Cross-account authorization for network instances

Updated at:

To connect a transit router (TR) to a network instance (such as a VPC, VBR, CCN, ECR, or IPsec-VPN connection) that belongs to another Alibaba Cloud account, the network instance's owner must first authorize the transit router. A transit router can connect to the cross-account network instance only after this authorization is granted. This topic describes the network instance authorization process and related operations.

Billing

Connecting an Enterprise Edition transit router to a VPC, VBR, ECR, or IPsec-VPN connection incurs a network instance attachment fee and a data forwarding fee. During the authorization process, you can specify whether the fees are paid by the account that owns the network instance or the account that owns the Enterprise Edition transit router. For more information about the billing of Enterprise Edition transit routers, see Billing.

Limitations

  • A transit router instance that belongs to an Alibaba Cloud account for a Chinese Mainland site can connect only to network instances that belong to accounts for Chinese Mainland sites. A transit router instance that belongs to an Alibaba Cloud account for an international site can connect only to network instances that belong to accounts for international sites.

  • After connecting an Enterprise Edition transit router to a cross-account network instance, you cannot directly change the payment account. You must first detach the network instance from the transit router. For more information, see Change the payment account for a network instance.

Prerequisites

Before you authorize a network instance, make sure that the following requirements are met:

  • Confirm that the account owning the network instance and the account owning the transit router instance are of the same type.

    A transit router instance that belongs to an Alibaba Cloud account for a Chinese Mainland site can connect only to network instances that belong to accounts for Chinese Mainland sites. A transit router instance that belongs to an Alibaba Cloud account for an international site can connect only to network instances that belong to accounts for international sites.

  • Obtain the account ID of the primary account that owns the transit router instance.

  • Obtain the ID of the CEN instance to which the transit router instance belongs.

  • Before you authorize a VBR instance, you must request the necessary permissions. For more information, see Self-service application for connecting a VBR to a CEN instance or VPC that belongs to another account.

  • Before authorizing an IPsec-VPN connection, make sure that it is not attached to any resource:

    • If the IPsec-VPN connection is attached to a VPN Gateway instance, you cannot attach it to a transit router instance, regardless of whether they are in the same account.

    • If the IPsec-VPN connection is already attached to a transit router instance, you must detach it first. For more information, see Delete a network instance attachment.

Scenario

This topic uses the scenario in the following figure as an example, where Account A authorizes a transit router in Account B to access its network instances.

image

Authorize a network instance

VPC instance

  1. Log on to the VPC console with Account A.

  2. In the top navigation bar, select the region where the target VPC instance is deployed.

  3. On the VPC page, find the target VPC instance and click its instance ID.

  4. Click the Cross-account Authorization tab. On the CEN tab, click Cross-account Authorization.

  5. In the Attach to CEN dialog box, configure the parameters and click OK.

    Parameter

    Description

    Peer Account UID

    The account ID of the primary account that owns the transit router instance.

    Peer CEN Instance ID

    The ID of the CEN instance to which the transit router instance belongs.

    Payer

    Select the payer.

    • CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the VPC instance.

    • VPC Users: The account that owns the VPC instance pays the network instance attachment fee and data forwarding fee incurred by the VPC instance.

    Important

    Select the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.

    After you configure the settings, the authorization is complete. You can view the authorization information on the Cross-account Authorization tab.

  6. Take note of the VPC ID and account ID from Account A. They are required to create the VPC attachment. For more information, see Create a VPC attachment.

    You can view your account ID on the Account Center page.

VBR instance

  1. Log on to the Express Connect console with Account A.

  2. In the top navigation bar, select the region where the target VBR instance is deployed.

  3. In the left-side navigation pane, click Virtual Border Routers (VBRs).

  4. On the Virtual Border Routers (VBRs) page, click the ID of the target VBR instance.

  5. Click the CEN Authorization tab. On this tab, click Authorize CEN of Another Account to Load Instance.

  6. In the Authorize CEN of Another Account to Load Instance panel, configure the parameters and click OK.

    Parameter

    Description

    CEN Instance ID

    The ID of the CEN instance to which the transit router instance belongs.

