IPsec-VPN supports various scenarios. This topic provides an overview of the best practices in different scenarios and provides links to the relevant references.
Association with a VPN gateway in dual-tunnel mode
VPN gateway network type | Scenario | Reference |
Internet | Enable communication between virtual private clouds (VPCs) by using a VPN gateway | Enable communication between two VPCs by using an IPsec-VPN connection in dual-tunnel mode |
Synchronize or migrate data by using Data Transmission Service (DTS) over a VPN gateway | ||
Establish IPsec-VPN connections between Alibaba Cloud VPN gateways and other cloud services | ||
Query and analyze the data transfer information of a VPN gateway | Query and analyze the data transfer information of a VPN gateway based on ENI flow logs |
Association with a VPN gateway in single-tunnel mode
VPN gateway network type | Scenario | Reference |
Internet | Enable communication between VPCs by using a VPN gateway | |
Establish high-availability IPsec-VPN connections | ||
Use VPN Gateway together with other services | ||
Connect multiple offices to each other and to a VPC | ||
Internal network | Encrypt a private connection by using a private VPN gateway |
Association with a transit router
In scenarios in which an IPsec-VPN connection is associated with a transit router, the IPsec-VPN connection supports only the single-tunnel mode.
IPsec-VPN connection network type | Scenario | Reference |
Internet | Establish high-availability IPsec-VPN connections | |
Create multiple IPsec-VPN connections over the Internet for load balancing | ||
Internal network | Enable encrypted connections by using IPsec-VPN | Create multiple private IPsec-VPN connections to implement load balancing |
More best practices
You can use IPsec-VPN together with other Alibaba Cloud services to meet other business requirements. The following table lists the scenarios in which IPsec-VPN is used together with other services and provides links to the relevant references.
The following references are not included in the VPN Gateway documentation. After you click a link, you are redirected to the relevant service documentation.
Category | Alibaba Cloud service | Reference |
Network connection | NAT Gateway | Use a VPC NAT gateway and a VPN gateway to connect a data center and a VPC |
Cloud Enterprise Network (CEN) | ||
Elastic Desktop Service (EDS) | ||
EDS and Express Connect | ||
Network monitoring | Network Intelligence Service (NIS) | |
CloudMonitor | ||
DNS services | Alibaba Cloud DNS PrivateZone | |
Access Alibaba Cloud DNS from an on-premises network through a VPN Gateway | ||
Databases | Database Backup (DBS) |