Manage IPsec-VPN O&M events

Updated at:

To provide a stable IPsec-VPN service, VPN Gateway performs periodic system maintenance, such as restarting an instance. These maintenance activities are called O&M events. The VPN Gateway service initiates and automatically performs O&M events, typically for system upgrades, hardware updates, or bug fixes. After an O&M event is scheduled, you can log on to the VPN Gateway console to view the affected resources and the default execution time. You can also modify the execution time. If you do not specify a time, the O&M event runs automatically at the default time. An O&M event may affect your network connectivity. You can modify your configuration to mitigate the impact of the event.

Background information

IPsec-VPN O&M events are integrated with Network Intelligence Service (NIS). After an O&M event is created, you can view event details in both the NIS console and the VPN Gateway console, including the affected resources and the default execution time.

  • In the NIS console, you can also view O&M events for the VPN Gateway service from the last 30 days, view historical alert trends for your VPN Gateway resources.

  • In the VPN Gateway console, you can view detailed information about the resources affected by an O&M event and modify the event execution time.

This topic describes how to view O&M event information in the VPN Gateway console. For information about how to view O&M event information in the NIS console, see View NIS exception events.

Impact of O&M events

This section describes how O&M events affect IPsec-VPN connections. Before an O&M event is performed, you can use the solutions in the following table to mitigate the impact on your IPsec-VPN connections.

Note

If SSL-VPN clients are connected to the VPN Gateway instance, their network connections are interrupted during the O&M event. The clients must reconnect after the event is complete.

Resource

Impact

Mitigation strategy

IPsec-VPN connection in dual-tunnel mode

  • If both tunnels of an IPsec-VPN connection are available, an O&M event on the active tunnel interrupts it. Alibaba Cloud automatically reroutes traffic to the other tunnel. This causes a brief network interruption that lasts no more than one minute. After the O&M event is complete, Alibaba Cloud automatically switches traffic back to the original tunnel. If the tunnel has no traffic, your network is not affected when the tunnel is maintained.

    Note

    When a tunnel is interrupted, ensure that your local gateway device supports automatic path failover. Otherwise, traffic rerouting on the Alibaba Cloud side may cause asymmetric routing and lead to a prolonged network interruption.

  • If an IPsec-VPN connection has only one available tunnel, a network interruption of up to 10 minutes occurs when the system maintains it. Your network is not affected when the system maintains the unavailable tunnel.

  1. Configure both tunnels of the IPsec-VPN connection to ensure that they are both available.

  2. Before system maintenance starts on a tunnel, modify the configuration on your local gateway device to reroute all traffic to the other tunnel and then interrupt the tunnel scheduled for maintenance. After the O&M event is complete, restore the configuration to switch traffic back to the original tunnel. This solution can prevent network interruptions.

IPsec-VPN connection in single-tunnel mode

A network interruption of up to 5 minutes occurs.

  • For an IPsec-VPN connection associated with a VPN Gateway instance, we recommend first upgrading the IPsec-VPN connection to dual-tunnel mode. Then, follow the mitigation strategy for dual-tunnel mode.

  • For an IPsec-VPN connection that is associated with a Transit Router, we recommend creating multiple IPsec-VPN connections between your on-premises data center and the Transit Router to build redundant links.

    Before system maintenance starts on an IPsec-VPN connection, modify the configuration on your local gateway device to reroute all traffic to another IPsec-VPN connection and then interrupt the connection to be maintained. After the O&M event is complete, restore the configuration to switch traffic back to the original IPsec-VPN connection. This solution can prevent network interruptions.

View O&M events

To view O&M events for VPN Gateway instances and IPsec-VPN connection instances, perform the following steps.

VPN Gateway instance

  1. Log on to the VPN gateway console.
  2. In the top navigation bar, select the region where the VPN gateway instance resides.

  3. On the VPN Gateways page, find the target VPN Gateway instance.

  4. The O&M Events column shows the event ID, the default (automatic) execution time of the current event, and the execution time of the previous event.

IPsec-VPN connection

  1. Log on to the VPN gateway console.
  2. In the left-side navigation pane, choose VPN > IPsec Connections.
  3. In the top navigation bar, select the region where the IPsec-VPN connection is created.
  4. On the IPsec-VPN connection page, find the target IPsec-VPN connection instance.

  5. The O&M Events column shows the event ID, the default (automatic) execution time of the current event, and the execution time of the previous event.

View affected resources and modify execution time

Important

An O&M event for a VPN Gateway instance or an IPsec-VPN connection instance indicates that the instance is at high risk and is running on a best-effort basis. View the affected resources, understand the impact of O&M events, and then perform the event as soon as possible.

VPN Gateway instance

  1. On the VPN Gateways page, find the target VPN Gateway instance.

  2. In the Actions column, click O&M Events.

    The O&M Events dialog box shows the affected resources and allows you to modify the event execution time.

    Note

    If you only want to view the resources affected by the O&M event and do not plan to modify the event execution time, do not click OK in the dialog box.

    Parameter

    Description

    Latest Execution Time

    Specifies the execution time for the O&M event.

    • Execute Now (default)

      After you click OK in the O&M Events dialog box, the system immediately performs the O&M event.

    • Specify Execution Time

      Allows you to specify a custom execution time. The specified time cannot be later than the default execution time. The system automatically performs the O&M event at the specified time.

    Affected VPN Public IP Addresses

    The public IP address of the gateway affected by the O&M event.

    • For a VPN Gateway instance that supports IPsec-VPN connections in dual-tunnel mode, identify the affected gateway IP address:

      • If the affected address is SSL Address:, all IPsec-VPN connections on the VPN Gateway instance are not affected. Only SSL-VPN clients are affected.

      • If the affected address is IPsec Address 1: or IPsec Address 2:, the tunnels of the IPsec-VPN connections that are associated with the gateway IP address are affected. A gateway IP address and a customer gateway identify a tunnel. All tunnels associated with this IP address are affected. SSL-VPN clients on the VPN Gateway instance are not affected.

    • For a VPN Gateway instance that supports IPsec-VPN connections in single-tunnel mode, an O&M event affects all associated IPsec-VPN connections and SSL-VPN clients.

IPsec-VPN connection instance

  1. On the IPsec-VPN connection page, find the target IPsec-VPN connection instance.

  2. In the Actions column, click O&M Events.

    The O&M Events dialog box shows the affected resources and allows you to modify the event execution time.

    Note

    If you only want to view the resources affected by the O&M event and do not plan to modify the event execution time, do not click OK in the dialog box.

    Parameter

    Description

    Latest Execution Time

    Specifies the execution time for the O&M event.

    • Execute Now (default)

      After you click OK in the O&M Events dialog box, the system immediately performs the O&M event.

    • Specify Execution Time

      Allows you to specify a custom execution time. The specified time cannot be later than the default execution time.

    Affected VPN Public IP Addresses

    The public IP address of the gateway affected by the O&M event.

    The event affects the IPsec-VPN connection or tunnels associated with this gateway IP address. For an IPsec-VPN connection in dual-tunnel mode, a gateway IP address and a customer gateway identify the affected tunnel.