    CEN Account

    The account ID of the primary account that owns the transit router instance.

    Payer

    Select the payer.

    • CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the VBR instance.

    • VBR Owner: The account that owns the VBR instance pays the network instance attachment fee and data forwarding fee incurred by the VBR instance.

    Important

    Select the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.

    After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Authorization tab.

  7. Take note of the VBR ID and account ID from Account A. They are required to create the VBR attachment. For more information, see Create a VBR attachment.

    You can view your account ID on the Account Center page.

CCN instance

  1. Log on to the Smart Access Gateway (SAG) console with Account A.

  2. In the top navigation bar, select the region where the target CCN instance is deployed.

  3. In the left-side navigation pane, click CCN.

  4. On the CCN page, click the ID of the target CCN instance.

  5. On the instance details page, click the CEN Cross Account Authorization Information tab. On this tab, click CEN Cross Account Authorization.

  6. In the Attach to CEN dialog box, enter the account ID for Account B and the CEN instance ID from Account B, and click OK.

    After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Cross Account Authorization Information tab.

  7. Take note of the CCN ID and account ID from Account A. They are required to create the CCN attachment. For more information, see Create a CCN attachment.

    You can view your account ID on the Account Center page.

IPsec-VPN connection

  1. Log on to the VPN Gateway console.

  2. In the left navigation pane, choose Interconnections > VPN > IPsec Connections.

  3. In the top navigation bar, select the region of the IPsec-VPN connection.
  4. On the IPsec Connections page, find the target IPsec-VPN connection and click its ID.

  5. On the connection details page, click the Cross-account Authorization tab, and then click Cross-account Authorization.

  6. In the Attach to CEN dialog box, configure the parameters and click OK.

    Parameter

    Description

    Peer Account UID

    The account ID of the primary account that owns the transit router instance.

    Peer CEN Instance ID

    The ID of the CEN instance to which the transit router instance belongs.

    Payer

    Select the payer.

    • CEN Instance Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee for the IPsec-VPN connection.

    • VPN Owner: The account that owns the IPsec-VPN connection pays the network instance attachment fee and data forwarding fee for the IPsec-VPN connection.

    Important
    • Select the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.

    • After an IPsec-VPN connection is attached to a transit router, its owner remains responsible for the connection's instance and data transfer fees.

    After you configure the settings, the authorization is complete. You can view the authorization information on the Cross-account Authorization tab.

  7. Take note of the IPsec-VPN connection ID and the account ID of the primary account that owns the connection. They are required to create the VPN attachment. For more information, see Create a VPN attachment.

    You can view your account ID on the Account Center page.

ECR instance

  1. Log on to the Express Connect console with Account A.

  2. In the left-side navigation pane, click Express Connect Router (ECR).

  3. On the Express Connect Router (ECR) page, click the ID of the target ECR instance.

  4. Click the CEN Authorization tab. On this tab, click Authorize CEN of Another Account to Load Instance.

  5. In the Join CEN dialog box, configure the parameters and click OK.

    Parameter

    Description

    CEN Instance ID

    The ID of the CEN instance to which the transit router instance belongs.

    CEN Account

    The account ID of the primary account that owns the transit router instance.

    Payer

    Select the payer.

    • CEN Owner (default): The account that owns the transit router instance pays the network instance attachment fee and data forwarding fee incurred by the ECR instance.

    • ECR Owner: The account that owns the ECR instance pays the network instance attachment fee and data forwarding fee incurred by the ECR instance.

    Important

    Select the payer with caution. Changing the payer may affect your services. For more information, see Change the payment account for a network instance.

    After you configure the settings, the authorization is complete. You can view the authorization information on the CEN Authorization tab.

  6. Take note of the ECR ID and account ID from Account A. They are required to create the ECR attachment. For more information, see Create an ECR attachment.

    You can view your account ID on the Account Center page.

