傳統版 VPN 動態轉送功能淘汰
傳統版 VPN 通道的動態轉送或邊界閘道通訊協定 (BGP) 將於 2025 年 8 月 1 日淘汰。如果工作負載需要使用 BGP 進行 VPN 連線,則必須使用高可用性 VPN。
如需高可用性 VPN 的相關資訊,請參閱 Cloud VPN 總覽。
本頁其餘部分將協助您規劃及實作遷移作業。
已淘汰的設定
您無法建立使用動態轉送 (BGP) 的新傳統版 VPN 通道,這類通道由 Cloud Router 管理。
自 2025 年 8 月 1 日起,系統將不再支援使用動態轉送 (BGP) 建立傳統版 VPN 通道,無論通道連線至哪個閘道皆是如此。包括連線至在 Compute Engine 虛擬機器 (VM) 執行個體中運作的 VPN 閘道軟體,或連線至 Trusted Cloud外部。
系統不支援使用動態轉送 (BGP) 的現有傳統版 VPN 通道。使用中的通道仍可繼續運作,但沒有服務水準協議。
已淘汰的設定會怎麼樣?
如果您刪除以 BGP 設定的傳統 VPN 通道,就無法重新建立支援 BGP 的通道。現有未修改的傳統 VPN 通道可能仍會傳輸流量 (不含 SLA)。如要進行任何變更,必須使用高可用性 VPN,否則需要重新建立或修改 BGP 設定。
支援的設定
您仍可繼續建立下列傳統版 VPN 設定,並取得相關支援:
- 使用靜態轉送的傳統版 VPN 通道,從傳統版 VPN 閘道連線至地端部署 VPN 閘道,以及從地端部署 VPN 閘道連線至傳統版 VPN 閘道。
- 使用靜態轉送的傳統版 VPN 通道,從傳統版 VPN 閘道連線至做為 VPN 閘道的 Compute Engine VM,以及從該 VM 連線至傳統版 VPN 閘道。
建議
如要處理需要動態轉送 (BGP) 的所有正式版流量,請使用高可用性 VPN。
如果內部部署 VPN 裝置不支援 BGP,因此無法使用高可用性 VPN,建議您保留傳統版 VPN。不過,我們強烈建議您升級這些裝置,以支援 BGP,因為與靜態轉送相比,高可用性 VPN 解決方案更靈活、可靠且高可用性,而且是 Cloud VPN 中 BGP 功能的唯一路徑。
詳情請參閱高可用性 VPN 拓撲。
帳單異動
為高可用性 VPN 建立並使用額外的備援通道後,系統會按照 Cloud VPN 定價頁面的說明,向您收取費用。
如要達到高可用性,高可用性 VPN 需要您成對建立 VPN 通道。兩個通道的計費費率相同,都是以小時為單位。
如果只將一個通道用於容錯移轉,則只有作用中的通道會產生輸出資料傳輸費用。
自 2025 年 8 月 1 日起,如果流量尚未移至高可用性 VPN,且持續透過已建立的傳統版 VPN 閘道和通道傳輸,將以傳統版 VPN 的標準費率計費。
改用高可用性 VPN
如要改用高可用性 VPN,您可能需要進行一些轉送或基礎架構變更,才能支援高可用性 VPN。網路管理員或網站可靠性工程師 (SRE) 必須安排維護時段,才能執行遷移作業。
我可前往何處尋求協助
如有任何疑問或需要協助,請與支援團隊聯絡。Trusted Cloud by S3NS
除非另有註明,否則本頁面中的內容是採用創用 CC 姓名標示 4.0 授權,程式碼範例則為阿帕契 2.0 授權。詳情請參閱《Google Developers 網站政策》。Java 是 Oracle 和/或其關聯企業的註冊商標。
上次更新時間:2025-08-12 (世界標準時間)。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["缺少我需要的資訊","missingTheInformationINeed","thumb-down"],["過於複雜/步驟過多","tooComplicatedTooManySteps","thumb-down"],["過時","outOfDate","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["示例/程式碼問題","samplesCodeIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-08-12 (世界標準時間)。"],[],[],null,["# Classic VPN dynamic routing deprecation\n\nDynamic routing or Border Gateway Protocol (BGP) for Classic VPN\ntunnels is deprecated on August 1, 2025. If your workloads require BGP\nfor VPN connectivity, you must use HA VPN.\n\nFor information about HA VPN, see the\n[Cloud VPN overview](/network-connectivity/docs/vpn/concepts/overview#ha-vpn).\n\nThe rest of this page helps you with planning and implementing your\nmigration.\n\nDeprecated configurations\n-------------------------\n\nYou cannot create new Classic VPN tunnels that use dynamic routing\n(BGP) that is managed by a Cloud Router.\n\nAs of August 1, 2025, the creation of Classic VPN tunnels\nusing dynamic routing (BGP) is no longer supported, regardless of the gateway\nthe tunnel connects to. This includes connections to VPN gateway software running\ninside a Compute Engine virtual machine (VM) instance or connections\noutside of Google Cloud.\n\nExisting Classic VPN tunnels that use dynamic routing (BGP)\nare not supported. While tunnels that are in use will continue to function,\nbut without an availability SLA.\n\n### What happens to deprecated configurations?