To maintain SSL-VPN service stability, SSL-VPN undergoes periodic system maintenance such as instance restarts. These maintenance activities are called O&M events. The VPN Gateway service initiates and automatically executes O&M events, typically triggered by routine system upgrades, hardware specification upgrades, or fixes for issues in previous versions. When an O&M event is scheduled for your SSL-VPN service, you can view the affected resources and default execution time in the VPN Gateway console. You can also change the execution time. If you do not specify a time, the O&M event runs automatically at the default scheduled time and takes no more than 5 minutes. An O&M event interrupts SSL-VPN client connections. After the event completes, clients must reconnect.
Background
If your VPN Gateway instance has IPsec-VPN connections, manage their O&M events by following the instructions in the IPsec-VPN connection documentation.
SSL-VPN O&M events integrate with Network Intelligence Service (NIS). When an O&M event is scheduled for SSL-VPN, you can view event details, including the affected resources and default execution time, in both the NIS console and the VPN Gateway console.
-
In the NIS console, you can also view O&M events for the VPN Gateway service from the last 30 days, view historical alert trends for your VPN Gateway resources.
-
In the VPN Gateway console, you can view detailed information about the resources affected by an O&M event and modify the event execution time.
This topic describes how to view O&M event information in the VPN Gateway console. For information about how to view O&M event information in the NIS console, see View NIS exception events.
View O&M events
- Log on to the VPN gateway console.
In the top navigation bar, select the region where the VPN gateway instance resides.
-
On the VPN Gateways page, find the target VPN Gateway instance.
-
The O&M Events column shows the event ID, the default execution time for the current O&M event, and the execution time of the previous event.
View resources and set the execution time
An O&M event on a VPN Gateway instance often indicates that the instance is operational but at high risk. Execute the O&M event as soon as possible after you review the affected resources. After the event completes, SSL-VPN clients need only reconnect.
-
On the VPN Gateways page, find the target VPN Gateway instance.
-
In the Actions column, click O&M Events.
The O&M Events dialog box displays the affected resources and allows you to change the execution time.
NoteIf you only want to view the resources affected by the O&M event without changing the execution time, do not click OK in the O&M Events dialog box.
O&M events may cause up to 5 minutes of VPN connection interruption.
Number
Description
①
Change the execution time for the O&M event.
-
Execute Now (default)
After you click OK in the O&M Events dialog box, the system immediately executes the O&M event.
-
Specify Execution Time
Set a custom execution time for the O&M event. The specified time cannot be later than the default execution time. The system automatically executes the O&M event at the specified time.
②
The gateway IP address affected by the current O&M event.
-
For a VPN Gateway instance that supports IPsec-VPN connections in dual-tunnel mode, check which gateway IP address is affected:
-
If the affected address is an SSL Address:: This O&M event affects all SSL-VPN clients associated with the VPN Gateway instance. IPsec-VPN connections on the instance are not affected.
-
If the affected address is not an SSL Address:: This O&M event does not affect SSL-VPN clients. Only IPsec-VPN connections on the VPN Gateway instance are affected.
-
-
For a VPN Gateway instance that supports IPsec-VPN connections in single-tunnel mode, an O&M event affects all associated SSL-VPN clients and IPsec-VPN connections.
NoteIf this O&M event affects IPsec-VPN connections, follow the instructions in the IPsec-VPN connection documentation.
-