Updated on 2026-04-24 GMT+08:00

Procedure

Prerequisites

  • Cloud side
    • A VPC has been created. For details, see Creating a VPC and Subnet.
    • Security group rules have been configured for the VPC, and ECSs can communicate with other devices on the cloud. For details about how to configure security group rules, see Security Group Rules.
  • Data center side

    The VPN client software has been configured on a user terminal. For details, see Administrator Guide.

Precautions

Changing the client authentication mode or identity provider will interrupt existing VPN connections. Exercise caution when performing this operation.

Procedure

  1. Configure single sign-on (SSO) for Microsoft Entra ID.

    1. Use an enterprise administrator account to log in to the system.
    2. Choose Microsoft Entra ID. In the Quick actions area, click Add enterprise application.
    3. Click Create your own application.
    4. Enter an application name and click Create.
    5. After the application is created, click Get started in the Set up single sign on tablet.
    6. Select SAML-based single sign-on.
    7. Download the metadata file of Huawei Cloud.

      You are advised to use Google Chrome to access the Huawei Cloud metadata page at https://auth.huaweicloud.com/authui/saml/metadata.xml, right-click on the page, and save it as a metadata file to your local PC.

    8. Click Upload metadata file, select the Huawei Cloud metadata file, and click Add.
    9. When a message is displayed indicating that the XML file is successfully uploaded, click Save to save the SSO configuration.
    10. Click Edit in the Attributes & Claims tablet.
    11. Configure a unique user identifier.

      In this example, the unique user identifier is set to user.userprincipalname.

    12. View and record the claim name corresponding to user.userprincipalname.

      This claim name will be used in step 5.4 for configuring identity conversion rules.

    13. Click Download to download the federation metadata file of Microsoft Entra ID to your local PC.
    14. Grant users access to the application.
      1. Choose Users and groups and click Add user/group.
      2. Click None Selected, select existing users, and click Assign. When "Application assignment succeeded" is displayed, the access permission is assigned to users.

        Only the selected users can access the VPN gateway through federated authentication.

  2. Log in to Huawei Cloud management console.
  3. Click in the upper left corner and select the desired region and project.
  4. Click in the upper left corner of the page, and choose Management & Governance > Identity and Access Management.
  5. Configure an identity provider.

    1. Create a user group and grant permission to it.
      1. Create a user group.
        1. Choose User Groups from the navigation pane.
        2. On the User Groups page, click Create User Group.
        3. Configure user group information, such as the user group name.
        4. Click OK. The user group is created.

          You can view the created user group in the user group list.

      2. Grant permission to the user group.
        1. Click Authorize in the Operation column of the created user group.
        2. In the search box in the upper right corner, search for VPN SSOAccessPolicy and select it.
        3. Click Next and select the authorization scope as required.
        4. Click OK. The permission is granted to the user group.
    2. Create an identity provider.
      1. Choose Identity Providers from the navigation pane.
      2. On the Identity Providers page, click Create Identity Provider.
      3. Set parameters including the name, protocol, SSO type, and status.
      4. Click OK. The identity provider is created.
    3. Upload metadata of Microsoft Entra ID.
      1. On the Identity Providers page, click Modify in the Operation column of the target identity provider.
      2. In the Metadata Configuration area, click Add and import the downloaded metadata file of Microsoft Entra ID.
      3. Click Upload, confirm the metadata configuration information, and click OK.
    4. Configure identity conversion rules.
      1. In the Identity Conversion Rules area, click Create Rule.
      2. Set parameters as prompted.
        Table 1 Rule parameters

        Parameter

        Description

        Example Value

        Username

        The username configured here will be displayed as the operator name for a Microsoft Entra ID user in Cloud Trace Service.

        NOTICE:
        • Each federated user of the same identity provider must have a unique username. Otherwise, duplicate usernames will be identified as the same IAM user on Huawei Cloud.
        • The username can be any string that does not contain <, >, {, or }, or you can use a placeholder {0..n}. {0} indicates the first attribute of the user information in remote, and {1} indicates the second attribute.

        FederationUser-IdP_001

        User Groups

        Select the user group to which permission has been granted. In federated authentication mode, the selected user group must have the VPN SSOAccessPolicy permission.

        vpn_user_group

        Rule Conditions

        Federated users who meet the conditions inherit the permission granted to their user group. Federated users who do not meet the conditions are denied access to Huawei Cloud. You can create a maximum of 10 conditions for an identity conversion rule.

        For more information about rule conditions, see Syntax of Identity Conversion Rules.

        NOTE:
        • A rule can contain multiple conditions, and takes effect only when all conditions are met.
        • Multiple identity conversion rules can be created for an identity provider. If none of the rules apply to a federated user, the user is denied access to Huawei Cloud.
        • Attribute: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
        • Condition: empty
      3. Click OK. The rule is created.

