Cross-account authorization for network instances
To connect a transit router (TR) to a network instance (such as a VPC, VBR, CCN, ECR, or IPsec-VPN connection) that belongs to another Alibaba Cloud account, the network instance's owner must first authorize the transit router. A transit router can connect to the cross-account network instance only after this authorization is granted. This topic describes the network instance authorization process and related operations.
Billing
Connecting an Enterprise Edition transit router to a VPC, VBR, ECR, or IPsec-VPN connection incurs a network instance attachment fee and a data forwarding fee. During the authorization process, you can specify whether the fees are paid by the account that owns the network instance or the account that owns the Enterprise Edition transit router. For more information about the billing of Enterprise Edition transit routers, see Billing.
Limitations
A transit router instance that belongs to an Alibaba Cloud account for a Chinese Mainland site can connect only to network instances that belong to accounts for Chinese Mainland sites. A transit router instance that belongs to an Alibaba Cloud account for an international site can connect only to network instances that belong to accounts for international sites.
After connecting an Enterprise Edition transit router to a cross-account network instance, you cannot directly change the payment account. You must first detach the network instance from the transit router. For more information, see Change the payment account for a network instance.
Prerequisites
Before you authorize a network instance, make sure that the following requirements are met:
Confirm that the account owning the network instance and the account owning the transit router instance are of the same type.
A transit router instance that belongs to an Alibaba Cloud account for a Chinese Mainland site can connect only to network instances that belong to accounts for Chinese Mainland sites. A transit router instance that belongs to an Alibaba Cloud account for an international site can connect only to network instances that belong to accounts for international sites.
Obtain the account ID of the primary account that owns the transit router instance.
Obtain the ID of the CEN instance to which the transit router instance belongs.
Before you authorize a VBR instance, you must request the necessary permissions. For more information, see Self-service application for connecting a VBR to a CEN instance or VPC that belongs to another account.
Before authorizing an IPsec-VPN connection, make sure that it is not attached to any resource:
If the IPsec-VPN connection is attached to a VPN Gateway instance, you cannot attach it to a transit router instance, regardless of whether they are in the same account.
If the IPsec-VPN connection is already attached to a transit router instance, you must detach it first. For more information, see Delete a network instance attachment.
Scenario
This topic uses the scenario in the following figure as an example, where Account A authorizes a transit router in Account B to access its network instances.
Authorize a network instance
VPC instance
Log on to the VPC console with Account A.
In the top navigation bar, select the region where the target VPC instance is deployed.
On the VPC page, find the target VPC instance and click its instance ID.
Click the Cross-account Authorization tab. On the CEN tab, click Cross-account Authorization.
In the Attach to CEN dialog box, configure the parameters and click OK.
Parameter
Description
Peer Account UID
The account ID of the primary account that owns the transit router instance.
Peer CEN Instance ID
The ID of the CEN instance to which the transit router instance belongs.
Payer
Select the payer.
CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the VPC instance.
VPC Users: The account that owns the VPC instance pays the network instance attachment fee and data forwarding fee incurred by the VPC instance.
ImportantSelect the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.
After you configure the settings, the authorization is complete. You can view the authorization information on the Cross-account Authorization tab.
Take note of the VPC ID and account ID from Account A. They are required to create the VPC attachment. For more information, see Create a VPC attachment.
You can view your account ID on the Account Center page.
VBR instance
Log on to the Express Connect console with Account A.
In the top navigation bar, select the region where the target VBR instance is deployed.
In the left-side navigation pane, click Virtual Border Routers (VBRs).
On the Virtual Border Routers (VBRs) page, click the ID of the target VBR instance.
Click the CEN Authorization tab. On this tab, click Authorize CEN of Another Account to Load Instance.
In the Authorize CEN of Another Account to Load Instance panel, configure the parameters and click OK.
Parameter
Description
CEN Instance ID
The ID of the CEN instance to which the transit router instance belongs.
CEN Account
The account ID of the primary account that owns the transit router instance.
Payer
Select the payer.
CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the VBR instance.
VBR Owner: The account that owns the VBR instance pays the network instance attachment fee and data forwarding fee incurred by the VBR instance.
ImportantSelect the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.
After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Authorization tab.
Take note of the VBR ID and account ID from Account A. They are required to create the VBR attachment. For more information, see Create a VBR attachment.
You can view your account ID on the Account Center page.
CCN instance
Log on to the Smart Access Gateway (SAG) console with Account A.
In the top navigation bar, select the region where the target CCN instance is deployed.
In the left-side navigation pane, click CCN.
On the CCN page, click the ID of the target CCN instance.
On the instance details page, click the CEN Cross Account Authorization Information tab. On this tab, click CEN Cross Account Authorization.
In the Attach to CEN dialog box, enter the account ID for Account B and the CEN instance ID from Account B, and click OK.
After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Cross Account Authorization Information tab.
Take note of the CCN ID and account ID from Account A. They are required to create the CCN attachment. For more information, see Create a CCN attachment.
You can view your account ID on the Account Center page.
IPsec-VPN connection
Log on to the VPN Gateway console.
In the left navigation pane, choose .
- In the top navigation bar, select the region of the IPsec-VPN connection.
On the IPsec Connections page, find the target IPsec-VPN connection and click its ID.
On the connection details page, click the Cross-account Authorization tab, and then click Cross-account Authorization.
In the Attach to CEN dialog box, configure the parameters and click OK.
Parameter
Description
Peer Account UID
The account ID of the primary account that owns the transit router instance.
Peer CEN Instance ID
The ID of the CEN instance to which the transit router instance belongs.
Payer
Select the payer.
CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee for the IPsec-VPN connection.
