All Products
Search
Document Center

VPN Gateway:Monitor an IPsec-VPN connection

Last Updated:Jun 21, 2026

Monitoring is key to maintaining the reliability, availability, and performance of your ipsec-vpn connection. By monitoring metrics like the tunnel negotiation status and traffic rates, you get a clear overview of your connection's running status and bandwidth usage. This helps you quickly identify network bandwidth bottlenecks, detect faults or anomalies, and improve overall network reliability and availability. VPN Gateway is integrated with Cloud Monitor, so you can centrally monitor and manage all your Alibaba Cloud resources from the Cloud Monitor console.

Monitor IPsec-VPN tunnel status

VPN Gateway lets you monitor tunnel status changes. You can view the current status of tunnels on the VPN Gateway console. You can also subscribe to system events or create threshold-triggered alert rules for metrics to be promptly notified of tunnel status changes.

  • View the status of IPsec-VPN connection tunnels

    Click to view the procedure

    Log on to the VPN Gateway console and select the region where the IPsec connection is deployed. In the left-side navigation pane, choose IPsec Connections:

    • IPsec-VPN connection in dual-tunnel mode

      On the IPsec-VPN connection page, click the ID of an IPsec connection to go to its details page. On the Tunnel tab, check the negotiation status of the active/standby tunnels in the Connection Status column. The list of tunnels on this tab includes information such as Tunnel role (active/standby), Gateway IP, Pre-shared key, Tunnel CIDR block, Local BGP address, Connection status, Customer gateway, and Status. If the Connection status for both tunnels is Phase 1 negotiation failed, a VPN negotiation issue has occurred and requires further troubleshooting. You can click View Details to understand the cause of the negotiation failure or click View Logs to view the tunnel logs.

    • IPsec-VPN connection in single-tunnel mode

      On the IPsec-VPN connection page, find the target IPsec connection and check the Connection Status column. If the status is indicated by a green dot and shows Phase 2 negotiation succeeded, the IPsec-VPN tunnel negotiation is successful.

    Note

    If the status of an IPsec-VPN connection or tunnel is abnormal, you can troubleshoot the issue based on the error code displayed on the console.

  • VPN Gateway system events

System events are predefined by VPN Gateway to record and report changes in tunnel negotiation and health check status. You can go to the CloudMonitor console to view system events generated by VPN Gateway and subscribe to system events. This allows you to stay informed of resource status changes and respond promptly.

Click to view the system events supported by VPN Gateway

Important

A system event is generated only when the status of a resource changes.

For example, after you configure a health check for an IPsec connection, its initial health check status is failed. By default, the system does not generate a health check failed system event. The system generates a health check success or health check failed system event only when the health check status changes from failed to success or from success to failed. After you subscribe to system events, the system sends you alert notifications for these events.

Resource

Event name

Event description

Description

Event type

Event level

IPsec-VPN connection in dual-tunnel mode

ipsec_tunnel_nego_success

IPsec tunnel negotiation succeeded

Indicates that a tunnel for an IPsec-VPN connection in dual-tunnel mode has successfully negotiated.

Status Notification

Info

ipsec_tunnel_nego_failed

IPsec tunnel negotiation failed

Indicates that a tunnel for an IPsec-VPN connection in dual-tunnel mode failed to negotiate.

Status Notification

Warning

ipsec_vco_tunnel_all_nego_failed

All IPsec connection tunnels failed to be negotiated

Indicates that both tunnels for an IPsec-VPN connection in dual-tunnel mode failed to negotiate.

Status Notification

Warning

IPsec-VPN connection in single-tunnel mode

ipsec_phase1_nego_failed

IPsec phase 1 negotiation failed

Indicates that phase 1 negotiation for an IPsec connection on a VPN Gateway has failed.

Status Notification

Warning

ipsec_phase1_nego_success

IPsec phase 1 negotiation succeeded

Indicates that phase 1 negotiation for an IPsec connection on a VPN Gateway was successful.

Status Notification

Info

ipsec_phase2_nego_failed

IPsec phase 2 negotiation failed

Indicates that phase 2 negotiation for an IPsec connection on a VPN Gateway has failed.

