Release notes

更新时间:
复制 MD 格式

VPN Gateway new features, enhancements, and related documentation.

May 2026

Feature

Category

Description

References

DNS configuration for SSL-VPN clients

New feature

You can configure and distribute private DNS server addresses from the SSL server, enabling clients to resolve private domain names within a VPC.

Configure DNS for clients

New features for TR-associated IPsec-VPN connections

New feature

IPsec-VPN connections associated with a Transit Router now support multiple encryption algorithms, authentication algorithms, and DH groups. Newly supported encryption algorithms include AES128-GCM16 and AES256-GCM16, along with DH groups 15 to 24. A 3 Gbps bandwidth option is also available for a single tunnel, in addition to the existing 1 Gbps option.

[New Feature] Enhancements for TR-associated IPsec-VPN connections

February 2026

Feature

Category

Description

References

Enhanced VPN Gateway

New feature

Enhanced VPN Gateway is a new type of IPsec-VPN gateway.

[New Feature] Enhanced IPsec-VPN release (invitational preview)

CDT billing for TR-associated IPsec-VPN connections

New feature

Starting from 00:00 (UTC+8) on March 1, 2026, public data transfer fees for IPsec-VPN connections associated with a Transit Router will be gradually billed through Cloud Data Transfer (CDT).

[Billing Update] CDT billing for Internet traffic from IPsec-VPN connections on Transit Routers

September 2025

Feature

Category

Description

References

New monitoring metrics for BGP and tunnel status

New feature

VPN Gateway now integrates with CloudMonitor, providing metrics for IPsec tunnel status and BGP negotiation status.

Monitor IPsec-VPN connections

May 2025

Feature

Category

Description

References

New region support

New feature

VPN Gateway now supports the Mexico (Queretaro) region.

December 2024

Feature

Category

Description

References

O&M event

New feature

The system periodically performs operations and maintenance (O&M) events on VPN Gateway resources, typically triggered by system upgrades, hardware updates, or bug fixes. After an event is scheduled, you can view the affected resource and its default execution time in the VPN Gateway console. You can change the execution time or let the system run it at the default time. You can also adjust your configurations to minimize any network impact.

November 2024

Feature

Category

Description

References

Dual-tunnel IPsec-VPN connections

Enhancement

Associating an IPsec-VPN connection with a Transit Router upgrades it to dual-tunnel mode. Each connection consists of two tunnels that form an ECMP (Equal-Cost Multipath Routing) link. If one tunnel fails, traffic automatically fails over to the other. In regions with multiple availability zones, the tunnels are distributed across different zones for zone-level disaster recovery.

(Deprecated) Associate with a Transit Router

May 2024

Feature

Category

Description

References

SSL-VPN two-factor authentication

Enhancement

With the discontinuation of IDaaS (Identity as a Service) EIAM 1.0, VPN Gateway now supports IDaaS EIAM 2.0 for SSL-VPN two-factor authentication. To use this feature, create a new VPN Gateway instance or upgrade an existing one.

[Change Notice] SSL-VPN two-factor authentication now supports IDaaS EIAM 2.0

June 2023

Feature

Category

Description

References

Dual-tunnel IPsec-VPN connections

Enhancement

Associating an IPsec-VPN connection with a VPN Gateway instance upgrades it to dual-tunnel mode. Each connection includes an active and a standby tunnel distributed across different availability zones. If the active tunnel fails, traffic automatically fails over to the standby tunnel, providing zone-level disaster recovery.

February 2023

Feature

Category

Description

References

Troubleshooting

New feature

VPN Gateway provides logs for IPsec-VPN and SSL-VPN connections and error codes for IPsec-VPN connections. Through integration with Network Intelligence Service (NIS), you can use instance diagnostics and Reachability Analyzer to troubleshoot VPN Gateway issues.

You can quickly diagnose VPN Gateway issues on the Troubleshooting page of the VPC console.

Reachability Analyzer

New feature

Through integration with Network Intelligence Service (NIS), Reachability Analyzer diagnoses network connectivity and traffic issues for resources connected through a VPN Gateway.

January 2023

Feature

Category

Description

References

IPsec-VPN connection error codes

New feature

VPN Gateway provides error codes for IPsec-VPN connections. If a connection fails, you can use the error code and logs in the VPN Gateway console to troubleshoot the issue.

Troubleshoot IPsec-VPN connection issues

VPN Gateway instance diagnostics

New feature

Through integration with Network Intelligence Service (NIS), VPN Gateway can diagnose instances and recommend fixes for issues such as IPsec-VPN negotiation failures, route configuration errors, and incorrect instance statuses.

View SSL-VPN connection logs

Enhancement

SSL server logs and SSL client logs are now retained for 180 days and can be queried in 10-minute intervals.

View SSL-VPN connection logs

December 2022

Feature

Category

Description

References

View SSL client connections

New feature

Once a client connects via SSL-VPN, you can view the client connection details on the SSL server.

View SSL client connections

Policy priority

Enhancement

Policy-based routes now support priority settings. The system matches traffic against policy-based routes in descending order of priority (a smaller value indicates a higher priority) and forwards traffic based on the matched route.

(Deprecated) Policy-based routes (for classic VPN gateways only)

November 2022

Feature

Category

Description

References

Supported bandwidth for VPN Gateway instances

Enhancement

The maximum bandwidth for VPN Gateway instances is now 1,000 Mbps in multiple regions.

Limits on VPN gateways

SM-based VPN gateway

Enhancement

SM-based VPN gateways now use SSL certificates instead of Key Management Service (KMS) certificates.

Manage SSL certificates

August 2022

Feature

Category

Description

References

IPsec connections support association with Transit Router instances

New feature

Associating an IPsec-VPN connection with a Transit Router instance enables communication between your data center and VPCs with high availability through ECMP (Equal-Cost Multipath Routing).

Association with a Transit Router: Quick Start

April 2022

Feature

Category

Description

References

Private VPN gateways

New feature

Private VPN gateways encrypt private traffic over Express Connect connections and improve network security.

Encrypt a private connection by using a private VPN gateway

August 2021

Feature

Category

Description

References

Self-service upgrade for VPN gateways

New feature

The latest version of VPN Gateway supports BGP dynamic routing and dead peer detection (DPD). You can upgrade your VPN gateway to use these features.

Upgrade a VPN gateway

December 2020

Feature

Category

Description

References

SM-based VPN gateway

New feature

VPN Gateway now supports SM algorithms. You can use an SM-based VPN gateway to establish an IPsec-VPN connection.

Use an SM-based VPN gateway to connect VPCs

June 2020

Feature

Category

Description

References

BGP dynamic routing

New feature

VPN Gateway supports BGP dynamic routing, allowing the gateway to automatically learn and advertise routes.

March 2020

Feature

Category

Description

References

SSL-VPN two-factor authentication

New feature

SSL-VPN integrates with IDaaS (Identity as a Service), offering multiple authentication methods for SSL clients.

SSL-VPN two-factor authentication

April 2019

Feature

Category

Description

References

Route-based IPsec-VPN

Enhancement

VPN Gateway has transitioned from policy-based IPsec-VPN to route-based IPsec-VPN, providing more flexible traffic routing.

Route configuration