Create and manage VBR-to-VPC connections

Updated at:
Important

VBR-to-VPC connections are no longer available for purchase. We recommend that you use Express Connect Router (ECR). ECR is a forwarding service component for global hybrid cloud networks that are built by using Express Connect. It provides features such as global network interconnection, fully dynamic routing, and unified route advertisement and management.

By creating a VBR-to-VPC connection, you can establish private connectivity between a VBR and a VPC. This topic describes how to create and manage VBR-to-VPC connections.

Prerequisites

Create a VBR-to-VPC connection

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, choose Peering Connections > VBR-to-VPC.

  3. On the VBR-to-VPC page, click Create Peering Connection.

  4. On the Establish VBR-VPC Interconnection page, configure the following parameters.

    You can create VBR-to-VPC connections for the following scenarios: same-account and intra-region, same-account and inter-region, cross-account and intra-region, and cross-account and inter-region.

    The following table describes the parameters.

    Parameter

    Description

    Resource Group

    Select the resource group to which the VBR instance belongs.

    Initiator Region

    Select the region where the initiator VBR instance is deployed.

    Initiator VBR

    Select the initiator VBR instance from the drop-down list.

    Acceptor Region Type

    Select the region type of the acceptor VPC instance.

    • Intra-Region: The acceptor VPC instance and the initiator VBR instance are in the same region.

    • Inter-Region: The acceptor VPC instance and the initiator VBR instance are in different regions.

      If you select Inter-Region, select the region where the acceptor VPC instance is deployed from the Acceptor Region drop-down list.

    Acceptor Account Type

    Select the type of the Alibaba Cloud account to which the acceptor VPC instance belongs.

    • Current Account: The acceptor VPC instance and the initiator VBR instance belong to the same Alibaba Cloud account.

      After the initiator sends a connection request, the system automatically establishes the connection. The acceptor is not required to accept the request.

    • Another Account: The acceptor VPC instance and the initiator VBR instance belong to different Alibaba Cloud accounts.

      After the initiator sends a connection request, the acceptor must accept it to establish the peering connection. The acceptor can also reject the connection request to terminate the process.

      If you select Another Account, enter the ID of the Alibaba Cloud account to which the acceptor VPC instance belongs in the Acceptor Account ID field.

    Note
    • For security and compliance reasons, cross-account VBR connectivity is not enabled by default. If you want to connect your VBR to a Cloud Enterprise Network (CEN) instance or a VPC that belongs to a different Alibaba Cloud account, you must provide a document to prove that the main accounts of these Alibaba Cloud accounts belong to the same entity. Then, contact your account manager to request this feature.

      The following figure shows a sample proof of affiliation:

      image
    • To create a cross-account connection, the VBR instance must be authorized by the account to which the acceptor VPC belongs. After authorization is successful, you can select the Alibaba Cloud account ID of the acceptor and the acceptor VPC instance. For more information, see Create a cross-account VBR-to-VPC connection.

    Acceptor VPC

    Select the acceptor VPC instance from the drop-down list.

    Tags

    Select an existing tag key and value, or enter a new key and value. You can add tags to VBR-to-VPC connection instances to categorize and manage them.

    Billing Method

    Select a billing method for the peering connection. Only Pay-as-you-go, Pay-by-bandwidth and are supported.

    Note

    This parameter is required if you set Acceptor Region Type to Inter-Region.

    Select Bandwidth

    Select a bandwidth for the peering connection.

    You do not need to specify the bandwidth for the acceptor instance. It uses the default bandwidth.

    Note

    This parameter is required if you set Acceptor Region Type to Inter-Region.

    Fee Details

    The system automatically displays the Bandwidth Fee.

  5. Read and select the terms of service, and then click OK.

    Note

    If the connection is cross-border, which means one region is in the Chinese mainland and the other is outside the Chinese mainland, you must also select the corresponding cross-border declaration to create the connection.

    After the connection is established, the status of both the initiator and the acceptor changes to Activated.

Configure routes

After you establish the peering connection, you must configure routes for both the VBR and the VPC.

  1. Log on to the Express Connect console.

  2. In the top navigation bar, select a region. Then, in the left-side navigation pane, choose Peering Connections > VBR-to-VPC.

