This topic explains why you cannot ping Alibaba Cloud resources through an SAG-100WM device and provides solutions.

Symptoms

A local terminal cannot connect to Alibaba Cloud, for example, you cannot ping Elastic Compute Service (ECS) instances deployed in Cloud Enterprise Network (CEN), or other local terminals deployed in Cloud Connect Network (CCN).

Causes

  • The connection between the local terminal and the SAG-100WM device is faulty.
  • The VPN tunnel between the SAG-100WM device and Alibaba Cloud is faulty.
  • The target ECS instance is faulty.
  • The Internet service provider (ISP) network is faulty.

Solutions

  1. Log on to the Smart Access Gateway (SAG) console.
  2. Click the ID of the target SAG instance, check whether the status is Ready.
  3. Check whether the CLOUD indicator of the SAG-100WM device is on.
    • If the CLOUD indicator is on, the VPN tunnel between the SAG-100WM device and Alibaba Cloud is functioning. Log on to the ECS console to check whether the rules of the security group allows access from the local terminal.
    • If the CLOUD indicator is off, the VPN tunnel between the SAG-100WM device and Alibaba Cloud is not established. Go to 4.
  4. Check the intermediary device such as a router.
    • Configure PPPoE for the WAN port and connect the WAN port to the ISP network without a router.
    • If the CLOUD indicator is still off, go to 5.
  5. The software of the SAG-100WM device may be faulty. Restart the SAG-100WM device or submit a ticket.