All Products
Search
Document Center

Cloud Config:Check the outbound bandwidth usage of a VPN Gateway

Last Updated:Sep 26, 2025

A VPN Gateway is considered non-compliant if its outbound bandwidth usage is greater than or equal to a specified value for at least 8 hours within a specific time range. This rule does not apply if the VPN Gateway is not connected to CloudMonitor or if monitoring data is unavailable. By default, the detection time range is the last 7 days. This check uses the CloudMonitor monitoring data API and consumes the free quota for basic CloudMonitor. To ensure detection quality, you can enable Hybrid Cloud Monitoring. For more information about billing for Hybrid Cloud Monitoring, see CloudMonitor billing.

Risk level

Default risk level: Medium.

You can change the risk level as needed.

Detection logic

  • A VPN Gateway is considered non-compliant if its outbound bandwidth usage is greater than or equal to a specified value for at least 8 hours within a specific time range. This rule does not apply if the VPN Gateway is not connected to CloudMonitor or if monitoring data is unavailable. By default, the detection time range is the last 7 days. This check uses the CloudMonitor monitoring data API and consumes the free quota for basic CloudMonitor. To ensure detection quality, you can enable Hybrid Cloud Monitoring. For more information about billing for Hybrid Cloud Monitoring, see CloudMonitor billing.

Rule details

Parameter

Description

Rule name

Check the outbound bandwidth usage of a VPN Gateway

Rule identifier

vpn-gateway-out-bandwidth-utilization-check

Tag

VPN

Automatic remediation

Not supported

Rule trigger

Periodic execution

Trigger frequency

24 hours

Supported resource types

ACS::VPN::VpnGateway

Rule input parameters

relativeTime (Default value: 168)
utilization (Default value: 80)