All Products
Search
Document Center

Smart Access Gateway:Access failures from an SAG-100WM device to a cloud service

Last Updated:Apr 01, 2026

When an SAG-100WM device loses connectivity to Alibaba Cloud, the root cause is typically one of four things: a faulty connection between the on-premises terminal and the device, a faulty VPN tunnel, an ECS instance issue, or an ISP network outage. Work through the steps below in order to isolate the problem.

Symptoms

An on-premises terminal cannot reach Alibaba Cloud. Common signs include:

  • A terminal connected to a Cloud Enterprise Network (CEN) instance cannot ping Elastic Compute Service (ECS) instances also connected to that CEN instance.

  • A terminal connected to a Cloud Connect Network (CCN) instance cannot ping clients also connected to that CCN instance.

Causes

#Possible cause
1The connection between the on-premises terminal and the SAG-100WM device is faulty.
2The VPN tunnel between the SAG-100WM device and Alibaba Cloud is faulty.
3The ECS instance is faulty.
4The Internet service provider (ISP) network is faulty.

Troubleshooting steps

Step 1 — Check the SAG instance status

  1. Log on to the SAG console.

  2. Click the SAG instance ID and check whether the status is Ready.

StatusNext action
DisconnectedThe device has lost its connection to Alibaba Cloud. See SAG device disconnections for further troubleshooting.
ConnectedThe connection is intact. Proceed to Step 2.

Step 2 — Check the CLOUD indicator light

Look at the physical SAG-100WM device and check whether the CLOUD indicator light is on.

CLOUD lightMeaningNext action
OnThe VPN tunnel is error-free.Log on to the ECS console and verify that the security group rules of the ECS instance allow network traffic from the on-premises network.
OffThe VPN tunnel is faulty.Proceed to Step 3.

Step 3 — Bypass the intermediary device

An intermediate device such as a router may be interfering with the WAN connection. Configure PPPoE on the WAN port and connect the WAN port directly to the ISP network, bypassing any router.

CLOUD light after bypassingNext action
OnThe issue is resolved.
OffProceed to Step 4.

Step 4 — Check the SAG device software

Check whether the software on the SAG device has errors. If errors are present, restart the SAG device.