Create and Manage Express Connect Router

更新时间:
复制 MD 格式

An Express Connect Router (ECR) provides high-performance, high-capacity, and low-latency connections between a Virtual Private Cloud and a data center.

Limitations

  • When you add a virtual border router (VBR) to an ECR, the ASN of the VBR's BGP group must match the ECR's ASN. If the ASN of your ECR is not 45104, associate the VBR with the ECR before you configure BGP settings for the VBR.

  • You cannot add a VBR that does not support MPBGP to an ECR. To check if your VBR supports MPBGP, go to its details page and find Basic Information in the Advanced features of ports: section.

Prerequisites

  • You have created a virtual border router (VBR) instance.

  • If you plan to associate a VPC with the ECR, ensure that you have created the required Virtual Private Cloud (VPC).

    Note

    A VPC can receive dynamic routes from only one source at a time. If the VPC is already associated with a transit router (TR) and has route synchronization enabled, you cannot associate the VPC with an ECR. For more information, see the description of Route tables in the dynamic routing topic.

  • If you plan to associate a transit router (TR) instance with the ECR, ensure that you have created the required transit router (TR) instance.

Create an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click Create ECR.

  3. In the Create ECR dialog box, set the parameters, select I have read and understand the billing rules, and then click OK.

    Parameter

    Description

    Name

    Enter a name for the ECR.

    ASN

    Enter an ASN. The value can be 45104 (default), a number from 64512 to 65534, or a number from 4200000000 to 4294967294. 65025 is reserved by Alibaba Cloud.

    Resource Group

    Select the resource group to which the ECR belongs.

    Description

    Enter a description for the ECR.

Associate a VBR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.

  3. On the VBR tab, click Associate VBR.

  4. In the Associate VBR dialog box, set the following parameters and click OK.

    Parameter

    Description

    Resource Owner

    The account that owns the VBR. Valid values:

    • Current Account.

    • Another Account: To add a VBR from another Alibaba Cloud account, the VBR's owner must first authorize your ECR to access it. For more information, see Cross-account VBR authorization.

    Region

    Select the region where the VBR resource is deployed.

    Peer Account UID

    Enter the UID of the peer Alibaba Cloud account.

    Note

    This parameter is required when Resource Owner is set to Another Account.

    Network Instance

    Select the target VBR instance.

    Allow Business Access Between Data Centers

    Select whether to allow traffic between data centers.

    Note

    This feature is disabled by default. To enable it, contact your Alibaba Cloud account manager.

Associate a VPC

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.

  3. On the VPC tab, click Associate VPC.

  4. In the Associate VPC dialog box, set the following parameters and click OK.

    Parameter

    Description

    Resource Owner

    The account that owns the VPC. Valid values:

    • Current Account.

    • Another Account: To associate a VPC from another Alibaba Cloud account, the VPC's owner must first authorize your ECR to access it. For more information, see Cross-account VPC authorization.

    Region

    Select the region where the target VPC is deployed.

    Peer Account UID

    Enter the UID of the peer Alibaba Cloud account.

    Note

    This parameter is required when Resource Owner is set to Another Account.

    VPC ID

    Select the ID of the target VPC.

    If a VPC is grayed out and cannot be selected, move the pointer over the small lock icon to the right of the VPC instance ID to view the reason why it cannot be selected. A typical reason is The dynamic source already exists. (a VPC route table receives dynamic routes from only a single dynamic routing source at a time. For more information, see Limits on VPC dynamic routing).

    Allowed Route Prefixes

    Enter the route prefixes that you want to advertise from the ECR to the data center. You can select Matching Mode or Incremental Mode to configure the route prefixes.

    Note
    • The ECR (Express Connect Router) supports adding IPv4 prefix routes and IPv6 prefix routes.

    • When configuring prefix routes, you can select or switch between the following modes:

      • Match mode: Express Connect will withdraw the specific (detailed) routes already advertised to the IDC and instead advertise the configured allowed prefix routes to the IDC.

      • Incremental mode: Express Connect will withdraw the specific routes that have been advertised to the IDC and fall within the configured prefix route range, while specific routes outside the prefix route range remain advertised.

      • Switching from Match mode to Incremental mode: Express Connect will re-advertise the specific routes that fall outside the prefix route range to the IDC, while the configured prefix routes remain advertised.

      • Switching from Incremental mode to Match mode: Express Connect will withdraw the specific routes that have been advertised to the IDC and fall outside the prefix route range, while the configured prefix routes remain advertised.

      If no prefix route is configured, or if the configured prefix routes are cleared, Express Connect will automatically advertise the specific routes to the IDC.

