Why am I unable to delete a VPN gateway?
What does a 50 Mbps bandwidth cap mean?
A bandwidth cap for a VPN gateway is the maximum outbound bandwidth from the VPN gateway to the Internet.
Why is the data upload speed only 2 Mbps while the gateway bandwidth is 50 Mbps?
50Mbps is the bandwidth you purchased. The data upload speed depends on your public network speed.
Can I change an IPsec VPN gateway to an SSL VPN gateway?
No, IPSec VPN and SSL VPN are different types of VPNs and cannot be interchanged.
Does a VPN gateway support bandwidth configuration adjustment?
Currently, you can upgrade the bandwidth only within the following ranges: [5 Mbps, 100 Mbps], [200 Mbps, 1000 Mbps], and [2000 Mbps, 3000 Mbps]. For example, you can upgrade from 50 Mbps to 100 Mbps. However, to upgrade from 100 Mbps to 200 Mbps, you need to create a new gateway that supports a bandwidth of 200 Mbps. Downgrading the bandwidth is not supported. For more information, see Purchase Methods.
Why does the monitoring data displayed on the VPN gateway and VPN tunnel sometimes differ?
Currently, VPN gateway and VPN tunnel collect data at a different interval. The statistical granularity of the VPN gateway is 1 minute, and that of the VPN tunnel is 10 seconds. Therefore, the statistical data shown on the monitoring page of the VPN gateway may be different from that of the VPN tunnel.
How does a VPN gateway work? How about its availability?
A VPN gateway uses network functions virtualization (NFV) and an active-active hot backup mechanism. When one server fails, automatic switchover helps ensure the normal operation of your business.
A VPN tunnel runs in the public network. Therefore, congestion, jitter, or delay in the public network may affect the VPN network. If your business is sensitive to delay and jitter, we recommend using the Direct Connect.
How can I query the VPN gateway details?
Why am I unable to ping a VPN tunnel that is in the connected state?
If the tunnel is in a normal status yet the private network cannot be connected, the possible causes are as follows:
No routes directing to the private IP range in the IDC are added in the route table of the VPC subnet.
The security policy on the VPC/IDC side does not allow access to the corresponding source and destination IPs.
No tunnels directing to the private IP range in the IDC are added to the VPN gateway (route-based gateway).
The firewall of the operating system of the private network server on the VPC/IDC side does not allow the IP addresses in the customer IP range to pass.
The SPD policy on the VPC/IDC side does not contain the source and destination IPs.
No routing policies are configured on the VPN gateway.
Why is a VPN tunnel in the unconnected state?
The possible causes are as follows:
No traffic exists to activate the tunnel.
The public IP address of the VPN gateway is not connected.
The security policy is not correctly configured.
Inconsistent negotiation parameters and modes exist.
Channel negotiation failed error code, how to interpret?
Why does my gateway suddenly fail when it is in use?
The possible causes are as follows:
The public IP address that you access is under Internet censorship and is blocked due to regulation compliance.
You have modified the local settings, such as the protocol, or new protocol parameters are automatically enabled during local upgrade but the parameters are not configured on Tencent Cloud.
Access to Tencent Cloud is prohibited by the local firewall.
Negotiation parameter values, such as SA lifetime, are inconsistent.
The VPN tunnel is deleted.
Why do I need to configure an SPD policy?
An SPD policy specifies the IP ranges in the network in which the VPN gateway resides and the IP ranges in the IDC that can communicate with each other.
Note:
The IP ranges specified in an SPD policy must not overlap with those specified in another SPD policy of the same VPN gateway.
How can I configure health check?
1. First, ensure that the communication mode of the created VPN tunnel is destination routing.
Note:
Create primary and secondary VPN tunnels before you configure health check, to avoid impacts on your business. We recommend that you do not configure health check without primary and secondary VPN tunnels.
Ensure that the IP addresses of the VPN gateway and the customer gateway do not conflict. If the two IP addresses belong to the same IP range, there is no need to configure a separate route to specify the customer gateway.
3. Configure the VPN gateway route and set its priority.
Why is the tunnel in the "unhealthy" status?
The ping test of IP that you configured for health check failed. Please check the configuration.
Do VPNs support the aggresive mode?
How do I configure an SPD policy? Can I enter any peer IP range?
The SPD policy specifies which network segments within the VPN gateway can communicate with which segments in the IDC. The peer IP range is a subset of your local network's IPs accessible to the public network and cannot overlap. For details, see Creating VPN Tunnel.
For an SPD policy-based VPN tunnel, is there a sequence requirement for the local and peer IP ranges in the SPD policy?
No sequence requirements are imposed for the local and peer IP ranges in an SPD policy.
How can I modify the VPN tunnel configuration?
How can I create a VPN tunnel?
What are the mappings between the local and peer IP ranges in an SPD policy?