How can I configure a VPN connection to the BEEM platform?
Set up a secure, private network connection between your environment and BEEM — available on demand for customers who need to extract data from on-premises systems or legacy databases.
Overview
For customers who prefer a private, encrypted data path between their on-premises systems and the BEEM platform, BEEM offers an optional VPN configuration service.
This VPN setup enables secure data transfers from your internal network, databases, or data warehouses to your BEEM cloud environment — ideal for environments where data privacy or compliance requires traffic isolation.
The BEEM Advanced Data Services team can guide you through every step of the setup process.
Step 1 — Gather your network requirements
Before configuration begins, please document your current network setup. This information will help BEEM generate the correct VPN configuration files for your environment.
|
Information Needed |
Description |
Example / Notes |
|---|---|---|
|
Internet Service Provider (ISP) |
Name of your ISP |
e.g. Bell, Telus, AT&T |
|
Upload/Download speeds |
Measured or provided by ISP |
e.g. 500 Mbps / 500 Mbps |
|
External Gateway IP |
Public IP of your network gateway |
Static or dynamic |
|
Routing Type |
Static or BGP dynamic routing |
Dynamic routing is recommended for seamless failover between tunnels |
|
VPN Device Vendor |
Firewall or VPN platform in use |
e.g. Fortinet, pfSense, Palo Alto |
|
Device Model / Platform |
Hardware or software platform |
e.g. FortiGate 200F |
|
Software Version |
Firmware or OS version |
e.g. FortiOS 7.2.3 |
|
On-premises network IP range |
Internal network CIDR |
e.g. 10.0.0.0/16 ⚠️ Note: The 192.168.0.0/16 address range is reserved and cannot be used for VPN connections to BEEM. We offer an alternative gateway to connect to those network, ask our ADS team. |
|
Tunnel Redundancy |
Two tunnels are required for reliability |
Active/active configuration recommended |
Step 3 — Configure your VPN
Once BEEM receives your survey, our team will generate and provide:
-
The BEEM endpoint configuration (CIDR, pre-shared keys, tunnel parameters)
-
Setup instructions tailored to your VPN appliance
(Fortinet, pfSense, Palo Alto, etc.)
Follow the provided configuration to:
-
Import BEEM’s VPN settings into your appliance
-
Establish both tunnels
-
Verify connectivity and routing
Step 4 — Test reliability and performance
Before starting any data extractions, BEEM will schedule a validation session with your team to confirm performance and redundancy.
Test Procedure:
-
Using a test VM on your end and another one on BEEM’s side measure throughput and latency
-
Validate that both tunnels are active and monitored
-
Confirm keepalive and failover behavior
💡 Keeping both tunnels active ensures continuous operation, even if one connection experiences an outage.
Summary
Setting up an optional VPN connection with BEEM enhances data security and reliability for hybrid or legacy systems.
The BEEM team will support you through every step — from information gathering and configuration to testing and validation — to ensure your data flows securely between your environment and the BEEM platform.