Monitoring is an important part of maintaining the reliability, availability, and performance of an IPsec-VPN connection. VPN Gateway allows you to monitor metrics such as the negotiation status of IPsec-VPN connection tunnels and inbound/outbound traffic rates. This gives you clear insights into the operational status and bandwidth usage of your IPsec-VPN connection, helping you quickly identify network bottlenecks, detect network faults or anomalies, and improve network reliability and availability. VPN Gateway is integrated with CloudMonitor, which lets you centrally monitor and manage your Alibaba Cloud resources from the CloudMonitor console.
Monitor IPsec-VPN tunnel status
VPN Gateway allows you to monitor the status of each tunnel. You can view the current status of a tunnel in the VPN Gateway console. You can also subscribe to system events or create threshold-triggered alert rules for metrics to receive timely notifications about tunnel status changes.
View the status of an IPsec-VPN connection tunnel
VPN Gateway system events
VPN Gateway system events are predefined events that record and notify you about changes in tunnel negotiation status and health check status. You can view system events generated by VPN Gateway in the CloudMonitor console and subscribe to system events to stay informed of resource status changes and respond quickly.
Metrics for IPsec-VPN connection tunnel status
VPN Gateway provides metrics related to tunnel status. You can create threshold-triggered alert rules for these metrics to receive notifications about tunnel status changes.
Monitor IPsec-VPN traffic rate
VPN Gateway lets you view inbound/outbound traffic rates, packet rates, and bandwidth utilization at the VPN Gateway instance, IPsec-VPN connection, and tunnel levels. This helps you quickly identify network congestion points or abnormal traffic and optimize bandwidth utilization.
View the traffic rate of an IPsec-VPN connection
The following sections describe how to view traffic rate information in the VPN Gateway console. You can also view this information in the CloudMonitor console. For more information, see Cloud service monitoring.
Create a threshold-triggered alert rule for traffic rate metrics
In the CloudMonitor console, create a threshold-triggered alert rule for IPsec-VPN traffic rate metrics. If the rate exceeds your configured threshold, the system sends an alert, so you can respond to issues promptly.
Traffic rate metrics
Query and analyze IPsec-VPN traffic information
While monitoring your IPsec-VPN connection, you may need to analyze specific traffic details, such as source and destination IP addresses, ports, and protocols. You can use the flow log feature to capture inbound and outbound traffic information. You can then query and analyze these logs for a detailed view of your IPsec-VPN traffic.
For an IPsec-VPN connection associated with a VPN Gateway instance, you can use the VPC Flow Log feature to record inbound and outbound traffic. For a tutorial, see Query and analyze traffic transmitted over a VPN Gateway instance by using ENI flow logs.
For a VPN Connection, you can use the Transit Router flow log feature to record inbound and outbound traffic of the VPN Connection. For a tutorial, see Query top traffic across regions by using flow logs.
Related documents
You can call CloudMonitor API operations to query monitoring data for IPsec-VPN resources.
For information about the API operations provided by CloudMonitor, see Cloud service monitoring.
For information about the required parameters such as Namespace, MetricName, Dimensions, and Period when calling API operations, see Appendix 1: Cloud service metrics.


