diff --git a/docs/vpn/umn/ALL_META.TXT.json b/docs/vpn/umn/ALL_META.TXT.json new file mode 100644 index 000000000..8d6736bd1 --- /dev/null +++ b/docs/vpn/umn/ALL_META.TXT.json @@ -0,0 +1,372 @@ +[ + { + "uri":"en-us_topic_0035391332.html", + "product_code":"vpn", + "code":"1", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"Overview", + "title":"Overview", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391393.html", + "product_code":"vpn", + "code":"2", + "des":"A Virtual Private Network (VPN) establishes an encrypted, Internet-based communications tunnel between a user and a Virtual Private Cloud (VPC). With VPN, you can connect", + "doc_type":"usermanual", + "kw":"Virtual Private Network,Overview,User Guide", + "title":"Virtual Private Network", + "githuburl":"" + }, + { + "uri":"en-us_topic_0160974607.html", + "product_code":"vpn", + "code":"3", + "des":"The Internet Protocol Security (IPsec) VPN is an encrypted tunneling technology that uses encrypted security services to establish confidential and secure communication t", + "doc_type":"usermanual", + "kw":"IPsec VPN,Overview,User Guide", + "title":"IPsec VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391412.html", + "product_code":"vpn", + "code":"4", + "des":"With the VPN between the VPC and your traditional data center, you can easily use the ECSs and block storage resources provided by the cloud platform.Applications can be ", + "doc_type":"usermanual", + "kw":"Application Scenarios,Overview,User Guide", + "title":"Application Scenarios", + "githuburl":"" + }, + { + "uri":"en-us_topic_0081947484.html", + "product_code":"vpn", + "code":"5", + "des":"The following standards and protocols are associated with the IPsec VPN:RFC 4301: Security Architecture for the Internet ProtocolRFC 2403: The Use of HMAC-MD5-96 within E", + "doc_type":"usermanual", + "kw":"Reference Standards and Protocols,Overview,User Guide", + "title":"Reference Standards and Protocols", + "githuburl":"" + }, + { + "uri":"en-us_topic_0185622695.html", + "product_code":"vpn", + "code":"6", + "des":"A region and availability zone (AZ) identify the location of a data center. You can create resources in a specific region and AZ.A region is a physical data center, which", + "doc_type":"usermanual", + "kw":"Region and AZ,Overview,User Guide", + "title":"Region and AZ", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391382.html", + "product_code":"vpn", + "code":"7", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"Getting Started", + "title":"Getting Started", + "githuburl":"" + }, + { + "uri":"en-us_topic_0122970066.html", + "product_code":"vpn", + "code":"8", + "des":"A VPC provides an isolated virtual network for ECSs. You can configure and manage the network as required.Create a VPC by following the procedure provided in this section", + "doc_type":"usermanual", + "kw":"(Optional) Create a VPC,Getting Started,User Guide", + "title":"(Optional) Create a VPC", + "githuburl":"" + }, + { + "uri":"en-us_topic_0122970067.html", + "product_code":"vpn", + "code":"9", + "des":"You can add subnets during VPC creation. If required, you can also create subnets for an existing VPC.The created subnet is configured with DHCP by default. After an ECS ", + "doc_type":"usermanual", + "kw":"(Optional) Create a Subnet for the VPC,Getting Started,User Guide", + "title":"(Optional) Create a Subnet for the VPC", + "githuburl":"" + }, + { + "uri":"en-us_topic_0060118606.html", + "product_code":"vpn", + "code":"10", + "des":"By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. You need to create a VPN in your V", + "doc_type":"usermanual", + "kw":"Creating a VPN,Getting Started,User Guide", + "title":"Creating a VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035634996.html", + "product_code":"vpn", + "code":"11", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"(Optional) Configure Security Group Rules", + "title":"(Optional) Configure Security Group Rules", + "githuburl":"" + }, + { + "uri":"en-us_topic_0013748715.html", + "product_code":"vpn", + "code":"12", + "des":"To improve ECS access security, you can create a security group, define security group rules, and add ECSs in the VPC to the security group. We recommend that you allocat", + "doc_type":"usermanual", + "kw":"Creating a Security Group,(Optional) Configure Security Group Rules,User Guide", + "title":"Creating a Security Group", + "githuburl":"" + }, + { + "uri":"en-us_topic_0030969470.html", + "product_code":"vpn", + "code":"13", + "des":"After a security group is created, you can add rules to the security group. A rule applies either to inbound traffic (ingress) or outbound traffic (egress). After ECSs ar", + "doc_type":"usermanual", + "kw":"Adding a Security Group Rule,(Optional) Configure Security Group Rules,User Guide", + "title":"Adding a Security Group Rule", + "githuburl":"" + }, + { + "uri":"en-us_topic_0030969471.html", + "product_code":"vpn", + "code":"14", + "des":"If the source of an inbound security group rule or destination of an outbound security group rule needs to be changed, you need to first delete the security group rule an", + "doc_type":"usermanual", + "kw":"Deleting a Security Group Rule,(Optional) Configure Security Group Rules,User Guide", + "title":"Deleting a Security Group Rule", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391378.html", + "product_code":"vpn", + "code":"15", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"Management", + "title":"Management", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035506845.html", + "product_code":"vpn", + "code":"16", + "des":"You can view details about an existing VPN.Log in to the management console.Click in the upper left corner and select the desired region and project.On the console homep", + "doc_type":"usermanual", + "kw":"Viewing a VPN,Management,User Guide", + "title":"Viewing a VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391295.html", + "product_code":"vpn", + "code":"17", + "des":"If the VPN network information conflicts the VPC network information or you need to adjust VPN configurations, you can modify a VPN.Log in to the management console.Click", + "doc_type":"usermanual", + "kw":"Modifying a VPN,Management,User Guide", + "title":"Modifying a VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035616925.html", + "product_code":"vpn", + "code":"18", + "des":"You can delete a VPN to release network resources if the VPN is no longer required.Log in to the management console.Click in the upper left corner and select a region an", + "doc_type":"usermanual", + "kw":"Deleting a VPN,Management,User Guide", + "title":"Deleting a VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0107396413.html", + "product_code":"vpn", + "code":"19", + "des":"A VPN tag identifies a VPN. Tags can be added to VPNs to facilitate VPN identification and administration. You can add a tag to a VPN when creating the VPN. Alternatively", + "doc_type":"usermanual", + "kw":"Managing VPN Tags,Management,User Guide", + "title":"Managing VPN Tags", + "githuburl":"" + }, + { + "uri":"en-us_topic_0114174493.html", + "product_code":"vpn", + "code":"20", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"VPN Best Practice", + "title":"VPN Best Practice", + "githuburl":"" + }, + { + "uri":"en-us_topic_0066871940.html", + "product_code":"vpn", + "code":"21", + "des":"By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. After a VPN is created, configure ", + "doc_type":"usermanual", + "kw":"Connecting to a VPC Through a VPN,VPN Best Practice,User Guide", + "title":"Connecting to a VPC Through a VPN", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391365.html", + "product_code":"vpn", + "code":"22", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"FAQs", + "title":"FAQs", + "githuburl":"" + }, + { + "uri":"vpn_faq_0021.html", + "product_code":"vpn", + "code":"23", + "des":"By default, a user can have a maximum of five IPsec VPNs. If your quota cannot fulfill your service requirements, submit a service ticket to increase the quota.", + "doc_type":"usermanual", + "kw":"How Many IPsec VPNs Can I Have?,FAQs,User Guide", + "title":"How Many IPsec VPNs Can I Have?