VPN Owner: The account that owns the IPsec-VPN connection pays the network instance attachment fee and data forwarding fee for the IPsec-VPN connection.
ImportantSelect the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.
After an IPsec-VPN connection is attached to a transit router, its owner remains responsible for the connection's instance and data transfer fees.
After you configure the settings, the authorization is complete. You can view the authorization information on the Cross-account Authorization tab.
Take note of the IPsec-VPN connection ID and the account ID of the primary account that owns the connection. They are required to create the VPN attachment. For more information, see Create a VPN attachment.
You can view your account ID on the Account Center page.
ECR instance
Log on to the Express Connect console with Account A.
In the left-side navigation pane, click Express Connect Router (ECR).
On the Express Connect Router (ECR) page, click the ID of the target ECR instance.
Click the CEN Authorization tab. On this tab, click Authorize CEN of Another Account to Load Instance.
In the Join CEN dialog box, configure the parameters and click OK.
Parameter
Description
CEN Instance ID
The ID of the CEN instance to which the transit router instance belongs.
CEN Account
The account ID of the primary account that owns the transit router instance.
Payer
Select the payer.
CEN Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the ECR instance.
ECR Owner: The account that owns the ECR instance pays the network instance attachment fee and data forwarding fee incurred by the ECR instance.
ImportantSelect the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.
After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Authorization tab.
Take note of the ECR ID and account ID from Account A. They are required to create the ECR attachment. For more information, see Create an ECR attachment.
You can view your account ID on the Account Center page.
Change the payment account
If the Enterprise Edition transit router is not yet attached to the cross-account network instance, you must go to the resource account (the account that owns the network instance), revoke the existing authorization, and then grant a new authorization with the updated payment setting.
If a cross-account network instance is already attached to the Enterprise Edition transit router, you must first modify the payer in the resource account, then modify it on the transit router side, and finally wait for the change to take effect at the top of the next hour.
You can change the payer only for VPC, VBR, and VPN attachments. This feature is not supported for ECR attachments.
Console
This example demonstrates how to change the payer for a cross-account VPC attachment. The following assumptions apply:
Account A owns the CEN instance. Account B owns the VPC instance.
The current payer is Account A (CEN Instance Owner).
To change the payer to Account B (VPC Owner), follow these steps:
Log on with Account B and change the payer on the VPC instance details page.
On the details page of the target VPC instance, go to the Cross-account Authorization tab. In the Payer column for the authorization rule, click Edit and select VPC Users.
Log on with Account A and change the payer for the VPC attachment.
Go to the target transit router. Find the target VPC attachment, and in the Payer Account column, click Edit and select Resource Owner Account.
Wait for the change to take effect.
The change takes effect at the top of the next hour.
API
Log on to the resource account and call the ModifyGrantInstanceToTransitRouter operation. Set the
OrderTypeparameter to the desired payer.Log on to the account that owns the transit router and change the payer:
For a VPC instance, call the UpdateTransitRouterVpcAttachmentAttribute operation. Set the
OrderTypeparameter to the desired payer.For a VBR instance, call the UpdateTransitRouterVbrAttachmentAttribute operation. Set the
OrderTypeparameter to the desired payer.For a VPN attachment, call the UpdateTransitRouterVpnAttachmentAttribute operation. Set the
OrderTypeparameter to the desired payer.
Wait for the change to take effect at the top of the next hour. You can log on to the transit router account and call the DescribeGrantRulesToCen operation to confirm that the value of the
EffectiveOrderTypeparameter is updated to the desired payer.
Revoke authorization
Before revoking authorization for a network instance, you must first detach it from the transit router. For more information, see Delete a network instance attachment.
VPC instance
Log on to the VPC console with Account A.
In the top navigation bar, select the region where the target VPC instance is deployed.
On the VPC page, find the target VPC instance and click its instance ID.
Click the Cross-account Authorization tab. On the CEN tab, find the target authorization rule and click Revoke Permissions in the Actions column.
In the Revoke Permissions dialog box, confirm the information and then click OK.
VBR instance
Log on to the Express Connect console with Account A.
In the top navigation bar, select the region where the target VBR instance is deployed.
In the left-side navigation pane, click Virtual Border Routers (VBRs).
On the Virtual Border Routers (VBRs) page, click the ID of the target VBR instance.
Click the CEN Authorization tab. Find the target authorization rule and click Delete in the Actions column.
In the Revoke Authorization dialog box, confirm the information and then click OK.
CCN instance
Log on to the Smart Access Gateway (SAG) console with Account A.
In the top navigation bar, select the region where the target CCN instance is deployed.
In the left-side navigation pane, click CCN.
On the CCN page, click the ID of the target CCN instance.
Click the CEN Cross Account Authorization Information tab. Find the target authorization rule and click Revoke Authorization in the Actions column.
In the Note dialog box, confirm the information and then click OK.
IPsec-VPN connection
Log on to the VPN Gateway console with Account A.
In the top navigation bar, select the region where the target IPsec-VPN connection is deployed.
In the left-side navigation pane, choose Network Interconnection > VPN > IPsec Connections.
On the IPsec Connections page, find the target IPsec-VPN connection and click its ID.
On the connection details page, go to the Cross-account Authorization tab, find the target authorization rule, and click Revoke Permissions in the Actions column.
In the Revoke Permissions dialog box, confirm the information and then click OK.
ECR instance
Log on to the Express Connect console with Account A.
In the left-side navigation pane, click Express Connect Router (ECR).
On the Express Connect Router (ECR) page, click the ID of the target ECR instance.
Click the CEN Authorization tab. Find the target authorization rule and click Delete in the Actions column.
In the Revoke Authorization dialog box, confirm the information and then click OK.