> ## Documentation Index
> Fetch the complete documentation index at: https://docs.getcollate.io/llms.txt
> Use this file to discover all available pages before exploring further.

# Connect Collate to your network over AWS Site-to-Site VPN

> Establish an encrypted AWS Site-to-Site VPN so Collate can reach data sources in your private network without exposing them to the public internet.

# Connect Collate to your network over AWS Site-to-Site VPN

AWS Site-to-Site VPN creates an encrypted IPSec connection between Collate's dedicated network for your instance and your own AWS network. It lets Collate reach data sources that live in your private network, such as a database with no public access, without exposing them to the public internet. Traffic is encrypted end to end and rides over two redundant tunnels.

This is the reverse direction from [AWS PrivateLink](/ai-2-0/how-to-guides/deployment/privatelink), which secures traffic going into Collate. Use Site-to-Site VPN when you need Collate to reach out to resources inside your network.

<Note>
  **Note**: Site-to-Site VPN is available for Collate SaaS instances. Contact your Collate representative to have a VPN provisioned before you begin. Collate exchanges tunnel details with you as part of setup.
</Note>

## How It Works

Collate runs two dedicated private networks for each SaaS customer. The VPN connects the network where your Collate compute runs to your own cloud network, so Collate can reach internal resources over private IPs. The setup follows the standard [AWS Site-to-Site VPN](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPC_VPN.html) model:

* You create a customer gateway, a virtual private gateway, and a VPN connection in your AWS account.
* Collate provisions the matching VPN on its side using the tunnel details you exchange.
* Each connection brings up two IPSec tunnels across different Availability Zones for redundancy.
* Once both ends are up, Collate reaches your data sources over the tunnel using their private IPs.

## When to Use This

Site-to-Site VPN is one of a few ways to let Collate read from private data sources. Consider the alternatives too:

* The [Hybrid Runner](/ai-2-0/how-to-guides/deployment/hybrid-runner) runs ingestion inside your own environment, so credentials and data never leave it. This is usually the simplest option and needs no VPN.
* Site-to-Site VPN is a good fit when you'd rather Collate connect directly to your data sources over an encrypted link than run ingestion yourself.

## Before You Begin

Setup starts by contacting Collate support to provision the VPN. You then exchange the following.

**Collate provides you with**:

| Item | Notes |
| - | - |
| Tunnel inside IPv4 CIDRs | A `/30` from the `169.254.0.0/16` range, one per tunnel |
| Collate-side outside IP | The public IP you point your customer gateway at |
| Collate's private network CIDR | The IPv4 range of your servers inside the Collate VPC (your remote network) |
| Pre-shared key (PSK) | One per tunnel, for IKE |

**You provide Collate with**:

| Item | Why it's needed |
| - | - |
| The IPv4 CIDR ranges routed through the tunnel | The networks Collate needs to reach, such as your database subnets |
| Your tunnel outside IP addresses | Two, one per tunnel. Generated after you create the VPN connection. Collate configures its customer gateway with them. |
| Any tunnel option overrides | If you need to change the [default tunnel options](https://docs.aws.amazon.com/vpn/latest/s2svpn/VPNTunnels.html) |

You also need permissions in your AWS account to create customer gateways, virtual private gateways, VPN connections, and to edit route tables and security groups.

## Step 1: Create the Customer Gateway

The customer gateway represents Collate's end of the tunnel in your account.

<Tabs>
  <Tab title="AWS Console">
    1. Open the [Amazon VPC console](https://console.aws.amazon.com/vpc/) and choose **Customer gateways** > **Create customer gateway**.
    2. For **Name tag**, enter something identifiable, such as `collate-vpn`.
    3. For **BGP ASN**, enter `65001`.
    4. For **IP address**, enter the Collate-side outside IP provided by Collate.
    5. Choose **Create customer gateway**.
  </Tab>

  <Tab title="AWS CLI">
    ```bash theme={null}
    aws ec2 create-customer-gateway \
      --type ipsec.1 \
      --bgp-asn 65001 \
      --public-ip <collate-outside-ip> \
      --tag-specifications 'ResourceType=customer-gateway,Tags=[{Key=Name,Value=collate-vpn}]'
    ```
  </Tab>
</Tabs>

## Step 2: Create and Attach the Virtual Private Gateway

The virtual private gateway (VGW) is the VPN endpoint on your side. Attach it to the VPC that holds the resources Collate needs to reach.