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0036149069.html", + "product_code":"vpn", + "code":"24", + "des":"The IPsec VPN tunnel works in passive mode, which triggers automatic negotiation only when traffic sent by the local end passes through the tunnel.", + "doc_type":"usermanual", + "kw":"Do IPsec VPNs Support Automatic Negotiation?,FAQs,User Guide", + "title":"Do IPsec VPNs Support Automatic Negotiation?", + "githuburl":"" + }, + { + "uri":"vpn_faq_0055.html", + "product_code":"vpn", + "code":"25", + "des":"Log in to the management console and click Virtual Private Network.In the VPN list, locate the target VPN and click View Policyin the Operationcolumn to view IKE and IPse", + "doc_type":"usermanual", + "kw":"What Do I Do If VPN Setup Fails?,FAQs,User Guide", + "title":"What Do I Do If VPN Setup Fails?", + "githuburl":"" + }, + { + "uri":"vpn_faq_0056.html", + "product_code":"vpn", + "code":"26", + "des":"The security group denies the access from all sources by default. If you want to access your ECSs, modify the security group configuration and allow the access from the r", + "doc_type":"usermanual", + "kw":"How Can I Handle the Failure in Accessing the ECSs from My Data Center or LAN Even If the VPN Has Be", + "title":"How Can I Handle the Failure in Accessing the ECSs from My Data Center or LAN Even If the VPN Has Been Set Up?", + "githuburl":"" + }, + { + "uri":"vpn_faq_0057.html", + "product_code":"vpn", + "code":"27", + "des":"Check whether you have properly configured the firewall policies for the access from the public IP address of the cloud VPN to the public IP address of your data center o", + "doc_type":"usermanual", + "kw":"What Do I Do If I Cannot Access My Data Center or LAN from the ECSs After a VPN Connection Has Been ", + "title":"What Do I Do If I Cannot Access My Data Center or LAN from the ECSs After a VPN Connection Has Been Set Up?", + "githuburl":"" + }, + { + "uri":"vpn_faq_0058.html", + "product_code":"vpn", + "code":"28", + "des":"If the two VPCs are in the same region, you can use a VPC peering connection to enable communication between them.If the two VPCs are in different regions, you can use a ", + "doc_type":"usermanual", + "kw":"Does a VPN Allow for Communication Between Two VPCs?,FAQs,User Guide", + "title":"Does a VPN Allow for Communication Between Two VPCs?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0044789110.html", + "product_code":"vpn", + "code":"29", + "des":"The maximum number obtained by multiplying the number of local subnets and that of remote subnets cannot exceed 2500.", + "doc_type":"usermanual", + "kw":"What Is the Limitation on the Number of Local and Remote Subnets of a VPN?,FAQs,User Guide", + "title":"What Is the Limitation on the Number of Local and Remote Subnets of a VPN?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0045305370.html", + "product_code":"vpn", + "code":"30", + "des":"After a VPN is created, its status changes to Normalonly after the VMs or physical servers on the two sides of the VPN communicate with each other.IKE v1:If no traffic go", + "doc_type":"usermanual", + "kw":"Why Is Not Connected Displayed as the Status for a Successfully Created VPN?,FAQs,User Guide", + "title":"Why Is Not Connected Displayed as the Status for a Successfully Created VPN?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0051518174.html", + "product_code":"vpn", + "code":"31", + "des":"The time required for VPN configurations to take effect increases linearly with the number obtained by multiplying the number of local subnets and that of remote subnets.", + "doc_type":"usermanual", + "kw":"How Long Is Required for Issued VPN Configurations to Take Effect?,FAQs,User Guide", + "title":"How Long Is Required for Issued VPN Configurations to Take Effect?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0109312453.html", + "product_code":"vpn", + "code":"32", + "des":"Due to the symmetry of the tunnel, the VPN parameters configured on the cloud must be the same as those configured in your own data center. If they are different, a VPN c", + "doc_type":"usermanual", + "kw":"How Do I Configure a Remote Device for a VPN?,FAQs,User Guide", + "title":"How Do I Configure a Remote Device for a VPN?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0109676043.html", + "product_code":"vpn", + "code":"33", + "des":"Most devices that meet IPsec VPN standard and reference protocol requirements can be used as the remote VPN devices, for example, Cisco ASA firewalls, Huawei USG6xxxxseri", + "doc_type":"usermanual", + "kw":"Which Remote VPN Devices Are Supported?,FAQs,User Guide", + "title":"Which Remote VPN Devices Are Supported?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0142368417.html", + "product_code":"vpn", + "code":"34", + "des":"You can perform the following steps to handle the issues:Check the ECS specifications. Rate limiting is not performed for the VPN ingress on the cloud, so the issue may b", + "doc_type":"usermanual", + "kw":"What Can I Do If the VPN Fails or the Network Speed of the VPN Is Slow?,FAQs,User Guide", + "title":"What Can I Do If the VPN Fails or the Network Speed of the VPN Is Slow?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0142373840.html", + "product_code":"vpn", + "code":"35", + "des":"Currently, the VPN service does not support the SSL VPNs.", + "doc_type":"usermanual", + "kw":"Are SSL VPNs Supported?,FAQs,User Guide", + "title":"Are SSL VPNs Supported?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0035391366.html", + "product_code":"vpn", + "code":"36", + "des":"Quotas are enforced for service resources on the platform to prevent unforeseen spikes in resource usage. Quotas can limit the number or amount of resources available to ", + "doc_type":"usermanual", + "kw":"What Is the VPN Quota?,FAQs,User Guide", + "title":"What Is the VPN Quota?", + "githuburl":"" + }, + { + "uri":"en-us_topic_0041174633.html", + "product_code":"vpn", + "code":"37", + "des":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "doc_type":"usermanual", + "kw":"A Change History,User Guide", + "title":"A Change History", + "githuburl":"" + } +] \ No newline at end of file diff --git a/docs/vpn/umn/CLASS.TXT.json b/docs/vpn/umn/CLASS.TXT.json new file mode 100644 index 000000000..07b96ae31 --- /dev/null +++ b/docs/vpn/umn/CLASS.TXT.json @@ -0,0 +1,335 @@ +[ + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"Overview", + "uri":"en-us_topic_0035391332.html", + "doc_type":"usermanual", + "p_code":"", + "code":"1" + }, + { + "desc":"A Virtual Private Network (VPN) establishes an encrypted, Internet-based communications tunnel between a user and a Virtual Private Cloud (VPC). With VPN, you can connect", + "product_code":"vpn", + "title":"Virtual Private Network", + "uri":"en-us_topic_0035391393.html", + "doc_type":"usermanual", + "p_code":"1", + "code":"2" + }, + { + "desc":"The Internet Protocol Security (IPsec) VPN is an encrypted tunneling technology that uses encrypted security services to establish confidential and secure communication t", + "product_code":"vpn", + "title":"IPsec VPN", + "uri":"en-us_topic_0160974607.html", + "doc_type":"usermanual", + "p_code":"1", + "code":"3" + }, + { + "desc":"With the VPN between the VPC and your traditional data center, you can easily use the ECSs and block storage resources provided by the cloud platform.Applications can be ", + "product_code":"vpn", + "title":"Application Scenarios", + "uri":"en-us_topic_0035391412.html", + "doc_type":"usermanual", + "p_code":"1", + "code":"4" + }, + { + "desc":"The following standards and protocols are associated with the IPsec VPN:RFC 4301: Security Architecture for the Internet ProtocolRFC 2403: The Use of HMAC-MD5-96 within E", + "product_code":"vpn", + "title":"Reference Standards and Protocols", + "uri":"en-us_topic_0081947484.html", + "doc_type":"usermanual", + "p_code":"1", + "code":"5" + }, + { + "desc":"A region and availability zone (AZ) identify the location of a data center. You can create resources in a specific region and AZ.A region is a physical data center, which", + "product_code":"vpn", + "title":"Region and AZ", + "uri":"en-us_topic_0185622695.html", + "doc_type":"usermanual", + "p_code":"1", + "code":"6" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"Getting Started", + "uri":"en-us_topic_0035391382.html", + "doc_type":"usermanual", + "p_code":"", + "code":"7" + }, + { + "desc":"A VPC provides an isolated virtual network for ECSs. You can configure and manage the network as required.Create a VPC by following the procedure provided in this section", + "product_code":"vpn", + "title":"(Optional) Create a VPC", + "uri":"en-us_topic_0122970066.html", + "doc_type":"usermanual", + "p_code":"7", + "code":"8" + }, + { + "desc":"You can add subnets during VPC creation. If required, you can also create subnets for an existing VPC.The created subnet is configured with DHCP by default. After an ECS ", + "product_code":"vpn", + "title":"(Optional) Create a Subnet for the VPC", + "uri":"en-us_topic_0122970067.html", + "doc_type":"usermanual", + "p_code":"7", + "code":"9" + }, + { + "desc":"By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. You need to create a VPN in your V", + "product_code":"vpn", + "title":"Creating a VPN", + "uri":"en-us_topic_0060118606.html", + "doc_type":"usermanual", + "p_code":"7", + "code":"10" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"(Optional) Configure Security Group