All Products
Search
Document Center

VPN Gateway:ModifyTunnelAttribute

Last Updated:Jun 19, 2026

Calls the ModifyTunnelAttribute operation to modify the tunnel configuration of a highly available VPN gateway.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

vpc:ModifyTunnelAttribute

update

*VpnConnection

acs:vpc:{#regionId}:{#accountId}:vpnconnection/{#VpnConnectionId}

None None

Request parameters

Parameter

Type

Required

Description

Example

ClientToken

string

No

The client token that is used to ensure the idempotence of the request.

You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters.

Note

If you do not specify this parameter, the system automatically uses the RequestId as the ClientToken. The RequestId may be different for each request.

02fb3da4-130e-11e9-8e44-0016e04115b

TunnelOptionsSpecification

object

No

The tunnel configuration to modify.

EnableDpd

boolean

No

Specifies whether to enable the Dead Peer Detection (DPD) feature. Valid values:

  • true: Enabled. The initiator of the IPsec-VPN connection sends DPD packets to check whether the peer is alive. If no correct response is received within the specified period of time, the connection fails. The ISAKMP SA and the corresponding IPsec SA are deleted, and the tunnel is also deleted.

  • false: Disabled. The initiator of the IPsec-VPN connection does not send DPD packets.

true

EnableNatTraversal

boolean

No

Specifies whether to enable NAT traversal. Valid values:

  • true: Enabled. After NAT traversal is enabled, the verification of the UDP port number is removed during IKE negotiations, and the NAT gateway device in the VPN tunnel can be discovered.

  • false: Disabled.

true

RemoteCaCertificate

string

No

The CA certificate of the peer when you use an IPsec-VPN connection with a Chinese SM VPN gateway.

-----BEGIN CERTIFICATE----- MIIB7zCCAZW**** -----END CERTIFICATE-----

TunnelBgpConfig

object

No

The BGP configuration of the tunnel to modify.

If BGP was not previously enabled for the tunnel, call the ModifyVpnConnectionAttribute operation to enable BGP for the tunnel and add the BGP configuration.

LocalAsn

integer

No

The autonomous system number (ASN) of the local end of the tunnel. Valid values: 1 to 4294967295.

65530

LocalBgpIp

string

No

The BGP IP address of the local end of the tunnel. The IP address must fall within the TunnelCidr CIDR block.

169.254.11.1

TunnelCidr

string

No

The CIDR block of the BGP IP address on the local end of the tunnel.

The CIDR block must be a CIDR block with a mask length of 30 within 169.254.0.0/16 and cannot be 169.254.0.0/30, 169.254.1.0/30, 169.254.2.0/30, 169.254.3.0/30, 169.254.4.0/30, 169.254.5.0/30, 169.254.6.0/30, or 169.254.169.252/30.

Note

The IPsec tunnel CIDR block of each IPsec-VPN connection under a VPN gateway instance must be unique.

169.254.11.0/30

TunnelIkeConfig

object

No

The IKE phase (Phase 1) configuration of the tunnel to modify.

IkeAuthAlg

string

No

The authentication algorithm used in Phase 1 negotiations.

Valid values: md5, sha1, sha256, sha384, and sha512.

.

sha1

IkeEncAlg

string

No

The encryption algorithm used in Phase 1 negotiations.

Valid values: aes, aes192, aes256, des, and 3des.

.

aes

IkeLifetime

integer

No

The lifetime of the SA negotiated in Phase 1. Unit: seconds. Valid values: 0 to 86400.

86400

IkeMode

string

No

The negotiation mode of the IKE version. Valid values:

  • main: main mode. This mode offers high security during negotiations.

  • aggressive: aggressive mode. This mode supports fast negotiations and a higher success rate.

main

IkePfs

string

No

The Diffie-Hellman key exchange algorithm used in Phase 1 negotiations. Valid values: group1, group2, group5, and group14.

group2

IkeVersion

string

No

The version of the IKE protocol. Valid values: ikev1 and ikev2.

ikev2

LocalId

string

No

The identifier of the local end of the tunnel. The identifier can be up to 100 characters in length and cannot contain spaces. It supports FQDN and IP formats. Default value: the IP address of the tunnel.

47.XX.XX.87

Psk

string

No

The pre-shared key used for identity authentication between the tunnel and the peer.

  • The key must be 1 to 100 characters in length and can contain digits, uppercase letters, lowercase letters, and the following characters. It cannot contain spaces. ~!`@#$%^&*()_-+={}[]|;:',.<>/?

  • If you do not specify a pre-shared key, the system generates a random 16-character string as the pre-shared key. You can call the DescribeVpnConnection operation to query the pre-shared key that is automatically generated by the system.

Note

The pre-shared keys configured on the tunnel and the peer must be the same. Otherwise, the tunnel cannot be established.

