Uploaded April 2026 | Updated September 2026, 11 hours ago
This demo shows how to configure and use Distributed Cloud External Connectors on a Customer Edge (CE) site running in AWS. It includes how to build an IPsec VPN tunnel to a Cisco 8000v router in a separate AWS VPC, and how to configure BGP to use the tunnel. In the final section learn how to verify the tunnel, BGP status and routes using the Distributed Cloud console dashboards, and then filter the routes received by denying a specific IP prefix and adding an allow-all rule in the correct rule order.
00:00 Demo overview and topology
01:01 Objective #1 - Establish IPsec VPN tunnels
01:03 IPsec profiles basics
01:31 External connector setup
03:13 IKE IDs tunnel details
06:33 Cisco IPsec configuration
09:32 Objective #2 - Establish BGP peering
09:34 BGP over tunnel setup
12:26 Objective #2 - Verify tunnel and BGP
14:43 Objective #3 - BGP routing policy - inbound filtering
18:37 Wrap Up Resources
The following companion article includes additional information shown in this video.
#mcn #bgp #distributed-cloud #f5xc #aws #cisco
Notes:
- Contributed by: Dave Potter
- Related Article: community.f5.com/kb/technicalarticles/integrating-external-connectors-in-distributed-cloud-ipsec-bgp--routing-policy-w/346032
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Aubrey King: linkedin.com/in/aubreyking | https://x.com/aubreykingf5
👋 Chase Abbott: linkedin.com/in/chaseabbott1
This demo shows how to configure and use Distributed Cloud External Connectors on a Customer Edge (CE) site running in AWS. It includes how to build an IPsec VPN tunnel to a Cisco 8000v router in a separate AWS VPC, and how to configure BGP to use the tunnel. In the final section learn how to verify the tunnel, BGP status and routes using the Distributed Cloud console dashboards, and then filter the routes received by denying a specific IP prefix and adding an allow-all rule in the correct rule order.
00:00 Demo overview and topology
01:01 Objective #1 - Establish IPsec VPN tunnels
01:03 IPsec profiles basics
01:31 External connector setup
03:13 IKE IDs tunnel details
06:33 Cisco IPsec configuration
09:32 Objective #2 - Establish BGP peering
09:34 BGP over tunnel setup
12:26 Objective #2 - Verify tunnel and BGP
14:43 Objective #3 - BGP routing policy - inbound filtering
18:37 Wrap Up Resources
The following companion article includes additional information shown in this video.
#mcn #bgp #distributed-cloud #f5xc #aws #cisco
Notes:
- Contributed by: Dave Potter
- Related Article: community.f5.com/kb/technicalarticles/integrating-external-connectors-in-distributed-cloud-ipsec-bgp--routing-policy-w/346032
⬇️⬇️ JOIN THE COMMUNITY! ⬇️⬇️⬇️
DevCentral is an online community of technical peers dedicated to learning, exchanging ideas, and solving problems—together.
Find all our platform links ⬇️ and follow our Community Evangelists! 👋
➡️ DEVCENTRAL: community.f5.com
➡️ YOUTUBE: youtube.com/devcentral
➡️ LINKEDIN: linkedin.com/showcase/f5-devcentral
➡️ X: https://x.com/devcentral
Your Community Evangelists:
👋 Jason Rahm: linkedin.com/in/jrahm | https://x.com/jasonrahm
👋 Buu Lam: linkedin.com/in/buulam | https://x.com/buulam
👋 Aubrey King: linkedin.com/in/aubreyking | https://x.com/aubreykingf5
👋 Chase Abbott: linkedin.com/in/chaseabbott1










