Todos os produtos
Search
Central de documentação

VPN Gateway:DescribeVpnConnection

Última atualização: Jun 29, 2026

Consulta as informações detalhadas sobre uma conexão IPsec-VPN.

Experimente agora

Experimente esta API no OpenAPI Explorer, sem necessidade de assinatura manual. Chamadas bem-sucedidas geram automaticamente código SDK correspondente aos seus parâmetros. Faça o download com segurança de credenciais integrada para uso local.

Testar

Autorização RAM

Nenhuma autorização necessária para esta operação. Se você encontrar problemas com esta operação, entre em contato com o suporte técnico.

Parâmetros da solicitação

Parâmetro

Tipo

Obrigatório

Descrição

Exemplo

RegionId

string

Sim

O bloco CIDR no lado do Alibaba Cloud.

Vários blocos CIDR são separados por vírgulas (,).

cn-hangzhou

VpnConnectionId

string

Sim

O ID da solicitação.

vco-bp1bbi27hojx80nck****

Elementos de resposta

Elemento

Tipo

Descrição

Exemplo

object

O ID da conexão IPsec-VPN.

Status

string

O bloco CIDR no lado do data center.

Vários blocos CIDR são separados por vírgulas (,).

ike_sa_not_established

RemoteCaCertificate

string

O ID do customer gateway associado à conexão IPsec-VPN.

-----BEGIN CERTIFICATE----- MIIB7zCCAZW****

EnableNatTraversal

boolean

O nome da conexão IPsec-VPN.

true

CreateTime

integer

Indica se o recurso de detecção de peer inativo (DPD) está ativado para a conexão IPsec-VPN. Valores válidos:

  • false

  • true

Após ativar o recurso DPD, o iniciador da conexão IPsec-VPN envia pacotes DPD para verificar a existência e a disponibilidade do peer. Se nenhuma resposta for recebida do peer dentro de um período de tempo especificado, a conexão falhará. Em seguida, a associação de segurança (SA) ISAKMP, a SA IPsec e o túnel IPsec são excluídos.

1492753817000

EffectImmediately

boolean

A configuração das negociações da Fase 1.

true

VpnGatewayId

string

O identificador da conexão IPsec-VPN no lado do data center.

vpn-bp1q8bgx4xnkm2ogj****

LocalSubnet

string

O tempo de vida na fase IKE. Unidade: segundos.

10.0.0.0/8

RequestId

string

O algoritmo de criptografia na fase IKE.

F2310D45-BCF6-4E2E-9082-B4503844BA4C

VpnConnectionId

string

O identificador da conexão IPsec-VPN no lado do Alibaba Cloud.

vco-bp1bbi27hojx80nck****

RemoteSubnet

string

O modo de negociação IKE.

  • main: Este modo oferece maior segurança durante as negociações.

  • aggressive: Este modo é mais rápido e tem uma taxa de sucesso maior.

192.168.0.0/16

CustomerGatewayId

string

A versão do protocolo IKE.

  • ikev1

  • ikev2

Em comparação com o IKEv1, o IKEv2 simplifica o processo de negociação de SA e é mais adequado para cenários em que vários blocos CIDR são utilizados.

cgw-bp1mvj4g9kogwwcxk****

Name

string

O grupo Diffie-Hellman (DH) na fase IKE.

ipsec1

EnableDpd

boolean

A chave pré-compartilhada.

true

IkeConfig

object

O algoritmo de autenticação na fase IKE.

RemoteId

string

A configuração das negociações da Fase 2.

139.34.XX.XX

IkeLifetime

integer

O algoritmo de autenticação na fase IPsec.

86400

IkeEncAlg

string

O tempo de vida na fase IPsec. Unidade: segundos.

aes

LocalId

string

O algoritmo de criptografia na fase IPsec.

116.28.XX.XX

IkeMode

string

O grupo DH na fase IPsec.

main

IkeVersion

string

As informações de verificação de integridade sobre a conexão IPsec-VPN.

ikev1

IkePfs

string

O estado da verificação de integridade. Valores válidos:

  • failed

  • success: normal

group2

Psk

string

O endereço IP de destino.

pgw6dy****

IkeAuthAlg

string

O intervalo entre duas verificações de integridade consecutivas. Unidade: segundos.

sha1

IpsecConfig

object

O número máximo de tentativas de verificação de integridade.

IpsecAuthAlg

string

O endereço IP de origem.

sha1

IpsecLifetime

integer

Indica se o recurso de verificação de integridade está ativado para a conexão IPsec-VPN. Valores válidos:

  • false

  • true

86400

IpsecEncAlg

string

Indica se as rotas anunciadas são retiradas quando a verificação de integridade falha. Valores válidos:

  • revoke_route: As rotas anunciadas são retiradas.

