All Products
Search
Document Center

VPN Gateway:Self-service diagnostics

Last Updated:Jun 04, 2026

VPN Gateway lets you view IPsec-VPN connection logs and error codes. It integrates with Network Intelligence Service (NIS) for instance diagnosis and path analysis. Use these features to troubleshoot IPsec-VPN issues.

Diagnostic features and documents

The following table lists diagnostic features and documents by issue category.

Issue category

Applicable diagnostic features and documents

Abnormal IPsec-VPN connection negotiation

Successful IPsec-VPN connection negotiation but abnormal traffic

  • Path analysis (Feature, recommended)

    Diagnoses network connectivity between resources connected through a VPN Gateway instance. Suitable for abnormal traffic forwarding issues.

  • IPsec-VPN connection FAQ (Document)

    Covers common negotiation and connectivity issues with solutions.

Abnormal instance status

VPN Gateway instance diagnosis (Feature)

Billing issues

IPsec-VPN billing (Document)

Insufficient resource quota

IPsec-VPN quota management (Document)

Other issues

VPN Gateway instance diagnosis (Feature)

Self-service diagnostic methods

Shortcut

Diagnose IPsec-VPN issues from the Self-service Troubleshooting page of the Virtual Private Cloud console.

  1. Log on to the VPC console.

  2. In the navigation pane on the left, click Self-service Troubleshooting.

  3. Click the VPN Gateway tab.

  4. Select an issue category and follow the on-screen instructions to get troubleshooting suggestions.

    To diagnose a VPN Gateway instance or perform a path analysis, see Diagnose a VPN gateway and Use path analysis.

Other methods

You can also start instance diagnosis and path analysis from the following locations.

Method 1: On the VPN Gateway page

Log on to the VPN Gateway console. On the VPN Gateways page, find the VPN Gateway instance. In the Diagnosis column, click Start Diagnosis. Then, select instance diagnosis or path analysis.

Method 2: On the VPN Gateway instance details page

  1. Log on to the VPN Gateway console.

  2. On the VPN Gateways page, click the ID of the VPN Gateway instance.

  3. On the instance details page, click the Diagnosis tab. Then, select instance diagnosis or path analysis.

Method 3: In the Network Intelligence Service console

Use instance diagnosis. Use path analysis.