Skip to main content

Connect Collate to your network over AWS Site-to-Site VPN

AWS Site-to-Site VPN creates an encrypted IPSec connection between Collate’s dedicated network for your instance and your own AWS network. It lets Collate reach data sources that live in your private network, such as a database with no public access, without exposing them to the public internet. Traffic is encrypted end to end and rides over two redundant tunnels. This is the reverse direction from AWS PrivateLink, which secures traffic going into Collate. Use Site-to-Site VPN when you need Collate to reach out to resources inside your network.
Note: Site-to-Site VPN is available for Collate SaaS instances. Contact your Collate representative to have a VPN provisioned before you begin. Collate exchanges tunnel details with you as part of setup.

How It Works

Collate runs two dedicated private networks for each SaaS customer. The VPN connects the network where your Collate compute runs to your own cloud network, so Collate can reach internal resources over private IPs. The setup follows the standard AWS Site-to-Site VPN model:
  • You create a customer gateway, a virtual private gateway, and a VPN connection in your AWS account.
  • Collate provisions the matching VPN on its side using the tunnel details you exchange.
  • Each connection brings up two IPSec tunnels across different Availability Zones for redundancy.
  • Once both ends are up, Collate reaches your data sources over the tunnel using their private IPs.

When to Use This

Site-to-Site VPN is one of a few ways to let Collate read from private data sources. Consider the alternatives too:
  • The Hybrid Runner runs ingestion inside your own environment, so credentials and data never leave it. This is usually the simplest option and needs no VPN.
  • Site-to-Site VPN is a good fit when you’d rather Collate connect directly to your data sources over an encrypted link than run ingestion yourself.

Before You Begin

Setup starts by contacting Collate support to provision the VPN. You then exchange the following. Collate provides you with: You provide Collate with: You also need permissions in your AWS account to create customer gateways, virtual private gateways, VPN connections, and to edit route tables and security groups.

Step 1: Create the Customer Gateway

The customer gateway represents Collate’s end of the tunnel in your account.
  1. Open the Amazon VPC console and choose Customer gateways > Create customer gateway.
  2. For Name tag, enter something identifiable, such as collate-vpn.
  3. For BGP ASN, enter 65001.
  4. For IP address, enter the Collate-side outside IP provided by Collate.
  5. Choose Create customer gateway.

Step 2: Create and Attach the Virtual Private Gateway

The virtual private gateway (VGW) is the VPN endpoint on your side. Attach it to the VPC that holds the resources Collate needs to reach.
  1. Choose Virtual private gateways > Create virtual private gateway.
  2. For Name tag, enter collate-vpn.
  3. For Autonomous System Number (ASN), choose Custom and enter 65002.
  4. Choose Create virtual private gateway.
  5. Select the gateway, then choose Actions > Attach to VPC and pick your VPC.

Step 3: Set Up Routing

Traffic to Collate’s private network needs a route through the virtual private gateway. Route propagation (recommended). In the route table associated with your subnets, open the Route propagation tab, choose Edit route propagation, select the virtual private gateway, and save. AWS then propagates the VPN routes automatically. Manual routing. If you don’t enable propagation, add a static route yourself: in the route table, choose Routes > Edit, set the Destination to Collate’s private network CIDR, set the Target to the virtual private gateway, and save.

Step 4: Update Your Security Groups

Allow inbound traffic from Collate’s private network on the resources Collate connects to (for example, your database’s security group). Collate provides the source CIDR, and it is dedicated to your instance. Scope the port to the specific service Collate needs to reach rather than opening the range wider than necessary.

Step 5: Create the Site-to-Site VPN Connection

  1. Choose Site-to-Site VPN connections > Create VPN connection.
  2. For Name tag, enter collate-vpn.
  3. For Target gateway type, choose Virtual private gateway, then select the VGW from Step 2.
  4. For Customer gateway, choose Existing and select the customer gateway from Step 1.
  5. For Routing options, choose Static, and under Static IP prefixes add Collate’s private network CIDR.
  6. Under Tunnel options, set each tunnel’s inside IPv4 CIDR and pre-shared key to the values Collate provided. Leave the rest at their defaults unless Collate asked for an override.
  7. Choose Create VPN connection. It takes a few minutes to provision.
  8. Once available, open Tunnel details and share both Tunnel outside IP addresses with Collate.
After you share your tunnel outside IPs, Collate configures its customer gateway with them, brings up the tunnels on its side, and confirms connectivity with you.

Troubleshooting

The tunnel isn’t establishing at all. Confirm your customer gateway points at the Collate-side outside IP that Collate provided, and that the pre-shared keys in the VPN connection’s tunnel options match the ones Collate provided for each tunnel.
IPSec has negotiated but the tunnel isn’t passing the phase-2 selectors. Set the remote IPv4 network CIDR on the connection to 0.0.0.0/0 so the tunnel accepts the full range.
The tunnel is healthy but traffic isn’t reaching the data source. Check two things: the data source’s security group allows inbound traffic from Collate’s private network CIDR on the right port, and your route tables have an entry sending Collate’s private network CIDR through the virtual private gateway.