A VPN connection is an encrypted and secure site-to-site virtual private network tunnel over the Internet. Monthly Recurring Cost is assessed per customer gateway. The Delta1 UAT VPN provides access to the UAT Delta1 Trading Platform Instance. During the time when a firm is developing, troubleshooting, and certifying applications for Delta1, fees for Delta1 UAT VPNs will be collected. The firm will receive a credit for up to 2 months of the monthly VPN cost (for the equal number of connectivity methods) incurred during the development effort once the firm has established connectivity to the Production Delta1 Trading Platform Instance.
The User Acceptance Testing Delta1 TPI is accessible via a VPN gateway hosted at a single US-based site. The Delta1 UAT VPN provides access to select UAT services. (see Available Services below).
Suggested Customer Configuration
Only the UAT Delta1 Trading Platform Instance is available from Site-UAT. When a customer requests a VPN setup, configurations are deployed to Site-UAT. This provides site specific access to a Delta1 TPI, in this case the UAT instance. Customers are to configure connectivity to the designated public gateway (vpn.site-uat.onechicago.com) and ensure the appropriate routing design to eliminate the potential of routing traffic over other connectivity methods to non-testing Delta1 TPIs. Customers can elect to establish multiple customer gateways to support site-level redundancy for their source infrastructure. To determine what networks to route over VPN tunnels please see Required Networks and Ports.
Minimal Recommended Design
In the below design, a customer has provided the exchange one (1) gateway from which their tunnel will initiate. The exchange has deployed one (1) configurations to support exchange side site access. The customer has configured one (1) exchange gateway to support an active IKE security association to the specified exchange site.
Customer Multi-Site Redundant Design
In the below design, a customer has provided the exchange two (2) gateways from which their tunnels will initiate. The exchange has deployed two (2) configurations to support exchange side site access. The customer has configured one (1) exchange gateways at each customer site to support an active IKE security association to the specified exchange site.
A Customer selecting a VPN connection as its desired connection method is required to have an internet connection and one of the following manufacturers:
The device must support IKE Version 2, phase 1 authentication of SHA-256, and the interesting traffic must be a publicly registered subnet.