Rules", + "uri":"en-us_topic_0035634996.html", + "doc_type":"usermanual", + "p_code":"7", + "code":"11" + }, + { + "desc":"To improve ECS access security, you can create a security group, define security group rules, and add ECSs in the VPC to the security group. We recommend that you allocat", + "product_code":"vpn", + "title":"Creating a Security Group", + "uri":"en-us_topic_0013748715.html", + "doc_type":"usermanual", + "p_code":"11", + "code":"12" + }, + { + "desc":"After a security group is created, you can add rules to the security group. A rule applies either to inbound traffic (ingress) or outbound traffic (egress). After ECSs ar", + "product_code":"vpn", + "title":"Adding a Security Group Rule", + "uri":"en-us_topic_0030969470.html", + "doc_type":"usermanual", + "p_code":"11", + "code":"13" + }, + { + "desc":"If the source of an inbound security group rule or destination of an outbound security group rule needs to be changed, you need to first delete the security group rule an", + "product_code":"vpn", + "title":"Deleting a Security Group Rule", + "uri":"en-us_topic_0030969471.html", + "doc_type":"usermanual", + "p_code":"11", + "code":"14" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"Management", + "uri":"en-us_topic_0035391378.html", + "doc_type":"usermanual", + "p_code":"", + "code":"15" + }, + { + "desc":"You can view details about an existing VPN.Log in to the management console.Click in the upper left corner and select the desired region and project.On the console homep", + "product_code":"vpn", + "title":"Viewing a VPN", + "uri":"en-us_topic_0035506845.html", + "doc_type":"usermanual", + "p_code":"15", + "code":"16" + }, + { + "desc":"If the VPN network information conflicts the VPC network information or you need to adjust VPN configurations, you can modify a VPN.Log in to the management console.Click", + "product_code":"vpn", + "title":"Modifying a VPN", + "uri":"en-us_topic_0035391295.html", + "doc_type":"usermanual", + "p_code":"15", + "code":"17" + }, + { + "desc":"You can delete a VPN to release network resources if the VPN is no longer required.Log in to the management console.Click in the upper left corner and select a region an", + "product_code":"vpn", + "title":"Deleting a VPN", + "uri":"en-us_topic_0035616925.html", + "doc_type":"usermanual", + "p_code":"15", + "code":"18" + }, + { + "desc":"A VPN tag identifies a VPN. Tags can be added to VPNs to facilitate VPN identification and administration. You can add a tag to a VPN when creating the VPN. Alternatively", + "product_code":"vpn", + "title":"Managing VPN Tags", + "uri":"en-us_topic_0107396413.html", + "doc_type":"usermanual", + "p_code":"15", + "code":"19" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"VPN Best Practice", + "uri":"en-us_topic_0114174493.html", + "doc_type":"usermanual", + "p_code":"", + "code":"20" + }, + { + "desc":"By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. After a VPN is created, configure ", + "product_code":"vpn", + "title":"Connecting to a VPC Through a VPN", + "uri":"en-us_topic_0066871940.html", + "doc_type":"usermanual", + "p_code":"20", + "code":"21" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"FAQs", + "uri":"en-us_topic_0035391365.html", + "doc_type":"usermanual", + "p_code":"", + "code":"22" + }, + { + "desc":"By default, a user can have a maximum of five IPsec VPNs. If your quota cannot fulfill your service requirements, submit a service ticket to increase the quota.", + "product_code":"vpn", + "title":"How Many IPsec VPNs Can I Have?", + "uri":"vpn_faq_0021.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"23" + }, + { + "desc":"The IPsec VPN tunnel works in passive mode, which triggers automatic negotiation only when traffic sent by the local end passes through the tunnel.", + "product_code":"vpn", + "title":"Do IPsec VPNs Support Automatic Negotiation?", + "uri":"en-us_topic_0036149069.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"24" + }, + { + "desc":"Log in to the management console and click Virtual Private Network.In the VPN list, locate the target VPN and click View Policyin the Operationcolumn to view IKE and IPse", + "product_code":"vpn", + "title":"What Do I Do If VPN Setup Fails?", + "uri":"vpn_faq_0055.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"25" + }, + { + "desc":"The security group denies the access from all sources by default. If you want to access your ECSs, modify the security group configuration and allow the access from the r", + "product_code":"vpn", + "title":"How Can I Handle the Failure in Accessing the ECSs from My Data Center or LAN Even If the VPN Has Been Set Up?", + "uri":"vpn_faq_0056.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"26" + }, + { + "desc":"Check whether you have properly configured the firewall policies for the access from the public IP address of the cloud VPN to the public IP address of your data center o", + "product_code":"vpn", + "title":"What Do I Do If I Cannot Access My Data Center or LAN from the ECSs After a VPN Connection Has Been Set Up?", + "uri":"vpn_faq_0057.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"27" + }, + { + "desc":"If the two VPCs are in the same region, you can use a VPC peering connection to enable communication between them.If the two VPCs are in different regions, you can use a ", + "product_code":"vpn", + "title":"Does a VPN Allow for Communication Between Two VPCs?", + "uri":"vpn_faq_0058.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"28" + }, + { + "desc":"The maximum number obtained by multiplying the number of local subnets and that of remote subnets cannot exceed 2500.", + "product_code":"vpn", + "title":"What Is the Limitation on the Number of Local and Remote Subnets of a VPN?", + "uri":"en-us_topic_0044789110.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"29" + }, + { + "desc":"After a VPN is created, its status changes to Normalonly after the VMs or physical servers on the two sides of the VPN communicate with each other.IKE v1:If no traffic go", + "product_code":"vpn", + "title":"Why Is Not Connected Displayed as the Status for a Successfully Created VPN?", + "uri":"en-us_topic_0045305370.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"30" + }, + { + "desc":"The time required for VPN configurations to take effect increases linearly with the number obtained by multiplying the number of local subnets and that of remote subnets.", + "product_code":"vpn", + "title":"How Long Is Required for Issued VPN Configurations to Take Effect?", + "uri":"en-us_topic_0051518174.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"31" + }, + { + "desc":"Due to the symmetry of the tunnel, the VPN parameters configured on the cloud must be the same as those configured in your own data center. If they are different, a VPN c", + "product_code":"vpn", + "title":"How Do I Configure a Remote Device for a VPN?", + "uri":"en-us_topic_0109312453.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"32" + }, + { + "desc":"Most devices that meet IPsec VPN standard and reference protocol requirements can be used as the remote VPN devices, for example, Cisco ASA firewalls, Huawei USG6xxxxseri", + "product_code":"vpn", + "title":"Which Remote VPN Devices Are Supported?", + "uri":"en-us_topic_0109676043.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"33" + }, + { + "desc":"You can perform the following steps to handle the issues:Check the ECS specifications. Rate limiting is not performed for the VPN ingress on the cloud, so the issue may b", + "product_code":"vpn", + "title":"What Can I Do If the VPN Fails or the Network Speed of the VPN Is Slow?", + "uri":"en-us_topic_0142368417.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"34" + }, + { + "desc":"Currently, the VPN service does not support the SSL VPNs.", + "product_code":"vpn", + "title":"Are SSL VPNs Supported?", + "uri":"en-us_topic_0142373840.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"35" + }, + { + "desc":"Quotas are enforced for service resources on the platform to prevent unforeseen spikes in resource usage. Quotas can limit the number or amount of resources available to ", + "product_code":"vpn", + "title":"What Is the VPN Quota?", + "uri":"en-us_topic_0035391366.html", + "doc_type":"usermanual", + "p_code":"22", + "code":"36" + }, + { + "desc":"HUAWEI CLOUD Help Center presents technical documents to help you quickly get started with HUAWEI CLOUD services. The technical documents include Service Overview, Price Details, Purchase Guide, User Guide, API Reference, Best Practices, FAQs, and Videos.", + "product_code":"vpn", + "title":"A Change History", + "uri":"en-us_topic_0041174633.html", + "doc_type":"usermanual", + "p_code":"", + "code":"37" + } +] \ No newline at end of file diff --git a/docs/vpn/umn/PARAMETERS.txt b/docs/vpn/umn/PARAMETERS.txt new file mode 100644 index 000000000..6da8d5f07 --- /dev/null +++ b/docs/vpn/umn/PARAMETERS.txt @@ -0,0 +1,3 @@ +version="" +language="en-us" +type="" \ No newline at end of file diff --git a/docs/vpn/umn/en-us_image_0000001404528466.png b/docs/vpn/umn/en-us_image_0000001404528466.png new file mode 100644 index 000000000..daf53fd45 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001404528466.png differ diff --git a/docs/vpn/umn/en-us_image_0000001404848230.jpg b/docs/vpn/umn/en-us_image_0000001404848230.jpg new file mode 100644 index 000000000..b02afe636 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001404848230.