Destination-based routing is a technique that routes network traffic to specified destination IP addresses. This topic describes how to create, advertise, modify, and delete a destination-based route.

Prerequisites

An IPsec-VPN connection is created. For more information, see Create an IPsec-VPN connection.

Create a destination-based route

After you create an IPsec-VPN connection, you can create a destination-based route for the IPsec-VPN connection.

  1. Log on to the VPN Gateway console.
  2. In the top navigation bar, select the region where the VPN gateway is deployed.
  3. On the VPN Gateways page, find the VPN gateway and click its ID.
  4. On the Destination-based routing tab, click Add Route Entry.
  5. In the Add Route Entry dialog box, set the following parameters and click OK.
    Parameter Description
    Destination CIDR block The private CIDR block that you want to access.
    Next Hop Type Select IPsec Connection.
    Next Hop Select the IPsec-VPN connection for which you want to create a destination-based route.
    Publish to VPC Specify whether to advertise the destination-based route to the virtual private cloud (VPC) route table.
    • Yes: automatically advertises the route to the route table of the VPC. We recommend that you select this value.
    • No: does not advertise the destination-based route to the VPC route table.
    Note If you select No, you must manually advertise the destination-based route to the VPC route table.
    Weight Select a weight:
    • 100: specifies a high priority for the destination-based route.
    • 0: specifies a low priority for the destination-based route.
    Note If two destination-based routes are configured with the same destination CIDR block, you cannot set the weights of the routes to 100.

Advertise the destination-based route

  1. Log on to the VPN Gateway console.
  2. In the top navigation bar, select the region where the VPN gateway is deployed.
  3. On the VPN Gateways page, find the VPN gateway and click its ID.
  4. On the Destination-based Routing tab, find the destination-based route that you want to manage and click Publish in the Actions column.
  5. In the Publish Route Entry message, click OK.
    If you want to withdraw the destination-based route, click Unpublish.

Modify the destination-based route

You can change the weight of the destination-based route.

  1. Log on to the VPN Gateway console.
  2. In the top navigation bar, select the region where the VPN gateway is deployed.
  3. On the VPN Gateways page, find the VPN gateway and click its ID.
  4. On the Destination-based Routing tab, find the destination-based route that you want to manage and click Edit in the Actions column.
  5. In the panel that appears, specify the weight of the destination-based route and click OK.

Delete the destination-based route

  1. Log on to the VPN Gateway console.
  2. In the top navigation bar, select the region where the VPN gateway is deployed.
  3. On the VPN Gateways page, find the VPN gateway and click its ID.
  4. On the Destination-based Routing tab, find the destination-based route that you want to delete and click Delete in the Actions column.
  5. In the Delete Route Entry message, click OK.