[[["易于理解","easyToUnderstand","thumb-up"],["解决了我的问题","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["很难理解","hardToUnderstand","thumb-down"],["信息或示例代码不正确","incorrectInformationOrSampleCode","thumb-down"],["没有我需要的信息/示例","missingTheInformationSamplesINeed","thumb-down"],["翻译问题","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["最后更新时间 (UTC):2025-08-12。"],[],[],null,["# Advanced configurations\n\nThis page describes advanced configuration details for the following\nscenarios:\n\n- High-availability VPNs\n- High-throughput VPNs\n- Multiple subnet VPNs\n\nTo learn about the basic concepts of Cloud VPN, see the\n[Cloud VPN overview](/network-connectivity/docs/vpn/concepts/overview).\n\nOrder of routes\n---------------\n\nYou can create a VPN tunnel that has the same IP range as another tunnel,\na subset of the other tunnel's range, or a superset of the other tunnel's range.\n\nFor details, see\n[Order of routes](/network-connectivity/docs/vpn/concepts/order-of-routes).\n\nConfigure IKE, including multiple subnet support\n------------------------------------------------\n\nIn [Supported IKE ciphers](/network-connectivity/docs/vpn/concepts/supported-ike-ciphers),\nyou can find details about how Cloud VPN supports multiple\nIKE ciphers.\n\nIn [Networks and tunnel routing](/network-connectivity/docs/vpn/concepts/choosing-networks-routing),\nyou can find information about supported Virtual Private Cloud (VPC) networks\nand routing options, including traffic selectors.\n\nUDP encapsulation\n-----------------\n\nCloud VPN only supports *one-to-one NAT* by using UDP encapsulation for\nNAT-Traversal (NAT-T). NAT-T is required so that IPsec traffic can reach\ndestinations without external (public) IP addresses behind the NAT.\n*One-to-many NAT* and *port-based address translation* are\nnot supported. In other words, Cloud VPN *cannot* connect to\nmultiple [peer VPN gateways](/network-connectivity/docs/vpn/concepts/key-terms#peer-definition)\nthat share a single external IP address.\n\nFor more details about VPN gateways behind one-to-one NAT, see\n[On-premises gateways behind NAT](/network-connectivity/docs/vpn/support/troubleshooting#gateways_behind_nat)\non the Troubleshooting page.\n\nMaximum transmission unit (MTU) considerations\n----------------------------------------------\n\nThe Cloud VPN MTU size is 1460 bytes. For a description of how to\nconfigure your peer VPN gateway to support this MTU size if required, see\n[MTU considerations](/network-connectivity/docs/vpn/concepts/mtu-considerations).\n\nHigh-availability VPNs, high-throughput VPNs, and failover\n----------------------------------------------------------\n\nHA VPN is the recommended method of implementing\nhigh-availability VPNs and high-throughput VPNs. If your peer VPN gateway\nsupports BGP, you can configure an\n[HA VPN gateway with a 99.99% uptime SLA](/network-connectivity/docs/vpn/concepts/topologies#configurations_that_support_9999_availability)\nby using an\n[active/active or active/passive](/network-connectivity/docs/vpn/concepts/overview#active)\ntunnel configuration.\n| **Caution:** We recommend that you use an active/passive configuration only with *one* HA VPN gateway. If you use an active/passive configuration across *multiple HA VPN gateways*, with an active and passive tunnel pair configured on each gateway, HA VPN doesn't use the passive tunnels for failover until all the active tunnels on all gateways have failed. Configuring multiple gateways with an active/passive configuration can cause bandwidth loss.\n\nFor Classic VPN gateways, you can provide VPN redundancy\nand failover by using these\n[throughput and load balancing options](/network-connectivity/docs/vpn/concepts/classic-topologies#vpn-throughput).\nHowever, with this configuration, you receive a 99.9% availability SLA.\n\nWhat's next\n-----------\n\n- To learn about the basic concepts of Cloud VPN, see the [Cloud VPN overview](/network-connectivity/docs/vpn/concepts/overview).\n- To help you solve common issues that you might encounter when using Cloud VPN, see [Troubleshooting](/network-connectivity/docs/vpn/support/troubleshooting)."]]