This topic summarizes frequently asked questions (FAQs) about VPN Gateway.
Quick links
Product inquiries
-
Can VPCs in different regions communicate through a VPN Gateway?
-
Can ECS instances in other zones of a VPC forward traffic through a VPN Gateway instance?
-
Can a VPN Gateway encrypt traffic between a VPC and a public IP address?
IPsec-VPN features
-
How many IPsec-VPN connections can I create for each VPN Gateway?
-
Can I configure multiple remote networks in one IPsec-VPN connection?
-
Single-tunnel vs. dual-tunnel mode
SSL-VPN features
What are non-cross-border and cross-border connections?
Alibaba Cloud VPN Gateway provides services in compliance with the relevant policies and regulations in China. It supports only non-cross-border connections and does not support cross-border connections. If you need to access cross-border resources through a VPN connection, see How to access cross-border resources through a VPN connection?.
Non-cross-border connections
-
An IPsec-VPN connection is considered non-cross-border if the regions of the on-premises data center and the peer resources meet one of the following conditions:
-
The on-premises data center is located in the Chinese mainlandregion, and the peer resources are in an Alibaba Cloud region in the Chinese mainland.
-
The on-premises data center is located outside the Chinese mainland, and the peer resources are in an Alibaba Cloud region outside the Chinese mainland.
-
-
An SSL-VPN connection is considered non-cross-border if the regions of the client and the peer resources meet one of the following conditions:
-
The client is located in the Chinese mainland, and the peer resources are in an Alibaba Cloud region in the Chinese mainland.
-
The client is located outside the Chinese mainland, and the peer resources are in an Alibaba Cloud region outside the Chinese mainland.
-
|
Example 1 |
Example 2 |
|
|
|
Cross-border connections
-
An IPsec-VPN connection is considered cross-border if the regions of the on-premises data center and the peer resources meet one of the following conditions:
-
The on-premises data center is located in the Chinese mainland, and the peer resources are in an Alibaba Cloud region outside the Chinese mainland.
-
The on-premises data center is located outside the Chinese mainland, and the peer resources are in an Alibaba Cloud region in the Chinese mainland.
-
-
An SSL-VPN connection is considered cross-border if the regions of the client and the peer resources meet one of the following conditions:
-
The client is located in the Chinese mainland, and the peer resources are in an Alibaba Cloud region outside the Chinese mainland.
-
The client is located outside the Chinese mainland, and the peer resources are in an Alibaba Cloud region in the Chinese mainland.
-
|
Example 1 |
Example 2 |
|
|
|
Region classification
Region classification | Included regions |
The Chinese mainland | China (Qingdao), China (Beijing), China (Zhangjiakou), China (Hohhot), China (Ulanqab), China (Shenzhen), China (Heyuan), China (Guangzhou), China (Hangzhou), China (Shanghai), China (Nanjing - Local Region), China (Chengdu) |
Outside the Chinese mainland | China (Hong Kong), Singapore, Malaysia (Kuala Lumpur), Japan (Tokyo), Indonesia (Jakarta), Philippines (Manila), South Korea (Seoul), Thailand (Bangkok), Germany (Frankfurt), UK (London), UAE (Dubai), US (Silicon Valley), US (Virginia), SAU (Riyadh - Partner Region)), Mexico |
How do I access cross-border resources over a VPN connection?
To access cross-border resources over a VPN connection, use a Transit Router. A TR enables flexible, private network communication between resources across regions, including cross-border ones.
Sample network topologies:
|
IPsec-VPN |
SSL-VPN |
|
|
|
Can I use a VPN Gateway to access the internet?
No.
A VPN Gateway provides private network access to a VPC. It does not provide internet access.
IPsec-VPN connection prerequisites
-
The gateway device in the data center must support the IKEv1 and IKEv2 protocols.
IPsec-VPN supports the IKEv1 and IKEv2 protocols. Any device that supports either protocol can connect to an Alibaba Cloud VPN Gateway. For more information about how to select an IKE version, see Selecting an IKE version.
-
The gateway device in the data center must be assigned a static public IP address.
-
The CIDR blocks of the data center and the VPC must not overlap.
For information about how a data center can connect to a VPC by using an IPsec-VPN connection, see Get started with a legacy VPN gateway.
Compatible on-premises gateways
An Alibaba Cloud VPN Gateway supports the standard IKEv1 and IKEv2 protocols. Therefore, any device that supports these protocols can connect to an Alibaba Cloud VPN Gateway. Examples include devices from H3C, Hillstone, Sangfor, Cisco ASA, Juniper, SonicWall, Nokia, IBM, and Ixia. For more information, see Customer gateway configuration examples.
