPSec tunnel. |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the tunnel. |
cpeIp | string | The IP address of the CPE device's VPN headend. Example: 203.0.113.22 |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
dpdMode | string | Dead peer detection (DPD) mode set on the Oracle side of the connection. This mode sets whether Oracle can only respond to a request from the CPE device to start DPD, or both respond to and initiate requests. (INITIATE_AND_RESPOND, RESPOND_ONLY) |
dpdTimeoutInSec | integer | DPD timeout in seconds. |
encryptionDomainConfig | object | Configuration information used by the encryption domain policy. |
lifecycleState | string | The tunnel's lifecycle state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
natTranslationEnabled | string | By default (the AUTO setting), IKE sends packets with a source and destination port set to 500, and when it detects that the port used to forward packets has changed (most likely because a NAT device is between the CPE device and the Oracle VPN headend) it will try to negotiate the use of NAT-T. The ENABLED option sets the IKE protocol to use port 4500 instead of 500 and forces encapsulating traffic with the ESP protocol inside UDP packets. The DISABLED option directs IKE to completely refuse to negotiate NAT-T even if it senses there may be a NAT device in use. . (ENABLED, DISABLED, AUTO) |
oracleCanInitiate | string | Indicates whether Oracle can only respond to a request to start an IPSec tunnel from the CPE device, or both respond to and initiate requests. (INITIATOR_OR_RESPONDER, RESPONDER_ONLY) |
phaseOneDetails | object | IPSec tunnel details specific to ISAKMP phase one. |
phaseTwoDetails | object | IPsec tunnel detail information specific to phase two. |
routing | string | The type of routing used for this tunnel (BGP dynamic routing, static routing, or policy-based routing). (BGP, STATIC, POLICY) |
status | string | The status of the tunnel based on IPSec protocol characteristics. (UP, DOWN, DOWN_FOR_MAINTENANCE, PARTIAL_UP) |
timeCreated | string (date-time) | The date and time the IPSec tunnel was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
timeStatusUpdated | string (date-time) | When the status of the IPSec tunnel last changed, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vpnIp | string | The IP address of the Oracle VPN headend for the connection. Example: 203.0.113.21 |
Information about a single IPSec tunnel in an IPSec connection. This object does not include the tunnel's<br />shared secret (pre-shared key), which is found in the<br />[IPSecConnectionTunnelSharedSecret](#/en/iaas/latest/IPSecConnectionTunnelSharedSecret/) object.<br />
| Name | Datatype | Description |
|---|---|---|
id | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the tunnel. |
associatedVirtualCircuits | array | The list of virtual circuit [OCID](/iaas/Content/General/Concepts/identifiers.htm)s over which your network can reach this tunnel. |
bgpSessionInfo | object | Information for establishing a BGP session for the IPSec tunnel. |
compartmentId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the compartment containing the tunnel. |
cpeIp | string | The IP address of the CPE device's VPN headend. Example: 203.0.113.22 |
displayName | string | A user-friendly name. Does not have to be unique, and it's changeable. Avoid entering confidential information. |
dpdMode | string | Dead peer detection (DPD) mode set on the Oracle side of the connection. This mode sets whether Oracle can only respond to a request from the CPE device to start DPD, or both respond to and initiate requests. (INITIATE_AND_RESPOND, RESPOND_ONLY) |