  • reserve_route: As rotas anunciadas não são retiradas.

aes

IpsecPfs

string

A configuração do Border Gateway Protocol (BGP) da conexão IPsec-VPN.

group2

VcoHealthCheck

object

O estado de negociação do protocolo de roteamento BGP. Valores válidos:

  • success: normal

  • failed

Status

string

O endereço IP BGP do peer.

failed

Dip

string

O bloco CIDR BGP da conexão IPsec-VPN. O bloco CIDR está dentro de 169.254.0.0/16. A máscara de sub-rede do bloco CIDR deve ter 30 bits de comprimento.

10.0.0.1

Interval

integer

Indica se o BGP está ativado. Valores válidos:

  • true

  • false

3

Retry

integer

O endereço IP BGP no lado do Alibaba Cloud.

3

Sip

string

O número do sistema autônomo (ASN) do peer.

192.168.1.1

Enable

string

O ASN no lado do Alibaba Cloud.

true

Policy

string

A chave de autenticação do protocolo de roteamento BGP.

revoke_route

VpnBgpConfig

object

O tipo de recurso associado à conexão IPsec-VPN. Valores válidos:

  • CEN: indica que a conexão IPsec-VPN está associada a um transit router de uma instância do Cloud Enterprise Network (CEN).

  • NO_ASSOCIATED: indica que a conexão IPsec-VPN não está associada a nenhum recurso.

  • VPNGW: indica que a conexão IPsec-VPN está associada a um VPN gateway.

Status

string

O tipo de rede da conexão IPsec-VPN. Valores válidos:

  • public: uma conexão criptografada pela Internet

  • private: uma conexão criptografada por redes privadas

success

PeerBgpIp

string

O ID da instância CEN à qual o transit router pertence.

169.254.11.1

TunnelCidr

string

A especificação de largura de banda da conexão IPsec-VPN. Unidade: Mbit/s.

169.254.11.0/30

EnableBgp

string

O estado de associação da conexão IPsec-VPN. Valores válidos:

  • active: A conexão IPsec-VPN está associada a um VPN gateway.

  • init: A conexão IPsec-VPN não está associada a nenhum recurso e está sendo inicializada.

  • attaching: A conexão IPsec-VPN está sendo associada a um transit router.

  • attached: A conexão IPsec-VPN está associada a um transit router.

  • detaching: A conexão IPsec-VPN está sendo desassociada de um transit router.

  • financialLocked: A conexão IPsec-VPN está bloqueada devido a pagamentos em atraso.

  • provisioning: A conexão IPsec-VPN está sendo preparada.

  • updating: A conexão IPsec-VPN está sendo atualizada.

  • Upgrading: A conexão IPsec-VPN está sendo atualizada para uma versão superior.

  • deleted: A conexão IPsec-VPN foi excluída.

true

LocalBgpIp

string

O ID da zona onde a conexão IPsec-VPN está implantada.

Você pode chamar DescribeZones para consultar os IDs de zona e o mapeamento entre IDs de zona e nomes de zona.

169.254.11.2

PeerAsn

integer

O endereço IP do gateway da conexão IPsec-VPN.

65530

LocalAsn

integer

O ID do transit router ao qual a conexão IPsec-VPN está associada.

65531

AuthKey

string

O nome do transit router.

AuthKey****

AttachType

string

Indica se a conexão IPsec-VPN está associada a um transit router que pertence a outra conta do Alibaba Cloud. Valores válidos:

  • true

  • false

CEN

NetworkType

string

A lista de tags adicionadas à conexão IPsec-VPN.

public

AttachInstanceId

string

As informações da tag.

cen-lxxpbpalc776qz****

Spec

string

A chave da tag.

1000M

State

string

O valor da tag.

attached

ZoneNo

string

As configurações de túnel da conexão IPsec-VPN.

Os parâmetros em TunnelOptionsSpecification são retornados apenas se você consultar uma conexão IPsec-VPN no modo de túnel duplo.

cn-hangzhou-h

InternetIp

string

As configurações do túnel.

47.XX.XX.162

TransitRouterId

string

O ID do túnel.

tr-p0we2edef9qr44a85****

TransitRouterName

string

O ID do customer gateway associado ao túnel.

nametest

CrossAccountAuthorized

boolean

Indica se o recurso DPD está ativado para o túnel. Valores válidos:

  • false

  • true

false

Tags

object

Tag

array<object>

Indica se o NAT traversal está ativado para o túnel. Valores válidos:

  • false

  • true

object

O endereço IP do túnel.

Key

string

The CA certificate of the tunnel peer.

This parameter is returned only if the VPN gateway is of the ShangMi (SM) type.

TagKey

Value

string

The tunnel role. Valid values:

  • master: The tunnel is an active tunnel.