Can VPCs in different regions communicate through a VPN Gateway?
Yes.
For more information, see Establish a VPC-to-VPC IPsec-VPN connection in dual-tunnel mode.
If you establish an IPsec-VPN connection between VPCs in different regions, the connection quality depends on public network conditions. We recommend that you use Cloud Enterprise Network (CEN) to establish connections between VPCs in different regions. For more information, see Enable communication between VPCs that belong to different accounts.
Does traffic between VPCs travel over the internet?
When you use a VPN Gateway to enable communication between VPCs:
-
If the two VPCs are in the same region, traffic is transmitted over the Alibaba Cloud network, not the internet.
-
If the two VPCs are in different regions, traffic is transmitted over the internet.
IPsec server vs. SSL server
Item | IPsec server | SSL server |
Use scenario | Provides end-to-site connections. | Provides end-to-site connections. |
Client mode | Allows mobile clients that run iOS to establish IPsec-VPN connections to Alibaba Cloud. | Allows mobile clients that run Android and computers to establish SSL-VPN connections to Alibaba Cloud. |
Connection mode | Allows mobile clients that run iOS to establish IPsec-VPN connections to Alibaba Cloud by using the built-in VPN feature. | Allows mobile clients that run Android and computers to establish SSL-VPN connections to Alibaba Cloud by using OpenVPN. |
Encryption methods | IPsec | SSL certificates |
Can I configure multiple remote networks in one IPsec-VPN connection?
Yes.
Before you configure multiple remote networks for an IPsec-VPN connection, we recommend that you review the configuration suggestions for multiple CIDR blocks. For more information, see Configuration suggestions for multi-CIDR block scenarios.
How many IPsec-VPN connections can I create for each VPN Gateway?
By default, you can create up to 10 IPsec-VPN connections for each VPN Gateway. You can adjust the quota on the Alibaba Cloud console. For more information, see Manage IPsec-VPN quotas.
How to configure network ACLs
|
VPN Gateway type |
Required rules |
|
IPsec-VPN |
In the network ACL, configure outbound and inbound rules to allow traffic from the following CIDR blocks and IP addresses. This ensures that the VPN Gateway can establish IPsec-VPN connections.
|
|
SSL-VPN |
In the network ACL, configure outbound and inbound rules to allow traffic from the following CIDR blocks and IP addresses, and open the SSL-VPN port. This ensures that the VPN Gateway can establish SSL-VPN connections.
|
Can I upgrade or downgrade a VPN Gateway?
Yes.
-
To upgrade or downgrade the bandwidth of your VPN Gateway, see Upgrade or downgrade a VPN gateway.
-
To upgrade or downgrade the maximum number of concurrent SSL connections for your VPN Gateway, see Modify the maximum number of concurrent SSL connections.
-
To enable the IPsec-VPN or SSL-VPN feature for your VPN Gateway, see Enable IPsec-VPN and Enable the SSL-VPN feature.
Viewing SSL client connection information
Yes.
For more information, see View SSL client connection information.
-
VPN Gateway instances created after December 10, 2022 support this feature by default.
-
By default, VPN Gateway instances created before December 10, 2022 do not support viewing SSL client connection information. To enable this, upgrade the VPN Gateway instance.
SSL-VPN on legacy instances
No.
To use the SSL-VPN feature, you must upgrade the VPN Gateway to the latest version. For more information, see Upgrade a VPN gateway.
Selecting an IKE version
When you configure an IPsec-VPN connection, select an IKE version based on the IKE version the peer gateway device supports and whether you need to communicate across multiple CIDR blocks.
Communication among multiple CIDR blocks means that you configure multiple Local Network or Remote Network CIDR blocks for an IPsec-VPN connection.