123456****

RemoteId

string

No

The identifier of the peer end of the tunnel. The identifier can be up to 100 characters in length and cannot contain spaces. It supports FQDN and IP formats. Default value: the IP address of the customer gateway instance associated with the tunnel.

47.XX.XX.207

TunnelIpsecConfig

object

No

The IPsec phase (Phase 2) configuration of the tunnel to modify.

IpsecAuthAlg

string

No

The authentication algorithm used in Phase 2 negotiations.

Valid values: md5, sha1, sha256, sha384, and sha512.

.

sha1

IpsecEncAlg

string

No

The encryption algorithm used in Phase 2 negotiations.

Valid values: aes, aes192, aes256, des, and 3des.

.

aes

IpsecLifetime

integer

No

The lifetime of the SA negotiated in Phase 2. Unit: seconds. Valid values: 0 to 86400.

86400

IpsecPfs

string

No

The Diffie-Hellman key exchange algorithm used in Phase 2 negotiations. Valid values: disabled, group1, group2, group5, and group14.

group2

CustomerGatewayId

string

No

The instance ID of the customer gateway associated with the tunnel.

cgw-1nmwbpgrp7ssqm1yn****

RegionId

string

No

The region ID of the IPsec-VPN connection.

You can call the DescribeRegions operation to query the region ID.

cn-hangzhou

VpnConnectionId

string

Yes

The ID of the IPsec-VPN connection.

vco-gw69vm1i71y354****

TunnelId

string

Yes

The tunnel ID.

tun-gbyz2e070xzo93****

Response elements

Element

Type

Description

Example

object

The response parameters.

TunnelId

string

The tunnel ID.

tun-gbyz2e070xzo93****

RequestId

string

The request ID.

E6F36FF0-9544-3AEE-8673-A4647D50064C

TunnelIkeConfig

object

The IKE phase (Phase 1) configuration of the tunnel.

IkeAuthAlg

string

The IKE authentication algorithm.

sha1

IkeEncAlg

string

The IKE encryption algorithm.

aes

IkeLifetime

integer

The IKE lifetime. Unit: seconds.

86400

IkeMode

string

The IKE negotiation mode.

  • main: main mode. This mode offers high security during negotiations.

  • aggressive: aggressive mode. This mode supports fast negotiations and a higher success rate.

main

IkePfs

string

The DH group.

group2

IkeVersion

string

The IKE protocol version.

  • ikev1

  • ikev2

Compared with IKEv1, IKEv2 simplifies the SA negotiation process and provides better support for multi-CIDR-block scenarios.

ikev2

LocalId

string

The identifier of the local end of the tunnel. It supports FQDN and IP formats. Default value: the IP address of the current tunnel.

47.XX.XX.87

Psk

string

The pre-shared key.

123456****

RemoteId

string

The identifier of the peer end of the tunnel. It supports FQDN and IP formats. Default value: the IP address of the customer gateway instance associated with the tunnel.

47.XX.XX.207

TunnelIpsecConfig

object

The IPsec phase (Phase 2) configuration of the tunnel.

IpsecAuthAlg

string

The IPsec authentication algorithm.

sha1

IpsecEncAlg

string

The IPsec encryption algorithm.

aes

IpsecLifetime

integer

The IPsec lifetime. Unit: seconds.

86400

IpsecPfs

string

The DH group.

group2

TunnelBgpConfig

object

The BGP configuration of the tunnel.

EnableBgp

boolean

The enabling status of BGP.

  • true: Enabled.

  • false: Disabled.

true

LocalAsn

integer

The autonomous system number (ASN) of the local end of the tunnel.

65530

LocalBgpIp

string

The BGP IP address of the local end of the tunnel.

169.254.11.1

PeerAsn

integer

The autonomous system number (ASN) of the peer end of the tunnel.

65531

PeerBgpIp

string

The BGP IP address of the peer end of the tunnel.

169.254.11.2

TunnelCidr

string

The CIDR block of the tunnel BGP IP address.

169.254.11.0/30

EnableNatTraversal

boolean

Indicates whether NAT traversal is enabled. Valid values:

  • false: disabled.

  • true: enabled.

true

EnableDpd

boolean

Indicates whether the Dead Peer Detection (DPD) feature is enabled.

  • false: disabled.

  • true: enabled.

true

RemoteCaCertificate

string

The CA certificate of the peer when an IPsec-VPN connection is created with a Chinese SM VPN gateway.

-----BEGIN CERTIFICATE----- MIIB7zCCAZW**** -----END CERTIFICATE-----

CustomerGatewayId

string

The instance ID of the customer gateway associated with the tunnel.

cgw-p0wx48ayhrygitm80****

Role

string

The role of the tunnel.

  • master: the active tunnel.

