FAQ

更新时间:
复制 MD 格式

This topic answers frequently asked questions about CEN.

FAQ quick links

Category

Question

Basics

Billing

Billing FAQ

Network instance attachment

Route learning

Route conflicts

Network connectivity

Cross-account operations

Same-region cross-account VPC interconnection

Yes.

You can configure this connection without purchasing a bandwidth plan or creating an inter-region connection:

Cross-region communication for same-account VPCs

Yes.

See the following topics for instructions. You can skip the authorization steps for cross-account VPCs.

Transit router instances per region

Within a CEN instance, you can create only one transit router instance per region. For network instances to communicate, they must be attached to the same CEN instance.

You can create multiple CEN instances, which are isolated from each other by default. This means you can have multiple transit router instances in the same region, as long as each belongs to a different CEN instance.

For example, you can create multiple transit router instances in China (Hangzhou): one for CEN instance 1 and another for CEN instance 2.

CEN vs. VBR-to-VPC connection

Both CEN and VBR-to-VPC connections over Express Connect can connect a data center to a VPC. However, they differ in network connection, route management, and billing.

Item

CEN

VBR-to-VPC connection

Network connection

Point-to-multipoint connectivity.

Connecting a VBR instance and a VPC to a transit router enables communication between your data center and the VPC. The data center can also communicate with other network instances attached to the transit router, such as other VPCs, VBR instances, CCN instances, and IPsec-VPN connections.

Point-to-point connection.

VBR-to-VPC connections do not support transitive routing. A VBR-to-VPC connection allows the data center to communicate only with the connected VPC.

Route management

  • Automatic learning

    Connecting a VBR instance and a VPC to a transit router lets you use advanced features for automatic route propagation and learning, eliminating the need for manual route configuration.

  • Manual configuration

    Alternatively, for fine-grained control, you can manually configure routing features on the transit router, such as route learning, associated forwarding, routing policies, and prefix lists.

Manual configuration.

You must manually add routes to both the VBR instance and the VPC. Advanced route management capabilities such as routing policies are not supported.

Billing

  • If the VBR instance and VPC are in the same region, you are charged connection fees and data transfer fees for the Enterprise Edition transit router.

  • If the VBR instance and VPC are in different regions, you are charged connection fees and data transfer fees for the Enterprise Edition transit router, plus fees for the cross-region connection. These connections are billed either through a Bandwidth Package or by data transfer.

For details, see CEN billing details.

  • You are not charged for same-region connections between a VBR instance and a VPC.

  • Cross-region connections between a VBR instance and a VPC incur fees.

For details, see VBR-to-VPC connection billing details.

Differences between CEN and VPC peering connections

Both CEN and VPC peering connections enable private network communication between VPCs. However, they differ in network scale, network topology, network scalability, route configuration, and billing.

Item

CEN

VPC peering connection

Supported scenarios

Communication between VPCs in the same region and under the same Alibaba Cloud account

Communication between VPCs in the same region but under different Alibaba Cloud accounts

Cross-region communication between VPCs under the same Alibaba Cloud account

Cross-region communication between VPCs under different Alibaba Cloud accounts

Communication between VPCs in the same region and under the same Alibaba Cloud account

Communication between VPCs in the same region but under different Alibaba Cloud accounts

Cross-region communication between VPCs under the same Alibaba Cloud account

Cross-region communication between VPCs under different Alibaba Cloud accounts

Network scale

A Transit Router supports connections to up to 1,000 VPCs.

By default, a VPC can establish peering connections with up to 10 VPCs in the same region and 20 VPCs across different regions.

Network topology

Point-to-multipoint

VPCs attached to a Transit Router can communicate with each other and with other connected network instances, such as VBRs, CCN instances, and IPsec-VPN connections.

Point-to-point

A VPC can communicate only with its direct peer. To connect multiple VPCs, you must create a separate peering connection and configure routes between each pair of VPCs.

Network scalability

High

CEN offers simple configuration. To expand your network, attach new VPCs to the Transit Router and configure routes or inter-region connections as needed.

Low

VPC peering connections require end-to-end manual configuration. To add a VPC, you must create a peering connection and configure routes between the new VPC and each VPC that it needs to communicate with.

