Monitoring is key to maintaining the reliability, availability, and performance of your ipsec-vpn connection. By monitoring metrics like the tunnel negotiation status and traffic rates, you get a clear overview of your connection's running status and bandwidth usage. This helps you quickly identify network bandwidth bottlenecks, detect faults or anomalies, and improve overall network reliability and availability. VPN Gateway is integrated with Cloud Monitor, so you can centrally monitor and manage all your Alibaba Cloud resources from the Cloud Monitor console.
Monitor IPsec-VPN tunnel status
VPN Gateway lets you monitor tunnel status changes. You can view the current status of tunnels on the VPN Gateway console. You can also subscribe to system events or create threshold-triggered alert rules for metrics to be promptly notified of tunnel status changes.
-
View the status of IPsec-VPN connection tunnels
Click to view the procedure
Log on to the VPN Gateway console and select the region where the IPsec connection is deployed. In the left-side navigation pane, choose IPsec Connections:
-
IPsec-VPN connection in dual-tunnel mode
On the IPsec-VPN connection page, click the ID of an IPsec connection to go to its details page. On the Tunnel tab, check the negotiation status of the active/standby tunnels in the Connection Status column. The list of tunnels on this tab includes information such as Tunnel role (active/standby), Gateway IP, Pre-shared key, Tunnel CIDR block, Local BGP address, Connection status, Customer gateway, and Status. If the Connection status for both tunnels is Phase 1 negotiation failed, a VPN negotiation issue has occurred and requires further troubleshooting. You can click View Details to understand the cause of the negotiation failure or click View Logs to view the tunnel logs.
-
IPsec-VPN connection in single-tunnel mode
On the IPsec-VPN connection page, find the target IPsec connection and check the Connection Status column. If the status is indicated by a green dot and shows Phase 2 negotiation succeeded, the IPsec-VPN tunnel negotiation is successful.
NoteIf the status of an IPsec-VPN connection or tunnel is abnormal, you can troubleshoot the issue based on the error code displayed on the console.
-
-
VPN Gateway system events
System events are predefined by VPN Gateway to record and report changes in tunnel negotiation and health check status. You can go to the CloudMonitor console to view system events generated by VPN Gateway and subscribe to system events. This allows you to stay informed of resource status changes and respond promptly.
Click to view the system events supported by VPN Gateway
A system event is generated only when the status of a resource changes.
For example, after you configure a health check for an IPsec connection, its initial health check status is failed. By default, the system does not generate a health check failed system event. The system generates a health check success or health check failed system event only when the health check status changes from failed to success or from success to failed. After you subscribe to system events, the system sends you alert notifications for these events.
|
Resource |
Event name |
Event description |
Description |
Event type |
Event level |
|
IPsec-VPN connection in dual-tunnel mode |
ipsec_tunnel_nego_success |
IPsec tunnel negotiation succeeded |
Indicates that a tunnel for an IPsec-VPN connection in dual-tunnel mode has successfully negotiated. |
Status Notification |
Info |
|
ipsec_tunnel_nego_failed |
IPsec tunnel negotiation failed |
Indicates that a tunnel for an IPsec-VPN connection in dual-tunnel mode failed to negotiate. |
Status Notification |
Warning |
|
|
ipsec_vco_tunnel_all_nego_failed |
All IPsec connection tunnels failed to be negotiated |
Indicates that both tunnels for an IPsec-VPN connection in dual-tunnel mode failed to negotiate. |
Status Notification |
Warning |
|
|
IPsec-VPN connection in single-tunnel mode |
ipsec_phase1_nego_failed |
IPsec phase 1 negotiation failed |
Indicates that phase 1 negotiation for an IPsec connection on a VPN Gateway has failed. |
Status Notification |
Warning |
|
ipsec_phase1_nego_success |
IPsec phase 1 negotiation succeeded |
Indicates that phase 1 negotiation for an IPsec connection on a VPN Gateway was successful. |
Status Notification |
Info |
|
|
ipsec_phase2_nego_failed |
IPsec phase 2 negotiation failed |
Indicates that phase 2 negotiation for an IPsec connection on a VPN Gateway has failed. |
Status Notification |
