There is a problem with the AMI. When creating an IPsec site-to-site VPN connection, it's assuming to use the Internal NIC's private IP which is wrong. And hence the opposite router has errors like this:
we require peer to have ID 'xx.xx.xx.xx', but
peer declares '10.243.45.92'
where 'xx.xx.xx.xx' is the public IP of the Astaro.
I have tested also by creating 2 Astaro EC2 instances and they can't VPN to each other.
So then I also tried adding my own IP alias to the Internal NIC, and I can't! It complains saying that it's write-protected.
I assume these things will be fixed?
This thread was automatically locked due to age.