  • slave: the standby tunnel.

master

ZoneNo

string

The zone of the tunnel.

cn-hangzhou-h

InternetIp

string

The IP address of the tunnel.

47.XX.XX.87

State

string

The status of the tunnel.

  • active: available.

  • updating: being updated.

  • deleting: being deleted.

active

Examples

Success response

JSON format

{
  "TunnelId": "tun-gbyz2e070xzo93****",
  "RequestId": "E6F36FF0-9544-3AEE-8673-A4647D50064C",
  "TunnelIkeConfig": {
    "IkeAuthAlg": "sha1",
    "IkeEncAlg": "aes",
    "IkeLifetime": 86400,
    "IkeMode": "main",
    "IkePfs": "group2",
    "IkeVersion": "ikev2",
    "LocalId": "47.XX.XX.87",
    "Psk": "123456****",
    "RemoteId": "47.XX.XX.207"
  },
  "TunnelIpsecConfig": {
    "IpsecAuthAlg": "sha1",
    "IpsecEncAlg": "aes",
    "IpsecLifetime": 86400,
    "IpsecPfs": "group2"
  },
  "TunnelBgpConfig": {
    "EnableBgp": true,
    "LocalAsn": 65530,
    "LocalBgpIp": "169.254.11.1",
    "PeerAsn": 65531,
    "PeerBgpIp": "169.254.11.2",
    "TunnelCidr": "169.254.11.0/30"
  },
  "EnableNatTraversal": true,
  "EnableDpd": true,
  "RemoteCaCertificate": "-----BEGIN CERTIFICATE----- MIIB7zCCAZW**** -----END CERTIFICATE-----",
  "CustomerGatewayId": "cgw-p0wx48ayhrygitm80****",
  "Role": "master",
  "ZoneNo": "cn-hangzhou-h",
  "InternetIp": "47.XX.XX.87",
  "State": "active"
}

Error codes

HTTP status code

Error code

Error message

Description

400 VpnGateway.Configuring The specified service is configuring.
400 VpnGateway.FinancialLocked The specified service is financial locked.
400 InvalidName The name is not valid
400 VpnRouteEntry.AlreadyExists The specified route entry is already exist. The route already exists.
400 VpnRouteEntry.Conflict The specified route entry has conflict. Route conflicts exist.
400 NotSupportVpnConnectionParameter.IpsecPfs The specified vpn connection ipsec Ipsec Pfs is not support. The PFS parameter set for the IPsec-VPN connection is not supported.
400 NotSupportVpnConnectionParameter.IpsecAuthAlg The specified vpn connection ipsec Auth Alg is not support. The authentication algorithm specified for the IPsec-VPN connection is not supported.
400 VpnConnectionParamInvalid.SameVpnAndCgwDifferentIkeConfigs IPSec connections associated with the same user gateway and VPN gateway should have the same pre-shared key and IKE configuration. The pre-shared key and IKE parameters must be the same for IPsec-VPN connections that are associated with the same VPN gateway and customer gateway.
400 VpnConnectionParamInvalid.SameVpnAndCgwTrafficSelectorOverlap Traffic selectors of IPSec connections associated with the same user gateway and VPN gateway should not overlap. The protected data flows of IPsec-VPN connections that are associated with the same VPN gateway and customer gateway cannot overlap.
400 IllegalParam.LocalAsn The param of LocalAsn is illegal The LocalAsn parameter is set to an invalid value.
400 IllegalParam.LocalBgpIp The specified LocalBgpIp is invalid. The local BGP IP address is invalid.
400 VpnGateway.task.conflict The VPN is in the configuration state, please wait a while before operating. The VPN is in the configuration state, please wait a while before operating.
400 ModifyIkeV1WithMultiRoutes.Invalid Failed to modify VPN connection parameters. Multi-network is configured while using IkeV1 protocol. Failed to modify VPN connection parameters. Multi-network is configured while using IkeV1 protocol.
400 EncAlgInvalid.DesIncompatible Des/3des in IkeEncAlg and IpsecEncAlg does not support multi algorithm. Des/3des in IkeEncAlg and IpsecEncAlg does not support multi algorithm.
400 IkeVersionInvalid.GcmIncompatible Ikev1 does not support IkeEncAlg of gcm16. Ikev1 does not support IkeEncAlg of gcm16.
400 CustomerGateway.ConflictVpnIp The specified customer gateway has conflict with vpn gateway ip. The specified customer gateway has conflict with vpn gateway ip.
403 Forbbiden.SubUser User not authorized to operate on the specified resource as your account is created by another user.
403 Forbidden User not authorized to operate on the specified resource. You do not have the permissions to manage the specified resource. Apply for the permissions and try again.
404 InvalidVpnConnectionInstanceId.NotFound The specified vpn connection instance id does not exist. The specified vpn connection instance id does not exist.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.