All Products
Search
Document Center

VPN Gateway:Upgrade VPN Gateway to dual-tunnel mode

Last Updated:Sep 10, 2026

An IPsec-VPN connection in dual-tunnel mode uses an active and a standby tunnel to provide high availability. If the active tunnel fails, traffic automatically fails over to the standby tunnel. This topic describes how to upgrade an IPsec-VPN connection to dual-tunnel mode.

Background

  • Before upgrading, we recommend that you first understand Description of dual-tunnel mode.

  • Only existing Standard VPN Gateways in single-tunnel mode can be upgraded to dual-tunnel mode. Enhanced VPN Gateways are all in dual-tunnel mode by default.

Bandwidth changes after the upgrade

  • For single-tunnel VPN gateway instances with a bandwidth of 100 Mbps or less:

    IPsec-VPN tunnel mode

    Outbound peak bandwidth

    Inbound peak bandwidth

    Before upgrade

    The bandwidth of the VPN gateway instance.

    100 Mbps.

    After upgrade

    The bandwidth of the VPN gateway instance.

    The bandwidth of the VPN gateway instance.

  • For single-tunnel VPN gateway instances with a bandwidth greater than 100 Mbps, the peak bandwidth is unchanged after the upgrade and matches the instance's bandwidth.

Supported regions and zones

VPN Gateways in the following regions and zones support upgrading to dual-tunnel mode.

You can also call the DescribeVpnGatewayAvailableZones API operation to query the zones supported in a specified region. If the results returned by the API are inconsistent with the following table, the API results shall prevail.

Region

Zones that support associating VPN gateways

China (Hangzhou)

K, J, I, H, G

China (Shanghai)

L, M, N, A, B, E, F, G

China (Nanjing) Local Region (Being deprecated)

A

China (Shenzhen)

A (no longer available for purchase), C, E, D, F

China (Heyuan)

A, B

China (Guangzhou)

A, B

China (Qingdao)

B, C

China (Beijing)

F, E, H, G, A, C, J, I, L, K

China (Zhangjiakou)

A, B, C

China (Hohhot)

A, B

China (Ulanqab)

A, B, C

China (Chengdu)

A, B

China (Zhongwei)

A, B

China (Hong Kong)

B, C, D

Singapore

A, B, C

Thailand (Bangkok)

A, B

Japan (Tokyo)

A, B, C

South Korea (Seoul)

A, B

Philippines (Manila)

A, B

Indonesia (Jakarta)

A, B, C

Malaysia (Kuala Lumpur)

A, B

Malaysia (Johor)

A, B

UK (London)

A, B

Germany (Frankfurt)

A, B, C

US (Silicon Valley)

A, B

US (Virginia)

A, B

US (Atlanta)

This region is currently not available. If you need to use it, contact your account manager to apply.

A, B

Mexico

A, B

SAU (Riyadh - Partner Region)

A, B

UAE (Dubai)

A, B

Prerequisites

Before you upgrade an IPsec-VPN connection to dual-tunnel mode, make sure that the following requirements are met:

  • The AliyunServiceRoleForVpn service-linked role must be created for your Alibaba Cloud account.

    During the upgrade, the system needs to assume the AliyunServiceRoleForVpn service-linked role to deploy VPN Gateway resources. On the VPN Gateway purchase page, verify that the AliyunServiceRoleForVpn service-linked role is created for your Alibaba Cloud account:

    • If the status is Created, the role exists and no further action is required.

    • If Create Service-linked Role is displayed, click Create Service-linked Role. The system automatically creates the AliyunServiceRoleForVpn service-linked role. For more information, see AliyunServiceRoleForVpn.

  • The VPN gateway instance must not have both the IPsec-VPN and SSL-VPN features enabled at the same time.

    If the IPsec-VPN and SSL-VPN features are enabled for the VPN gateway instance at the same time, you can downgrade the instance to disable the IPsec-VPN or SSL-VPN feature. For more information, see Downgrade.

    Before you disable a feature, make sure that no IPsec-VPN connections or SSL servers exist on the VPN gateway instance. For more information, see Delete an IPsec-VPN connection or Delete an SSL server.

  • The policy-based or destination-based route table of the VPN gateway instance does not contain conflicting routes that point to different IPsec-VPN connections.

    The following table describes scenarios and provides solutions.

    Route table

    Source CIDR block

    Destination CIDR block

    Next hop

    Upgradable

    Solution

    Policy-based route table

    10.10.10.0/24

    172.16.10.0/24

    IPsec-VPN connection 1

    No

    The policy-based route table contains two routes that have the same source and destination CIDR blocks but point to different IPsec-VPN connections.

    Delete one of the routes, or modify the source or destination CIDR block of one of the routes. For more information, see Configure policy-based routes.

    10.10.10.0/24

    172.16.10.0/24

    IPsec-VPN connection 2

    Destination-based route table

    Not applicable

    192.168.10.0/24

    IPsec-VPN connection 3

    No

    The destination-based route table contains two routes that have the same destination CIDR block but point to different IPsec-VPN connections.

    Delete one of the routes, or modify the destination CIDR block of one of the routes. For more information, see Configure routes for a VPN gateway.

