All Products
Search
Document Center

VPN Gateway:DescribeVpnGateway

Last Updated:Jun 19, 2026

Queries the details of a specified VPN gateway by calling the DescribeVpnGateway operation.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

vpc:DescribeVpnGateway

get

*VpnGateway

acs:vpc:{#regionId}:{#accountId}:vpngateway/{#VpnGatewayId}

None None

Request parameters

Parameter

Type

Required

Description

Example

RegionId

string

Yes

The region ID of the VPN gateway.

You can call the DescribeRegions operation to query the region ID.

cn-hangzhou

VpnGatewayId

string

Yes

The instance ID of the VPN gateway.

vpn-bp1r3v1xqkl0w519g****

IncludeReservationData

boolean

No

Specifies whether to include pending order data. Valid values:

  • false (default): does not include pending order data.

  • true: includes pending order data.

true

Response elements

Element

Type

Description

Example

object

The response parameters.

VpnType

string

The type of the VPN gateway. Value: Normal, which indicates a standard VPN gateway.

Normal

Status

string

The status of the VPN gateway. Valid values:

  • init: initializing.

  • provisioning: preparing.

  • active: Normal.

  • updating: updating.

  • deleting: deleting.

init

VpcId

string

The ID of the VPC to which the VPN gateway belongs.

vpc-bp19m2yx1m5q0avyq****

SslMaxConnections

integer

The maximum number of concurrent SSL-VPN connections.

5

Spec

string

The bandwidth specification of the VPN gateway. Unit: Mbit/s.

5

InternetIp

string

  • If the VPN gateway instance supports creating single-tunnel IPsec-VPN connections, this address is the IP address of the VPN gateway instance and can be used to create IPsec-VPN connections or SSL-VPN connections.

  • If the VPN gateway instance supports creating dual-tunnel IPsec-VPN connections, this address is the first IP address used to create IPsec-VPN connections and cannot be used to create SSL-VPN connections.

    If the VPN gateway instance supports creating dual-tunnel IPsec-VPN connections, the system assigns two IPsec IP addresses to the VPN gateway instance for creating dual-tunnel IPsec-VPN connections.

47.22.XX.XX

CreateTime

integer

The timestamp when the VPN gateway was created. Unit: milliseconds.

The timestamp follows the UNIX time format, which represents the total number of milliseconds elapsed since January 1, 1970, 00:00:00 UTC.

1495382400000

AutoPropagate

boolean

Indicates whether the routing automatic propagation feature is enabled for the VPN gateway. Valid values:

  • true: enabled.

  • false: disabled.

true

ChargeType

string

The billing method. Value:

POSTPAY: pay-as-you-go billing method.

中国站示例值:Prepay,国际站示例值:POSTPAY

VpnGatewayId

string

The instance ID of the VPN gateway.

vpn-bp1r3v1xqkl0w519g****

Tag

string

The labels automatically generated by the system for the VPN gateway.

  • VpnEnableBgp: indicates whether the VPN gateway supports the BGP feature.
    • true: Supported.

    • false: Not supported.

  • VisuallySsl: indicates whether the VPN gateway supports viewing connection information of SSL clients.
    • true: Supported.

    • false: Not supported.

  • PbrPriority: indicates whether the VPN gateway supports configuring policy priority for policy-based routing.
    • true: Supported.

    • false: Not supported.

  • VpnNewImage: indicates whether the VPN gateway is a new-generation VPN gateway.
    • true: Yes.

    • false: No.

  • description: the description of the VPN gateway, which is used only for internal system purposes.

  • VpnVersion: the version number of the VPN gateway.

  • IDaaSNewVersion: indicates whether the VPN gateway supports attaching to an EIAM 2.0 instance.
    • true: Supported.

    • false: Not supported.

