All Products
Search
Document Center

VPN Gateway:CreateCustomerGateway

Last Updated:Aug 07, 2026

Creates a customer gateway.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

vpc:CreateCustomerGateway

create

*CustomerGateway

acs:vpc:{#regionId}:{#accountId}:customergateway/*

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID of the customer gateway.

You can call the DescribeRegions operation to query the region ID.

cn-shanghai

ClientToken

string

No

The client token that is used to ensure the idempotence of the request.

You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters and cannot exceed 64 characters in length.

Note

If you do not specify this parameter, the system automatically uses the RequestId of the API request as the ClientToken. The RequestId may be different for each API request.

02fb3da4-130e-11e9-8e44****

IpAddress

string

Yes

The static IP address of the gateway device in the on-premises data center.

  • If you want to create an IPsec-VPN connection that uses the public network type, enter a public IP address.

  • If you want to create an IPsec-VPN connection that uses the private network type, enter a private IP address.

The following IP addresses are not supported. If you use these IP addresses, the IPsec-VPN connection cannot be established:

  • 100.64.0.0 to 100.127.255.255

  • 127.0.0.0 to 127.255.255.255

  • 169.254.0.0 to 169.254.255.255

  • 224.0.0.0 to 239.255.255.255

  • 255.0.0.0 to 255.255.255.255

101.12.XX.XX

Name

string

No

The name of the customer gateway.

The name must be 1 to 100 characters in length and cannot start with http:// or https://.

nametest

Description

string

No

The description of the customer gateway.

The description must be 1 to 100 characters in length and cannot start with http:// or https://.

desctest

Asn

string

No

If you plan to enable the BGP dynamic routing protocol for the IPsec-VPN connection, you need to allocate the Autonomous System Number (ASN) of the gateway device in the on-premises data center. Valid values: 1 to 4294967295. The value 45104 is not supported.

Asn is a 4-byte number. You can enter the number in two-segment format: the first 16 bits.the last 16 bits. Each segment is entered in decimal format.

For example, if you enter 123.456, the ASN is 123 × 65536 + 456 = 8061384.

Note
  • Use a private ASN to establish a BGP connection with Alibaba Cloud. For more information about the range of private ASNs, refer to the relevant documentation.

  • 45104 is a unique identity allocated to Alibaba Cloud Computing Co., Ltd. by the Internet Assigned Numbers Authority (IANA). It is used as an identity for Alibaba Cloud in global Internet routing and data transmission.

65530

AuthKey

string

No

The authentication key of the BGP routing protocol for the gateway device in the on-premises data center.

The key must be 1 to 64 characters in length and can contain only ASCII characters. Spaces, Chinese characters, and half-width question marks (?) are not supported.

AuthKey****

Tags

array<object>

No

The list of tags to add to the customer gateway.

You can add up to 20 tags to a customer gateway at a time.

object

No

The tag information.

Key

string

No

The tag key. If you specify this parameter, the value cannot be an empty string.

The tag key can be up to 64 characters in length and cannot start with aliyun or acs:. It cannot contain http:// or https://.

You can specify up to 20 tag keys at a time.

TagKey

Value

string

No

The tag value.

The tag value can be up to 128 characters in length and can be an empty string. It cannot start with aliyun or acs: and cannot contain http:// or https://.

Each tag key corresponds to one tag value. You can specify up to 20 tag values at a time.

TagValue

ResourceGroupId

string

No

The ID of the resource group to which the customer gateway belongs.

  • You can call the ListResourceGroups operation to query the resource group ID.

  • If you do not specify a resource group, the customer gateway belongs to the default resource group after it is created.

rg-aek2qo2h4jy****

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID.

D32B3C26-6C6C-4988-93E9-D2A6444CE6AE

IpAddress

string

The static IP address of the gateway device in the on-premises data center.

101.12.XX.XX

Description

string

The description of the customer gateway.

desctest

CustomerGatewayId

string

The instance ID of the customer gateway.

cgw-bp1jrawp82av6bws9****

CreateTime

integer

The timestamp when the customer gateway was created. Unit: milliseconds.

The timestamp is in the UNIX format and represents the number of milliseconds that have elapsed since January 1, 1970, 00:00:00 UTC.

1493363486000

Name

string

The name of the customer gateway.

nametest

Examples

Success response

JSON format

{
  "RequestId": "D32B3C26-6C6C-4988-93E9-D2A6444CE6AE",
  "IpAddress": "101.12.XX.XX",
  "Description": "desctest",
  "CustomerGatewayId": "cgw-bp1jrawp82av6bws9****",
  "CreateTime": 1493363486000,
  "Name": "nametest"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidAuthkey.Malformed The specified BGP authentication key (%s) is malformed. The BGP authentication key is invalid.
400 InvalidIpAddress.AlreadyExist Specified IpAddress is already exist. The IP address already exists. You cannot specify duplicate IP addresses by using the same account in the same region.
400 InvalidIpAddress.WrongFormat Specified IpAddress is invalid.
400 InvalidName The name is not valid
400 InvalidDescription The description is not valid
400 Resource.QuotaFull The quota of resource is full
400 IllegalParam.Asn The specified Asn is invalid. The error message returned because the ASN is invalid.
400 OperationDenied.MissingAsn The autonomous system number of the customer gateway is mandatory when BGP authentication key is specified. The autonomous system number of the customer gateway is mandatory when BGP authentication key is specified.
400 InvalidParameter.TagValue The specified parameter TagValue is invalid. The error message returned because the specified tag value is invalid.
400 SizeLimitExceeded.TagNum The maximum number of tags is exceeded. The number of tags has reached the upper limit.
400 Forbidden.TagKey.Duplicated The specified tag key already exists. The tag resources are duplicate.
400 InvalidParameter.TagKey The specified parameter TagKey is invalid. The error message returned because the specified tag key is invalid.
400 Duplicated.TagKey The specified parameter TagKey is duplicated. The error message returned because the specified tag key already exists.
400 OperationFailed.NoRamPermission Vpn Service has no permission to operate your IDaaS instances. The VPN service does not have the permissions to manage your IDaaS instance.
400 CreateVpnUserGatewayQuotaFull.QuotaFull The number of created VPN customer gateways exceeds the quota. The number of created VPN customer gateways exceeds the quota.
403 Forbidden.SubUser User not authorized to operate on the specified resource as your account is created by another user. The error message returned because you are unauthorized to perform this operation on the specified resource. Acquire the required permissions and try again.
403 Forbidden User not authorized to operate on the specified resource. You do not have the permissions to manage the specified resource. Apply for the permissions and try again.
409 OperationConflict The operation against this instance is too frequent, please try again later. Operations are too frequently performed on the instance. Try again later.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.