  • slave: The tunnel is a standby tunnel.

TagValue

TunnelOptionsSpecification

object

TunnelOptions

array<object>

A ordem em que o túnel é criado.

  • 1: Túnel 1.

  • 2: Túnel 2.

Nota

Este parâmetro é retornado apenas se a conexão IPsec-VPN estiver associada a um transit router.

array<object>

O status do túnel. Valores válidos:

  • active

  • updating

  • deleting

TunnelId

string

The state of the IPsec-VPN connection. Valid values:

  • ike_sa_not_established: Phase 1 negotiations failed.

  • ike_sa_established: Phase 1 negotiations succeeded.

  • ipsec_sa_not_established: Phase 2 negotiations failed.

  • ipsec_sa_established: Phase 2 negotiations succeeded.

tun-opsqc4d97wni27****

CustomerGatewayId

string

The BGP configurations.

cgw-p0wy363lucf1uyae8****

EnableDpd

string

The negotiation state of BGP. Valid values:

  • success

  • false

true

EnableNatTraversal

string

The ASN on the Alibaba Cloud side.

true

InternetIp

string

The BGP address on the Alibaba Cloud side.

47.21.XX.XX

RemoteCaCertificate

string

The ASN of the tunnel peer.

-----BEGIN CERTIFICATE----- MIIB7zCCAZW**** -----END CERTIFICATE-----

Role

string

The BGP IP address of the tunnel peer.

master

TunnelIndex

integer

The BGP CIDR block of the tunnel.

1

State

string

The configuration of Phase 1 negotiations.

active

Status

string

The authentication algorithm in the IKE phase.

ipsec_sa_established

TunnelBgpConfig

object

The encryption algorithm in the IKE phase.

BgpStatus

string

The lifetime in the IKE phase. Unit: seconds.

success

LocalAsn

string

The IKE negotiation mode.

  • main: This mode offers higher security during negotiations.

  • aggressive: This mode is faster and has a higher success rate.

65530

LocalBgpIp

string

The Diffie-Hellman (DH) group in the IKE phase.

169.254.10.1

PeerAsn

string

The version of the IKE protocol.

65531

PeerBgpIp

string

The identifier of the tunnel on the Alibaba Cloud side.

169.254.10.2

TunnelCidr

string

The pre-shared key.

169.254.10.0/30

TunnelIkeConfig

object

The identifier of the tunnel peer.

IkeAuthAlg

string

The configurations of Phase 2 negotiations.

sha1

IkeEncAlg

string

The authentication algorithm in the IPsec phase.

aes

IkeLifetime

string

The encryption algorithm in the IPsec phase.

86400

IkeMode

string

The lifetime in the IPsec phase. Unit: seconds.

main

IkePfs

string

The DH group in the IPsec phase.

group2

IkeVersion

string

The zone where the tunnel is deployed.

You can call DescribeZones to query zone IDs.

ikev1

LocalId

string

Indicates whether BGP is enabled for the tunnel. Valid values:

  • true

  • false

47.21.XX.XX

Psk

string

The ID of the resource group to which the IPsec-VPN connection belongs.

You can call the ListResourceGroups operation to query the resource group information.

123456****

RemoteId

string

The identifier of the tunnel peer.

47.42.XX.XX

TunnelIpsecConfig

object

Theconfigurations of Phase 2 negotiations.

IpsecAuthAlg

string

The authentication algorithm in the IPsec phase.

sha1

IpsecEncAlg

string

The encryption algorithm in the IPsec phase.

aes

IpsecLifetime

string

The lifetime in the IPsec phase. Unit: seconds.

86400

IpsecPfs

string

The DH group in the IPsec phase.

group2

ZoneNo

string

The tunnel zone.

cn-hangzhou-i

EnableTunnelsBgp

boolean

Indica se o BGP está ativado para o túnel. Valores válidos:

  • true

  • false

Este parâmetro é retornado apenas por conexões IPsec-VPN de túnel duplo.

true

ResourceGroupId

string

O ID do grupo de recursos ao qual a conexão VPN pertence.