    Not applicable

    192.168.10.0/24

    IPsec-VPN connection 4

  • The route table of the VPC associated with the VPN gateway instance must not contain a route whose destination CIDR block is a subnet of the Client CIDR Block of the SSL server or a subnet of the Client CIDR Block of the IPsec server, and whose next hop is the VPN gateway instance.

    For example, the Client CIDR Block of an SSL server is 192.168.10.0/24. In this case, the route table of the VPC that is associated with the VPN gateway cannot contain a route whose destination CIDR block is a subnet such as 192.168.10.0/25 or 192.168.10.0/26 and whose next hop is the VPN gateway instance.

    You can manage custom routes in the route table of the VPC. For more information, see Create and manage a route table.

  • If multiple IPsec-VPN connections with BGP are created on the VPN gateway instance, their BGP tunnel CIDR blocks must be unique.

    You can modify the CIDR block of a BGP tunnel. For more information, see Modify an IPsec-VPN connection.

  • You must select two VSwitches from the VPC that is associated with the VPN gateway instance and ensure the VSwitches have enough available IP addresses.

    • The zones to which the VSwitches belong must support dual-tunnel mode for IPsec-VPN connections. For information about the supported zones, see Supported regions and zones.

    • If multiple zones in the current region support dual-tunnel mode for IPsec-VPN connections, the two VSwitches that you select must belong to different zones to implement zone-level disaster recovery for the IPsec-VPN connection. Each VSwitch must have at least two available IP addresses.

    • If only one zone in the current region supports dual-tunnel mode for IPsec-VPN connections, you must select two VSwitches from this zone:

      • If you select the same VSwitch, make sure that the VSwitch has at least four available IP addresses.

      • If you select two different VSwitches, make sure that each VSwitch has at least two available IP addresses.

Upgrade impact

Warning

The VPN gateway is unavailable during the upgrade, which interrupts existing connections. We recommend performing the upgrade during a maintenance window to avoid service disruptions.

  • The upgrade takes about 10 minutes, during which the VPN gateway instance cannot forward traffic.

  • You cannot perform operations on the VPN gateway instance during the upgrade.

Procedure

  1. Log on to the VPN gateway console.
  2. In the top navigation bar, select the region where the VPN gateway instance resides.

  3. On the VPN Gateways page, find the target VPN gateway instance and click the instance ID.

  4. In the upper-right corner of the instance details page, click Enable Zone Redundancy.

  5. In the Enable Zone Redundancy dialog box, specify the vSwitch instance, then enable the upgrade environment check. After ensuring that the environment meets the upgrade requirements and understanding the upgrade risks, click Enable.

    • If the precheck fails, troubleshoot the issue based on the prerequisites. For more information, see Prerequisites.

    • After clicking Enable, the system will start the upgrade directly. Please wait patiently.

Next steps

After the VPN gateway instance is upgraded:

  • If only the IPsec-VPN feature was retained before the upgrade, you must enable the standby tunnel:

    • After the upgrade, the VPN gateway instance will have two IPsec addresses: one is the original address (IPsec address 1), and the other is the address newly allocated by the system (IPsec address 2), which are used to establish the active tunnel and the standby tunnel respectively. These two addresses are displayed in the IP address column of the instance list, and by default both tunnels are associated with the same customer gateway.

    • The active tunnel is the tunnel that existed before the upgrade, and its configuration remains unchanged; the standby tunnel is unavailable by default. On the Tunnel tab of the IPsec connection details page, Tunnel 1 (Primary) shows Phase 2 negotiations succeeded., and Tunnel 1 (Backup) shows Phase 1 negotiations failed..

    • You need to add the relevant configuration on the peer gateway device to connect the standby tunnel and ensure that its status is displayed as successful. For more information, see Standard VPN Gateway quick start.

  • If the SSL-VPN feature was retained before the upgrade, then after the upgrade:

    • The SSL-VPN configuration remains unchanged. You can enable the IPsec-VPN feature in the Feature Configuration column of the VPN gateway instance, and then start creating an IPsec-VPN connection in dual-tunnel mode. For more information, see IPsec connections (VPN gateway).

    • The VPN gateway IP address will become an SSL address, which can be used only for the SSL-VPN feature. After you enable the IPsec-VPN feature, the system reallocates two IPsec addresses to the VPN gateway instance to establish an IPsec-VPN connection in dual-tunnel mode. In the VPN gateway instance list, you can view the SSL address field to confirm that the SSL-VPN connection address is retained.

  • If the VPC associated with the VPN gateway instance is connected to Cloud Enterprise Network:

    • If a custom route entry that points to the VPN gateway instance exists in the route table of the VPC, and the route entry has been advertised to Cloud Enterprise Network, then after the upgrade is complete, the route entry becomes unadvertised. You need to advertise the route entry to Cloud Enterprise Network again. For more information, see Advertise routes to a transit router.

Important

When using an IPsec-VPN connection in dual-tunnel mode, ensure that both the active and standby tunnels are available. If you configure or use only one of the tunnels, the IPsec-VPN connection cannot provide active-standby redundancy or zone-level disaster recovery.