Route configuration

  • Automatic route learning

    When you attach a VPC to a Transit Router, you can use advanced features to enable automatic route propagation and learning, eliminating the need for manual configuration.

  • Manual configuration

    If you do not use the advanced features, you can manually customize network connectivity and achieve fine-grained control using Transit Router features such as route learning, associated forwarding, routing policies, and prefix lists.

Manual configuration

  • After you create a VPC peering connection, you must manually configure end-to-end routes.

  • VPC peering connections are non-transitive.

    For example, if VPC1 is peered with VPC2 and VPC2 is peered with VPC3, VPC1 cannot communicate with VPC3 through VPC2.

  • VPC peering connections do not support advanced routing features such as routing policies.

Billing

  • Communication between VPCs in the same region incurs connection and data processing fees for the Enterprise Edition Transit Router.

  • For cross-region communication between VPCs, costs include connection and data processing fees for the Enterprise Edition Transit Router, as well as a bandwidth package or data transfer fee for the inter-region connection.

For more information, see CEN billing details.

  • There are no fees for communication between VPCs in the same region.

  • For cross-region communication between VPCs, Cloud Data Transfer (CDT) charges a data transfer fee for outbound data transfer.

For more information, see CDT Billing Overview.

Recommended use cases

  • Private network communication among a large number of VPCs.

  • Scenarios requiring fine-grained control over network connectivity.

  • Networks requiring frequent configuration changes.

  • Private network communication among a small number of VPCs.

  • Simple connectivity scenarios with minimal routing control requirements.

  • Networks with infrequent configuration changes.

Check inter-region communication latency

  • If you have an inter-region connection in your CEN instance, check the inter-region communication latency in its monitoring data. For more information, see Monitor inter-region connections.

  • If you do not have an inter-region connection in your CEN instance, use the CEN Speed Test to check the inter-region communication latency.

    Note
    • The CEN Speed Test currently tests only the latency and packet loss rate between cross-border regions.

    • The data from the CEN Speed Test is for reference only. Test results may vary across attempts due to external factors such as connection quality and distance.

Connect VPCs across accounts with CEN

For example, if VPC1 in account A, VPC2 in account B, and VPC3 in account C need to communicate with each other, you can grant cross-account authorization to the CEN instance in account A for VPC2 and VPC3. Then, connect VPC2 and VPC3 to the CEN instance in account A to enable communication among the three VPCs. For more information, see Connect VPCs across accounts and Use CEN and Basic Edition transit routers to connect VPCs in different regions and accounts.

image

Console error: "VPCs that belong to different bid accounts cannot be attached"

A transit router can connect to a VPC in another account only if the transit router and the VPC belong to the same account type.

For example, a transit router from an Alibaba Cloud China site account can only connect to VPCs from Alibaba Cloud China site accounts. Similarly, a transit router from an Alibaba Cloud International site account can only connect to VPCs from Alibaba Cloud International site accounts.

The console reports the following error if the transit router and VPC belong to different account types. For other VPC connectivity solutions, see network connectivity.

Error connecting a VBR to a transit router

This error indicates that the underlying access device associated with the VBR does not support connections to a transit router. To resolve this, submit a ticket, and Alibaba Cloud will help you make the connection.连接VBR报错

VPC connection for non-upgraded transit routers

When you connect a VPC to an Enterprise Edition transit router that has not been upgraded, you must specify a primary and a secondary zone for the transit router. The VPC must have at least one vSwitch in each of these zones, and each vSwitch must have at least one available IP address. During the connection process, the transit router creates an elastic network interface (ENI) in a vSwitch in each zone. Each ENI consumes one IP address and connects the VPC to the Enterprise Edition transit router.

By default, traffic from the VPC is routed to the Enterprise Edition transit router through the ENI in the primary zone. If the ENI in the primary zone becomes unavailable, traffic automatically fails over to the ENI in the secondary zone.

When you specify the zones, note the following:

  • The primary and secondary zones must belong to the same VPC, and each zone must contain at least one vSwitch.

  • The route table and network ACL associated with the vSwitch containing the ENI affect how the VPC processes traffic from the Enterprise Edition transit router. If the vSwitches in the primary and secondary zones are associated with different route tables or network ACLs, traffic may be handled inconsistently during a failover. For more information about network ACLs, see Network ACL.

