Skip to main content
版本:v1.6

阿里云 VPN-GATEWAY

描述​

Create VPN resources on AliCloud based on Terraform module。

参数说明​

名称描述类型是否必须默认值
cgw_descriptionThe description of the VPN customer gateway instance。stringfalse
cgw_idThe customer gateway id used to connect with vpn gateway。stringfalse
cgw_ip_addressThe IP address of the customer gateway。stringfalse
cgw_nameThe name of the VPN customer gateway. Defaults to null。stringfalse
ike_auth_algThe authentication algorithm of phase-one negotiation. Valid value: md5sha1. Default value: sha1。stringfalse
ike_enc_algThe encryption algorithm of phase-one negotiation. Valid value: aesaes192aes256des
ike_lifetimeThe SA lifecycle as the result of phase-one negotiation. The valid value of n is [0, 86400], the unit is second and the default value is 86400。numberfalse
ike_local_idThe identification of the VPN gateway。stringfalse
ike_modeThe negotiation mode of IKE V1. Valid value: main (main mode)aggressive (aggressive mode). Default value: main。stringfalse
ike_pfsThe Diffie-Hellman key exchange algorithm used by phase-one negotiation. Valid value: group1group2group5group14
ike_remote_idThe identification of the customer gateway。stringfalse
ike_versionThe version of the IKE protocol. Valid value: ikev1ikev2. Default value: ikev1。stringfalse
ipsec_auth_algThe authentication algorithm of phase-two negotiation. Valid value: md5sha1. Default value: sha1。stringfalse
ipsec_connection_nameThe name of the IPsec connection。stringfalse
ipsec_effect_immediatelyWhether to delete a successfully negotiated IPsec tunnel and initiate a negotiation again. Valid value:true,false。boolfalse
ipsec_enc_algThe encryption algorithm of phase-two negotiation. Valid value: aesaes192aes256des
ipsec_lifetimeThe SA lifecycle as the result of phase-two negotiation. The valid value is [0, 86400], the unit is second and the default value is 86400。numberfalse
ipsec_local_subnetThe CIDR block of the VPC to be connected with the local data center. This parameter is used for phase-two negotiation。list(string)false
ipsec_pfsThe Diffie-Hellman key exchange algorithm used by phase-two negotiation. Valid value: group1group2group5group14
ipsec_remote_subnetThe CIDR block of the local data center. This parameter is used for phase-two negotiation。list(string)false
pskUsed for authentication between the IPsec VPN gateway and the customer gateway。stringfalse
region(Deprecated from version 1.2.0) The region used to launch this module resources。stringfalse
ssl_cipherThe encryption algorithm used by the SSL-VPN server. Valid value: AES-128-CBC (default)AES-192-CBCAES-256-CBCnone。
ssl_client_cert_namesThe names of the client certificates。list(string)false
ssl_client_ip_poolThe CIDR block from which access addresses are allocated to the virtual network interface card of the client。stringfalse
ssl_compressSpecify whether to compress the communication. Valid value: true (default)false。boolfalse
ssl_local_subnetThe CIDR block to be accessed by the client through the SSL-VPN connection。stringfalse
ssl_portThe port used by the SSL-VPN server. The default value is 1194.The following ports cannot be used: [22, 2222, 22222, 9000, 9001, 9002, 7505, 80, 443, 53, 68, 123, 4510, 4560, 500, 4500]。numberfalse
ssl_protocolThe protocol used by the SSL-VPN server. Valid value: UDP(default)TCP。stringfalse
ssl_vpn_server_nameThe name of the SSL-VPN server。stringfalse
vpc_idThe VPN belongs the vpc_id, the field can't be changed。stringfalse
vpn_bandwidthThe value should be 10, 100, 200, 500, 1000 if the user is postpaid, otherwise it can be 5, 10, 20, 50, 100, 200, 500, 1000。numberfalse
vpn_charge_typeThe charge type for instance. Valid value: PostPaid, PrePaid. Default to PostPaid。stringfalse
vpn_descriptionThe description of the VPN instance。stringfalse
vpn_enable_ipsecEnable or Disable IPSec VPN. At least one type of VPN should be enabled。boolfalse
vpn_enable_sslEnable or Disable SSL VPN. At least one type of VPN should be enabled。boolfalse
vpn_nameName of the VPN gateway。stringfalse
vpn_periodThe filed is only required while the InstanceChargeType is prepaid。numberfalse
vpn_ssl_connectionsThe max connections of SSL VPN. Default to 5. This field is ignored when enable_ssl is false。numberfalse
writeConnectionSecretToRefThe secret which the cloud resource connection will be written to。writeConnectionSecretToReffalse

writeConnectionSecretToRef​

名称描述类型是否必须默认值
nameThe secret name which the cloud resource connection will be written to。stringtrue
namespaceThe secret namespace which the cloud resource connection will be written to。stringfalse