An IPsec-VPN connection in dual-tunnel mode has an active tunnel and a standby tunnel. If the active tunnel is down, the standby tunnel takes over to ensure service availability. This topic describes how to upgrade a VPN gateway to enable the dual-tunnel mode.
Supported regions and zones
Only IPsec-VPN connections in the following regions and zones can be upgraded to the dual-tunnel mode.
Region | Zone |
Australia (Sydney) | B |
Prerequisites
Before you upgrade a VPN gateway, make sure that the following requirements are met:
Descriptions of the upgrade
A VPN gateway is unavailable during the upgrade and existing connections are interrupted. We recommend that you upgrade a VPN gateway during a network maintenance window to avoid service interruptions.
The upgrade takes about 10 minutes. During this period, the VPN gateway cannot forward traffic.
You cannot manage the VPN gateway during the upgrade process.
Procedure
- Log on to the VPN gateway console.
- In the top navigation bar, select the region of the VPN gateway.
On the VPN Gateways page, find the VPN gateway that you want to manage and click its ID.
In the upper-right corner of the details page, click Enable Zone Redundancy.
In the Enable Zone Redundancy dialog box, specify a vSwitch and enable environment verification. Make sure that the requirements are met and click Enable.
If the environment verification failed, refer to Prerequisites for troubleshooting.
After you click Enable, the system starts the upgrade.