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001405148354.jpg b/docs/vpn/umn/en-us_image_0000001405148354.jpg new file mode 100644 index 000000000..28092c102 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405148354.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001405148570.png b/docs/vpn/umn/en-us_image_0000001405148570.png new file mode 100644 index 000000000..fcd4cf4b2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405148570.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405151706.png b/docs/vpn/umn/en-us_image_0000001405151706.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405151706.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405171846.png b/docs/vpn/umn/en-us_image_0000001405171846.png new file mode 100644 index 000000000..1a8fd5bdc Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405171846.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405176804.png b/docs/vpn/umn/en-us_image_0000001405176804.png new file mode 100644 index 000000000..28a39f44b Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405176804.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405314402.jpg b/docs/vpn/umn/en-us_image_0000001405314402.jpg new file mode 100644 index 000000000..949fed3e9 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405314402.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001405317654.png b/docs/vpn/umn/en-us_image_0000001405317654.png new file mode 100644 index 000000000..9e0a935fb Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405317654.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405485434.png b/docs/vpn/umn/en-us_image_0000001405485434.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405485434.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405496560.png b/docs/vpn/umn/en-us_image_0000001405496560.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405496560.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405630570.png b/docs/vpn/umn/en-us_image_0000001405630570.png new file mode 100644 index 000000000..10e3a9d76 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405630570.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405640430.png b/docs/vpn/umn/en-us_image_0000001405640430.png new file mode 100644 index 000000000..3880d33d1 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405640430.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405646142.png b/docs/vpn/umn/en-us_image_0000001405646142.png new file mode 100644 index 000000000..e2b98462e Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405646142.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405650458.png b/docs/vpn/umn/en-us_image_0000001405650458.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405650458.png differ diff --git a/docs/vpn/umn/en-us_image_0000001405655248.png b/docs/vpn/umn/en-us_image_0000001405655248.png new file mode 100644 index 000000000..8530092e9 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001405655248.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455555929.png b/docs/vpn/umn/en-us_image_0000001455555929.png new file mode 100644 index 000000000..5ac6e2e6c Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455555929.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455557817.png b/docs/vpn/umn/en-us_image_0000001455557817.png new file mode 100644 index 000000000..e65a9f184 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455557817.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455569161.png b/docs/vpn/umn/en-us_image_0000001455569161.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455569161.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455570241.png b/docs/vpn/umn/en-us_image_0000001455570241.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455570241.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455711269.jpg b/docs/vpn/umn/en-us_image_0000001455711269.jpg new file mode 100644 index 000000000..49464ad58 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455711269.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001455717309.png b/docs/vpn/umn/en-us_image_0000001455717309.png new file mode 100644 index 000000000..3880d33d1 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455717309.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455827749.jpg b/docs/vpn/umn/en-us_image_0000001455827749.jpg new file mode 100644 index 000000000..50d93d434 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455827749.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001455829029.png b/docs/vpn/umn/en-us_image_0000001455829029.png new file mode 100644 index 000000000..3880d33d1 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455829029.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455829553.jpg b/docs/vpn/umn/en-us_image_0000001455829553.jpg new file mode 100644 index 000000000..6c709cff4 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455829553.jpg differ diff --git a/docs/vpn/umn/en-us_image_0000001455845961.png b/docs/vpn/umn/en-us_image_0000001455845961.png new file mode 100644 index 000000000..a06a21362 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455845961.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455909921.png b/docs/vpn/umn/en-us_image_0000001455909921.png new file mode 100644 index 000000000..3880d33d1 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455909921.png differ diff --git a/docs/vpn/umn/en-us_image_0000001455916097.png b/docs/vpn/umn/en-us_image_0000001455916097.png new file mode 100644 index 000000000..3880d33d1 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0000001455916097.png differ diff --git a/docs/vpn/umn/en-us_image_0107432228.png b/docs/vpn/umn/en-us_image_0107432228.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0107432228.png differ diff --git a/docs/vpn/umn/en-us_image_0109860229.png b/docs/vpn/umn/en-us_image_0109860229.png new file mode 100644 index 000000000..32d225a39 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0109860229.png differ diff --git a/docs/vpn/umn/en-us_image_0118534037.png b/docs/vpn/umn/en-us_image_0118534037.png new file mode 100644 index 000000000..595a9b056 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0118534037.png differ diff --git a/docs/vpn/umn/en-us_image_0118696493.png b/docs/vpn/umn/en-us_image_0118696493.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0118696493.png differ diff --git a/docs/vpn/umn/en-us_image_0118696764.png b/docs/vpn/umn/en-us_image_0118696764.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0118696764.png differ diff --git a/docs/vpn/umn/en-us_image_0118696766.png b/docs/vpn/umn/en-us_image_0118696766.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0118696766.png differ diff --git a/docs/vpn/umn/en-us_image_0123091916.png b/docs/vpn/umn/en-us_image_0123091916.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0123091916.png differ diff --git a/docs/vpn/umn/en-us_image_0141273034.png b/docs/vpn/umn/en-us_image_0141273034.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0141273034.png differ diff --git a/docs/vpn/umn/en-us_image_0147165026.png b/docs/vpn/umn/en-us_image_0147165026.