        When Microsoft Entra ID users connect to a VPN gateway, their operator names displayed in Cloud Trace Service are the same by default.

        To ensure that the operator name displayed in Cloud Trace Service is the same as the Microsoft Entra ID username, perform the following operations:

        1. Click Edit Rule.
        2. Delete the default rule.
        3. Change the username to the placeholder {0}.
        4. Click Validate.
        5. When "Validation successful" is displayed, click OK. The identity conversion rule is configured.
    5. On the Modify Identity Provider page, click OK.

  6. Click in the upper left corner, and choose Networking > Virtual Private Network.
  7. In the navigation pane on the left, choose Virtual Private Network > Enterprise – VPN Gateways.
  8. Click the P2C VPN Gateways tab. The P2C VPN gateway list is displayed.
  9. Configure a VPN gateway.

    1. On the P2C VPN Gateways page, click Buy P2C VPN Gateway.
    2. Set parameters as prompted and click Buy Now.

      Table 1 describes the VPN gateway parameters.

      Table 2 Description of VPN gateway parameters

      Parameter

      Description

      Example Value

      Region

      For low network latency and fast resource access, select the region nearest to your target users.

      Resources cannot be shared across regions.

      Set this parameter based on the actual condition.

      Name

      Enter the name of a VPN gateway.

      p2c-vpngw-001

      VPC

      Select a VPC.

      vpc-001(192.168.0.0/16)

      Interconnection Subnet

      This subnet is used for communication between the VPN gateway and VPC. Ensure that the selected interconnection subnet has three or more assignable IP addresses.

      192.168.66.0/24

      Specification

      Two options are available: Professional 1 and Professional 2.

      For details about the differences between specifications, see Specifications Introduction.

      Professional 1

      AZ

      An AZ is a geographic location with independent power supply and network facilities in a region. AZs in the same VPC are interconnected through private networks and are physically isolated.

      • If two or more AZs are available, select two AZs.

        The VPN gateway deployed in two AZs has higher availability. You are advised to select the AZs where resources in the VPC are located.

      • If only one AZ is available, select this AZ.

      AZ1, AZ2

      Connections

      Ten VPN connections are included free of charge with the purchase of a VPN gateway. You can select or customize the number of required VPN connections.

      10

      Shared Bandwidth

      • When Billing Mode is set to Yearly/Monthly, the shared bandwidth is enabled by default.
      • When Billing Mode is set to Pay-per-use, the shared bandwidth is disabled by default.

      Enabled

      EIP Type

      Select the type of the EIP to be bound to the VPN gateway.

      Dynamic BGP: Dynamic BGP provides automatic failover and chooses the optimal path when a network connection fails.

      For more information about EIP types, see What Is Elastic IP?.

      Dynamic BGP

      Bandwidth Name

      Select the name of the EIP bandwidth.

      p2c-vpngw-bandwidth1

      EIP

      Set the EIP used by the VPN gateway to communicate with clients.

      • Create Now: Buy a new EIP.
      • Use existing: Use an existing EIP.
        NOTE:

        If an existing EIP is used, its billing mode can be pay-per-use or yearly/monthly.

      Create now

  10. Configure a server.

    1. On the P2C VPN Gateways page, click Configure Server in the Operation column of the target VPN gateway. Alternatively, click the name of the target VPN gateway and then click the Server tab.
    2. Set parameters as prompted and click OK.

      Table 2 describes the server parameters.

      Table 3 Server parameters

      Area

      Parameter

      Description

      Example Value

      Basic Information

      Local CIDR Block

      Destination CIDR block that clients need to access through the P2C VPN gateway. The CIDR block can be within or connected to a Huawei Cloud VPC.

      A maximum of 20 local CIDR blocks can be specified. The local CIDR block cannot be set to 0.0.0.0. The local CIDR block cannot overlap or conflict with the following special CIDR blocks: 0.0.0.0/8, 224.0.0.0/4, 240.0.0.0/4, and 127.0.0.0/8.

      • Select subnet

        Select subnets of the local VPC.

      • Enter CIDR block

        Enter subnets of the local VPC or subnets of the VPC that establishes a peering connection with the local VPC.

      NOTE:

      After the local CIDR block is modified, clients need to be reconnected.

      192.168.0.0/24

      Client CIDR Block

      CIDR block for assigning IP addresses to virtual NICs of clients. It cannot overlap with the local CIDR block or the CIDR blocks in the route table of the VPC where the VPN gateway is located.

      The client CIDR block must be in the format of dotted decimal notation/mask. The mask ranges from 16 to 26. When assigning an IP address to a client, the system assigns a smaller CIDR block with the mask of 30 to ensure proper network communication. As such, ensure that the number of available IP addresses in the specified client CIDR block is at least four times the number of VPN connections.

