A procedure that includes: at a first network device (120, 122) between a second network device (112) and a third network device (154), detecting an
Internet Key Exchange Protocol (IKE) key negotiation between the second network device and the third network device; based on the detection of the IKE key negotiation! between the second network device and the third network device, creating a firewall session in the first network device between the second and the third network device, wherein a first
Internet Protocol Security (
IPSec) tunnel (212) is established by the first network device between the second and the third network device using the IKE key negotiation, the first tunnel being compliant with the firewall session and allowing the passage of
IPSec data packets through the first network device between the second and the third network device; Passing the
IPSec data packets exchanged between the second and third network devices through the first network device based on the establishment of the first tunnel using cloud-managed IPSec keys from a cloud-based orchestrator (142), wherein the IPSec data packets are exchanged as part of a
handshake operation that results in the establishment of a second tunnel between the second and third network devices according to the cloud-managed IPSec keys, the second tunnel being an
overlay tunnel (218) on an
underlay network; and After the second tunnel has been established and the cloud-managed IPSec keys are active, discard the negotiated IKE and carefully dismantle the first IPSec tunnel without disrupting encrypted communication between the second and third network devices.