An IPsec-VPN connection in dual-tunnel mode uses an active and a standby tunnel to provide high availability. If the active tunnel fails, traffic automatically fails over to the standby tunnel. This topic describes how to upgrade an IPsec-VPN connection to dual-tunnel mode.
Background
Before upgrading, we recommend that you first understand Description of dual-tunnel mode.
Only existing Standard VPN Gateways in single-tunnel mode can be upgraded to dual-tunnel mode. Enhanced VPN Gateways are all in dual-tunnel mode by default.
Bandwidth changes after the upgrade
For single-tunnel VPN gateway instances with a bandwidth of 100 Mbps or less:
IPsec-VPN tunnel mode
Outbound peak bandwidth
Inbound peak bandwidth
Before upgrade
The bandwidth of the VPN gateway instance.
100 Mbps.
After upgrade
The bandwidth of the VPN gateway instance.
The bandwidth of the VPN gateway instance.
For single-tunnel VPN gateway instances with a bandwidth greater than 100 Mbps, the peak bandwidth is unchanged after the upgrade and matches the instance's bandwidth.
Supported regions and zones
VPN Gateways in the following regions and zones support upgrading to dual-tunnel mode.
You can also call the DescribeVpnGatewayAvailableZones API operation to query the zones supported in a specified region. If the results returned by the API are inconsistent with the following table, the API results shall prevail.
Region | Zones that support associating VPN gateways |
China (Hangzhou) | K, J, I, H, G |
China (Shanghai) | L, M, N, A, B, E, F, G |
China (Nanjing) Local Region (Being deprecated) | A |
China (Shenzhen) | A (no longer available for purchase), C, E, D, F |
China (Heyuan) | A, B |
China (Guangzhou) | A, B |
China (Qingdao) | B, C |
China (Beijing) | F, E, H, G, A, C, J, I, L, K |
China (Zhangjiakou) | A, B, C |
China (Hohhot) | A, B |
China (Ulanqab) | A, B, C |
China (Chengdu) | A, B |
China (Zhongwei) | A, B |
China (Hong Kong) | B, C, D |
Singapore | A, B, C |
Thailand (Bangkok) | A, B |
Japan (Tokyo) | A, B, C |
South Korea (Seoul) | A, B |
Philippines (Manila) | A, B |
Indonesia (Jakarta) | A, B, C |
Malaysia (Kuala Lumpur) | A, B |
Malaysia (Johor) | A, B |
UK (London) | A, B |
Germany (Frankfurt) | A, B, C |
US (Silicon Valley) | A, B |
US (Virginia) | A, B |
US (Atlanta) This region is currently not available. If you need to use it, contact your account manager to apply. | A, B |
Mexico | A, B |
SAU (Riyadh - Partner Region) | A, B |
UAE (Dubai) | A, B |
Prerequisites
Before you upgrade an IPsec-VPN connection to dual-tunnel mode, make sure that the following requirements are met:
Upgrade impact
The VPN gateway is unavailable during the upgrade, which interrupts existing connections. We recommend performing the upgrade during a maintenance window to avoid service disruptions.
The upgrade takes about 10 minutes, during which the VPN gateway instance cannot forward traffic.
You cannot perform operations on the VPN gateway instance during the upgrade.
Procedure
- Log on to the VPN gateway console.
In the top navigation bar, select the region where the VPN gateway instance resides.
On the VPN Gateways page, find the target VPN gateway instance and click the instance ID.
In the upper-right corner of the instance details page, click Enable Zone Redundancy.
In the Enable Zone Redundancy dialog box, specify the vSwitch instance, then enable the upgrade environment check. After ensuring that the environment meets the upgrade requirements and understanding the upgrade risks, click Enable.
If the precheck fails, troubleshoot the issue based on the prerequisites. For more information, see Prerequisites.
After clicking Enable, the system will start the upgrade directly. Please wait patiently.
Next steps
After the VPN gateway instance is upgraded:
If only the IPsec-VPN feature was retained before the upgrade, you must enable the standby tunnel:
After the upgrade, the VPN gateway instance will have two IPsec addresses: one is the original address (IPsec address 1), and the other is the address newly allocated by the system (IPsec address 2), which are used to establish the active tunnel and the standby tunnel respectively. These two addresses are displayed in the IP address column of the instance list, and by default both tunnels are associated with the same customer gateway.
The active tunnel is the tunnel that existed before the upgrade, and its configuration remains unchanged; the standby tunnel is unavailable by default. On the Tunnel tab of the IPsec connection details page, Tunnel 1 (Primary) shows Phase 2 negotiations succeeded., and Tunnel 1 (Backup) shows Phase 1 negotiations failed..
You need to add the relevant configuration on the peer gateway device to connect the standby tunnel and ensure that its status is displayed as successful. For more information, see Standard VPN Gateway quick start.
If the SSL-VPN feature was retained before the upgrade, then after the upgrade:
The SSL-VPN configuration remains unchanged. You can enable the IPsec-VPN feature in the Feature Configuration column of the VPN gateway instance, and then start creating an IPsec-VPN connection in dual-tunnel mode. For more information, see IPsec connections (VPN gateway).
The VPN gateway IP address will become an SSL address, which can be used only for the SSL-VPN feature. After you enable the IPsec-VPN feature, the system reallocates two IPsec addresses to the VPN gateway instance to establish an IPsec-VPN connection in dual-tunnel mode. In the VPN gateway instance list, you can view the SSL address field to confirm that the SSL-VPN connection address is retained.
If the VPC associated with the VPN gateway instance is connected to Cloud Enterprise Network:
If a custom route entry that points to the VPN gateway instance exists in the route table of the VPC, and the route entry has been advertised to Cloud Enterprise Network, then after the upgrade is complete, the route entry becomes unadvertised. You need to advertise the route entry to Cloud Enterprise Network again. For more information, see Advertise routes to a transit router.
When using an IPsec-VPN connection in dual-tunnel mode, ensure that both the active and standby tunnels are available. If you configure or use only one of the tunnels, the IPsec-VPN connection cannot provide active-standby redundancy or zone-level disaster recovery.