Updated on 2025-08-19 GMT+08:00

Scenario

Figure 1 shows the typical networking where a Huawei Cloud VPN gateway connects to a Hillstone firewall in an on-premises data center in BGP routing mode.

Figure 1 Typical networking diagram

In this scenario, the Hillstone firewall has only one IP address, and the Huawei Cloud VPN gateway uses the active-active mode. A VPN connection needs to be created between each of the two active EIPs of the VPN gateway and the IP address of the Hillstone firewall.

Limitations and Constraints

  • Hillstone firewalls support only IKEv1 policies.
  • Huawei Cloud VPN and Hillstone firewalls support different authentication and encryption algorithms. When creating connections, ensure that the policy settings at both ends are the same.