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0147165026.png differ diff --git a/docs/vpn/umn/en-us_image_0152727234.png b/docs/vpn/umn/en-us_image_0152727234.png new file mode 100644 index 000000000..35e283157 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0152727234.png differ diff --git a/docs/vpn/umn/en-us_image_0152926732.png b/docs/vpn/umn/en-us_image_0152926732.png new file mode 100644 index 000000000..79ca15dd5 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0152926732.png differ diff --git a/docs/vpn/umn/en-us_image_0154037992.png b/docs/vpn/umn/en-us_image_0154037992.png new file mode 100644 index 000000000..13e196ca6 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0154037992.png differ diff --git a/docs/vpn/umn/en-us_image_0155717676.png b/docs/vpn/umn/en-us_image_0155717676.png new file mode 100644 index 000000000..12f0d879f Binary files /dev/null and b/docs/vpn/umn/en-us_image_0155717676.png differ diff --git a/docs/vpn/umn/en-us_image_0155784843.png b/docs/vpn/umn/en-us_image_0155784843.png new file mode 100644 index 000000000..cbb489151 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0155784843.png differ diff --git a/docs/vpn/umn/en-us_image_0159197475.png b/docs/vpn/umn/en-us_image_0159197475.png new file mode 100644 index 000000000..33c844036 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0159197475.png differ diff --git a/docs/vpn/umn/en-us_image_0159201188.png b/docs/vpn/umn/en-us_image_0159201188.png new file mode 100644 index 000000000..8e09bc614 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0159201188.png differ diff --git a/docs/vpn/umn/en-us_image_0159206951.png b/docs/vpn/umn/en-us_image_0159206951.png new file mode 100644 index 000000000..1466ed0b7 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0159206951.png differ diff --git a/docs/vpn/umn/en-us_image_0160993816.png b/docs/vpn/umn/en-us_image_0160993816.png new file mode 100644 index 000000000..8f2039895 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0160993816.png differ diff --git a/docs/vpn/umn/en-us_image_0161052507.png b/docs/vpn/umn/en-us_image_0161052507.png new file mode 100644 index 000000000..1909444d2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0161052507.png differ diff --git a/docs/vpn/umn/en-us_image_0161052509.png b/docs/vpn/umn/en-us_image_0161052509.png new file mode 100644 index 000000000..3322328b6 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0161052509.png differ diff --git a/docs/vpn/umn/en-us_image_0170041086.png b/docs/vpn/umn/en-us_image_0170041086.png new file mode 100644 index 000000000..e6ce3d56d Binary files /dev/null and b/docs/vpn/umn/en-us_image_0170041086.png differ diff --git a/docs/vpn/umn/en-us_image_0184026531.png b/docs/vpn/umn/en-us_image_0184026531.png new file mode 100644 index 000000000..1303a51c2 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0184026531.png differ diff --git a/docs/vpn/umn/en-us_image_0210485645.png b/docs/vpn/umn/en-us_image_0210485645.png new file mode 100644 index 000000000..5666bb1f5 Binary files /dev/null and b/docs/vpn/umn/en-us_image_0210485645.png differ diff --git a/docs/vpn/umn/en-us_image_0210486152.png b/docs/vpn/umn/en-us_image_0210486152.png new file mode 100644 index 000000000..d36739fdf Binary files /dev/null and b/docs/vpn/umn/en-us_image_0210486152.png differ diff --git a/docs/vpn/umn/en-us_topic_0013748715.html b/docs/vpn/umn/en-us_topic_0013748715.html new file mode 100644 index 000000000..fe3a0fb1e --- /dev/null +++ b/docs/vpn/umn/en-us_topic_0013748715.html @@ -0,0 +1,46 @@ + + +
To improve ECS access security, you can create a security group, define security group rules, and add ECSs in the VPC to the security group. We recommend that you allocate ECSs that have different Internet access policies to different security groups.
+
in the upper left corner and select the desired region and project.
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Name + |
+Specifies the security group name. This parameter is mandatory. +The security group name can contain a maximum of 64 characters, which may consist of letters, digits, underscores (_), hyphens (-), and periods (.). The name cannot contain spaces. + NOTE:
+You can change the security group name after a security group is created. It is recommended that you use different names for different security groups. + |
+sg-318b + |
+
Description + |
+Provides supplementary information about the security group. This parameter is optional. +The security group description can contain a maximum of 255 characters and cannot contain angle brackets (< or >). + |
+N/A + |
+
After a security group is created, you can add rules to the security group. A rule applies either to inbound traffic (ingress) or outbound traffic (egress). After ECSs are added to the security group, they are protected by the rules of that group.
+
in the upper left corner and select the desired region and project.You can click + to add more inbound rules.
+
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Protocol/Application + |
+Specifies the network protocol. Currently, the value can be All, TCP, UDP, ICMP, GRE, or others. + |
+TCP + |
+
Port & Source + + |
+Port: specifies the port or port range over which the traffic can reach your ECS. The value ranges from 1 to 65535. + |
+22 or 22-30 + |
+
Source: specifies the source of the security group rule. The value can be another security group, a CIDR block, or a single IP address. For example: +
|
+0.0.0.0/0 +default + |
+|
Description + |
+Provides supplementary information about the security group rule. This parameter is optional. +The security group rule description can contain a maximum of 255 characters and cannot contain angle brackets (< or >). + |
+N/A + |
+
You can click + to add more outbound rules.
+
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Protocol/Application + |
+Specifies the network protocol. Currently, the value can be All, TCP, UDP, ICMP, GRE, or others. + |
+TCP + |
+
Port & Destination + |
+Port: specifies the port or port range over which the traffic can leave your ECS. The value ranges from 1 to 65535. + |
+22 or 22-30 + |
+
Destination: specifies the destination of the security group rule. The value can be another security group, a CIDR block, or a single IP address. For example: +
|
+0.0.0.0/0 +default + |
+|
Description + |
+Provides supplementary information about the security group rule. This parameter is optional. +The security group rule description can contain a maximum of 255 characters and cannot contain angle brackets (< or >). + |
+N/A + |
+
If the source of an inbound security group rule or destination of an outbound security group rule needs to be changed, you need to first delete the security group rule and add a new one.
+
Security group rules use whitelists. Deleting a security group rule may result in ECS access failures. Exercise caution when deleting security group rules.
+
in the upper left corner and select the desired region and project.Deleting Multiple Security Group Rules at Once.
+You can also select multiple security group rules and click Delete above the security group rule list to delete multiple rules at a time.
+ +If the VPN network information conflicts the VPC network information or you need to adjust VPN configurations, you can modify a VPN.
+
in the upper left corner and select a region and project.Quotas are enforced for service resources on the platform to prevent unforeseen spikes in resource usage. Quotas can limit the number or amount of resources available to users. For example, the VPN quota limits the number of VPNs that you can create. You can also request more quotas if you need them.
+This section describes how to view the VPN resource usage and the total quotas in a specified region.
+
in the upper left corner and select the desired region and project.
.The Service Quota page is displayed.
+If a quota cannot meet service requirements, click Increase Quota to adjust it.
+The system does not support online quota adjustment. If you need to adjust a quota, call the hotline or send an email to the customer service mailbox. Customer service personnel will timely process your request for quota adjustment and inform you of the real-time progress by making a call or sending an email.
+You need to prepare the following information before dialing the hotline number or sending an email:
+Log in to the management console using the cloud account, click the username in the upper right corner, select My Credential from the drop-down list, and obtain the domain name, project name, and project ID on the My Credential page.
+A Virtual Private Network (VPN) establishes an encrypted, Internet-based communications tunnel between a user and a Virtual Private Cloud (VPC). With VPN, you can connect to a VPC and access service resources in it.
+By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN.
+A VPN consists of a VPN gateway and one or more VPN connections. A VPN gateway provides an Internet egress for a VPC and works together with the remote gateway in the local data center. A VPN connection uses the Internet-based encryption technology to connect the VPN gateway and the remote gateway to enable communication between the local data center and VPC. The VPN connection allows you to quickly build secure hybrid cloud environment. Figure 1 shows the VPN networking.
+ +With the VPN between the VPC and your traditional data center, you can easily use the ECSs and block storage resources provided by the cloud platform. Applications can be migrated to the cloud and additional web servers can be deployed to increase the computing capacity on a network. In this way, a hybrid cloud is built, which reduces IT O&M costs and protects enterprise core data from being leaked.
+The VPN service allows you to set up site-to-site VPN connections or VPN connections from one site to multiple sites.
