All Products
Search
Document Center

VPN Gateway:Overview of best practices

Last Updated:Sep 06, 2024

IPsec-VPN supports various scenarios. This topic provides an overview of the best practices in different scenarios and provides links to the relevant references.

Association with a VPN gateway in dual-tunnel mode

VPN gateway network type

Scenario

Reference

Internet

Enable communication between virtual private clouds (VPCs) by using a VPN gateway

Enable communication between two VPCs by using an IPsec-VPN connection in dual-tunnel mode

Synchronize or migrate data by using Data Transmission Service (DTS) over a VPN gateway

Establish IPsec-VPN connections between Alibaba Cloud VPN gateways and other cloud services

Query and analyze the data transfer information of a VPN gateway

Query and analyze the data transfer information of a VPN gateway based on ENI flow logs

Association with a VPN gateway in single-tunnel mode

VPN gateway network type

Scenario

Reference

Internet

Enable communication between VPCs by using a VPN gateway

Establish IPsec-VPN connections between two VPCs

Establish high-availability IPsec-VPN connections

Use VPN Gateway together with other services

Connect multiple offices to each other and to a VPC

Connect multiple offices to each other and to a VPC

Internal network

Encrypt a private connection by using a private VPN gateway

Association with a transit router

Note

In scenarios in which an IPsec-VPN connection is associated with a transit router, the IPsec-VPN connection supports only the single-tunnel mode.

IPsec-VPN connection network type

Scenario

Reference

Internet

Establish high-availability IPsec-VPN connections

Configure active/standby connections by using IPsec-VPN (transit router associated) and an Express Connect circuit

Create multiple IPsec-VPN connections over the Internet for load balancing

Internal network

Enable encrypted connections by using IPsec-VPN

Create multiple private IPsec-VPN connections to implement load balancing

More best practices

You can use IPsec-VPN together with other Alibaba Cloud services to meet other business requirements. The following table lists the scenarios in which IPsec-VPN is used together with other services and provides links to the relevant references.

Note

The following references are not included in the VPN Gateway documentation. After you click a link, you are redirected to the relevant service documentation.

Category

Alibaba Cloud service

Reference

Network connection

NAT Gateway

Use a VPC NAT gateway and a VPN gateway to connect a data center and a VPC

Cloud Enterprise Network (CEN)

Connect a third-party SD-WAN appliance to a transit router to establish communication between data centers and VPCs

Elastic Desktop Service (EDS)

Use IPsec-VPN to access a cloud computer from the Alibaba Cloud Workspace client over a private network

EDS and Express Connect

Use Express Connect circuits and IPsec-VPN gateways to establish active/standby connections to access cloud computers over private networks

Network monitoring

Network Intelligence Service (NIS)

Self-service diagnostics for IPsec-VPN connections

CloudMonitor

Monitor system events of an IPsec-VPN connection

DNS services

Alibaba Cloud DNS PrivateZone

Use Alibaba Cloud DNS PrivateZone and VPN Gateway to allow ECS instances in a VPC to access an on-premises DNS

Access Alibaba Cloud DNS from an on-premises network through a VPN Gateway

Databases

Database Backup (DBS)

Back up a self-managed database in an on-premises data center connected to Alibaba Cloud through VPN Gateway or Smart Access Gateway to OSS or DBS