This topic describes how to update a VPN gateway. After you update a VPN gateway to the latest version, you can use more features. These features include BGP dynamic routing and Dead Peer Detection (DPD).


  • It takes about 10 minutes to update a VPN gateway. The VPN gateway remains unavailable during the update process. Connections that are established to the VPN gateway are also closed. We recommend that you update a VPN gateway during a network maintenance window to avoid service interruptions.
  • If multiple CIDR blocks are specified for an IPsec-VPN connection and the IKE version is IKE V1, you must update IKE V1 to IKE V2 or create an IPsec-VPN connection for each of the CIDR blocks. Otherwise, the update will fail.
  • You can check whether your VPN gateway is already updated to the latest version based on the status of the Upgrade button.
    • If your VPN gateway uses the latest version, the Upgrade button is dimmed and unavailable. If you move the pointer over the Upgrade button, the console prompts that the VPN gateway is already updated to the latest version.

      Newly created VPN gateways use the latest version by default.

    • If the Upgrade is not dimmed, you can click it to update the VPN gateway. For more information, see Procedure.


  1. Log on to the VPN gateway console.
  2. In the top navigation bar, select the region of the VPN gateway.
  3. On the VPN Gateways page, find the VPN gateway that you want to update and click its ID.
  4. On the details page of the VPN gateway, click Upgrade.
    Manual update
  5. In the Upgrade VPN Gateway dialog box, read and accept the update agreement, and then click OK.
    After you click OK, the system starts to update the VPN gateway. Wait until the update is completed.