dpdTimeoutInSec | integer | DPD timeout in seconds. |
encryptionDomainConfig | object | Configuration information used by the encryption domain policy. |
lifecycleState | string | The tunnel's lifecycle state. (PROVISIONING, AVAILABLE, TERMINATING, TERMINATED) |
natTranslationEnabled | string | By default (the AUTO setting), IKE sends packets with a source and destination port set to 500, and when it detects that the port used to forward packets has changed (most likely because a NAT device is between the CPE device and the Oracle VPN headend) it will try to negotiate the use of NAT-T. The ENABLED option sets the IKE protocol to use port 4500 instead of 500 and forces encapsulating traffic with the ESP protocol inside UDP packets. The DISABLED option directs IKE to completely refuse to negotiate NAT-T even if it senses there may be a NAT device in use. . (ENABLED, DISABLED, AUTO) |
oracleCanInitiate | string | Indicates whether Oracle can only respond to a request to start an IPSec tunnel from the CPE device, or both respond to and initiate requests. (INITIATOR_OR_RESPONDER, RESPONDER_ONLY) |
phaseOneDetails | object | IPSec tunnel details specific to ISAKMP phase one. |
phaseTwoDetails | object | IPsec tunnel detail information specific to phase two. |
routing | string | The type of routing used for this tunnel (BGP dynamic routing, static routing, or policy-based routing). (BGP, STATIC, POLICY) |
status | string | The status of the tunnel based on IPSec protocol characteristics. (UP, DOWN, DOWN_FOR_MAINTENANCE, PARTIAL_UP) |
timeCreated | string (date-time) | The date and time the IPSec tunnel was created, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
timeStatusUpdated | string (date-time) | When the status of the IPSec tunnel last changed, in the format defined by [RFC3339](https:​//tools.ietf.org/html/rfc3339). Example: 2016-08-25T21:10:29.600Z |
vpnIp | string | The IP address of the Oracle VPN headend for the connection. Example: 203.0.113.21 |
Methods​
The following methods are available for this resource:
| Name | Accessible by | Required Params | Optional Params | Description |
|---|---|---|---|---|
get | select | ipscId, tunnelId, region | Gets the specified tunnel's information. The resulting object does not include the tunnel's<br />shared secret (pre-shared key). To retrieve that, use<br />[GetIPSecConnectionTunnelSharedSecret](#/en/iaas/latest/IPSecConnectionTunnelSharedSecret/GetIPSecConnectionTunnelSharedSecret).<br /> | |
list | select | ipscId, region | limit, page | Lists the tunnel information for the specified IPSec connection.<br /> |
update | update | ipscId, tunnelId, region | if-match, opc-request-id | Updates the specified tunnel. This operation lets you change tunnel attributes such as the<br />routing type (BGP dynamic routing or static routing). Here are some important notes:<br /><br /> * If you change the tunnel's routing type or BGP session configuration, the tunnel will go<br /> down while it's reprovisioned.<br /><br /> * If you want to switch the tunnel's routing from STATIC to BGP, make sure the tunnel's<br /> BGP session configuration attributes have been set ([bgpSessionConfig](#/en/iaas/latest/datatypes/BgpSessionInfo)).<br /><br /> * If you want to switch the tunnel's routing from BGP to STATIC, make sure the<br /> [IPSecConnection](#/en/iaas/latest/IPSecConnection/) already has at least one valid CIDR<br /> static route.<br /> |
Parameters​
Parameters can be passed in the WHERE clause of a query. Check the Methods section to see which parameters are required or optional for each operation.