  1. Log on to the CEN console.

  2. On the CEN Instance page, click the ID of the CEN instance that you want to manage.

  3. Go to the Basic Information > Transit Router tab and click the ID of the transit router that you want to manage.

  4. On the Connection with Peer Network Instance page, configure the parameters for the network instance and click OK.

    The following table describes only the relevant parameters. For more information about other parameters, see Create VPC connections.

    Parameter

    Description

    Instance Type

    Select VPC.

    Region

    Select the region where the VPC is deployed.

    Transit Router

    The system automatically displays the transit router in the current region.

    Select the primary and secondary zones for the transit router.

    Select the primary and secondary zones for the transit router.

    After you select the zones, the system creates an ENI in a vSwitch in each of the specified zones.

    Networks

    Select the VPC instance ID.

    vSwitch

    Select a vSwitch in each of the primary and secondary zones.

VPC communication without route synchronization

The route synchronization feature lets an Enterprise Edition transit router propagate routes to its attached network instances. If you disable this feature for a VPC, the transit router stops propagating routes to it. To enable communication, add a route to the peer network instance in the VPC's route table.

If you do not enable route synchronization, use one of the following methods to route traffic from the VPC to the peer network instance through the transit router:

  • When you create a VPC connection, select the Auto-add transit router routes to all VPC route tables advanced feature. For more information, see Create a VPC connection.

    The system automatically adds routes with the destination CIDR blocks 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16 to all route tables in the VPC. The next hop for these routes is the VPC connection.

    Important

    If a route table in the VPC already contains a route with one of these destination CIDR blocks, the system cannot automatically add the new route. You must manually add a route that points to the VPC connection.

    When you create the VPC connection, you can click Check Route to check if these routes exist in the network instance.

  • Manually add a route to the VPC's route table. The route must point to the peer network instance and use the transit router as the next hop. For more information, see Use custom route tables to manage network traffic.

VBRs in a CEN fail to learn routes

Cause

When a VBR is attached to a CEN, the system automatically adds a routing policy to the route table of the associated transit router. This policy has a direction of Egress Regional Gateway, a priority of 5000, and an action of Reject. By default, this policy prevents the VBR from communicating with other VBRs attached to the same transit router. Note that a Basic Edition transit router has only one route table. For more information, see Default routing policies.

Solution

This automatic routing policy has a priority of 5000 and cannot be modified. To override this default policy, add a custom routing policy with a higher priority (a value less than 5000) to permit communication between the VBRs. For more information, see Use routing policies.

VBR instance cannot learn VPC routes

The troubleshooting steps depend on the edition of the transit router that connects the VBR and VPC instances.

Enterprise edition transit router

If the instances are connected to an enterprise edition transit router, follow these steps:

  1. Use path analysis and transit router instance diagnostics. For details, see Use path analysis and Diagnose a transit router instance.

  2. If the VBR instance and VPC instance are in different regions, ensure that an inter-region connection exists between the two transit routers. For details, see Use an enterprise edition transit router to create an inter-region connection.

  3. Ensure that the route table of the transit router connected to the VBR instance contains a route to the VPC instance.

  4. Check the routing policies applied to the route table of the transit router connected to the VBR instance. Ensure that the routing policy allows the VBR instance to learn routes from the VPC instance. For more information, see Routing Policy 1.0.

Basic edition transit router

If the VBR and VPC instances are connected to a basic edition transit router, follow these steps:

  1. If the VBR instance and VPC instance are in different regions, ensure that an inter-region connection exists between the two transit routers. For details, see Use a basic edition transit router to create an inter-region connection.

  2. Ensure that the route table of the basic edition transit router connected to the VBR instance contains a route to the VPC instance.

    By default, a basic edition transit router automatically learns routes from the route table of the VBR instance and system routes from the VPC instance. For the transit router to learn other routes from the VPC instance, you must advertise them. For details, see Advertise routes to a transit router.

  3. Check the routing policies applied to the route table of the basic edition transit router connected to the VBR instance. Ensure that the routing policy allows the VBR instance to learn routes from the VPC instance. For more information, see Routing Policy 1.0.