\n\nIf you delete a Classic VPN tunnel that was configured with BGP, you won't be\nable to recreate it with BGP support. While existing, unmodified\nClassic VPN tunnels may continue to pass traffic (without SLA).\nYou must use HA VPN for any changes requiring recreation\nor modification of BGP settings configurations.\n\nSupported configurations\n------------------------\n\nYou can continue to create and receive support only for the following\nClassic VPN configurations:\n\n- Classic VPN tunnels using static routing from Classic VPN gateways to on-premises VPN gateways and from on-premises VPN gateways to Classic VPN gateways.\n- Classic VPN tunnels using static routing from a Classic VPN gateway to and from a Compute Engine VM that is acting as a VPN gateway.\n\nRecommendations\n---------------\n\nFor all production traffic requiring dynamic routing (BGP),\nuse HA VPN.\n\nWe recommend that you only retain Classic VPN if your\non-premises VPN devices don't support BGP, and therefore HA VPN\ncannot be used. However, we strongly recommend upgrading those devices to\nsupport BGP, as HA VPN provides a more flexible, reliable,\nand highly available solution compared to static routing, and is the only path\nfor BGP functionality within Cloud VPN.\n\nFor more information, see\n[HA VPN topologies](/network-connectivity/docs/vpn/concepts/topologies).\n\nBilling changes\n---------------\n\nAfter instantiating and using the additional, redundant tunnel for\nHA VPN, you will see billing changes as described on\nthe [Cloud VPN pricing page](/network-connectivity/docs/vpn/pricing).\n\nTo achieve high availability, HA VPN requires you to\ncreate VPN tunnels in pairs. Both tunnels are billed at the same hourly rate.\nIf you use one tunnel solely for failover, outbound data transfer charges apply\nonly to the active tunnel.\n\nAs of August 1, 2025, any traffic that has not been migrated to HA VPN\nand continues to flow through established Classic VPN gateways\nand tunnels will be charged at the standard Classic VPN rates.\n\nMove to HA VPN\n--------------\n\nTo move to HA VPN, you might need to make some routing or\ninfrastructure changes to support HA VPN. Your network\nadministrators or [site reliability engineers (SREs)](https://sre.google/)\nneed to schedule a [maintenance window](/network-connectivity/docs/vpn/how-to#maintaining-vpns)\nto perform the migration.\n\nTo plan and prepare, watch the following video,\n*Upgrade to Google's HA VPN*,\nfor guidance on key use cases.\n\nWhen your organization is ready to switch your production workflows from\nClassic VPN to HA VPN, use the checklists\nand instructions provided in [Move to HA VPN](/network-connectivity/docs/vpn/how-to/moving-to-ha-vpn). \n\nWhere to get help\n-----------------\n\nIf you have any questions or require assistance, [contact\nGoogle Cloud Support](/network-connectivity/docs/vpn/support/getting-support)."]]