This topic describes how to establish a shared physical connection. In a shared physical connection, you can connect your on-premises data center to the network of an Alibaba Cloud partner (third-party service provider). By doing so, you can access Alibaba Cloud because some partners have pre-connected their access points with the access points of Alibaba Cloud. In this physical connection solution, the partner allocates the cloud connection link for you, and the connection between the partner network and Alibaba Cloud is shared by multiple customers.

For more information,see NSP partners.

Process overview

You can connect your on-premises data center to Alibaba Cloud by using the pre-connected leased line of an Alibaba Cloud partner. Because the leased line has been connected to the access point of Alibaba Cloud, you only need to contact the partner and ask the partner to use another leased line to connect your on-premises data center to its access point. The following figure shows the process.
Note Alibaba Cloud partners can provide customers with cross-cloud connection services to achieve multi-cloud interconnection. If you have this requirement, please submit a ticket.

Billing items

Compared with an exclusive physical connection, a shared physical connection involves the contract only with an Alibaba Cloud partner. No initial installation fee or resource occupation fee is charged by Alibaba Cloud.

Charged by Billing item Description Billing method
Third-party provider

Optical fiber laying fee

Indoor cable rental fee

A leased line rental fee is charged by the leased line provider (Alibaba Cloud partner). You must contact the provider yourself to obtain a price quote.

One-time charge.

Alibaba Cloud Outbound traffic fee An outbound traffic fee is charged for the traffic from the data center of the access point to the on-premises data center.

Fees are calculated on an hourly basis. Bills are generated on an hourly basis. Billing periods less than an hour are calculated as an hour.

Billed based on the actually used traffic.
Note No outbound traffic fee is charged until October 1, 2020.

Cable connections

Because the partner has connected its access points to the access points of Alibaba Cloud, you only need to ask the partner to connect your on-premises data center to its access point. This physical connection solution saves the construction time and is suitable for customers who require a shorter cloud connection time. The following figure shows the cable connections required to establish a shared physical connection.

Generally, this solution takes only one month.

Procedure

To establish a shared physical connection, follow these steps:

  1. Contact the Alibaba Cloud partner and consult the partner for a plan to access Alibaba Cloud through a leased line.
  2. Contact and ask the leased line provider to perform a site survey, check the end-to-end resources, and provide a price quote.
  3. The leased line provider connects your on-premises data center to an access point of the Alibaba Cloud partner by using a leased line.
  4. Provide your Alibaba Cloud account ID to the Alibaba Cloud partner.
    To know your account ID, log on to the Alibaba Cloud console and click the user image in the upper-right corner. On the page that appears, click Security Settings in the left-side navigation pane.
  5. The partner provides you with a VLAN number and the gateway IP address used for the connection between your on-premises data center and Alibaba Cloud.
  6. The partner logs on to the Express Connect console and creates a Virtual Border Router (VBR). To do so, the partner must:
    1. In the left-side navigation pane, choose Virtual Border Routers (VBRs) > Virtual Border Routers (VBRs).
    2. Click Create VBR.
    3. Configure the VBR, and click OK.
      Parameter Description
      Account By default, only Current account is available. In other words, you can create a VBR only for the current account by default.

      To create a VBR for another account, submit a ticket to apply for permissions. You can create a VBR for another account only when the account type indicates For others account create.

      Account This parameter is displayed only when the account type is set to For others account create. Set this parameter to the ID of another account.
      Name This parameter is displayed only when the account type is set to Current account. Set the name of the VBR.
      Physical Connection Interface Select a physical connection interface that works properly.
      VLAN ID Enter the VLAN ID of the VBR. Valid values: 0 to 2999.
      • If the VLAN ID is set to 0, the switch port of the VBR uses the Layer-3 route interface mode instead of the VLAN mode. In Layer-3 route interface mode, each physical connection corresponds to a VBR.
      • If the VLAN ID is set to a value ranging from 1 to 2999, the switch port on the VBR uses VLAN-based Layer-3 subinterface mode. In Layer-3 subinterface mode, each VLAN ID corresponds to a VBR. In this mode, the physical connection of the VBR can connect the VPCs created by multiple accounts. VBRs that correspond to different VLANs are isolated from one another by the Layer-2 network.

      For example, a company has multiple subdivisions or subsidiaries. Each has a separate Alibaba Cloud account. Each account has a separate VPC. If the company applies for a physical connection, they must plan a VLAN ID for each subdivision or subsidiary. When the company creates router interfaces, they use VLAN IDs to identify the subsidiaries or subdivisions that use the physical connection. This way, the subsidiaries or subdivisions are isolated by using the Layer-2 network.

      Gateway IP Address on Alibaba Cloud Side Enter the IP address of the gateway used for access from the VPC to your on-premises data center.
      Gateway IP Address on Customer Side Enter the IP address of the gateway used for access from your on-premises data center to the VPC.
      Subnet Mask Enter the subnet masks of the gateway IP address on the Alibaba Cloud side and of the gateway IP address on the customer side. Only two IP addresses are required. Therefore, you can enter longer subnet masks.
  7. After the partner tells you that the VBR has been created, you need to log on to the Express Connect console and click Confirm on the Virtual Border Routers (VBRs) page.
    If you want to modify the gateway IP addresses of the VBR and on-premises data center, click Edit in the Actions column.
  8. After the VBR enters the Active state, ping the gateway IP address of the VBR from the gateway IP address of the on-premises data center to test the connectivity of the exclusive physical connection.

What to do next

Connect to a VPC