VPC fails to learn CEN routes

Troubleshoot the issue based on the edition of the connected transit router:

Enterprise Edition transit router

  1. By default, a VPC does not learn routes from an Enterprise Edition transit router upon connection. You must associate the VPC connection with the transit router's route table and enable route synchronization. After you enable route synchronization, the VPC automatically learns route entries from the associated route table. Ensure that the route table contains the required routes.

  2. Check for any route entry conflicts between the route table of the Enterprise Edition transit router and the route table of the VPC.

  3. Check the routing policies on the Enterprise Edition transit router's route table. Ensure that the policies allow the VPC to learn route entries from the route table. For more information, see Routing Policy 1.0.

Basic Edition transit router

By default, a VPC connected to a Basic Edition transit router automatically learns route entries from its route table. If the VPC fails to learn route entries, perform the following steps:

  1. Ensure that the Basic Edition transit router's route table contains the required routes.

  2. Check for any route entry conflicts between the route table of the Basic Edition transit router and the route table of the VPC.

  3. Check the routing policies on the Basic Edition transit router's route table. Ensure that the policies allow the VPC to learn route entries from the route table. For more information, see Routing Policy 1.0.

Route conflicts in VPC or CEN

For instructions, see Resolve route conflicts in a VPC route table or in CEN.

Resolve overlapping CIDR blocks

For more information, see How to resolve overlapping CIDR blocks for vSwitches in a VPC within a Cloud Enterprise Network.

Troubleshooting service access failure in CEN

  • If both network instances use basic edition transit routers, create an inter-region connection between them. For more information, see Use a basic edition transit router to create an inter-region connection.

    By default, a basic edition transit router provides 1 Kbps of inter-region bandwidth. This bandwidth is for connectivity testing only and does not support service traffic.

  • If at least one network instance is connected to an enterprise edition transit router, create an inter-region connection between the transit routers. When you create the inter-region connection, set the Bandwidth Allocation Mode to Allocate From Bandwidth Plan. For more information, see Use an enterprise edition transit router to create an inter-region connection.

    If you set the Bandwidth Allocation Mode to Use Testing Bandwidth when creating the connection, the system allocates a default inter-region bandwidth of 1 Kbps. This bandwidth is for connectivity testing only and is not intended for service traffic.

Troubleshoot SAG access to cloud services via an Enterprise Edition transit router

  1. Ensure that at least one VPC in the region where the cloud service is deployed is connected to the Enterprise Edition transit router. For more information, see Create a VPC connection by using an Enterprise Edition transit router.

  2. Ensure that an inter-region connection exists between the transit router attached to the CCN instance and the Enterprise Edition transit router connected to the VPC. For more information, see Create an inter-region connection by using an Enterprise Edition transit router.

  3. Ensure the route table of the Enterprise Edition transit router contains a route to the cloud service, with its next hop set to the VPC connection. For more information, see Configure access to cloud services.

  4. Ensure that the route table of the transit router to which the CCN instance is attached contains a route to the CIDR block of the SAG instance.

  5. Check the routing policies applied to the route tables of the transit router to which the CCN instance is attached and the Enterprise Edition transit router. Ensure that the routing policies propagate the CIDR blocks of the SAG instance and the cloud service. For more information, see Routing policies 1.0.

  6. Check the VPC's route table for a route entry to the SAG instance's CIDR block. If not, manually add a route entry with the next hop set to the VPC connection. For more information, see Create and manage a route table.

  7. Check for route conflicts in the route tables of the transit router to which the CCN instance is attached, the Enterprise Edition transit router, and the VPC.

  8. Check the access control policies.

    • Check for any access control policies configured on the SAG instance. Ensure that the policy allows the SAG instance to access the cloud service. For more information, see Access control overview.

    • Check for any network ACLs configured on the VPC. Ensure that the network ACL allows the SAG instance to access the cloud service. For more information about network ACLs, see Network ACL.

  9. Ensure that the service using the SAG instance and the destination cloud service are running correctly.

Troubleshoot ECS communication in CEN-connected VPCs

Troubleshoot the issue based on the transit router edition connecting the VPCs:

Enterprise Edition transit router

If at least one VPC is connected to an Enterprise Edition transit router, follow these steps:

  1. Verify that the ECS instances' VPCs are attached to the same CEN.

    For ECS instances to communicate, their VPCs must be attached to the same CEN. For more information, see Create a VPC connection.

