Skip to content
Navigation Menu
IBM Cloud
  • CatalogCatalog
  • Cost EstimatorCost Estimator
    • HelpHelp
      • Docs
  • Log in
  • Sign up
  • Catalog
  • Cost Estimator
  • Help
    • Docs

  • Navigation settings

Error

Change theme

This feature is in early stage, some parts of the platform might not fully support different themes yet.

Themes
  1. Community registry

Cloud automation for Client to Site VPN
Community registry

Creates client-to-site VPN connectivity to VPC

  • IBM
  • Date of last update: 11/07/2025
  • Docs
  • Get help
  • Details

    Type
    • Terraform
    Provider
    • IBM
    Category
    • Networking
    • Platform engineering
    Last updated
    • 11/07/2025
    Product version
    • v3.4.4
    Variation
    • Fully configurable
    Est. deployment time:
    • 8min
    Copy
    Copy
    Copy
    Copy
    Copy
    Copy
  • Docs
  • Get help

Details

Type
  • Terraform
Provider
  • IBM
Category
  • Networking
  • Platform engineering
Last updated
  • 11/07/2025
Product version
  • v3.4.4
Variation
  • Fully configurable
Est. deployment time:
  • 8min
Copy
Copy
Copy
Copy
Copy
Copy
Focus sentinel
info icon
Community registry
This deployable architecture is located in the community registry and might change frequently or be discontinued at short notice. It's not covered by the IBM Cloud terms and conditions and IBM doesn't provide support for it.
Focus sentinel

Overview

Overview

Some VPC patterns are configured with private networks not available over the internet. To access these networks, there are several connectivity options. This deployable architecture pattern configures the client-to-site VPN Server connectivity with only a few required inputs to configure it within an existing VPC. Once deployed, you can install an OpenVPN client application and import a profile from the VPN Server on the devices you want to access the VPN. The configuration can include a list of users that will be provided access to the private network, controlled by IBM Cloud IAM.

ℹ️ This Terraform-based automation is part of a broader suite of IBM-maintained Infrastructure as Code (IaC) assets, each following the naming pattern "Cloud automation for servicename" and focusing on single IBM Cloud service. These single-service deployable architectures can be used on their own to streamline and automate service deployments through an IaC approach, or assembled together into a broader automated IaC stack to automate the deployment of an end-to-end solution architecture.

Community uses
Last week: 0
Last month: 4
Views
Last week: 1,040
Last month: 5,097
Badges (1)
Terraform IBM Modules (TIM)

Badges

Product version

v3.4.4

Variation

Fully configurable

Terraform IBM Modules (TIM): A collection of curated IBM Cloud Terraform modules. Learn more

Features and capabilities

Supports configuring an existing [Secrets Manager](https://cloud.ibm.com/docs/secrets-manager?topic=secrets-manager-getting-started) instance to create a secret group and a new private certificate.

Secrets Manager

The [network ACL](https://cloud.ibm.com/docs/vpc?topic=vpc-configuring-acls-vpn) on the `client-to-site-subnet` subnet grants access based on the rules defined by the `network_acls` input variable.

ACL rules

Creates a new [security group](https://cloud.ibm.com/docs/security-groups?topic=security-groups-about-ibm-security-groups) named `client-to-site-sg` that allows incoming requests from sources defined in the `security_group_rules` input variable.

Security group

Creates an [IAM access group](https://cloud.ibm.com/docs/account?topic=account-groups&interface=ui) that allows users to authenticate and connect to the client-to-site VPN gateway.

IAM access group

Creates a [VPN gateway](https://cloud.ibm.com/docs/vpc?topic=vpc-using-vpn) in the `client-to-site-subnet` subnet, with routes configured to allow access to the VPCs.

VPN gateway

Deployable architecture setup

Architecture variation
Architecture variation
Compare
Creates client-to-site VPN connectivity to VPC
Close
    Version
    v3.4.4

    Client-to-site VPN configuration.

    Starting from
    $0.00/month
    Fully configurable
    Configured to use IBM secure by default standards, but can be edited to fit your use case.

    Deployable architecture overview

    Client-to-site VPN configuration.

    Client-to-site VPN configuration.

    Help

    Getting support

    This product is in the community registry, as such support is handled through the originated repo. If you experience issues please open an issue in the repository https://github.com/terraform-ibm-modules/terraform-ibm-client-to-site-vpn/issues. Please note this product is not supported via the IBM Cloud Support Center.

    Summary

    Cloud automation for Client to Site VPN

      1 resources
      • Cloud automation for Client to Site VPN
        1 resources
        *
        • Client VPN for VPC
          *
            Resource Configuration
            Starting costs are based on this resource configuration. You can edit configurations after you add this product to a project, which might impact costs.
            region: us-south
            Usage costs
            VPN connection hours us-south *
            $0.0104/Hours
            VPN instance hours us-south *
            $0.1254/Hours
      • Total estimated cost
        *$0.00/mo
      Already have an account? Log in
      Focus sentinel
      Close

      (1/2) | Client-to-site VPN configuration.

      Focus sentinel
      Focus sentinel
      Close

      (1/2) | Client-to-site VPN configuration.

      Focus sentinel