<Tabs>
  <Tab title="AWS Console">
    1. Choose **Virtual private gateways** > **Create virtual private gateway**.
    2. For **Name tag**, enter `collate-vpn`.
    3. For **Autonomous System Number (ASN)**, choose **Custom** and enter `65002`.
    4. Choose **Create virtual private gateway**.
    5. Select the gateway, then choose **Actions** > **Attach to VPC** and pick your VPC.
  </Tab>

  <Tab title="AWS CLI">
    ```bash theme={null}
    # Create the VGW
    aws ec2 create-vpn-gateway \
      --type ipsec.1 \
      --amazon-side-asn 65002 \
      --tag-specifications 'ResourceType=vpn-gateway,Tags=[{Key=Name,Value=collate-vpn}]'

    # Attach it to your VPC
    aws ec2 attach-vpn-gateway \
      --vpn-gateway-id vgw-0123456789abcdef0 \
      --vpc-id vpc-0123456789abcdef0
    ```
  </Tab>
</Tabs>

## Step 3: Set Up Routing

Traffic to Collate's private network needs a route through the virtual private gateway.

**Route propagation (recommended).** In the route table associated with your subnets, open the **Route propagation** tab, choose **Edit route propagation**, select the virtual private gateway, and save. AWS then propagates the VPN routes automatically.

**Manual routing.** If you don't enable propagation, add a static route yourself: in the route table, choose **Routes** > **Edit**, set the **Destination** to Collate's private network CIDR, set the **Target** to the virtual private gateway, and save.

```bash theme={null}
# Route propagation via CLI
aws ec2 enable-vgw-route-propagation \
  --route-table-id rtb-0123456789abcdef0 \
  --gateway-id vgw-0123456789abcdef0
```

## Step 4: Update Your Security Groups

Allow inbound traffic from Collate's private network on the resources Collate connects to (for example, your database's security group). Collate provides the source CIDR, and it is dedicated to your instance.

| Direction | Protocol | Port | Source |
| - | - | - | - |
| Inbound | TCP | Your data source port (for example, `5432` for PostgreSQL) | Collate's private network CIDR |

Scope the port to the specific service Collate needs to reach rather than opening the range wider than necessary.

## Step 5: Create the Site-to-Site VPN Connection

<Tabs>
  <Tab title="AWS Console">
    1. Choose **Site-to-Site VPN connections** > **Create VPN connection**.
    2. For **Name tag**, enter `collate-vpn`.
    3. For **Target gateway type**, choose **Virtual private gateway**, then select the VGW from Step 2.
    4. For **Customer gateway**, choose **Existing** and select the customer gateway from Step 1.
    5. For **Routing options**, choose **Static**, and under **Static IP prefixes** add Collate's private network CIDR.
    6. Under **Tunnel options**, set each tunnel's inside IPv4 CIDR and pre-shared key to the values Collate provided. Leave the rest at their defaults unless Collate asked for an override.
    7. Choose **Create VPN connection**. It takes a few minutes to provision.
    8. Once available, open **Tunnel details** and share both **Tunnel outside IP addresses** with Collate.
  </Tab>

  <Tab title="AWS CLI">
    ```bash theme={null}
    # Create the connection with static routing
    aws ec2 create-vpn-connection \
      --type ipsec.1 \
      --customer-gateway-id cgw-0123456789abcdef0 \
      --vpn-gateway-id vgw-0123456789abcdef0 \
      --options '{"StaticRoutesOnly":true}'

    # Add the static route to Collate's private network
    aws ec2 create-vpn-connection-route \
      --vpn-connection-id vpn-0123456789abcdef0 \
      --destination-cidr-block <collate-private-cidr>
    ```

    Then read back the tunnel outside IPs and share them with Collate:

    ```bash theme={null}
    aws ec2 describe-vpn-connections \
      --vpn-connection-ids vpn-0123456789abcdef0 \
      --query 'VpnConnections[].VgwTelemetry[].OutsideIpAddress' \
      --output text
    ```
  </Tab>
</Tabs>

After you share your tunnel outside IPs, Collate configures its customer gateway with them, brings up the tunnels on its side, and confirms connectivity with you.

## Troubleshooting

<Accordion title="Tunnel Is DOWN and IPSec Is DOWN">
  The tunnel isn't establishing at all. Confirm your customer gateway points at the Collate-side outside IP that Collate provided, and that the pre-shared keys in the VPN connection's tunnel options match the ones Collate provided for each tunnel.
</Accordion>

<Accordion title="Tunnel Is DOWN but IPSec Is UP">
  IPSec has negotiated but the tunnel isn't passing the phase-2 selectors. Set the remote IPv4 network CIDR on the connection to `0.0.0.0/0` so the tunnel accepts the full range.
</Accordion>

<Accordion title="Tunnel Is UP but There's No Connectivity to My Databases">
  The tunnel is healthy but traffic isn't reaching the data source. Check two things: the data source's security group allows inbound traffic from Collate's private network CIDR on the right port, and your route tables have an entry sending Collate's private network CIDR through the virtual private gateway.
</Accordion>


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.