  2. Use path analysis and transit router diagnostics to identify the problem. For more information, see Use path analysis and Diagnose a transit router instance.

  3. If the two VPCs are in different regions, ensure an inter-region connection exists between the two transit routers. For more information, see Use an Enterprise Edition transit router to create an inter-region connection.

  4. Check the network ACLs configured for both VPCs. Ensure that the rules allow traffic to flow between the ECS instances. For more information about network ACLs, see Network ACLs.

  5. Check the security group rules applied to the ECS instances. Ensure that the security group rules allow traffic to flow between the ECS instances. For more information, see Query security group rules and Add a security group rule.

  6. Verify that the required CIDR blocks have been published to the transit router. For more information, see Publish a route to a transit router.

  7. Check the route table of the transit router for routing policies. Ensure that the routing policies permit traffic between the required CIDR blocks.

  8. Check for route entry conflicts between the route tables of the transit router and the VPCs.

  9. If the issue persists, capture packets on the ECS instances to check for incoming traffic. For more information, see the following topics:

Basic Edition transit router

If both VPCs are connected to Basic Edition transit routers, follow these steps:

  1. Verify that the ECS instances' VPCs are attached to the same CEN.

    For ECS instances to communicate, their VPCs must be attached to the same CEN. For more information, see Create a VPC connection.

  2. If the two VPCs are in different regions, ensure an inter-region connection exists between the two transit routers. For more information, see Use a Basic Edition transit router to create an inter-region connection.

  3. Check the network ACLs configured for both VPCs. Ensure that the rules allow traffic to flow between the ECS instances. For more information about network ACLs, see Network ACLs.

  4. Check the security group rules applied to the ECS instances. Ensure that the security group rules allow traffic to flow between the ECS instances. For more information, see Query security group rules and Add a security group rule.

  5. Verify that the required CIDR blocks have been published to the transit router.

    By default, a Basic Edition transit router automatically learns a VPC's system routes. If the transit router needs to learn other routes from the VPC, you must publish them. For more information, see Publish a route to a transit router.

  6. Check the route table of the transit router for routing policies. Ensure that the routing policies permit traffic between the required CIDR blocks.

  7. Check for route entry conflicts between the route tables of the transit router and the VPCs.

  8. If the issue persists, capture packets on the ECS instances to check for incoming traffic. For more information, see the following topics:

Troubleshoot telnet failures for CEN-connected VPCs

For details, see What to do when telnet fails but ping succeeds between VPC instances connected via Cloud Enterprise Network.

Cannot ping Express Connect interface IPs

For a solution, see What to do if you cannot ping the Alibaba Cloud side and customer side IP addresses after you enable an Express Connect circuit.

Network connectivity fails after cross-account CEN authorization

For more information, see Why does network connectivity fail after a cross-account VPC instance is authorized?.

"Unauthorized network instance" error during CEN firewall creation

For more information, see Troubleshoot the "unauthorized network instance" error when creating a VPC firewall for a CEN.

Cannot attach cross-account VPC to CEN

Follow these steps to troubleshoot the issue:

  1. Verify that the VPC instance and the CEN instance belong to accounts of the same type.

    For example, you cannot attach a VPC instance from an Alibaba Cloud China site account to a CEN instance from an Alibaba Cloud International site account. In this case, the CEN instance only supports VPC instances from Alibaba Cloud International site accounts.

  2. Verify that the CEN instance has been authorized to access the cross-account VPC instance. For more information, see VPC Instance Authorization.

Change a VPC attachment to a single VSwitch

Yes. However, this change removes high availability and may interrupt service traffic. Take precautions to prevent service disruptions.

To do this, call the UpdateTransitRouterVpcAttachmentZones operation and specify the RemoveZoneMappings parameter.

Cross-region routes in a Basic Edition TR

This is by design. By default, Basic Edition TRs within the same CEN instance automatically propagate routes to each other as part of their default routing logic.

Basic Edition TRs include a minimal test bandwidth of 1 Kbps by default. This bandwidth is for network reachability tests only. To handle cross-region traffic, you must purchase a bandwidth package and configure a cross-region connection.

For granular control over route propagation, upgrade to the Enterprise Edition.