Warning |
|
|
ipsec_phase2_nego_success |
IPsec phase 2 negotiation succeeded |
Indicates that phase 2 negotiation for an IPsec connection on a VPN Gateway was successful. |
Status Notification |
Info |
|
|
ipsec_health_check_failed |
health check failed |
Indicates that the health check for an IPsec connection on a VPN Gateway has failed. |
Status Notification |
Warning |
|
|
ipsec_health_check_success |
health check success |
Indicates that the health check for an IPsec connection on a VPN Gateway was successful. |
Status Notification |
Info |
|
|
vpn_connection_hc_failed |
VPN connection health check failed |
Indicates that the health check for an IPsec connection on a Transit Router has failed. |
Status Notification |
Warning |
|
|
vpn_connection_hc_success |
VPN connection health check succeeded |
Indicates that the health check for an IPsec connection on a Transit Router was successful. |
Status Notification |
Info |
|
|
vpn_connection_ph1_failed |
VPN connection phase 1 negotiation failed |
Indicates that phase 1 negotiation for an IPsec connection on a Transit Router has failed. |
Status Notification |
Warning |
|
|
vpn_connection_ph1_success |
VPN connection phase 1 negotiation succeeded |
Indicates that phase 1 negotiation for an IPsec connection on a Transit Router was successful. |
Status Notification |
Info |
|
|
vpn_connection_ph2_failed |
VPN connection phase 2 negotiation failed |
Indicates that phase 2 negotiation for an IPsec connection on a Transit Router has failed. |
Status Notification |
Warning |
|
|
vpn_connection_ph2_success |
VPN connection phase 2 negotiation succeeded |
Indicates that phase 2 negotiation for an IPsec connection on a Transit Router was successful. |
Status Notification |
Info |
|
|
SSL-VPN connection |
CertKeyExpired |
Certificate expired |
The SSL client certificate has expired. |
Exception |
Critical |
-
Metrics for IPsec-VPN connection tunnel status
VPN Gateway provides metrics related to the tunnel status. You can create threshold-triggered alert rules for these metrics to be promptly notified of tunnel status changes.
Click to view tunnel status metrics
Resource
Metric
Metric description
Description
vpn (VPN Gateway)
An IPsec-VPN connection on a VPN Gateway.
ipsec.state
The negotiation status of an IPsec connection on a VPN Gateway
The negotiation status of an IPsec-VPN connection in single-tunnel mode. A value of
0indicates that the negotiation was unsuccessful. A value of1indicates that the negotiation was successful.tun.state
The negotiation status of a tunnel of an IPsec connection on a VPN Gateway
The negotiation status of a tunnel of an IPsec-VPN connection in dual-tunnel mode. A value of 0 indicates that the tunnel negotiation was unsuccessful. A value of 1 indicates that the tunnel negotiation was successful.
ipsec.bgp_state
The BGP negotiation status of an IPsec connection on a VPN Gateway
The BGP negotiation status of an IPsec connection on a single-tunnel mode VPN Gateway. A value of
0indicates that the BGP negotiation was unsuccessful. A value of1indicates that the BGP negotiation was successful.tun.bgp_state
The BGP negotiation status of an IPsec tunnel on a VPN Gateway
The BGP negotiation status of an IPsec tunnel on a dual-tunnel mode VPN Gateway. A value of
0indicates that the BGP negotiation was unsuccessful. A value of1indicates that the BGP negotiation was successful.vpnconnection (VPN connection)
An IPsec-VPN connection on a Transit Router.
vpn_connection.state
The negotiation status of the IPsec connection.
The negotiation status of a VPN connection in single-tunnel mode. A value of
0indicates that the negotiation was unsuccessful. A value of1indicates that the negotiation was successful.vpn_connection_tun.state
The negotiation status of a tunnel.
The negotiation status for a tunnel in a dual-tunnel VPN connection. A value of
0indicates that the tunnel negotiation was unsuccessful. A value of1indicates that the tunnel negotiation was successful.vpn_connection.bgp_state
The BGP negotiation status of a VPN connection
The BGP negotiation status of a VPN connection in single-tunnel mode. A value of
0indicates that the BGP negotiation was unsuccessful. A value of1indicates that the BGP negotiation was successful.vpn_connection_tun.bgp_state
The BGP negotiation status of an IPsec tunnel of a VPN connection
The BGP negotiation status for an IPsec tunnel in a dual-tunnel VPN connection. A value of
0indicates that the BGP negotiation was unsuccessful. A value of1indicates that the BGP negotiation was successful.