Change the payment account

  • If the Enterprise Edition transit router is not yet attached to the cross-account network instance, you must go to the resource account (the account that owns the network instance), revoke the existing authorization, and then grant a new authorization with the updated payment setting.

  • If a cross-account network instance is already attached to the Enterprise Edition transit router, you must first modify the payer in the resource account, then modify it on the transit router side, and finally wait for the change to take effect at the top of the next hour.

    You can change the payer only for VPC, VBR, and VPN attachments. This feature is not supported for ECR attachments.

    Console

    This example demonstrates how to change the payer for a cross-account VPC attachment. The following assumptions apply:

    • Account A owns the CEN instance. Account B owns the VPC instance.

    • The current payer is Account A (CEN Instance Owner).

    To change the payer to Account B (VPC Owner), follow these steps:

    1. Log on with Account B and change the payer on the VPC instance details page.

      On the details page of the target VPC instance, go to the Cross-account Authorization tab. In the Payer column for the authorization rule, click Edit and select VPC Users.

    2. Log on with Account A and change the payer for the VPC attachment.

      Go to the target transit router. Find the target VPC attachment, and in the Payer Account column, click Edit and select Resource Owner Account.

    3. Wait for the change to take effect.

      The change takes effect at the top of the next hour.

    API

    1. Log on to the resource account and call the ModifyGrantInstanceToTransitRouter operation. Set the OrderType parameter to the desired payer.

    2. Log on to the account that owns the transit router and change the payer:

    3. Wait for the change to take effect at the top of the next hour. You can log on to the transit router account and call the DescribeGrantRulesToCen operation to confirm that the value of the EffectiveOrderType parameter is updated to the desired payer.

Revoke authorization

Before revoking authorization for a network instance, you must first detach it from the transit router. For more information, see Delete a network instance attachment.

VPC instance

  1. Log on to the VPC console with Account A.

  2. In the top navigation bar, select the region where the target VPC instance is deployed.

  3. On the VPC page, find the target VPC instance and click its instance ID.

  4. Click the Cross-account Authorization tab. On the CEN tab, find the target authorization rule and click Revoke Permissions in the Actions column.

  5. In the Revoke Permissions dialog box, confirm the information and then click OK.

VBR instance

  1. Log on to the Express Connect console with Account A.

  2. In the top navigation bar, select the region where the target VBR instance is deployed.

  3. In the left-side navigation pane, click Virtual Border Routers (VBRs).

  4. On the Virtual Border Routers (VBRs) page, click the ID of the target VBR instance.

  5. Click the CEN Authorization tab. Find the target authorization rule and click Delete in the Actions column.

  6. In the Revoke Authorization dialog box, confirm the information and then click OK.

CCN instance

  1. Log on to the Smart Access Gateway (SAG) console with Account A.

  2. In the top navigation bar, select the region where the target CCN instance is deployed.

  3. In the left-side navigation pane, click CCN.

  4. On the CCN page, click the ID of the target CCN instance.

  5. Click the CEN Cross Account Authorization Information tab. Find the target authorization rule and click Revoke Authorization in the Actions column.

  6. In the Note dialog box, confirm the information and then click OK.

IPsec-VPN connection

  1. Log on to the VPN Gateway console with Account A.

  2. In the top navigation bar, select the region where the target IPsec-VPN connection is deployed.

  3. In the left-side navigation pane, choose Network Interconnection > VPN > IPsec Connections.

  4. On the IPsec Connections page, find the target IPsec-VPN connection and click its ID.

  5. On the connection details page, go to the Cross-account Authorization tab, find the target authorization rule, and click Revoke Permissions in the Actions column.

  6. In the Revoke Permissions dialog box, confirm the information and then click OK.

ECR instance

  1. Log on to the Express Connect console with Account A.

  2. In the left-side navigation pane, click Express Connect Router (ECR).

  3. On the Express Connect Router (ECR) page, click the ID of the target ECR instance.

  4. Click the CEN Authorization tab. Find the target authorization rule and click Delete in the Actions column.

  5. In the Revoke Authorization dialog box, confirm the information and then click OK.