This topic applies only to VPN Gateway (Subscription). It does not cover Enhanced VPN gateways (an enhanced VPN gateway provides a default bandwidth of 1 Gbps for each IPsec connection and does not support SSL-VPN).
You can change VPN Gateway (Subscription) specifications in several ways: upgrade, downgrade, temporarily upgrade, or renew with a specification change.
Choose a specification change method
Select a method based on your requirements.
|
Requirement |
Method |
Effective time |
Supports downgrade |
|
Immediately increase bandwidth or enable a feature |
Upgrade |
Takes effect immediately |
No |
|
Immediately decrease bandwidth or disable a feature |
Downgrade |
Takes effect immediately |
Yes |
|
Handle short-term traffic bursts and automatically revert upon expiration |
Temporary upgrade |
Takes effect immediately and automatically reverts upon expiration |
Not supported before reversion |
|
Adjust specifications during renewal |
Renewal with specification change |
Takes effect in the next billing cycle |
Yes |
|
Only extend the expiration date |
Renewal |
Extends the expiration date immediately |
N/A |
Bandwidth specification change limits (single-tunnel mode)
These limits apply only to single-tunnel mode. Dual-tunnel mode has no bandwidth change limits.
-
If the bandwidth is 200 Mbps or less, you cannot upgrade to 500 Mbps or 1,000 Mbps.
-
If the bandwidth is 500 Mbps, you can only upgrade to 1,000 Mbps. Downgrades are not supported.
-
If the bandwidth is 1,000 Mbps, you can only downgrade to 500 Mbps.
Upgrade
Upgrading immediately increases specifications without service interruption.
What you can upgrade:
-
Increase the bandwidth specification
-
Enable the IPsec-VPN or SSL-VPN feature
-
Increase the SSL connection limit
Usage notes
-
If the instance has an unpaid order, pay for or cancel it before upgrading.
-
Single-tunnel mode instances have bandwidth upgrade limits. See the bandwidth change limits above.
-
The upgrade takes effect immediately but may take a few minutes to propagate.
Billing
After the upgrade, you are billed based on the new specifications. You must pay the price difference for the remainder of the current billing cycle. The actual price is shown on the console. For more information about VPN Gateway billing, see Billing.
Procedure
-
In the Bandwidth column of the target VPN Gateway instance, click Upgrade.
-
On the page that opens, increase the bandwidth specification, enable the IPsec-VPN or SSL-VPN feature, or upgrade the SSL connection limit for the instance as required.
Downgrade
Downgrading immediately decreases instance specifications.
What you can downgrade:
-
Decrease the bandwidth specification
-
Disable the IPsec-VPN or SSL-VPN feature
-
Decrease the SSL connection limit
Usage notes
-
If the instance has an unpaid order, pay for or cancel it before downgrading.
-
Before you disable IPsec-VPN, delete all IPsec connections from the instance. IPsec connection (attached to a VPN gateway).
-
Before you disable the SSL-VPN feature, you must delete all SSL servers and IPsec servers from the VPN Gateway instance. For more information, see Delete an SSL server and Delete an IPsec-VPN server.
-
Single-tunnel mode instances have bandwidth downgrade limits. See the bandwidth change limits above.
-
When you downgrade bandwidth, traffic exceeding the new limit may cause interruptions. Ensure your application has a reconnection mechanism.
-
When you decrease the SSL connection limit, interruptions may occur if connected clients exceed the new limit. Ensure your application has a reconnection mechanism.
-
The downgrade takes effect immediately but may take a few minutes to propagate.
Billing
After the downgrade, you are billed based on the new specifications. You may receive a refund for the price difference for the remainder of the billing cycle. The refund amount depends on factors such as discounts and coupons used at the time of purchase. The actual amount is shown on the order page. For more information, see Unsubscription rules.
Procedure
-
In the Bandwidth column of the target VPN Gateway instance, click Downgrade.
-
On the page that opens, decrease the Bandwidth, disable the IPsec-VPN or SSL-VPN feature, or decrease the SSL-VPN Connections for the instance as required.
Temporary upgrade
Temporarily increase specifications to handle short-term traffic bursts. The instance automatically reverts to the original specifications at the reversion time you set.
Usage notes
-
You cannot perform a temporary upgrade if a pending renewal with specification change order exists for the instance.
-
If the instance has an unpaid order, pay for or cancel it before performing a temporary upgrade.
-
Minimum duration: 48 hours.
-
A temporary upgrade cannot be downgraded or refunded before reversion. Choose the reversion time carefully.
-
Temporary upgrades support enabling IPsec-VPN or SSL-VPN but not disabling them.
-
The upgrade may take a few minutes to propagate.
At the reversion time, the instance automatically restores its original configuration without interrupting services. However, the bandwidth decrease may cause transient disconnections or packet loss. Ensure your application has a reconnection mechanism.
Temporary upgrades are billed by the hour. You must pay the price difference for the configuration during the temporary upgrade period. For the monthly prices of each feature, see Billing. The actual fee is shown on the console.
Procedure
-
In the Actions column of the target VPN Gateway instance, select .
-
On the new page, configure the Bandwidth, enable IPsec-VPN, enable SSL-VPN, set the SSL-VPN Connections (this option is available only after enabling SSL-VPN), and set the Restore Time.
Renewal with specification change
Modify instance specifications for the next billing cycle. New specifications take effect when the renewed cycle begins; the current cycle is unaffected.
Example: An instance with 10 Mbps bandwidth expires on April 30, 2025. You renew with a specification change to 100 Mbps for one month. The bandwidth stays at 10 Mbps until April 30, then upgrades to 100 Mbps in May.
Supported specification changes
-
Adjust the bandwidth specification (upgrade or downgrade)
-
Enable or disable the IPsec-VPN feature
-
Enable or disable the SSL-VPN feature
-
Adjust the SSL connection limit
Usage notes
-
If the instance has an unpaid order, pay for or cancel it before performing a renewal with specification change.
-
A temporary upgrade is not supported for the VPN Gateway instance before the order for renewal with specification change takes effect.
-
If you downgrade bandwidth or the SSL connection limit, connections may be interrupted. Ensure your application has a reconnection mechanism.
Billing
Fees are calculated based on the new specifications and the renewal duration. For more information about pricing, see Billing.
Procedure
-
In the Actions column of the target VPN Gateway instance, choose .
-
On the new page, configure the Billing Cycle, Bandwidth, whether to enable IPsec-VPN, whether to enable SSL-VPN, and set the SSL-VPN Connections. This option is available only after you enable SSL-VPN.
Renewal
If you only need to renew the VPN Gateway (Subscription) instance, in the Actions column of the target VPN Gateway instance, click Renew.
Pricing information.