View logs for an IPsec-VPN connection to troubleshoot connectivity issues.
Background
Logs for an IPsec-VPN connection are available for the past six months. You can query the logs in batches, with each query covering a time range of up to 10 minutes.
Procedure
Click the instance ID of the target IPsec-VPN connection. On its details page, find the Actions column for the target tunnel and click View Logs.
For legacy single-tunnel IPsec-VPN connections, select
-> Logs in the Actions column.In the IPsec Connection Logs panel, specify a time range to view the corresponding logs.
FAQ
Can VPN Gateway negotiation connection logs be delivered to Simple Log Service?
Currently, delivering the VPN Gateway negotiation connection log directly to Simple Log Service is not supported.
What should I do if the VPN Gateway console log page fails to load or keeps loading?
If the log page fails to load, keeps loading, or fails to load, troubleshoot by following these steps:
Retry after switching to a different browser.
If the log volume is too large, the page may load slowly. Please wait patiently for a while and observe whether the logs are displayed normally.
If the page still fails to load, you can export the logs by calling the OpenAPI: call DescribeVpnConnectionLogs for IPsec connection logs, and call DescribeVpnSslServerLogs for SSL server logs.