Alibaba Cloud DNS PrivateZone is a private Domain Name System (DNS) resolution and management service for Alibaba Cloud Virtual Private Cloud (VPC) environments. Smart Access Gateway (SAG) can access PrivateZone through Cloud Enterprise Network (CEN), enabling private domain name resolution from your on-premises network.
Background information
PrivateZone maps private domain names to IP addresses in one or more custom VPCs.
With PrivateZone, you can use private domain name records to manage Alibaba Cloud resources in a VPC, such as Elastic Compute Service (ECS) hostnames, Server Load Balancer (SLB) instances, and Object Storage Service (OSS) buckets. These private domain names are not accessible from outside the VPC. You can connect your on-premises network to a VPC through Smart Access Gateway (SAG) and Cloud Enterprise Network (CEN). After you configure PrivateZone access in the CEN console, your on-premises network and the VPC can use private domain names to access resources in each other's networks.

Prerequisites
-
You have configured private DNS resolution on Alibaba Cloud DNS PrivateZone. For more information, see .
-
You have created a CEN instance. For more information, see Create a CEN instance.
-
You have attached the VPC instance associated with the PrivateZone service and the Cloud Connect Network (CCN) instance associated with your on-premises network to transit routers. For more information, see Create a VPC connection and Create a CCN connection.
-
You have created an inter-region connection between the transit router attached to the VPC instance and the transit router attached to the CCN instance. For more information, see Inter-region connections.
NoteIf the CCN and VPC instances are in regions within the Chinese mainland, an inter-region connection is automatically created when you attach the instances to the transit routers. By default, the inter-region connection is associated with the default route tables of the transit routers for route learning and forwarding.
Configure access to PrivateZone
Log on to the CEN console.
On the CEN Instance page, click the ID of the CEN instance that you want to manage.
On the tab, click the ID of the transit router in the region of the VPC that is associated with PrivateZone.
If this is the first time that you configure the PrivateZone service, click the PrivateZone tab on the details page of the transit router, and click Authorization. On the RAM Quick Authorization page, click Authorize.
The authorized role is
AliyunSmartAGAccessingPVTZRole, and the access policy isAliyunSmartAGAccessingPVTZRolePolicy(system policy).After you grant permissions to the Smart Access Gateway (SAG) service associated with the on-premises network, the CCN instance that belongs to the SAG service can access the PrivateZone service.
-
Return to the Private Zone tab and click Set PrivateZone. In the Set PrivateZone dialog box, set the following parameters and click OK.
-
Service Region: The region where the PrivateZone service is deployed.
-
Service VPC: The VPC instance associated with the PrivateZone service.
-
Access Region: The region of the CCN instance that needs to access PrivateZone.
-