VPN Connections
Note the following when using a VPN connection:
After configuring VPN parameters, you need to add routing policies for your VPN gateway in the route table associated with the subnet, so that network requests from CVMs in the subnet to access the peer IP range can reach the customer gateway through the VPN tunnel.
For a VPN gateway v1.0, after configuring the route table, you need to ping an IP address in the peer IP range from a CVM in the VPC to activate the VPN tunnel.
The stability of the VPN connection depends on the ISP's public network.
The VPN connection only supports the PSK authentication method rather than CA authentication.
SPD or route IP ranges of the VPN connection cannot be specified as the following IP ranges:
Multicast addresses that are all 0, all 225, or start with 224.
Loopback addresses: 127.x.x.x/8.
IPv6 IP ranges.
VPN Gateway
VPN Connections is a region-level service, but you can also connect to your VPN gateway in any region over the internet.
You cannot specify a public IP or the ISP of the public IP for the VPN gateway. IPv6 and anycast IP addresses are also not supported.
The bandwidth allocated by Tencent Cloud for inbound and outbound traffic is equivalent to the bandwidth purchased by the user.
Currently, only VPN 4.0 gateways with specifications of 200 Mbps, 500 Mbps, 1,000 Mbps and 3,000 Mbps support the dynamic BGP feature.
Routing priority: Static routing > dynamic BGP routing.
Private VPN: Only VPC type IPSec VPN 4.0 version is supported. If you need to use a private VPN, submit a ticket for consultation. Customer Gateway
You must specify the IP address of the customer gateway. The public IP of the customer gateway cannot be the following IP addresses:
Multicast addresses that are all 0, all 225, or start with 224.
Loopback addresses: 127.x.x.x/8.
IP Addresses with host bits being all 0 or all 1, for example:
Class-A IP addresses that start with 1-126, such as 1-126.0.0.0
and 1-126.255.255.255
.
Class-B IP addresses that start with 128-191, such as 128-191.x.0.0
and 128-191.x.255.255
.
Class-C IP addresses that start with 192-223, such as 192-223.x.x.0
and 192-223.x.x.255
.
Internal service addresses: 169.254.x.x/16
.
IPv6 addresses.
If you use an IPsec VPN connection to interconnect resources in two VPCs, the VPCs are each other's customer gateway, and their IP ranges cannot overlap.
SSL VPN Server
The server supports only UDP but not TCP.
To modify information such as port, authentication method, and encryption algorithm, you need to download the client configuration again.
The client and local IP ranges cannot overlap.
Identity verification relies on an EIAM application and cannot be directly interconnected with other identity providers (IdPs) for verification. You can use EIAM to interconnect with the verification source of your enterprise. You can also select a verification method supported by EIAM, such as SMS, WeCom, and AD. Currently, identity verification is in beta test. To try it out, submit a ticket for application. You can use CAM if identity verification is enabled.
SSL VPN Client
You need to prepare the client on your own. An SSL VPN connection supports the open-source OpenVPN client or other compatible commercial clients.
Each client can use only one SSL client configuration certificate. You cannot use the same certificate for multiple clients.
Supported OpenVPN versions: 2.4.8–3.x.
Identity verification is supported only by OpenVPN 3.x or other compatible clients.
In a Windows environment, should your client's OpenVPN be version 3.4.0 or higher, it becomes imperative to configure both encryption and authentication algorithms for the SSL server setup. It is noteworthy that the authentication algorithm exclusively supports SHA1.
In a single operation, up to 100 SSL clients can be created in bulk.
Resource Limits
Limits on IPsec VPN
Note:
The private VPN gateway currently does not support dynamic BGP routing.
|
VPC IPsec VPN gateways per region per account | 10 |
CCN IPsec VPN gateways per region per account | 10 |
Customer gateways in one region | 20 |
VPN tunnels supported by one customer gateway | 20 Note: The number of VPN tunnels supported by a customer gateway is the quota for the account. Only one VPN tunnel can be established between a pair of customer gateway and VPN gateway. |
VPN tunnels that can be created on one VPN gateway | 20 |
SPDs in a VPN tunnel | 10 |
Peer IP ranges supported by a SPD | 50 |
Routes supported by each VPN gateway route table | 1,000 |
Number of routes can be added at one time on the console | 10 |
Dynamic BGP-learned routing entries supported by each VPN gateway | 500 |
Routing entries sent via the dynamic BGP for each VPN tunnel | 10,000 |
BGP ASN | The default value is 64,551, with an allowable range from 1 to 4,294,967,295. Notably, the numbers 139,341, 45,090 and 58,835 are unavailable for use. |
Limits on SSL VPN
|
VPC SSL VPN Gateways per Region per Account | 10 |
SSL VPN servers that can be created for an SSL VPN gateway | 1 |
Local IP ranges that can be added on an SSL VPN server | 5 |
Client IP ranges that can be added on an SSL VPN server | 1 Note: To ensure that all your clients can be assigned an IP address, we recommend you specify a client IP range containing IP addresses more than the SSL VPN connections. |
Validity period of the SSL VPN client certificate | In 3 |
SSL VPN connections | A [5,100] Mbps SSL VPN gateway can sustain up to 100 SSL VPN connections. A 200/500 Mbps SSL VPN gateway can sustain up to 500 SSL VPN connections. A 1,000 Mbps SSL VPN gateway can sustain up to 1,000 SSL VPN connections. Note: The maximum number of SSL VPN connections is the number of connections to the client. Once it is configured, it cannot be modified. Therefore, plan an appropriate value before configuration. The number of clients that can be connected to an SSL VPN gateway is also contingent upon the number of SSL connections configured at the time of creation. For instance, if you set up the gateway with five connections, then the maximum number of clients that can be connected to this gateway is five. |
Was this page helpful?