Monitor IPsec-VPN traffic rates
VPN Gateway lets you view inbound and outbound traffic rates, packet rates, and bandwidth utilization for VPN Gateway instances, IPsec-VPN connections, and tunnels. This helps you quickly identify network congestion or abnormal traffic and optimize bandwidth utilization.
-
View traffic rates of an IPsec-VPN connection
The following sections explain how to view traffic rate data in the VPN Gateway console. You can also view IPsec-VPN traffic rate data in the CloudMonitor console. For more information, see Cloud service monitoring.
View traffic rates for an IPsec-VPN connection and its tunnels
Log on to the VPN Gateway console and select the region where the IPsec connection is deployed. In the left navigation bar, select IPsec Connections. On the IPsec-VPN connection page, click the IPsec connection instance ID. On the Monitor tab of the IPsec connection instance details page, view the traffic rate information.
For an IPsec-VPN connection in dual-tunnel mode, you can select a Dimension to view the traffic rate of a specific tunnel.
Dimension
Metric
Description
IPsec connection
IPsec connection inbound packet rate
The rate at which the IPsec connection receives data packets. Unit: pps.
IPsec connection outbound packet rate
The rate at which the IPsec connection sends data packets. Unit: pps.
IPsec connection inbound traffic rate
The rate at which the IPsec connection receives traffic. Unit: bps.
IPsec connection outbound traffic rate
The rate at which the IPsec connection sends traffic. Unit: bps.
Tunnel
Tunnel inbound packet rate
The rate at which the tunnel receives data packets. Unit: pps.
Tunnel outbound packet rate
The rate at which the tunnel sends data packets. Unit: pps.
Tunnel inbound traffic rate
The rate at which the tunnel receives traffic. Unit: bps.
Tunnel outbound traffic rate
The rate at which the tunnel sends traffic. Unit: bps.
View the traffic rate for a VPN Gateway instance
If a VPN Gateway instance manages multiple IPsec-VPN connections, you can view its aggregated traffic rate, which represents the total across all connections.
Log on to the VPN Gateway console and select the region where the VPN Gateway instance is deployed. On the VPN Gateways page, click the ID of the instance to open its details page, then select the Monitor tab to view the traffic rate metrics.
If the VPN Gateway instance also has SSL-VPN connections, their traffic is included in the metrics.
Metric
Description
VPN Gateway inbound packet rate
The rate at which the VPN Gateway instance receives data packets. Unit: pps.
VPN Gateway outbound packet rate
The rate at which the VPN Gateway instance sends data packets. Unit: pps.
VPN Gateway inbound traffic rate
The rate at which the VPN Gateway instance receives traffic. Unit: bps.
VPN Gateway outbound traffic rate
The rate at which the VPN Gateway instance sends traffic. Unit: bps.
Number of SSL client connections
The number of clients with active SSL-VPN connections to the VPN Gateway instance. Unit: count.
Gateway.rx.utilization
The percentage of inbound bandwidth used by the VPN Gateway instance.
Gateway.tx.utilization
The percentage of outbound bandwidth used by the VPN Gateway instance.
-
Create threshold-triggered alert rules for traffic rate metrics
Create threshold-triggered alert rules for IPsec-VPN traffic rate metrics in the CloudMonitor console. When a traffic rate exceeds its configured threshold, CloudMonitor sends an alert, allowing you to promptly identify and resolve issues.
Traffic rate metrics
Product
Monitored resource
Metrics and descriptions
VPN Gateway
Use these metrics for IPsec connections associated with a VPN Gateway.
VPN Gateway instance
-
Gateway.rx.utilization (in_bandwidth_utilization): The percentage of inbound bandwidth used by the VPN Gateway instance.
-
Gateway.tx.utilization (out_bandwidth_utilization): The percentage of outbound bandwidth used by the VPN Gateway instance.
-
VpnGateway.rxPkgs (net.rxPkgs): The rate at which the VPN Gateway instance receives data packets.
-
VpnGateway.txPkgs (net.txPkgs): The rate at which the VPN Gateway instance sends data packets.
-
SSL Client Count (ssl_client.count): The number of clients with active SSL-VPN connections to the VPN Gateway instance.
-
Gateway Inbound Bandwidth (net_rx.rate): The rate at which the VPN Gateway instance receives traffic.
-
Gateway Outbound Bandwidth (net_tx.rate): The rate at which the VPN Gateway instance sends traffic.
IPsec-VPN connection
-
IPSec.connection.rxPkgs (ipsec.rxPkgs): The rate at which the IPsec connection receives data packets.
