Products

VPN

2022-02-18 07:39:44

Use Restrictions

JD Cloud & AI's requirements on client VPN devices

  • The client VPN devices shall support standard IPsec Protocol, tunnel mode and ESP;
  • They shall support parameters related to negotiation in the two stages including IKE and IPsec;
  • They shall support logical interfaces used to associate the tunnel to devices based on Route-Based VPN;
  • The Static and Internet-rountable IPV4 address used on client shall be used as the tunnel's outer-layer address to disable VPN Tunnel;
  • If the client is a firewall device or is configured with security policy, the following protocol ports shall be released:
    • UDP 500, for IKE negotiation;
    • IP 50, for IPsec ESP negotiated and encrypted data package transmission;
    • UDP 4500, NAT Traversal (NAT-T) shall be enabled at the same time if your client devices are behind the NAT devices;
  • MTU configured at the client contains no more than 1,400 bytes;

Other Restrictions for VPN Connection

  • Do not support IPv6;
  • Do not support path MTU discovery;

Compatible with Client

List of clients passing the test:
  • Hardware Device:
    • Cisco IOS 15.0(or later) software;
    • HUAWEI USG6500 Series Firewall;
    • H3C MSR800;
    • Juniper SRX12.1X47-D20.7 virtual firewall;
  • Open Source VPN Solutions: strongSwan and others;
  • VPN products from other public cloud manufacturers;
List of clients failing to pass the test connectivity:
  • Sangfor Hardware Device or Gateway Image. JD Cloud & AI VPN is a route-based IPsec tunnel, the mainstream devices of Sangfor only support route-based IPsec tunnels, and a problem exists during the second stage of tunnel negotiation, causing a failure to establish tunnels through negotiation, so the connectivity test fails to be passed. Communication with colleagues in relevant departments of Sangfor has been carried out and the parties will update their own software versions in a short term so as to support VPN connectivity between them.

Related Resources Quota for VPN

Product Resource Restriction Exceptional Application Method
VPN Connection Number of VPN Connections creatable supported by each Border Gateway in the same region 10 Ticket
Number of cloud public network addresses under the same VPN Connection 2 The number cannot be increased
Number of VPN Tunnels creatable for the same VPN Connection Up to (number of cloud public network address connected by VPN * number of Customer Gateway's public network address piece) VPN Tunnels can be created The number cannot be increased
Number of VPN Tunnels creatable between the same pair of cloud public network address and customer gateway public network addresses 1 The number cannot be increased
Border Gateway Number of Border Gateways in the same region 5 Ticket
Number of VPC Attachments creatable for each Border Gateway 50 Ticket
Number of Static Route rules for the same Border Gateway 50 Ticket
Number of Dynamic Route rules for the same Border Gateway 300 Ticket
VPC Attachment Number of VPC Attachments creatable between the same pair of VPC and Border Gateway 1 The number cannot be increased
Customer Gateway Number of Customer Gateways in the same region 10 Ticket
Number of public network addresses for the same Customer Gateway 4 The number cannot be increased
Feedback

开始与售前顾问沟通

可直接拨打电话 400-098-8505转1

我们的产品专家为您找到最合适的产品/解决⽅案

在线咨询 5*8⼩时

1v1线上咨询获取售前专业咨询

点击咨询
企微服务助手

专业产品顾问,随时随地沟通