Comparison route

Single service comparison

Back to main page

VPN Connectivity

Cloud VPN

Google Cloud Cloud VPN provides IPsec site-to-site tunnels between a VPC and an on-premises or peer network over the public internet. It comes as classic VPN (single tunnel per gateway) or HA VPN (two public IPs, 99.99% SLA via redundant tunnels). Traffic is encrypted with IKEv1/IKEv2, routed through Cloud Routers for dynamic BGP peering, and billed by gateway hours plus egress bytes. It targets hybrid connectivity without dedicated circuits.

Google Cloud logo

Google Cloud

Service information

Cloud VPN iconCloud VPN

Shortname: Cloud VPN

Huawei equivalent shortnames: VPN

Keywords: vpn, network, site-to-site

Differences vs Huawei

Service boundary differs. Google Cloud VPN exposes a Cloud VPN gateway, peer gateway, and tunnel resources under a regional network; dynamic routing relies on Cloud Router and BGP, with HA VPN provisioning two public IPs per gateway for redundancy. Huawei Cloud VPN separates Site-to-Cloud (S2C, IPsec) and Point-to-Cloud (P2C, SSL) products, where S2C uses a VPN gateway, customer gateway, and VPN connection objects. Huawei also offers an Enterprise Router (ER) integration for centralized hybrid routing with Direct Connect and VPN, a model Google approximates with Cloud Router+Network Connectivity Center but does not expose as a single router appliance.

Scaling and HA models diverge. HA VPN mandates two tunnels to two distinct public IPs and pairs with Cloud Router for 99.99% SLA; classic VPN is single-tunnel with no SLA. Huawei S2C VPN supports active-active and active/standby gateways, cross-AZ deployment, and dual connections for AZ-level HA, with gateway specification tiers offering Mbit/s-level bandwidth customization. Google's per-tunnel throughput equilibates around 1.5-3 Gbps per tunnel and scales by adding tunnels; Huawei's per-gateway bandwidth is set at purchase, so capacity planning must map GCP tunnel counts to Huawei gateway specs rather than assume auto-scaling.

Operational responsibility and pricing split differently. Google bills VPN gateway hours plus outbound data transfer (egress) processed by the tunnel, and SLA tiers depend on HA vs classic. Huawei bills the VPN gateway resource (EIP, spec, hours) plus bandwidth plans and traffic processed through EIP/NAT; cross-region or Direct Connect fallback traffic is metered separately. Encryption support overlaps (IKE/IPsec, AES, SM ciphers on Huawei), but Huawei's P2C (SSL/OpenVPN client) has no direct Google Cloud VPN equivalent—Google's analog is Client VPN-style workload only via third-party or IAP, so remote-user VPN use cases map to a different Huawei product line, not to S2C VPN interchangeably.

Migration to Huawei

Start with an assessment inventory of every GCP VPN gateway, peer gateway, tunnel, IKE/IPsec proposal, PSK or certificate, Cloud Router BGP session (ASN, advertised prefixes, route priorities), and route propagation scope. Classify each by HA profile (classic vs HA VPN), throughput, and remote-user vs site-to-site intent. Site-to-site tunnels map to Huawei S2C VPN; remote-user/endpoint access should be steered to Huawei P2C VPN, not retrofitted onto S2C. Decide gateway spec tier and active-active vs active/standby per Huawei's HA guidance, since GCP HA VPN's two-tunnel SLA does not translate one-to-one to a single Huawei gateway.

Rebuild the configuration on Huawei Cloud: create the VPC, VPN gateway (Enterprise Edition where ER or cross-AZ HA is needed), and customer gateway objects mirroring peer addresses and subnets. Recreate IKEv1/IKEv2 phase 1/2 proposals, PSKs/certificates, and traffic selectors; if using dynamic routing, attach the VPN gateway to an Enterprise Router and configure BGP peers with matching ASNs and route priorities to preserve GCP Cloud Router behavior. For multi-site or hub-and-spoke topologies, use Huawei's VPN hub and ER-based hybrid-cloud best practice patterns rather than flattening everything onto one gateway.

Validate before cutover. Stand up the Huawei tunnels in parallel with the GCP tunnels, confirm IKE/IPsec negotiation, BGP session establishment, and route advertisement on both sides, then run traffic tests for reachability, MTU/fragmentation, and failover (kill one tunnel/gateway and measure reconvergence). Verify that GCP route priorities and Huawei route priorities produce equivalent preferred/backup paths, since BGP local-priority and AS-path manipulation differ between the two control planes. Monitor via Huawei Cloud Eye and VPN connection status alarms before decommissioning GCP tunnels.

Model the cost delta and close gaps. GCP charges gateway-hours plus egress bytes; Huawei charges VPN gateway spec-hours, EIP/bandwidth, and processed traffic, with Direct Connect/ER resources metered separately if used for redundancy. Recompute TCO at peak and 95th-percentile egress, account for the P2C vs S2C product split, and provision EIPs/bandwidth plans to match GCP outbound volume. Note unsupported paths: cross-border VPN between Chinese mainland and other regions is blocked on Huawei, and there is no automated one-click migration tool—recreation is manual/IaC-driven, so script the config through Terraform/RMM to keep both environments reproducible.

Huawei Cloud logo

Huawei Cloud

Huawei equivalent service

Virtual Private Network iconVirtual Private Network

Shortname: VPN

General function: VPN Connectivity

Secure encrypted network connectivity service.

Keywords: vpn, site-to-site, secure network