VPN gateway versions are constantly evolving and iterating. The latest version supports more features, solves some problems, and optimizes the compatibility with third-party devices. If you use a VPN gateway of an early version, risks may occur. We recommend that you upgrade your VPN gateway to the latest version for more features and more stable network performance.
Availability of upgrade
You can determine whether your VPN gateway is already upgraded to the latest version based on the Upgrade button in the VPN Gateway console.
If your VPN gateway is already upgraded to the latest version, the Upgrade button is dimmed. If you move the pointer over the Upgrade button, the console prompts that the VPN gateway is already upgraded to the latest version.
Newly created VPN gateways use the latest version by default.
If the Upgrade button is not dimmed, you can click it to upgrade the VPN gateway.
Descriptions
It takes about 10 minutes to upgrade a VPN gateway.
WarningA VPN gateway is unavailable during the upgrade and existing connections are interrupted. We recommend that you upgrade a VPN gateway during a network maintenance window to avoid service interruptions.
You are not charged for upgrading a VPN gateway.
If no IPsec-VPN connection exists on the VPN gateway, the configurations of the VPN gateway remain unchanged after the upgrade. If an IPsec-VPN connection exists on the VPN gateway, take note of the following limits:
If your VPN gateway was created before March 21, 2019, you must configure routes for the VPN gateway to ensure network connectivity of the IPsec-VPN connection after you upgrade the VPN gateway. For more information, see Route overview. Other configurations of the IPsec-VPN connection remain unchanged after you upgrade the VPN gateway.
NoteIf your VPN gateway was created before March 21, 2019, you do not need to configure routes and only need to configure protected data flows when you create an IPsec-VPN connection on the VPN gateway. However, if you create an IPsec-VPN connection on a VPN gateway of the latest version, you must configure routes. Therefore, you must configure routes after you upgrade your VPN gateway.
If your VPN gateway was created after March 21, 2019, the configurations of the IPsec-VPN connection remain unchanged and you do not need to configure routes after you upgrade the VPN gateway.
Prerequisites
If your VPN gateway is associated with an IPsec-VPN connection that uses IKE V1 and multiple CIDR blocks are specified for the IPsec-VPN connection, you need to change IKE V1 to IKE V2 or create an IPsec-VPN connection for each of the CIDR blocks. Otherwise, the upgrade fails.
Upgrade
- Log on to the VPN gateway console.
In the top navigation bar, select the region of the VPN gateway.
On the VPN Gateways page, find the VPN gateway that you want to upgrade and click its ID.
On the details page of the VPN gateway, click Upgrade.
In the Upgrade VPN Gateway dialog box, read and accept the upgrade agreement, and then click OK.
After you click OK, the system starts to upgrade the VPN gateway. Wait until the upgrade is completed.