Patent attributes
A provider network includes a service that creates fault tolerant virtual private network (VPN) endpoint nodes. Each such VPN endpoint node is created as a plurality of virtual machines executing on host computers. Each of the virtual machines is configured from a common machine image that includes software capable of causing the respective virtual machine to configure a secure communication tunnel such as an IPSec tunnel. One of the virtual machines, however, is operated in an active mode to actively configure the tunnel and send and receive encrypted traffic over the tunnel, while another virtual machine is configured to operate in a standby mode. The standby mode VPN endpoint virtual machine can be quickly transitioned to the active mode to take over the role of configuring and exchanging encrypted packets over the tunnel should the active mode VPN endpoint experience a failure.