Status Notification

Warning

ipsec_phase2_nego_success

IPsec phase 2 negotiation succeeded

Indicates that phase 2 negotiation for an IPsec connection on a VPN Gateway was successful.

Status Notification

Info

ipsec_health_check_failed

health check failed

Indicates that the health check for an IPsec connection on a VPN Gateway has failed.

Status Notification

Warning

ipsec_health_check_success

health check success

Indicates that the health check for an IPsec connection on a VPN Gateway was successful.

Status Notification

Info

vpn_connection_hc_failed

VPN connection health check failed

Indicates that the health check for an IPsec connection on a Transit Router has failed.

Status Notification

Warning

vpn_connection_hc_success

VPN connection health check succeeded

Indicates that the health check for an IPsec connection on a Transit Router was successful.

Status Notification

Info

vpn_connection_ph1_failed

VPN connection phase 1 negotiation failed

Indicates that phase 1 negotiation for an IPsec connection on a Transit Router has failed.

Status Notification

Warning

vpn_connection_ph1_success

VPN connection phase 1 negotiation succeeded

Indicates that phase 1 negotiation for an IPsec connection on a Transit Router was successful.

Status Notification

Info

vpn_connection_ph2_failed

VPN connection phase 2 negotiation failed

Indicates that phase 2 negotiation for an IPsec connection on a Transit Router has failed.

Status Notification

Warning

vpn_connection_ph2_success

VPN connection phase 2 negotiation succeeded

Indicates that phase 2 negotiation for an IPsec connection on a Transit Router was successful.

Status Notification

Info

SSL-VPN connection

CertKeyExpired

Certificate expired

The SSL client certificate has expired.

Exception

Critical

  • Metrics for IPsec-VPN connection tunnel status

    VPN Gateway provides metrics related to the tunnel status. You can create threshold-triggered alert rules for these metrics to be promptly notified of tunnel status changes.

    Click to view tunnel status metrics

    Resource

    Metric

    Metric description

    Description

    vpn (VPN Gateway)

    An IPsec-VPN connection on a VPN Gateway.

    ipsec.state

    The negotiation status of an IPsec connection on a VPN Gateway

    The negotiation status of an IPsec-VPN connection in single-tunnel mode. A value of 0 indicates that the negotiation was unsuccessful. A value of 1 indicates that the negotiation was successful.

    tun.state

    The negotiation status of a tunnel of an IPsec connection on a VPN Gateway

    The negotiation status of a tunnel of an IPsec-VPN connection in dual-tunnel mode. A value of 0 indicates that the tunnel negotiation was unsuccessful. A value of 1 indicates that the tunnel negotiation was successful.

    ipsec.bgp_state

    The BGP negotiation status of an IPsec connection on a VPN Gateway

    The BGP negotiation status of an IPsec connection on a single-tunnel mode VPN Gateway. A value of 0 indicates that the BGP negotiation was unsuccessful. A value of 1 indicates that the BGP negotiation was successful.

    tun.bgp_state

    The BGP negotiation status of an IPsec tunnel on a VPN Gateway

    The BGP negotiation status of an IPsec tunnel on a dual-tunnel mode VPN Gateway. A value of 0 indicates that the BGP negotiation was unsuccessful. A value of 1 indicates that the BGP negotiation was successful.

    vpnconnection (VPN connection)

    An IPsec-VPN connection on a Transit Router.

    vpn_connection.state

    The negotiation status of the IPsec connection.

    The negotiation status of a VPN connection in single-tunnel mode. A value of 0 indicates that the negotiation was unsuccessful. A value of 1 indicates that the negotiation was successful.

    vpn_connection_tun.state

    The negotiation status of a tunnel.

    The negotiation status for a tunnel in a dual-tunnel VPN connection. A value of 0 indicates that the tunnel negotiation was unsuccessful. A value of 1 indicates that the tunnel negotiation was successful.

    vpn_connection.bgp_state

    The BGP negotiation status of a VPN connection

    The BGP negotiation status of a VPN connection in single-tunnel mode. A value of 0 indicates that the BGP negotiation was unsuccessful. A value of 1 indicates that the BGP negotiation was successful.

    vpn_connection_tun.bgp_state

    The BGP negotiation status of an IPsec tunnel of a VPN connection

    The BGP negotiation status for an IPsec tunnel in a dual-tunnel VPN connection. A value of 0 indicates that the BGP negotiation was unsuccessful. A value of 1 indicates that the BGP negotiation was successful.