{\"VpnEnableBgp\":\"true\",\"VisuallySsl\":\"true\",\"PbrPriority\":\"true\",\"VpnNewImage\":\"true\",\"description\":\"转发1.3.24\",\"VpnVersion\":\"v1.2.4\",\"IDaaSNewVersion\":\"true\"}

IpsecVpn

string

Indicates whether the IPsec-VPN feature is enabled. Valid values:

  • enable: enabled.

  • disable: disabled.

enable

EndTime

integer

The expiration timestamp of the VPN gateway. Unit: milliseconds.

The timestamp follows the UNIX time format, which represents the total number of milliseconds elapsed since January 1, 1970, 00:00:00 UTC.

1544666102000

VSwitchId

string

The ID of the vSwitch to which the VPN gateway belongs.

vsw-bp1dmzugdikc6hdgx****

RequestId

string

The request ID.

27E4E088-8DE0-4672-BF5C-0A412389DB9E

Description

string

The description of the VPN gateway.

vpngatewaydescription

EnableBgp

boolean

The enabling status of the BGP feature for the VPN gateway. Valid values:

  • true: enabled.

  • false: disabled.

true

BusinessStatus

string

The payment status of the VPN gateway. Valid values:

  • Normal: Normal.

  • FinancialLocked: locked due to overdue payment.

Normal

SslVpn

string

The enabling status of the SSL-VPN feature. Valid values:

  • enable: enabled.

  • disable: disabled.

enable

Name

string

The name of the VPN gateway.

vpngatewayname

ReservationData

object

The pending order data.

Note

This parameter is returned only when IncludeReservationData is set to true.

Status

string

The status of the pending order. Valid values:

  • 1: The renewal or renewal with specification change order has not taken effect.

  • 2: The temporary upgrade order has taken effect. After the restoration time is reached, the system restores the VPN gateway to the specification before the temporary upgrade. In this case, ReservationIpsec, ReservationMaxConnections, ReservationSpec, and ReservationSsl indicate the specifications before the temporary upgrade.

1

ReservationOrderType

string

The type of the pending order. Valid values:

  • RENEWCHANGE: renewal with specification change.

  • TEMP_UPGRADE: temporary upgrade.

  • RENEW: renewal.

TEMP_UPGRADE

ReservationIpsec

string

The enabling status of the IPsec-VPN feature for the pending order. Valid values:

  • enable: enabled.

  • disable: disabled.

enable

ReservationSpec

string

The bandwidth specification of the pending order. Unit: Mbit/s.

5

ReservationSsl

string

The enabling status of the SSL-VPN feature for the pending order. Valid values:

  • enable: enabled.

  • disable: disabled.

enable

ReservationMaxConnections

integer

The maximum number of concurrent SSL-VPN connections of the pending order.

5

ReservationEndTime

string

If the pending order type is TEMP_UPGRADE (temporary upgrade), this parameter indicates the revert time for the temporary upgrade.

If the pending order type is RENEWCHANGE (renewal with specification change) or RENEW (renewal), this parameter indicates the effective period when the renewal or renewal with specification change takes effect.

2020-07-20T16:00:00Z

Tags

object

Tag

array<object>

The list of tags bound to the VPN gateway instance.

object

The list of tags bound to the VPN gateway instance.

Key

string

Tag key.

aaa

Value

string

The tag value.

bbb

NetworkType

string

The network type of the VPN gateway.

  • public: public VPN gateway.

  • private: private VPN gateway.

public

DisasterRecoveryInternetIp

string

The second IP address assigned by the system to the VPN gateway instance for creating IPsec-VPN connections.

This parameter is returned only for VPN gateway instances that support creating dual-tunnel IPsec-VPN connections.

47.91.XX.XX

DisasterRecoveryVSwitchId

string

The ID of the second vSwitch associated with the VPN gateway instance.

This parameter is returned only for VPN gateway instances that support creating dual-tunnel IPsec-VPN connections.

vsw-p0w95ql6tmr2ludkt****

SslVpnInternetIp

string

The IP address of the SSL-VPN connection.

