# Select Virtual Edge as Access Point

## Prerequisites

You need to have at least one customer premise equipment (CPE).

## Procedures

[**Virtual Edge**](https://docs.console.zenlayer.com/welcome/overview/concepts#virtual-edge) connection is a cost-effective solution to connect your office far away. The Internet Protocol Security (IPsec) access is supported for now.

<div align="left"><figure><img src="https://3201622183-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9X3FDdkCL2HzhbPpPMFt%2Fuploads%2Fy4CgUT5vKlMbXb5nroCU%2Fimage.png?alt=media&#x26;token=9385f53c-cdff-431a-8c2d-d2ea43a52d64" alt="" width="563"><figcaption><p>IPsec Connection in HA</p></figcaption></figure></div>

1. Select the IPsec access method and decide whether to enable high availability (HA) according to your actual needs.\
   High availability (HA) supports both primary and backup access points' configuration to perform a failover, which is is critical to disaster recovery (DR).

   <img src="https://3201622183-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9X3FDdkCL2HzhbPpPMFt%2Fuploads%2Fgit-blob-5961bea9ac389c1aa2f03164b5622f10a99895e1%2FIcon.svg?alt=media" alt="" data-size="line"><mark style="color:blue;">**Note**</mark>

   * <mark style="color:blue;">The static routing is not supported in HA. IPsec connection in HA only support BGP routing.</mark>
   * <mark style="color:blue;">You need to configure both primary and backup informations, including locations, IPs, if you have enabled HA.</mark>
2. Select the location closest to your CPE. If you enable HA, select both primary and backup locations.
3. Label your IPsec connection for identification.

## IPsec Tunnel Configuration

After adding the virtual edge point, go to **Configuration** to configure the IPsec tunnel.

An IPsec tunnel is just like a virtual "tunnel" through a public network between two dedicated routers, enabling safe and secure transmission of data.

<div align="left"><figure><img src="https://3201622183-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9X3FDdkCL2HzhbPpPMFt%2Fuploads%2FiYYfviNYm9XYg00IqBOn%2Fimage.png?alt=media&#x26;token=2f346202-dc42-42c4-a1d9-a56ef8fde7bf" alt="" width="563"><figcaption><p>Configure IPsec Tunnel</p></figcaption></figure></div>

Select a mode and enter a pre-shared key (PSK) for negotiation. If you select **Customer IP Address** mode, provide your public remote IP address of your CPE.

### FQDN

A fully qualified domain name (FQDN) is the unique identification of the remote endpoint with which IPsec tunnel negotiations should be allowed.

### Customer IP Address

A public IP address of the remote endpoint with which IPsec tunnel negotiations should be allowed.

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>

* <mark style="color:blue;">You're recommended to use</mark> <mark style="color:blue;">**FQDN**</mark> <mark style="color:blue;">mode because you can have a more dynamic public IP planing.</mark>
* <mark style="color:blue;">If you choose</mark> <mark style="color:blue;">**Customer IP Address**</mark> <mark style="color:blue;">mode, please ensure the public IP cannot change.</mark>
* <mark style="color:blue;">If you enable HA, both primary and backup PSKs are required.</mark>
  {% endhint %}

## What to Do Next

Configure [**routing**](https://docs.console.zenlayer.com/welcome/cloud-networking/get-started/create-a-layer-3-connection/configure-routing-information) and [**bandwidth**](https://docs.console.zenlayer.com/welcome/cloud-networking/get-started/create-a-layer-3-connection/configure-network-information) to finish the virtual edge point adding.

After creating the cloud router, click the label of IPsec point to view the detailed information. Configure the IPsec and routing information on your CPE.

<figure><img src="https://3201622183-files.gitbook.io/~/files/v0/b/gitbook-x-prod.appspot.com/o/spaces%2F9X3FDdkCL2HzhbPpPMFt%2Fuploads%2Fgit-blob-955756aeae7b53b44080324635b5d8fd93a4c127%2Fimage%20(16).png?alt=media" alt=""><figcaption><p>Detailed Information of IPsec Point</p></figcaption></figure>

{% hint style="info" %} <mark style="color:blue;">**Note**</mark>

* <mark style="color:blue;">You'd better choose the</mark> <mark style="color:blue;">**Recommended**</mark> <mark style="color:blue;">configuration.</mark>
* <mark style="color:blue;">IKEv1 Main is only used for Remote IP negotiation.</mark>
  {% endhint %}