Monitor IPsec-VPN traffic rates

VPN Gateway lets you view inbound and outbound traffic rates, packet rates, and bandwidth utilization for VPN Gateway instances, IPsec-VPN connections, and tunnels. This helps you quickly identify network congestion or abnormal traffic and optimize bandwidth utilization.

  • View traffic rates of an IPsec-VPN connection

    The following sections explain how to view traffic rate data in the VPN Gateway console. You can also view IPsec-VPN traffic rate data in the CloudMonitor console. For more information, see Cloud service monitoring.

    View traffic rates for an IPsec-VPN connection and its tunnels

    Log on to the VPN Gateway console and select the region where the IPsec connection is deployed. In the left navigation bar, select IPsec Connections. On the IPsec-VPN connection page, click the IPsec connection instance ID. On the Monitor tab of the IPsec connection instance details page, view the traffic rate information.

    For an IPsec-VPN connection in dual-tunnel mode, you can select a Dimension to view the traffic rate of a specific tunnel.

    Dimension

    Metric

    Description

    IPsec connection

    IPsec connection inbound packet rate

    The rate at which the IPsec connection receives data packets. Unit: pps.

    IPsec connection outbound packet rate

    The rate at which the IPsec connection sends data packets. Unit: pps.

    IPsec connection inbound traffic rate

    The rate at which the IPsec connection receives traffic. Unit: bps.

    IPsec connection outbound traffic rate

    The rate at which the IPsec connection sends traffic. Unit: bps.

    Tunnel

    Tunnel inbound packet rate

    The rate at which the tunnel receives data packets. Unit: pps.

    Tunnel outbound packet rate

    The rate at which the tunnel sends data packets. Unit: pps.

    Tunnel inbound traffic rate

    The rate at which the tunnel receives traffic. Unit: bps.

    Tunnel outbound traffic rate

    The rate at which the tunnel sends traffic. Unit: bps.

    View the traffic rate for a VPN Gateway instance

    If a VPN Gateway instance manages multiple IPsec-VPN connections, you can view its aggregated traffic rate, which represents the total across all connections.

    Log on to the VPN Gateway console and select the region where the VPN Gateway instance is deployed. On the VPN Gateways page, click the ID of the instance to open its details page, then select the Monitor tab to view the traffic rate metrics.

    If the VPN Gateway instance also has SSL-VPN connections, their traffic is included in the metrics.

    Metric

    Description

    VPN Gateway inbound packet rate

    The rate at which the VPN Gateway instance receives data packets. Unit: pps.

    VPN Gateway outbound packet rate

    The rate at which the VPN Gateway instance sends data packets. Unit: pps.

    VPN Gateway inbound traffic rate

    The rate at which the VPN Gateway instance receives traffic. Unit: bps.

    VPN Gateway outbound traffic rate

    The rate at which the VPN Gateway instance sends traffic. Unit: bps.

    Number of SSL client connections

    The number of clients with active SSL-VPN connections to the VPN Gateway instance. Unit: count.

    Gateway.rx.utilization

    The percentage of inbound bandwidth used by the VPN Gateway instance.

    Gateway.tx.utilization

    The percentage of outbound bandwidth used by the VPN Gateway instance.

  • Create threshold-triggered alert rules for traffic rate metrics

    Create threshold-triggered alert rules for IPsec-VPN traffic rate metrics in the CloudMonitor console. When a traffic rate exceeds its configured threshold, CloudMonitor sends an alert, allowing you to promptly identify and resolve issues.

    Traffic rate metrics

    Product

    Monitored resource

    Metrics and descriptions

    VPN Gateway

    Use these metrics for IPsec connections associated with a VPN Gateway.

    VPN Gateway instance

    • Gateway.rx.utilization (in_bandwidth_utilization): The percentage of inbound bandwidth used by the VPN Gateway instance.