|
Peer device IKE support |
Multi-CIDR communication |
Configuration |
|
Only IKEv1 |
Yes |
|
|
No |
Use IKEv1 for both the IPsec-VPN connection and the peer gateway device. |
|
|
Only IKEv2 |
Yes |
|
|
No |
Use IKEv2 for both the IPsec-VPN connection and the peer gateway device. |
|
|
Both IKEv1 and IKEv2 |
Yes |
|
|
No |
We recommend that you use IKEv2 for both the IPsec-VPN connection and the peer gateway device. Compared with IKEv1, IKEv2 simplifies the Security Association (SA) negotiation process and provides better support for scenarios with multiple CIDR blocks. We recommend that you use IKEv2. |
IPsec-VPN connections with NAT
For example, a data center plans to use the IP address 42.XX.XX.1 to establish an IPsec-VPN connection with an Alibaba Cloud VPN Gateway. However, the data center uses SNAT, which translates the source IP address from 42.XX.XX.1 to 47.XX.XX.21. In this case, when you create a customer gateway on the VPN Gateway console, you must set the IP address of the customer gateway to 47.XX.XX.21. This allows the Alibaba Cloud VPN Gateway to establish an IPsec-VPN connection with the data center.
We recommend that you use the default IPsec ports (UDP 500 and 4500) to establish the IPsec-VPN connection between your data center and the VPN Gateway. We do not recommend that you translate the port numbers.
On the Alibaba Cloud side, if the VPC to which a public-facing VPN Gateway is associated also has a NAT Gateway configured, the NAT Gateway does not translate the IP address of the public-facing VPN Gateway instance.
Increasing IPsec-VPN bandwidth
When an IPsec-VPN connection is associated with a VPN Gateway instance, the maximum bandwidth of the instance is 1,000 Mbit/s (500 Mbit/s in some regions). To increase the bandwidth of the IPsec-VPN connection, we recommend that you associate the IPsec-VPN connection with a Transit Router instance to connect your data center to Alibaba Cloud. You can then use the TR to enable network communication between your data center and VPCs.
When an IPsec-VPN connection is associated with a TR instance, the maximum bandwidth of a single IPsec-VPN connection is 1,000 Mbit/s. To increase the total bandwidth, you can establish multiple IPsec-VPN connections between the TR and the data center. This allows traffic between the data center and Alibaba Cloud to be transmitted over multiple IPsec-VPN connections simultaneously, as shown in the following figures. For more information, see Create multiple public IPsec-VPN connections for load balancing and Create multiple private IPsec-VPN connections to achieve load balancing for private network traffic.
-
Public IPsec-VPN connection scenario:

-
Private IPsec-VPN connection scenario:

Forwarding traffic across zones
Yes.
When you create a VPN Gateway instance, you must specify a vSwitch. The system deploys the VPN Gateway in the zone where the specified vSwitch resides. After the VPN Gateway instance is created, it can forward traffic for ECS instances in all zones of the VPC.
Depending on your setup, you may need to add routes to enable the VPN Gateway instance to forward traffic from ECS instances. For example, if the vSwitches in some zones are associated with a custom route table of the VPC, you must add a custom route that points to the VPN Gateway instance to that custom route table.
Resolving route conflicts
If an error is reported when you add a route to a VPN Gateway instance, this error usually occurs for one of the following reasons:
-
The destination CIDR block of the route you want to add is the same as the destination CIDR block of an existing route in the VPC. Check the routes in the route table of the VPC to resolve the route conflict.
-
The route you want to add conflicts with an existing route of the VPN Gateway instance. Check the policy-based routes and destination-based routes of the VPN Gateway instance to resolve the route conflict.
-
If you add a destination-based route whose destination CIDR block and next hop are the same as those of an existing destination-based route of the VPN Gateway instance, a route conflict occurs.
-
If you add a policy-based route whose source CIDR block, destination CIDR block, and next hop are the same as those of an existing policy-based route of the VPN Gateway instance, a route conflict occurs.
-
Why doesn't a VPN connection reach its purchased bandwidth?
While a VPN Gateway provides your purchased bandwidth, the following factors affect actual throughput:
-
The features, connection capacity, average packet size, and protocols (TCP and UDP) of the device that is associated with the customer gateway.
-
The network latency between the device that is associated with the customer gateway and the VPN Gateway.
NoteIf you purchase a public-facing VPN Gateway instance or use a public-facing IPsec-VPN connection, public bandwidth capacity and internet latency may affect your throughput.
If you need to test the bandwidth of the VPN Gateway, we recommend that you use the iPerf3 tool. The transfer rates of commands such as FTP, SCP, and CP do not reflect actual network throughput because they are limited by disk I/O speed. For more information about how to use the iPerf3 tool, see Use iPerf3 to test the bandwidth of an Express Connect circuit.
If you have high requirements for transmission quality, we recommend that you use Cloud Enterprise Network (CEN).
Can a VPN Gateway encrypt traffic between a VPC and a public IP address?
Yes.