+You can set up a VPN to connect a local data center to a VPC, thus building a hybrid cloud. Figure 1 shows a site-to-site VPN connection.
+ +You can also set up a VPN to connect multiple local data centers to a VPC, thus building a hybrid cloud. Figure 2 shows a VPN connection from one site to multiple sites.
+
The subnet CIDR blocks of each site involved in the VPN connection cannot overlap.
+You can view details about an existing VPN.
+
in the upper left corner and select the desired region and project.Status + |
+Description + |
+
|---|---|
Normal + |
+Indicates that the VPN is successfully created and communication with the local data center through the VPN is normal. + |
+
Not connected + |
+Indicates that the VPN is successfully created but has not been used for communication with the local data center. + |
+
Creating + |
+Indicates that the VPN is being created. + |
+
Updating + |
+Indicates that VPN information is being updated. + |
+
Deleting + |
+Indicates that the VPN is being deleted. + |
+
Abnormal + |
+Indicates that the VPN is abnormal. + |
+
Frozen + |
+Indicates that the VPN is frozen. + |
+
You can delete a VPN to release network resources if the VPN is no longer required.
+
in the upper left corner and select a region and project.The IPsec VPN tunnel works in passive mode, which triggers automatic negotiation only when traffic sent by the local end passes through the tunnel.
+Release Date + |
+What's New + |
+
|---|---|
2019-02-22 + |
+This release incorporates the following changes: +Updated the region description in Table 2. + |
+
2019-02-18 + |
+Accepted in OTC-4.0/Agile-02.2019 + |
+
2019-02-11 + |
+This release incorporates the following changes: +
|
+
2019-02-02 + |
+This release incorporates the following changes: +
|
+
2019-01-30 + |
+This release incorporates the following changes: +
|
+
2019-01-23 + |
+This release incorporates the following changes: +
|
+
2019-01-02 + |
+This release incorporates the following change: +Added description about the PFS function to the section for configuring the IPsec policy of a VPN. + |
+
2018-04-30 + |
+This issue is the eighth official release, which incorporates the following change: +Added description about how to add tags during VPN creation. + |
+
2017-08-30 + |
+This issue is the seventh official release, which incorporates the following change: +Added description about VPC and subnet tags. + |
+
2017-07-30 + |
+This issue is the sixth official release, which incorporates the following change: +
|
+
2017-04-28 + |
+This issue is the fifth official release, which incorporates the following change: +
|
+
2017-03-30 + |
+This issue is the fourth official release, which incorporates the following change: +
|
+
2017-01-20 + |
+This issue is the third official release, which incorporates the following change: +
|
+
2016-12-30 + |
+This issue is the second official release, which incorporates the following change: +
|
+
2016-10-19 + |
+This issue is the first official release. + |
+
The maximum number obtained by multiplying the number of local subnets and that of remote subnets cannot exceed 2500.
+After a VPN is created, its status changes to Normal only after the VMs or physical servers on the two sides of the VPN communicate with each other.
+If no traffic goes through the VPN for a period of time, the VPN needs to be renegotiated. The negotiation time depends on the value of Lifecycle (s) in the IPsec policy. Generally, the value of Lifecycle (s) is 3600 (1 hour), indicating that the negotiation will be initiated in the fifty-fourth minute. If the negotiation succeeds, the connection remains to the next round of negotiation. If the negotiation fails, the status is set to be disconnected within one hour. The connection can be restored after the two sides of the VPN communicates with each other. The disconnection can be avoided by using a network monitoring tool, such as IP SLA, to generate packets.
+The time required for VPN configurations to take effect increases linearly with the number obtained by multiplying the number of local subnets and that of remote subnets.
+By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. You need to create a VPN in your VPC and update the security group rules.
+In Figure 1, a VPC has two subnets: 192.168.1.0/24 and 192.168.2.0/24. On your router deployed in your physical data center, you also have two subnets: 192.168.3.0/24 and 192.168.4.0/24. You can create a VPN to enable subnets in your VPC to communicate with those in your data center.
+ +Currently, the site-to-site VPN and hub-spoke VPN are supported. You need to set up VPNs in both your data center and the VPC to establish the VPN connection.
+Ensure that the VPN in your VPC and that in your data center use the same Internet Key Exchange (IKE) and IPsec policy configurations. Before creating a VPN, familiarize yourself with the protocols described in Table 1 and ensure that your device meets the requirements and configuration constraints of the involved protocols.
+ +Parameter + |
+Description + |
+Constraint + |
+
|---|---|---|
RFC 2409 + |
+Defines the IKE protocol, which negotiates and verifies key information to safeguard VPNs. + |
+
|
+
RFC 4301 + |
+Defines the IPsec architecture, the security services that IPsec offers, and the collaboration between components. + |
+Use the IPsec tunnel to set up a VPN connection. + |
+
Perform the following procedure to create a VPN that sets up a secure, isolated communication tunnel between your data center and cloud services.
+
in the upper left corner and select the desired region and project.Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Region + |
+Specifies the desired region. Regions are geographic areas isolated from each other. Resources are region-specific and cannot be used across regions through internal network connections. For low network latency and quick resource access, select the nearest region. + |
+eu-de + |
+
Name + |
+Specifies the VPN name. + |
+VPN-001 + |
+
VPC + |
+Specifies the VPC name. + |
+VPC-001 + |
+
Local Subnet + |
+A local subnet is a VPC subnet that accesses a customer network through a VPN. +
|
+192.168.1.0/24, +192.168.2.0/24 + |
+
Remote Gateway + |
+Specifies the public IP address of the VPN in your data center or on the private network. This IP address is used for communicating with the VPN in the VPC. + |
+N/A + |
+
Remote Subnet + |
+A remote subnet is a subnet in the customer data center that accesses a VPC through a VPN. The remote and local subnets cannot have overlapping or matching CIDR blocks. The remote subnet CIDR block cannot overlap with CIDR blocks involved in existing VPC peering connections created for the local VPC. + |
+192.168.3.0/24, +192.168.4.0/24 + |
+
PSK + |
+Specifies the pre-shared key, which is a private key shared by two ends of a VPN connection. The PSK configurations for both ends of a VPN connection must be the same. This key is used for VPN connection negotiation. +The value is a string of 6 to 128 characters. + |
+Test@123 + |
+
Confirm PSK + |
+Specifies the confirm pre-shared key. + |
+Test@123 + |
+
Tag + |
+Specifies the VPN tag, which consists of a key and value pair. You can add a maximum of ten tags to each VPN. +The tag key and value must meet the requirements listed in Table 3. + |
+
|
+
Advanced Settings + |
++ | +Custom + |
+
Parameter + |
+Requirement + |
+Example Value + |
+
|---|---|---|
Key + |
+
|
+vpn_key1 + |
+
Value + |
+
|
+vpn-01 + |
+
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Authentication Algorithm + |
+Specifies the authentication hash algorithm. The value can be SHA1, SHA2-256, SHA2-384, SHA2-512, or MD5. +The default value is SHA1. + |
+SHA1 + |
+
Encryption Algorithm + |
+Specifies the encryption algorithm. The value can be AES-128, AES-192, AES-256, or 3DES. The 3DES algorithm is not recommended because it is risky. +The default value is AES-128. + |
+AES-128 + |
+
DH Algorithm + |
+Specifies the Diffie-Hellman key exchange algorithm. The value can be Group 1, Group 2, Group 5, Group 14, Group 15, Group 16, Group 19, Group 20, or Group 21. +The DH group security level from the highest to lowest is as follows: Group 21 > Group 20 > Group 19 > Group 16 > Group 15 > Group 14 > Group 5 > Group 2 > Group 1. +The default value is Group 5. + |
+Group 5 + |
+
Version + |
+Specifies the version of the IKE protocol. The value can be v1 or v2. +The default value is v1. + |
+v1 + |
+
Lifecycle (s) + |
+Specifies the lifetime of the security association (SA), in seconds. +The SA will be renegotiated if its lifetime expires. +The default value is 86400. + |
