All Products
Search
Document Center

VPN Gateway:Resize (Standard VPNGW only)

Last Updated:May 27, 2026
Important

This topic applies only to VPN Gateway (Subscription). It does not cover Enhanced VPN gateways (an enhanced VPN gateway provides a default bandwidth of 1 Gbps for each IPsec connection and does not support SSL-VPN).

You can change VPN Gateway (Subscription) specifications in several ways: upgrade or downgrade the bandwidth and features.

Choose a specification change method

Select a method based on your requirements.

Requirement

Method

Effective time

Supports downgrade

Immediately increase bandwidth or enable a feature

Upgrade

Takes effect immediately

No

Immediately decrease bandwidth or disable a feature

Downgrade

Takes effect immediately

Yes

Important

Bandwidth specification change limits (single-tunnel mode)

These limits apply only to single-tunnel mode. Dual-tunnel mode has no bandwidth change limits.

  • If the bandwidth is 200 Mbps or less, you cannot upgrade to 500 Mbps or 1,000 Mbps.

  • If the bandwidth is 500 Mbps, you can only upgrade to 1,000 Mbps. Downgrades are not supported.

  • If the bandwidth is 1,000 Mbps, you can only downgrade to 500 Mbps.

Upgrade

Upgrading immediately increases specifications without service interruption.

What you can upgrade:

Increase the bandwidth specification of the VPN Gateway instance.

To enable or disable the IPsec-VPN or SSL-VPN feature, see Enable the IPsec-VPN feature, Enable the SSL-VPN feature, and Modify the SSL connection limit.

Usage notes

  • Single-tunnel mode instances have bandwidth upgrade limits. See the bandwidth change limits above.

  • The upgrade takes effect immediately but may take a few minutes to propagate.

Billing

After you submit a specification change order, you are billed at the new rate. Billing.

Procedure

  1. In the Bandwidth column of the target VPN Gateway instance, click Upgrade.

  2. On the page that opens, adjust the Maximum Bandwidth of the VPN Gateway instance.

Downgrade

Downgrading immediately decreases instance specifications.

What you can downgrade:

  • Decrease the bandwidth specification

  • Disable the IPsec-VPN or SSL-VPN feature

  • Decrease the SSL connection limit

Usage notes

  • Before you disable IPsec-VPN, delete all IPsec connections from the instance. IPsec connection (attached to a VPN gateway).

  • Before you disable the SSL-VPN feature, you must delete all SSL servers and IPsec servers from the VPN Gateway instance. For more information, see Delete an SSL server and Delete an IPsec-VPN server.

  • Single-tunnel mode instances have bandwidth downgrade limits. See the bandwidth change limits above.

  • When you downgrade bandwidth, traffic exceeding the new limit may cause interruptions. Ensure your application has a reconnection mechanism.

  • When you decrease the SSL connection limit, interruptions may occur if connected clients exceed the new limit. Ensure your application has a reconnection mechanism.

  • The downgrade takes effect immediately but may take a few minutes to propagate.

Billing

After you submit a downgrade order, you are billed at the new rate. Billing.

Procedure

  1. In the Bandwidth column of the target VPN Gateway instance, click Downgrade.

  2. On the page that opens, decrease the Maximum Bandwidth, disable the IPsec-VPN or SSL-VPN feature, or decrease the SSL-VPN Connections for the instance as required.