-
IPSec.connection.txpkgs (ipsec.txPkgs): The rate at which the IPsec connection sends data packets.
-
IPSec.connection.rx.rate (ipsec_rx.rate): The rate at which the IPsec connection receives traffic.
-
IPSec.connection.tx.rate (ipsec_tx.rate): The rate at which the IPsec connection sends traffic.
-
VPN gateway IPsec connection BGP negotiation status (ipsec.bgp_state): The BGP negotiation state of the connection. A value of
0indicates an abnormal state, while1indicates a normal state. -
IPSec.connection.state (ipsec.state): The negotiation state of the connection. A value of
0indicates an abnormal state, while1indicates a normal state.
Tunnel
-
Tunnel.rx.pps (tun.rx_pps): The rate at which the tunnel receives data packets.
-
Tunnel.tx.pps (tun.tx_pps): The rate at which the tunnel sends data packets.
-
Tunnel.rx.bps (tun.rx_bps): The rate at which the tunnel receives traffic.
-
Tunnel.tx.bps (tun.tx_bps): The rate at which the tunnel sends traffic.
-
BGP Negotiation Status of IPSec Tunnel in VPN Gateway (tun.bgp_state): The BGP negotiation state of the tunnel. A value of
0indicates an abnormal state, while1indicates a normal state. -
Tunnel.state (tun.state): The negotiation state of the tunnel. A value of
0indicates an abnormal state, while1indicates a normal state.
VPN connection
Use these metrics for IPsec connections associated with a Transit Router.
IPsec-VPN connection
-
vpn.connection.rxPkgs (vpn_connection.rxPkgs): The rate at which the VPN connection receives data packets.
-
vpn.connection.txPkgs (vpn_connection.txPkgs): The rate at which the VPN connection sends data packets.
-
vpn.connection.rx.rate (vpn_connection_rx.rate): The rate at which the VPN connection receives traffic.
-
vpn.connection.tx.rate (vpn_connection.tx.rate): The rate at which the VPN connection sends traffic.
-
BGP Negotiation Status of IPSec Connection in VPN Connection (vpn_connection.bgp_state): The BGP negotiation state of the connection. A value of
0indicates an abnormal state, while1indicates a normal state. -
vpn.connection.state (vpn_connection.state): The negotiation state of the connection. A value of
0indicates an abnormal state, while1indicates a normal state.
Tunnel
-
Single-tunnel Inbound Packet Rate of VPN Connection (vpn_connection_tun.rxPkgs): The rate at which the tunnel receives data packets.
-
Single-tunnel Outbound Packet Rate of VPN Connection (vpn_connection_tun.txPkgs): The rate at which the tunnel sends data packets.
-
Single-tunnel Inbound Bandwidth of VPN Connection (vpn_connection_tun.rx.rate): The rate at which the tunnel receives traffic.
-
Single-tunnel Outbound Bandwidth of VPN Connection (vpn_connection_tun.tx.rate): The rate at which the tunnel sends traffic.
-
BGP Negotiation Status of IPSec Tunnel in VPN Connection (vpn_connection_tun.bgp_state): The BGP negotiation state of the tunnel. A value of
0indicates an abnormal state, while1indicates a normal state. -
vpn.connection.tun.state (vpn_connection_tun.state): The negotiation state of the tunnel. A value of
0indicates an abnormal state, while1indicates a normal state.
-
Query and analyze IPsec-VPN traffic
While monitoring an IPsec-VPN connection, you can inspect specific traffic details, such as the source and destination IP addresses, source and destination ports, and protocols. You can use flow logs to record inbound and outbound traffic, and then query and analyze the logs:
-
For an IPsec-VPN connection on a VPN Gateway instance, you can use VPC flow log to record inbound and outbound traffic for the VPN Gateway instance. For more information, see Query and analyze traffic transmitted by a VPN Gateway instance by using ENI flow logs.
-
For an IPsec-VPN connection on a Transit Router, you can use Transit Router flow log to record inbound and outbound traffic. For more information, see Query top inter-region traffic using flow logs.
Related topics
You can call CloudMonitor API operations to query metrics for IPsec-VPN resources.
-
For information about the API operations provided by CloudMonitor, see Monitor Alibaba Cloud products.
-
For the parameters required to call an API operation, such as Namespace, MetricName, Dimensions, and Period, see Appendix 1: Metrics for Alibaba Cloud products.