+86400 + |
+
Negotiation Mode + |
+If the IKE policy version is v1, the negotiation mode can be configured. The value can only be Main. +The default value is Main. + |
+Main + |
+
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Authentication Algorithm + |
+Specifies the authentication hash algorithm. The value can be SHA1, SHA2-256, SHA2-384, SHA2-512, or MD5. +The default value is SHA1. + |
+SHA1 + |
+
Encryption Algorithm + |
+Specifies the encryption algorithm. The value can be AES-128, AES-192, AES-256, or 3DES. The 3DES algorithm is not recommended because it is risky. +The default value is AES-128. + |
+AES-128 + |
+
PFS + |
+Specifies the perfect forward secrecy (PFS), which is used to configure the IPsec tunnel negotiation. +This function enables two parties to exchange the DH keys during the phase-two negotiation, improving key security. It is recommended that you enable this function. +You can disable this function by selecting Disable from the drop-down list. +The PFS used at the two sides of a VPN must be the same. Otherwise, the negotiation will fail. If you disable this function on the console, you also need to disable it at the customer side of the VPN. +The value can be DH group 1, DH group 2, DH group 5, DH group 14, DH group 15, DH group 16, DH group 19, DH group 20, or DH group 21. +The PFS group security level from the highest to lowest is as follows: DH group 21 > DH group 20 > DH group 19 > DH group 16 > DH group 15 > DH group 14 > DH group 5 > DH group 2 > DH group 1. +The default value is DH group 5. + |
+DH group 5 + |
+
Transfer Protocol + |
+Specifies the security protocol used for IPsec to transmit and encapsulate user data. The value can be AH, ESP, or AH-ESP. +The default value is ESP. + |
+ESP + |
+
Lifecycle (s) + |
+Specifies the lifetime of the SA, in seconds. +The SA will be renegotiated if its lifetime expires. +The default value is 3600. + |
+3600 + |
+
The IKE policy specifies the encryption and authentication algorithms to use in the negotiation phase of an IPsec tunnel. The IPsec policy specifies the protocol, encryption algorithm, and authentication algorithm to use in the data transmission phase of an IPsec tunnel. These parameters must be the same between the VPN in your VPC and that in your data center. If they are different, the VPN cannot be set up.
+By default, ECSs in a VPC cannot communicate with your data center or private network. To enable communication between them, use a VPN. After a VPN is created, configure the security group and check the connectivity between the local and remote networks to ensure that the VPN is available. VPNs can be classified into the following two types:
+You have created the VPC and subnet required by the VPN.
+In Figure 1, a VPC has two subnets: 192.168.1.0/24 and 192.168.2.0/24. On your router deployed in your physical data center, you also have two subnets: 192.168.3.0/24 and 192.168.4.0/24. You can create a VPN to enable subnets in your VPC to communicate with those in your data center.
+ +The IP address pools for the local and remote subnets cannot overlap with each other. For example, if the local VPC has two subnets, 192.168.1.0/24 and 192.168.2.0/24, the IP address pool for the remote subnets cannot contain these two subnets.
+The security group must allow packets from the VPN to pass. You can run the ping command to check whether the security group of the VPC allows packets from the VPN to pass.
+A route must be configured for the remote LAN to enable VPN traffic to be forwarded to network devices on the LAN. If the VPN traffic cannot be forwarded to the network devices, check whether the remote LAN has policies configured to refuse the traffic.
+The following standards and protocols are associated with the IPsec VPN:
+A VPN tag identifies a VPN. Tags can be added to VPNs to facilitate VPN identification and administration. You can add a tag to a VPN when creating the VPN. Alternatively, you can add a tag to a created VPN on the VPN details page. A maximum of ten tags can be added to each VPN.
+A tag consists of a key and value pair. Table 1 lists the tag key and value requirements.
+ +Parameter + |
+Requirement + |
+Example Value + |
+
|---|---|---|
Key + |
+
|
+vpn_key1 + |
+
Value + |
+
|
+vpn-01 + |
+
in the upper left corner and select a region and project.Both the tag key and value must be specified.
+You can add multiple tag keys and values to refine your search results. If you add more than one tag to search for VPCs, the VPCs containing all specified tags will be displayed.
+The system displays the VPNs you are looking for based on the entered tag keys and values.
+
in the upper left corner and select a region and project.The page showing details about the particular VPN is displayed.
+On the Tags tab, you can view details about tags added to the current VPN, including the number of tags and the key and value of each tag.
+Click Add Tag in the upper left corner. In the displayed dialog box, enter the key and value of the tag to be added, and click OK.
+Locate the row that contains the tag to be edited and click Edit in the Operation column. In the Edit Tag dialog box, change the tag value and click OK.
+Locate the row that contains the tag to be deleted, and click Delete in the Operation column. In the displayed Delete Tag dialog box, click Yes.
+Due to the symmetry of the tunnel, the VPN parameters configured on the cloud must be the same as those configured in your own data center. If they are different, a VPN cannot be established.
+To set up a VPN, you also need to configure the IPsec VPN on the router or firewall in your own data center. The configuration method may vary depending on your network device in use. For details, see the configuration guide of your network device.
+This section describes how to configure the IPsec VPN on a Huawei USG6600 series V100R001C30SPC300 firewall for your reference.
+For example, the subnets of the data center are 192.168.3.0/24 and 192.168.4.0/24, the subnets of the VPC are 192.168.1.0/24 and 192.168.2.0/24, and the public IP address of the IPsec tunnel egress in the VPC is XXX.XXX.XX.XX, which can be obtained from the local gateway parameters of the IPsec VPN in the VPC.
+display version +17:20:502017/03/09 +Huawei Versatile Security Platform Software +Software Version: USG6600 V100R001C30SPC300 (VRP (R) Software, Version 5.30)+
acl number 3065 vpn-instance vpn64 +rule 1 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 +rule 2 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 +rule 3 permit ip source 192.168.4.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 +rule 4 permit ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 +q+
ike proposal 64 +dh group5 +authentication-algorithm sha1 +integrity-algorithm hmac-sha2-256 +sa duration 3600 +q+
ike peer vpnikepeer_64 +pre-shared-key ******** (******** specifies the pre-shared key.) +ike-proposal 64 +undo version 2 +remote-address vpn-instance vpn64 93.188.242.110 +sa binding vpn-instance vpn64 +q+
ipsec proposal ipsecpro64 +encapsulation-mode tunnel +esp authentication-algorithm sha1 +q+
ipsec policy vpnipsec64 1 isakmp +security acl 3065 +pfs dh-group5 +ike-peer vpnikepeer_64 +proposal ipsecpro64 +local-address xx.xx.xx.xx +q+
interface GigabitEthernet0/0/2.64 +ipsec policy vpnipsec64 +q+
After you perform the preceding operations, you can test the connectivity between your ECSs in the cloud and the hosts in your data center. For details, see the following figure.
+
Most devices that meet IPsec VPN standard and reference protocol requirements can be used as the remote VPN devices, for example, Cisco ASA firewalls, Huawei USG6xxxx series firewalls, USG9xxxx series firewalls, Hillstone firewalls, and Cisco ISR routers. Table 1 lists the supported Huawei USG6xxxx and USG9xxxx firewalls.
+ +Supported Remote VPN Device + |
+Description + |
+
|---|---|
Huawei USG6000 series + |
+USG6320/6310/6510-SJJ +USG6306/6308/6330/6350/6360/6370/6380/6390/6507/6530/6550/6570:2048 +USG6620/6630/6650/6660/6670/6680 + |
+
Huawei USG9000 series + |
+USG9520/USG9560/USG9580 + |
+
Other devices that meet the requirements in the reference protocols described in section Reference Standards and Protocols can also be deployed. However, some devices may fail to add because of inconsistent protocol implementation methods of these devices. If the connection setup fails, rectify the fault by following the instructions provided in section What Do I Do If VPN Setup Fails? or contact customer service.