    • Gateway.tx.utilization (out_bandwidth_utilization): The percentage of outbound bandwidth used by the VPN Gateway instance.

    • VpnGateway.rxPkgs (net.rxPkgs): The rate at which the VPN Gateway instance receives data packets.

    • VpnGateway.txPkgs (net.txPkgs): The rate at which the VPN Gateway instance sends data packets.

    • SSL Client Count (ssl_client.count): The number of clients with active SSL-VPN connections to the VPN Gateway instance.

    • Gateway Inbound Bandwidth (net_rx.rate): The rate at which the VPN Gateway instance receives traffic.

    • Gateway Outbound Bandwidth (net_tx.rate): The rate at which the VPN Gateway instance sends traffic.

    IPsec-VPN connection

    • IPSec.connection.rxPkgs (ipsec.rxPkgs): The rate at which the IPsec connection receives data packets.

    • IPSec.connection.txpkgs (ipsec.txPkgs): The rate at which the IPsec connection sends data packets.

    • IPSec.connection.rx.rate (ipsec_rx.rate): The rate at which the IPsec connection receives traffic.

    • IPSec.connection.tx.rate (ipsec_tx.rate): The rate at which the IPsec connection sends traffic.

    • VPN gateway IPsec connection BGP negotiation status (ipsec.bgp_state): The BGP negotiation state of the connection. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    • IPSec.connection.state (ipsec.state): The negotiation state of the connection. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    Tunnel

    • Tunnel.rx.pps (tun.rx_pps): The rate at which the tunnel receives data packets.

    • Tunnel.tx.pps (tun.tx_pps): The rate at which the tunnel sends data packets.

    • Tunnel.rx.bps (tun.rx_bps): The rate at which the tunnel receives traffic.

    • Tunnel.tx.bps (tun.tx_bps): The rate at which the tunnel sends traffic.

    • BGP Negotiation Status of IPSec Tunnel in VPN Gateway (tun.bgp_state): The BGP negotiation state of the tunnel. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    • Tunnel.state (tun.state): The negotiation state of the tunnel. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    VPN connection

    Use these metrics for IPsec connections associated with a Transit Router.

    IPsec-VPN connection

    • vpn.connection.rxPkgs (vpn_connection.rxPkgs): The rate at which the VPN connection receives data packets.

    • vpn.connection.txPkgs (vpn_connection.txPkgs): The rate at which the VPN connection sends data packets.

    • vpn.connection.rx.rate (vpn_connection_rx.rate): The rate at which the VPN connection receives traffic.

    • vpn.connection.tx.rate (vpn_connection.tx.rate): The rate at which the VPN connection sends traffic.

    • BGP Negotiation Status of IPSec Connection in VPN Connection (vpn_connection.bgp_state): The BGP negotiation state of the connection. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    • vpn.connection.state (vpn_connection.state): The negotiation state of the connection. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    Tunnel

    • Single-tunnel Inbound Packet Rate of VPN Connection (vpn_connection_tun.rxPkgs): The rate at which the tunnel receives data packets.

    • Single-tunnel Outbound Packet Rate of VPN Connection (vpn_connection_tun.txPkgs): The rate at which the tunnel sends data packets.

    • Single-tunnel Inbound Bandwidth of VPN Connection (vpn_connection_tun.rx.rate): The rate at which the tunnel receives traffic.

    • Single-tunnel Outbound Bandwidth of VPN Connection (vpn_connection_tun.tx.rate): The rate at which the tunnel sends traffic.

    • BGP Negotiation Status of IPSec Tunnel in VPN Connection (vpn_connection_tun.bgp_state): The BGP negotiation state of the tunnel. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

    • vpn.connection.tun.state (vpn_connection_tun.state): The negotiation state of the tunnel. A value of 0 indicates an abnormal state, while 1 indicates a normal state.

Query and analyze IPsec-VPN traffic

While monitoring an IPsec-VPN connection, you can inspect specific traffic details, such as the source and destination IP addresses, source and destination ports, and protocols. You can use flow logs to record inbound and outbound traffic, and then query and analyze the logs:

Related topics

You can call CloudMonitor API operations to query metrics for IPsec-VPN resources.