      The recommended client CIDR blocks vary according to the number of VPN connections. For details, see Table 3.

      NOTE:

      After the client CIDR block is modified, clients need to be reconnected.

      172.16.0.0/16

      Tunnel Type

      SSL is a transport layer protocol used to establish a secure channel between a client and a server.

      The value is fixed at OpenVPN (SSL).

      OpenVPN (SSL)

      Authentication Information

      Server Certificate

      Select Service self-signed certificate.

      Service self-signed certificate

      Client Authentication Mode

      Select Federated authentication.

      Federated authentication

      Identity Provider

      Select the created identity provider.

      idp-user001

      Advanced Settings

      Protocol

      Protocol used by P2C VPN connections.

      • TCP (default)

      TCP

      Port

      Port used by P2C VPN connections.

      • 443 (default)
      • 1194

      443

      Encryption Algorithm

      Encryption algorithm used by P2C VPN connections.

      • AES-128-GCM (default)
      • AES-256-GCM

      AES-128-GCM

      Authentication Algorithm

      Authentication algorithm used by P2C VPN connections.

      • When the encryption algorithm is AES-128-GCM, the authentication algorithm is SHA256.
      • When the encryption algorithm is AES-256-GCM, the authentication algorithm is SHA384.

      SHA256

      Compression

      Whether to compress the transmitted data.

      By default, this function is disabled and cannot be modified.

      Disabled

      Table 4 Recommended client CIDR blocks

      Number of VPN Connections

      Recommended Client CIDR Block

      10

      CIDR blocks with the mask less than or equal to 26

      Example: 10.0.0.0/26 and 10.0.0.0/25

      20

      CIDR blocks with the mask less than or equal to 25

      Example: 10.0.0.0/25 and 10.0.0.0/24

      50

      CIDR blocks with the mask less than or equal to 24

      Example: 10.0.0.0/24 and 10.0.0.0/23

      100

      CIDR blocks with the mask less than or equal to 23

      Example: 10.0.0.0/23 and 10.0.0.0/22

      200

      CIDR blocks with the mask less than or equal to 22

      Example: 10.0.0.0/22 and 10.0.0.0/21

      500

      CIDR blocks with the mask less than or equal to 21

      Example: 10.0.0.0/21 and 10.0.0.0/20

    3. Click OK.

  11. Download the client configuration file.

    1. On the P2C VPN Gateways page, click Download Client Configuration in the Operation column of the target VPN gateway.
    2. Decompress the package to obtain the client_config.conf, client_config.ovpn, and README.md files.
      • The client_config.conf file applies to the Linux operating system.
      • The client_config.ovpn file applies to the Windows, macOS, and Android operating systems.

  12. Configure a client.

    This example describes how to configure a client on the Windows operating system. The configuration process varies according to the type and version of the VPN client software.

    • Operating system: Windows 10
    • Client software: OpenVPN Connect 3.7.3 (4351)

      Only clients running 3.4.0 and later versions support federated authentication.

    For more client configuration cases, see Configuring a Client.

    1. Download OpenVPN Connect from the OpenVPN official website, and install it as prompted.
    2. Start the OpenVPN Connect client, click BROWSE on the UPLOAD FILE tab page, and upload the client_config.ovpn file.
      Figure 1 Uploading a configuration file
    3. Click CONNECT to establish a VPN connection.
    4. Log in to the Microsoft Entra ID system using an existing user account.
      If multi-factor authentication has been enabled, perform identity authentication as prompted.
      • If the login page displays "Authentication succeeded" and the client displays CONNECTED, the client successfully connects to the VPN gateway.
        Figure 2 Connection established
      • If the login page displays a message indicating that the authentication fails, modify the configuration based on the error information. For details about the error information, see Troubleshooting.

Verification

  1. Verify connectivity.
    1. Open the CLI on the client device.
    2. Run the following command to verify the connectivity:

      ping 192.168.1.10

      192.168.1.10 is the IP address of an ECS. Replace it with the actual IP address.

    3. If information similar to the following is displayed, the client can communicate with the ECS:
      Reply from xx.xx.xx.xx: bytes=32 time=28ms TTL=245
      Reply from xx.xx.xx.xx: bytes=32 time=28ms TTL=245
      Reply from xx.xx.xx.xx: bytes=32 time=28ms TTL=245
      Reply from xx.xx.xx.xx: bytes=32 time=27ms TTL=245
  2. Check whether the operator name in Cloud Trace Service is the same as the Microsoft Entra ID username.
    1. Click in the upper left corner of the page, and choose Management & Governance > Cloud Trace Service.
    2. On the Trace List page, select Trace Name, enter loginP2cVpnBySSO in the search box, and press Enter.
    3. Check the operator name in the trace information.

      If the operator name is the current Microsoft Entra ID username, the identity conversion rule is correctly configured.