This parameter is returned only when the SSL-VPN feature is enabled on a VPN gateway instance of the public network type that supports creating dual-tunnel IPsec-VPN connections.

47.74.XX.XX

ResourceGroupId

string

The ID of the resource group to which the VPN gateway belongs.

You can call the ListResourceGroups operation to query resource group information.

rg-acfmzs372yg****

EniInstanceIds

object

EniInstanceId

array

The list of Elastic Network Interfaces (ENIs) created by the system for the VPN gateway instance.

string

The ENI ID.

This parameter is returned only for VPN gateway instances that support creating dual-tunnel IPsec-VPN connections.

eni-7xvcxgmd4y2ypibn****

GatewayType

string

The type of the VPN gateway. Valid values:

  • Traditional: traditional VPN gateway that supports both IPsec and SSL features.

  • Enhanced.SiteToSite: enhanced site-to-cloud VPN gateway that supports only the IPsec feature.

Enhanced.SiteToSite

Examples

Success response

JSON format

{
  "VpnType": "Normal",
  "Status": "init",
  "VpcId": "vpc-bp19m2yx1m5q0avyq****",
  "SslMaxConnections": 5,
  "Spec": "5",
  "InternetIp": "47.22.XX.XX",
  "CreateTime": 1495382400000,
  "AutoPropagate": true,
  "ChargeType": "中国站示例值:Prepay,国际站示例值:POSTPAY",
  "VpnGatewayId": "vpn-bp1r3v1xqkl0w519g****",
  "Tag": "{\\\"VpnEnableBgp\\\":\\\"true\\\",\\\"VisuallySsl\\\":\\\"true\\\",\\\"PbrPriority\\\":\\\"true\\\",\\\"VpnNewImage\\\":\\\"true\\\",\\\"description\\\":\\\"转发1.3.24\\\",\\\"VpnVersion\\\":\\\"v1.2.4\\\",\\\"IDaaSNewVersion\\\":\\\"true\\\"}",
  "IpsecVpn": "enable",
  "EndTime": 1544666102000,
  "VSwitchId": "vsw-bp1dmzugdikc6hdgx****",
  "RequestId": "27E4E088-8DE0-4672-BF5C-0A412389DB9E",
  "Description": "vpngatewaydescription",
  "EnableBgp": true,
  "BusinessStatus": "Normal",
  "SslVpn": "enable",
  "Name": "vpngatewayname",
  "ReservationData": {
    "Status": "1",
    "ReservationOrderType": "TEMP_UPGRADE",
    "ReservationIpsec": "enable",
    "ReservationSpec": "5",
    "ReservationSsl": "enable",
    "ReservationMaxConnections": 5,
    "ReservationEndTime": "2020-07-20T16:00:00Z"
  },
  "Tags": {
    "Tag": [
      {
        "Key": "aaa",
        "Value": "bbb"
      }
    ]
  },
  "NetworkType": "public",
  "DisasterRecoveryInternetIp": "47.91.XX.XX",
  "DisasterRecoveryVSwitchId": "vsw-p0w95ql6tmr2ludkt****",
  "SslVpnInternetIp": "47.74.XX.XX",
  "ResourceGroupId": "rg-acfmzs372yg****",
  "EniInstanceIds": {
    "EniInstanceId": [
      "eni-7xvcxgmd4y2ypibn****"
    ]
  },
  "GatewayType": "Enhanced.SiteToSite"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidVpnGatewayInstanceId.NotFound The specified vpn gateway instance id does not exist. The specified VPN gateway does not exist. Check whether the specified VPN gateway is valid.
403 Forbbiden.SubUser User not authorized to operate on the specified resource as your account is created by another user.
403 Forbidden User not authorized to operate on the specified resource. You do not have the permissions to manage the specified resource. Apply for the permissions and try again.
404 InvalidVpnGatewayInstanceId.NotFound The specified vpn gateway instance id does not exist.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.