| Name | Datatype | Description |
|---|---|---|
ipscId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the IPSec connection. |
region | string | OCI region identifier (e.g. us-ashburn-1, ap-sydney-1); resolves from OCI_REGION when not supplied in the query. (default: us-ashburn-1, x-stackQL-envVar: OCI_REGION) |
tunnelId | string | The [OCID](/iaas/Content/General/Concepts/identifiers.htm) of the tunnel. |
if-match | string | For optimistic concurrency control. In the PUT or DELETE call for a resource, set the if-match parameter to the value of the etag from a previous GET or POST response for that resource. The resource will be updated or deleted only if the etag you provide matches the resource's current etag value. |
limit | integer | For list pagination. The maximum number of results per page, or items to return in a paginated "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). Example: 50 |
opc-request-id | string | Unique identifier for the request. If you need to contact Oracle about a particular request, please provide the request ID. |
page | string | For list pagination. The value of the opc-next-page response header from the previous "List" call. For important details about how pagination works, see [List Pagination](/iaas/Content/API/Concepts/usingapi.htm#nine). |
SELECT examples​
- get
- list
Gets the specified tunnel's information. The resulting object does not include the tunnel's<br />shared secret (pre-shared key). To retrieve that, use<br />[GetIPSecConnectionTunnelSharedSecret](#/en/iaas/latest/IPSecConnectionTunnelSharedSecret/GetIPSecConnectionTunnelSharedSecret).<br />
SELECT
id,
associatedVirtualCircuits,
bgpSessionInfo,
compartmentId,
cpeIp,
displayName,
dpdMode,
dpdTimeoutInSec,
encryptionDomainConfig,
lifecycleState,
natTranslationEnabled,
oracleCanInitiate,
phaseOneDetails,
phaseTwoDetails,
routing,
status,
timeCreated,
timeStatusUpdated,
vpnIp
FROM oci.network.ip_sec_connection_tunnels
WHERE ipscId = '{{ ipscId }}' -- required
AND tunnelId = '{{ tunnelId }}' -- required
AND region = '{{ region }}' -- required
;
Lists the tunnel information for the specified IPSec connection.<br />
SELECT
id,
associatedVirtualCircuits,
bgpSessionInfo,
compartmentId,
cpeIp,
displayName,
dpdMode,
dpdTimeoutInSec,
encryptionDomainConfig,
lifecycleState,
natTranslationEnabled,
oracleCanInitiate,
phaseOneDetails,
phaseTwoDetails,
routing,
status,
timeCreated,
timeStatusUpdated,
vpnIp
FROM oci.network.ip_sec_connection_tunnels
WHERE ipscId = '{{ ipscId }}' -- required
AND region = '{{ region }}' -- required
AND limit = '{{ limit }}'
AND page = '{{ page }}'
;
UPDATE examples​
- update
Updates the specified tunnel. This operation lets you change tunnel attributes such as the<br />routing type (BGP dynamic routing or static routing). Here are some important notes:<br /><br /> * If you change the tunnel's routing type or BGP session configuration, the tunnel will go<br /> down while it's reprovisioned.<br /><br /> * If you want to switch the tunnel's routing from STATIC to BGP, make sure the tunnel's<br /> BGP session configuration attributes have been set ([bgpSessionConfig](#/en/iaas/latest/datatypes/BgpSessionInfo)).<br /><br /> * If you want to switch the tunnel's routing from BGP to STATIC, make sure the<br /> [IPSecConnection](#/en/iaas/latest/IPSecConnection/) already has at least one valid CIDR<br /> static route.<br />
UPDATE oci.network.ip_sec_connection_tunnels
SET
bgpSessionConfig = '{{ bgpSessionConfig }}',
displayName = '{{ displayName }}',
dpdConfig = '{{ dpdConfig }}',
encryptionDomainConfig = '{{ encryptionDomainConfig }}',
natTranslationEnabled = '{{ natTranslationEnabled }}',
oracleInitiation = '{{ oracleInitiation }}',
phaseOneConfig = '{{ phaseOneConfig }}',
phaseTwoConfig = '{{ phaseTwoConfig }}',
routing = '{{ routing }}'
WHERE
ipscId = '{{ ipscId }}' --required
AND tunnelId = '{{ tunnelId }}' --required
AND region = '{{ region }}' --required
AND if-match = '{{ if-match}}'
AND opc-request-id = '{{ opc-request-id}}'
RETURNING
id,
associatedVirtualCircuits,
bgpSessionInfo,
compartmentId,
cpeIp,
displayName,
dpdMode,
dpdTimeoutInSec,
encryptionDomainConfig,
lifecycleState,
natTranslationEnabled,
oracleCanInitiate,
phaseOneDetails,
phaseTwoDetails,
routing,
status,
timeCreated,
timeStatusUpdated,
vpnIp;