    • If your ECR currently advertises only a single specified prefix route, and you modify that prefix route, Alibaba Cloud will briefly restore the specific routes to ensure your business traffic runs smoothly and continuously. Once the modified prefix route has been advertised, it will then switch back to your configured prefix route. Please pay close attention to the impact that advertising specific routes may have on your peer network.

Associate a TR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.

  3. On the TR tab, click Associate TR.

  4. In the Associate TR dialog box, set the following parameters and click OK.

    Parameter

    Description

    CEN ID

    Select the CEN instance that contains the target transit router.

    Region

    Select the region where the target transit router is deployed.

    TR

    Select the target transit router instance.

    Allowed Route Prefixes

    Enter the route prefixes that you want to advertise from the ECR to the data center. You can select Matching Mode or Incremental Mode to configure the route prefixes.

    Note
    • The ECR (Express Connect Router) supports adding IPv4 prefix routes and IPv6 prefix routes.

    • When configuring prefix routes, you can select or switch between the following modes:

      • Match mode: Express Connect will withdraw the specific (detailed) routes already advertised to the IDC and instead advertise the configured allowed prefix routes to the IDC.

      • Incremental mode: Express Connect will withdraw the specific routes that have been advertised to the IDC and fall within the configured prefix route range, while specific routes outside the prefix route range remain advertised.

      • Switching from Match mode to Incremental mode: Express Connect will re-advertise the specific routes that fall outside the prefix route range to the IDC, while the configured prefix routes remain advertised.

      • Switching from Incremental mode to Match mode: Express Connect will withdraw the specific routes that have been advertised to the IDC and fall outside the prefix route range, while the configured prefix routes remain advertised.

      If no prefix route is configured, or if the configured prefix routes are cleared, Express Connect will automatically advertise the specific routes to the IDC.

    • If your ECR currently advertises only a single specified prefix route, and you modify that prefix route, Alibaba Cloud will briefly restore the specific routes to ensure your business traffic runs smoothly and continuously. Once the modified prefix route has been advertised, it will then switch back to your configured prefix route. Please pay close attention to the impact that advertising specific routes may have on your peer network.

    Advanced Configurations

    The system selects the following advanced settings by default. To change them, click Modify to go to the TR console and modify the configuration.

    • Associate with Default Route Table of Transit Router

      If this feature is enabled, the ECR connection is automatically associated with the default route table of the transit router. The transit router uses this route table to forward traffic from the ECR.

    • Propagate System Routes to Default Route Table of Transit Router

      If this feature is enabled, the ECR propagates the BGP routes that it learns from the VBR to the default route table of the transit router. This allows the network instances to communicate with each other.

    • Advertise Routes to ECR

      If this feature is enabled, the TR automatically advertises routes to the ECR.

CEN authorization

Important

If you grant permissions to an account, that account can attach your on-premises network instances to its Cloud Enterprise Network (CEN) instance. This connects their network to yours. Proceed with caution.

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.

  3. On the CEN Authorization tab, click Authorize CEN of Another Account to Load Instance.

  4. In the Join CEN dialog box, set the following parameters and click OK.

    Parameter

    Description

    CEN Instance ID

    Enter the ID of the peer CEN instance.

    CEN Account

    Enter the UID of the Alibaba Cloud account that owns the CEN instance.

    Payer

    Select which account pays for the cross-account connection. Valid values:

    • CEN Owner.

    • ECR Owner.

Disable and enable a route entry

You can disable a route entry to prevent it from taking effect. It can be re-enabled later.

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.

  3. On the Routes tab, find the target route entry. In the Actions column, click Disable or Enable. In the dialog box that appears, click OK.

Delete an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to delete and click Actions in the Delete column.

Other operations

In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance. You can then perform the following operations as needed.

Actions

Procedure

Disassociate a VBR instance

Note

To disassociate a VBR that is part of a failover group, you must first disable the failover group. In the Failover Group ID column, set the status to Disabled. This action deletes the failover group. You can then disassociate the VBR instance.

  1. On the VBR tab, find the target VBR instance and click Actions in the Disassociate column.

  2. In the dialog box that appears, click OK.

Disassociate a TR instance

  1. On the TR tab, find the target TR instance and click Actions in the Disassociate column.

  2. In the dialog box that appears, click OK.

Disassociate a VPC instance

  1. On the VPC tab, find the target VPC instance and click Actions in the Disassociate column.

  2. In the dialog box that appears, click OK.

View and manage route entries

  1. On the Routes > Current Entry tab, you can view the current route entries.

  2. In the Actions column, you can click Disable or Enable to disable or enable a route entry.

Delete a CEN authorization

  1. On the CEN Authorization tab, find the target CEN instance and click Actions in the Delete column.

  2. In the dialog box that appears, click OK.