Você pode chamar a operação ListResourceGroups para consultar a lista de grupos de recursos.

rg-acfmzs372yg****

TunnelBandwidth

string

Especifica as especificações de largura de banda para um único túnel no anexo VPN. Opções disponíveis:

  • Standard: Padrão, 1 Gbps

  • Large: Grande, 3 Gbps

Standard

Exemplos

Resposta de sucesso

JSON formato

{
  "Status": "ike_sa_not_established",
  "RemoteCaCertificate": "-----BEGIN CERTIFICATE----- MIIB7zCCAZW****",
  "EnableNatTraversal": true,
  "CreateTime": 1492753817000,
  "EffectImmediately": true,
  "VpnGatewayId": "vpn-bp1q8bgx4xnkm2ogj****",
  "LocalSubnet": "10.0.0.0/8",
  "RequestId": "F2310D45-BCF6-4E2E-9082-B4503844BA4C",
  "VpnConnectionId": "vco-bp1bbi27hojx80nck****",
  "RemoteSubnet": "192.168.0.0/16",
  "CustomerGatewayId": "cgw-bp1mvj4g9kogwwcxk****",
  "Name": "ipsec1",
  "EnableDpd": true,
  "IkeConfig": {
    "RemoteId": "139.34.XX.XX",
    "IkeLifetime": 86400,
    "IkeEncAlg": "aes",
    "LocalId": "116.28.XX.XX",
    "IkeMode": "main",
    "IkeVersion": "ikev1",
    "IkePfs": "group2",
    "Psk": "pgw6dy****",
    "IkeAuthAlg": "sha1"
  },
  "IpsecConfig": {
    "IpsecAuthAlg": "sha1",
    "IpsecLifetime": 86400,
    "IpsecEncAlg": "aes",
    "IpsecPfs": "group2"
  },
  "VcoHealthCheck": {
    "Status": "failed",
    "Dip": "10.0.0.1",
    "Interval": 3,
    "Retry": 3,
    "Sip": "192.168.1.1",
    "Enable": "true",
    "Policy": "revoke_route"
  },
  "VpnBgpConfig": {
    "Status": "success",
    "PeerBgpIp": "169.254.11.1",
    "TunnelCidr": "169.254.11.0/30",
    "EnableBgp": "true",
    "LocalBgpIp": "169.254.11.2",
    "PeerAsn": 65530,
    "LocalAsn": 65531,
    "AuthKey": "AuthKey****"
  },
  "AttachType": "CEN",
  "NetworkType": "public",
  "AttachInstanceId": "cen-lxxpbpalc776qz****",
  "Spec": "1000M",
  "State": "attached",
  "ZoneNo": "cn-hangzhou-h",
  "InternetIp": "47.XX.XX.162",
  "TransitRouterId": "tr-p0we2edef9qr44a85****",
  "TransitRouterName": "nametest",
  "CrossAccountAuthorized": false,
  "Tags": {
    "Tag": [
      {
        "Key": "TagKey",
        "Value": "TagValue"
      }
    ]
  },
  "TunnelOptionsSpecification": {
    "TunnelOptions": [
      {
        "TunnelId": "tun-opsqc4d97wni27****",
        "CustomerGatewayId": "cgw-p0wy363lucf1uyae8****",
        "EnableDpd": "true",
        "EnableNatTraversal": "true",
        "InternetIp": "47.21.XX.XX",
        "RemoteCaCertificate": "-----BEGIN CERTIFICATE----- MIIB7zCCAZW**** -----END CERTIFICATE-----",
        "Role": "master",
        "TunnelIndex": 1,
        "State": "active",
        "Status": "ipsec_sa_established",
        "TunnelBgpConfig": {
          "BgpStatus": "success",
          "LocalAsn": "65530",
          "LocalBgpIp": "169.254.10.1",
          "PeerAsn": "65531",
          "PeerBgpIp": "169.254.10.2",
          "TunnelCidr": "169.254.10.0/30"
        },
        "TunnelIkeConfig": {
          "IkeAuthAlg": "sha1",
          "IkeEncAlg": "aes",
          "IkeLifetime": "86400",
          "IkeMode": "main",
          "IkePfs": "group2",
          "IkeVersion": "ikev1",
          "LocalId": "47.21.XX.XX",
          "Psk": "123456****",
          "RemoteId": "47.42.XX.XX"
        },
        "TunnelIpsecConfig": {
          "IpsecAuthAlg": "sha1",
          "IpsecEncAlg": "aes",
          "IpsecLifetime": "86400",
          "IpsecPfs": "group2"
        },
        "ZoneNo": "cn-hangzhou-i"
      }
    ]
  },
  "EnableTunnelsBgp": true,
  "ResourceGroupId": "rg-acfmzs372yg****",
  "TunnelBandwidth": "Standard"
}

Códigos de erro

Código de status HTTP

Código de erro

Mensagem de erro

Descrição

403 Forbbiden.SubUser User not authorized to operate on the specified resource as your account is created by another user.
403 Forbidden User not authorized to operate on the specified resource. You do not have the permissions to manage the specified resource. Apply for the permissions and try again.
404 InvalidVpnConnectionInstanceId.NotFound The specified vpn connection instance id does not exist. The specified vpn connection instance id does not exist.

Consulte Códigos de Erro para uma lista completa.

Notas de versão

Consulte Notas de Versão para uma lista completa.