To use a VPN Gateway to encrypt traffic from resources in a VPC to a public IP address, the following conditions must be met:
-
Add the CIDR block to which the public IP address belongs to the VPN Gateway:
-
If you use an IPsec-VPN connection, add the public CIDR block to the Remote Network of the IPsec-VPN connection.
-
If you use an SSL-VPN connection, add the public CIDR block to the Client CIDR Block of the SSL server.
-
-
Set the public CIDR block as a user-defined CIDR block for the VPC to ensure that the VPC can access the public CIDR block. For more information about user-defined CIDR blocks, see VPC FAQ and VPC FAQ.
Route entry quota exceeded
If you cannot add a new route entry or an IPsec-VPN connection cannot learn BGP routes because the route entry quota is exceeded, you can use one of the following methods to resolve the issue:
-
Increase the route entry quota.
You can request to increase the quotas for policy-based routes, destination-based routes, and BGP routes. For more information, see IPsec-VPN quotas.
-
Configure route summarization.
Without affecting your services, summarize multiple specific route entries into a single, more general route entry.
For example, if you have configured three destination-based routes with destination CIDR blocks 10.10.1.0/24, 10.10.2.0/24, and 10.10.3.0/24 that all point to the same IPsec-VPN connection (for example, IPsec connection 1), you can add a destination-based route with the destination CIDR block 10.10.0.0/22 that points to IPsec connection 1. Then, you can delete the three more specific routes to save destination-based route entries.
Finding top traffic sources
You can enable the VPC flow log feature to collect and analyze traffic from the Elastic Network Interface (ENI) of the VPN Gateway. For more information, see Query and analyze traffic transmitted by VPN Gateway instances by using ENI flow logs.
What type of public IP address does a VPN Gateway use?
A VPN Gateway uses a BGP (Multi-ISP) public IP address. This type of IP address is connected to the lines of multiple internet service providers (ISPs). The system automatically selects the optimal path to provide a fast and stable access experience.
Single-tunnel vs. dual-tunnel mode
IPsec-VPN connections for newly purchased VPN Gateway instances use dual-tunnel mode by default. For existing VPN Gateway instances, connections are created in single-tunnel mode by default. We recommend that you upgrade your IPsec-VPN connections to dual-tunnel mode to achieve higher availability. The upgrade does not change the billing method or incur additional fees.
|
Item |
Single-tunnel mode |
Dual-tunnel mode |
|
Number of tunnels per IPsec-VPN connection |
One |
Two |
|
Number of associated vSwitches |
You need to specify only one vSwitch when you create a VPN Gateway instance. |
You must specify two vSwitches that are deployed in different zones when you create a VPN Gateway instance. |
|
High availability |
To ensure high availability, you must create multiple IPsec-VPN connections for the VPN Gateway instance or create multiple VPN Gateway instances. |
High availability is achieved through the two tunnels of a single IPsec-VPN connection. |
|
Route weights |
Supported |
Not supported |
|
Health check |
Supported |
Not supported |
|
IP address of the VPN Gateway |
After you create a VPN Gateway instance, the system assigns only one IP address to the instance. The VPN Gateway uses this IP address to establish an IPsec-VPN or SSL-VPN connection. |
After you create a VPN Gateway instance, the system can assign up to three IP addresses if you enable both the IPsec-VPN and SSL-VPN features. The IPsec-VPN connection uses two IP addresses to establish two encrypted tunnels, and the SSL-VPN connection uses one IP address. The three IP addresses are different. |
Controlling public IP access
VPN Gateway does not provide a built-in feature to configure a source IP allowlist. The access control mechanism works as follows for IPsec-VPN and SSL-VPN connections:
-
IPsec-VPN: When you create an IPsec-VPN connection, you must specify the public IP address of the customer gateway on the Alibaba Cloud side. The VPN Gateway accepts IKE/IPsec negotiation requests only from that specific customer gateway IP address. Requests from other IP addresses cannot establish an IPsec tunnel, eliminating the need for additional source IP access control.
-
SSL-VPN: SSL-VPN connections do not restrict the source IP address of clients. Access control relies on client certificate validation. For enhanced security, you can implement two-factor authentication by using IDaaS.
To filter traffic by source IP address for the VPN Gateway's subnet, use the network ACL feature of the VPC. On the VPC console, create a network ACL, set inbound rules to restrict source IP addresses, and then associate the network ACL with the vSwitch where the VPN Gateway is deployed. For more information, see How to configure network ACLs.