  3. On the VBR-to-VPC page, find the target instance, and in the Initiator column, click Route Settings.

  4. In the Basic Information panel, click Add Route, enter the CIDR block of the acceptor VPC in the dialog box that appears, and then click OK.

    After the route is configured, you can view the route information in the Basic Information panel.

  5. Return to the VBR-to-VPC page and click Route Settings in the Acceptor column.

  6. In the Basic Information panel, click Add Route, enter the CIDR block of the initiator's on-premises data center in the dialog box that appears, and then click OK.

    After the route is configured, you can view the route information in the Basic Information panel.

VBR route table does not support priority settings. To implement active/standby switchover, configure primary and backup routes in the VPC route table: when adding a custom route entry, select router interface (VBR direction) for next hop type, and specify the next hops of the primary route and the backup route respectively. The weight of the primary route is 100, and the weight of the backup route is 0.

Delete a VBR-to-VPC connection

You can delete a VBR-to-VPC connection that you no longer need. This operation is irreversible. Before you proceed, ensure that deleting the connection does not affect your services.

  1. Log on to the Express Connect console.

  2. In the top navigation bar, select a region. Then, in the left-side navigation pane, choose Peering Connections > VBR-to-VPC.

  3. On the VBR-to-VPC page, find the pay-as-you-go VBR-to-VPC connection that you want to delete, and then click Delete in the Actions column.

  4. In the dialog box that appears, click OK.

Related operations

Configure VBR health checks

To ensure smooth failover between two physical connections in the event of a failure, you must configure a health check for the VBR. If a health check is no longer needed, you can clear its settings.

Actions

Procedure

Set up a health check

Important

If you use a cross-account VBR-to-VPC connection, you must configure the health check on the VBR side under the receiver account.

  1. On the VBR-to-VPC page, find the VBR-to-VPC connection instance for which you want to configure a health check, and then click Health Check in the Actions column.

  2. In the Health Check panel, click Configure.

  3. In the Edit VBR panel, configure the following parameters and click OK.

    1. Source IP: Enter an unused private IP address from within the connected VPC.

    2. Destination IP: Enter the interface IP address of the network device in your on-premises data center. If you want to perform an ICMP health check from the data center to the VPC, set the target IP address to the source IP address of the VPC health check and configure a route that points to the new health check destination.

    3. Send Packet Every (Seconds): The interval between probe packets. The recommended value is 2. This means that Alibaba Cloud sends a ping packet from each health check source IP address to the health check destination in your data center every 2 seconds.

    4. Packets Detected: The number of probe packets sent in succession. The recommended value is 8. If eight consecutive ping packets sent over a physical connection fail to receive a response, traffic fails over to the other physical connection. Make sure that the probe packet rate limit for the health check source IP address on your on-premises gateway device is not less than 500 packets per second.

Clear health check settings

  1. On the VBR-to-VPC page, find the VBR-to-VPC connection instance whose health check you want to clear, and then click Health Check in the Actions column.

  2. In the Health Check panel, click Clear.

  3. In the dialog box that appears, click OK.

Suspend or activate the initiator or acceptor

Suspend an active initiator or acceptor instance to stop data forwarding. To resume data forwarding, activate the instance.

Actions

Procedure

Suspend the initiator or acceptor

  1. On the VBR-to-VPC page, find the target VBR-to-VPC connection instance, and in the Actions column, click the More actions icon and choose > Suspend Initiator or click the More actions icon and choose > Suspend Acceptor.

  2. In the dialog box that appears, click OK.

Activate the initiator or acceptor

  1. On the VBR-to-VPC page, find the target VBR-to-VPC connection instance, and in the Actions column, click the More actions icon and choose > Activate Initiator or click the More actions icon and choose > Activate Acceptor.

  2. In the dialog box that appears, click OK.

Manage a pay-as-you-go VBR-to-VPC connection

Actions

Description

Procedure

Upgrade

Increase the bandwidth of the VBR-to-VPC connection.

  1. On the VBR-to-VPC page, find the pay-as-you-go VBR-to-VPC instance, and in the Actions column, click Modify Bandwidth Configurations or .

  2. In the Change Specification dialog box, select a bandwidth from the Change Bandwidth Limit drop-down list, read and select the terms of service, and then click OK.

References