# Basic Configuration

Enable and configure basic NAT settings.

Before enabling Gate, ensure that you have completed the following:

- Create a [Virtual Private Gateway](https://docs.soracom.io/en/services/vpg).
- Create a [Soracom Air for Cellular Group](https://docs.soracom.io/en/services/groups/usage).
- Configure your group's [Virtual Private Gateway option](https://docs.soracom.io/en/services/air/vpg) to use your VPG.
- [Add Air for Cellular subscribers](https://docs.soracom.io/en/services/groups/usage) to the group.

Then, enable Gate for your VPG:

1. Sign in to the **[User Console](https://console.soracom.io/?coverage_type=g)**. From the **☰ Menu**, open the **VPG** screen.

2. From the list of VPGs, click the **name** of the VPG you want to configure to open its settings page.

3. Click the **Device LAN** tab.

4. Enable Gate by switching the option to **ON**.

   ![Missing](https://docs.soracom.io/_astro/gate_enable.k12DM7Uj_2bnkoS.webp)

5. Click the **Save** button at the bottom of the panel.

> [!NOTE]
>
> When using Gate with an Arc Virtual SIM/Subscriber, you must add your VPG's **Device Subnet IP Range** to either your:
>
> - [WireGuard configuration file](https://docs.soracom.io/en/services/arc/configuration) under `AllowedIPs`.
> - [soratun configuration file](https://docs.soracom.io/en/services/arc/soratun/installation) under `additionalAllowedIPs`
>
> You can check your **Device Subnet IP Range** on the [VPG Settings Screen](https://docs.soracom.io/en/services/vpg/type-f2#configuring-vpg-settings). The default range is `10.128.0.0/9`.

## Programmatic Usage

### Soracom API

Enable Gate by using the **openGate** API method:

**Global**

```bash
curl -X POST \
  https://g.api.soracom.io/v1/virtual_private_gateways/<VPG-ID>/gate/open
```

**Japan**

```bash
curl -X POST \
  https://jp.api.soracom.io/v1/virtual_private_gateways/<VPG-ID>/gate/open
```

Once enabled, the API will return a response indicating the status of the VPG:

```json
{
  "operatorId": "OP0012345678",
  "vpgId": "abcdef00-0000-0000-0000-000012345678",
  "type": 12,
  "status": "running",
  "useInternetGateway": true,
  "tags": {
    "name": "my-vpg"
  },
  "createdTime": 1467007824685,
  "lastModifiedTime": 1467012076035,
  "primaryServiceName": "Gate",
  "vpcPeeringConnections": null,
  "virtualInterfaces": null,
  "gateOpened": true
}
```

You can disable gate similarly by using the **closeGate** API.

### Soracom CLI

Enable Gate by using the `open-gate` command:

**Global**

```bash
soracom vpg open-gate --vpg-id "<VPG-ID>" --coverage-type g
```

**Japan**

```bash
soracom vpg open-gate --vpg-id "<VPG-ID>" --coverage-type jp
```

The CLI will return a similar response indicating the VPG status.

You can disable Gate using the `close-gate` command.
