---
name: framework-financial-services-vpc-architecture-connectivity-management
title: Connecting application provider to the management VPC
description: 'The management VPC should be accessed only by you, the application provider. It''s important that the connection be secure to avoid bad actors gaining access and conducting malicious operations. There are two options to enable this connectivity from your on-premises enterprise network: Direct Link and VPN for VPC. Alternatively, if you want to support connectivity without going through your enterprise network, you can deploy your own full tunnel client-to-site VPN solution. After a connection is established, operators can complete actions through a bastion host in the management VPC.'
last-updated: 2025-03-22
---

> ## Documentation Index
> The table of contents for this documentation set is at https://cloud.ibm.com/docs/framework-financial-services?format=markdown
> The index for all IBM Cloud docs is at: https://cloud.ibm.com/docs/llms.txt
> Use these files to discover more information as needed.

# Connecting application provider to the management VPC
{: #vpc-architecture-connectivity-management}

The management VPC should be accessed only by you, the application provider. It's important that the connection be secure to avoid bad actors gaining access and conducting malicious operations. There are two options to enable this connectivity from your on-premises enterprise network: [Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-dl-about&format=markdown) and [VPN for VPC](https://cloud.ibm.com/docs/vpc?topic=vpc-using-vpn&format=markdown). Alternatively, if you want to support connectivity without going through your enterprise network, you can deploy your own full tunnel client-to-site VPN solution. After a connection is established, operators can [complete actions through a bastion host](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-bastion&format=markdown) in the management VPC.
{: shortdesc}

Operators who are connecting to the on-premises enterprise network from offsite (such as their home) should connect to the enterprise network only by using a full tunnel client-to-site VPN solution. After connected to the enterprise network through a full tunnel, they can access the management VPC to perform their duties.
{: note}

## Direct Link
{: #direct-link}

Direct Link is the most secure way to enable connectivity from the application provider's on-premises environment to the management VPC. The speed and reliability of Direct Link extends your organization’s data center network and offers more consistent, higher-throughput connectivity, keeping traffic within the IBM Cloud network. When using Direct Link, a private [Application Load Balancer for VPC (ALB)](https://cloud.ibm.com/docs/vpc?topic=vpc-load-balancers&format=markdown) is used to distribute traffic among multiple server instances within the same region of your VPC.

The following diagram shows the Direct Link connection pattern.

![Application provider on-premises to management VPC by using Direct Link](../images/network-connectivity/provider-to-management-vpc/vpc-architecture-provider-on-prem-to-management-vpc-DL-fsv2.0.1.svg){: caption="Application provider on-prem to management VPC using Direct Link" caption-side="bottom"}

For more information, see:

* [Interconnecting your VPC that uses IBM Cloud offerings](https://cloud.ibm.com/docs/vpc?topic=vpc-interconnectivity&format=markdown)
* [Getting started with Direct Link](https://cloud.ibm.com/docs/dl/getting-started?topic=dl-get-started-with-ibm-cloud-dl&format=markdown)
* [Ordering IBM Cloud Direct Link](https://cloud.ibm.com/docs/dl?topic=dl-how-to-order-ibm-cloud-dl-dedicated&format=markdown)
* [Integrating with Virtual Private Endpoint for VPC](https://cloud.ibm.com/docs/dl?topic=dl-vpe-connection&interface=cli&format=markdown)



## VPN for VPC
{: #vpn-gateway}

An alternative connectivity pattern is to use the VPN for VPC service to securely connect from your private network to the management VPC. VPN for VPC can be used as a static, route-based VPN or a policy-based VPN to set up an IPsec site-to-site tunnel between your VPC and your on-premises private network, or another VPC.

The following diagram shows the VPN for VPC connection pattern.