+A VPC provides an isolated virtual network for ECSs. You can configure and manage the network as required.
+Create a VPC by following the procedure provided in this section. Then, create subnets, security groups, and VPNs, and assign EIPs by following the procedure provided in subsequent sections based on your actual network requirements.
+
in the upper left corner and select the desired region and project.During VPC creation, a default subnet will be created and you can also click Add Subnet to create more subnets for the VPC.
+ +Category + |
+Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|---|
Basic Information + |
+Region + |
+Specifies the desired region. Regions are geographic areas isolated from each other. Resources are region-specific and cannot be used across regions through internal network connections. For low network latency and quick resource access, select the nearest region. + |
+eu-de + |
+
Basic Information + |
+Name + |
+Specifies the VPC name. + |
+VPC-001 + |
+
Basic Information + |
+CIDR Block + |
+Specifies the CIDR block for the VPC. The CIDR block of a subnet can be the same as the CIDR block for the VPC (for a single subnet in the VPC) or a subset (for multiple subnets in the VPC). +The following CIDR blocks are supported: +10.0.0.0 – 10.255.255.255 +172.16.0.0 – 172.31.255.255 +192.168.0.0 – 192.168.255.255 + |
+192.168.0.0/16 + |
+
Basic Information + |
+Tag + |
+Specifies the VPC tag, which consists of a key and value pair. You can add a maximum of ten tags to each VPC. +The tag key and value must meet the requirements listed in Table 2. + |
+
|
+
Subnet Settings + |
+Name + |
+Specifies the subnet name. + |
+Subnet + |
+
Subnet Settings + |
+CIDR Block + |
+Specifies the CIDR block for the subnet. This value must be within the VPC CIDR range. + |
+192.168.0.0/24 + |
+
Subnet Settings + |
+Gateway + |
+Specifies the gateway address of the subnet. + |
+192.168.0.1 + |
+
Subnet Settings + |
+DNS Server Address + |
+The external DNS server address is used by default. If you need to change the DNS server address, ensure that the configured DNS server address is available. + |
+192.168.1.0 + |
+
Subnet Settings + |
+NTP Server Address + |
+Specifies the NTP server IP address. A maximum of four IP addresses can be configured. Multiple IP addresses must be separated using commas (,). + |
+192.168.2.1 + |
+
Subnet Settings + |
+Tag + |
+Specifies the subnet tag, which consists of a key and value pair. You can add a maximum of ten tags to each subnet. +The tag key and value must meet the requirements listed in Table 3. + |
+
|
+
Parameter + |
+Requirements + |
+Example Value + |
+
|---|---|---|
Key + |
+
|
+vpc_key1 + |
+
Value + |
+
|
+vpc-01 + |
+
Parameter + |
+Requirements + |
+Example Value + |
+
|---|---|---|
Key + |
+
|
+subnet_key1 + |
+
Value + |
+
|
+subnet-01 + |
+
You can add subnets during VPC creation. If required, you can also create subnets for an existing VPC.
+The created subnet is configured with DHCP by default. After an ECS using this VPC starts, the ECS automatically obtains an IP address using DHCP.
+
in the upper left corner and select the desired region and project.
Parameter + |
+Description + |
+Example Value + |
+
|---|---|---|
Name + |
+Specifies the subnet name. + |
+Subnet + |
+
CIDR Block + |
+Specifies the CIDR block for the subnet. This value must be within the VPC CIDR range. + |
+192.168.0.0/24 + |
+
Gateway + |
+Specifies the gateway address of the subnet. + |
+192.168.0.1 + |
+
NTP Server Address + |
+Specifies the NTP server IP address. A maximum of four IP addresses can be configured. Multiple IP addresses must be separated using commas (,). + |
+192.168.2.1 + |
+
Tag + |
+Specifies the subnet tag, which consists of a key and value pair. You can add a maximum of ten tags to each subnet. +The tag key and value must meet the requirements listed in Table 2. + |
+
|
+
DNS Server Address + |
+The external DNS server address is used by default. If you need to change the DNS server address, ensure that the configured DNS server address is available. + |
+- + |
+
Parameter + |
+Requirements + |
+Example Value + |
+
|---|---|---|
Key + |
+
|
+subnet_key1 + |
+
Value + |
+
|
+subnet-01 + |
+
After a subnet is created, five IP addresses in the subnet will be reserved and cannot be used. For example, in a subnet with CIDR block 192.168.0.0/24, the following IP addresses are reserved:
+If you set Advanced Settings to Custom during subnet creation, the reserved IP addresses may be different from the preceding default ones. The system will reserve five IP addresses based on your subnet settings.
+You can perform the following steps to handle the issues:
+Currently, the VPN service does not support the SSL VPNs.
+The Internet Protocol Security (IPsec) VPN is an encrypted tunneling technology that uses encrypted security services to establish confidential and secure communication tunnels between different networks.
+In Figure 1, a VPC has two subnets: 192.168.1.0/24 and 192.168.2.0/24. On your router deployed in your physical data center, you also have two subnets: 192.168.3.0/24 and 192.168.4.0/24. You can use VPN to enable subnets in your VPC to communicate with those in your data center.
+ +Currently, the site-to-site VPN and hub-spoke VPN are supported. You need to set up VPNs in both your data center and the VPC to establish the VPN connection.
+You must ensure that the VPN in your VPC and that in your data center use the same IKE and IPsec policy configurations. Before creating a VPN, familiarize yourself with the protocols described in Table 1 and ensure that your device meets the requirements and configuration constraints of the involved protocols.
+ +Protocol + |
+Description + |
+Constraint + |
+
|---|---|---|
RFC 2409 + |
+Defines the IKE protocol, which negotiates and verifies key information to safeguard VPNs. + |
+
|
+
RFC 4301 + |
+Defines the IPsec architecture, the security services that IPsec offers, and the collaboration between components. + |
+Use the IPsec tunnel to set up a VPN connection. + |
+
A region and availability zone (AZ) identify the location of a data center. You can create resources in a specific region and AZ.
+Figure 1 shows the relationship between regions and AZs.
+ +Select a region closest to your target users for low network latency and quick access.
+When deploying resources, consider your applications' requirements on disaster recovery (DR) and network latency.
+Before you use an API to call resources, specify its region and endpoint. For more details, see Regions and Endpoints.
+By default, a user can have a maximum of five IPsec VPNs. If your quota cannot fulfill your service requirements, submit a service ticket to increase the quota.
+If the subnets of your data center are 192.168.3.0/24 and 192.168.4.0/24, and the VPC subnets are 192.168.1.0/24 and 192.168.2.0/24, configure the ACL rules for each data center subnet to permit the communication with the VPC subnets. The following provides an example of ACL configurations:
+rule 1 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 +rule 2 permit ip source 192.168.3.0 0.0.0.255 destination 192.168.2.0 0.0.0.255 +rule 3 permit ip source 192.168.4.0 0.0.0.255 destination 192.168.1.0 0.0.0.255 +rule 4 permit ip source 192.168.4.0 0.0.0.255 destination 192.168.2.0 0.0.0.255+
The security group denies the access from all sources by default. If you want to access your ECSs, modify the security group configuration and allow the access from the remote subnets.
+Check whether you have properly configured the firewall policies for the access from the public IP address of the cloud VPN to the public IP address of your data center or LAN. No policies are configured to limit the access by default.
+If the two VPCs are in the same region, you can use a VPC peering connection to enable communication between them.
+If the two VPCs are in different regions, you can use a VPN to enable communication between the VPCs. The CIDR blocks of the two VPCs are the local and remote subnets, respectively.
+