![Application provider on-premises to management VPC by using VPN for VPC](../images/network-connectivity/provider-to-management-vpc/vpc-architecture-provider-on-prem-to-management-vpc-VPN-fsv2.0.1.svg){: caption="Application provider on-prem to management VPC using VPN for VPC" caption-side="bottom"}

For more information, see:

* [About VPN gateways](https://cloud.ibm.com/docs/vpc?topic=vpc-using-vpn&format=markdown)
* [Creating a VPN gateway](https://cloud.ibm.com/docs/vpc?topic=vpc-vpn-create-gateway&format=markdown)
* [Use a VPC/VPN gateway for secure and private on-premises access to cloud resources](https://cloud.ibm.com/docs/solution-tutorials?topic=solution-tutorials-vpc-site2site-vpn&format=markdown)

## Full tunnel client-to-site VPN
{: #vpn-client-to-site}

The third option for connectivity for your operators is to use a full tunnel client-to-site VPN, so they do not have to be on your on-premises network. However, IBM does not provide a Financial Services Validated full tunnel client-to-site VPN solution. So, if you want to use this option, you need to deploy your own. See [Setting up full tunnel VPN with FS BIG-IP](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-full-tunnel-vpn&format=markdown) for one example of how to do this.

## Related controls in IBM Cloud Framework for Financial Services
{: #related-controls}

{{site.data.content.related-controls-disclaimer}}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-4 (21) Information Flow Enforcement &#124; Physical or Logical Separation of Information Flows](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-4.21&format=markdown) \n [AC-17 Remote Access](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-17&format=markdown) \n [AC-20 Use of External Systems](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ac-20&format=markdown)  |
| Audit and Accountability (AU) | [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-au-10&format=markdown)  |
| Security Assessment and Authorization (CA)  | [CA-3 Information Exchange](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-ca-3&format=markdown)  |
| System and Communications Protection (SC)  | [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7&format=markdown) \n [SC-7 (4) Boundary Protection &#124; External Telecommunications Services](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.4&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny by Default - Allow by Exception](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.5&format=markdown) \n [SC-7 (10) Boundary Protection &#124; Prevent Exfiltration](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-7.10&format=markdown) \n [SC-8 Transmission Confidentiality and Integrity](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-8&format=markdown) \n [SC-8 (1) Transmission Confidentiality and Integrity &#124; Cryptographic Protection](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-8.1&format=markdown) \n [SC-10 Network Disconnect](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-10&format=markdown) \n [SC-11 Trusted Path](https://cloud.ibm.com/docs/framework-financial-services-controls?topic=framework-financial-services-controls-sc-11&format=markdown)  |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv2.0]" caption-side="top"}
{: #related-controls-fsv2.0}
{: tab-title="FSv2.0"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


| Family              | Control                                           |
|---------------------|---------------------------------------------------|
| Access Control (AC) | [AC-4 (21) Information Flow Enforcement &#124; Physical or Logical Separation of Information Flows](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-4.21&format=markdown) \n [AC-17 Remote Access](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-17&format=markdown) \n [AC-20 Use of External Systems](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ac-20&format=markdown)  |
| Audit and Accountability (AU) | [AU-10 Non-repudiation](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-au-10&format=markdown)  |
| Security Assessment and Authorization (CA)  | [CA-3 Information Exchange](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-ca-3&format=markdown)  |
| System and Communications Protection (SC)  | [SC-7 Boundary Protection](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7&format=markdown) \n [SC-7 (4) Boundary Protection &#124; External Telecommunications Services](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.4&format=markdown) \n [SC-7 (5) Boundary Protection &#124; Deny By Default - Allow By Exception](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.5&format=markdown) \n [SC-7 (10) Boundary Protection &#124; Prevent Exfiltration](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-7.10&format=markdown) \n [SC-8 Transmission Confidentiality and Integrity](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-8&format=markdown) \n [SC-8 (1) Transmission Confidentiality and Integrity &#124; Cryptographic Protection](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-8.1&format=markdown) \n [SC-10 Network Disconnect](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-10&format=markdown) \n [SC-11 Trusted Path](https://cloud.ibm.com/docs/framework-financial-services-controls-fsv1-1?topic=framework-financial-services-controls-fsv1-1-sc-11&format=markdown)  |
{: caption="Related controls in IBM Cloud Framework for Financial Services [FSv1.1]" caption-side="top"}
{: #related-controls-fsv1.1}
{: tab-title="FSv1.1"}
{: tab-group="RelatedControls-1"}
{: class="simple-tab-table"}


## Next steps
{: #next-steps}

* [Performing operator actions through a bastion host](https://cloud.ibm.com/docs/framework-financial-services?topic=framework-financial-services-vpc-architecture-connectivity-bastion&format=markdown)