After you acquire the permissions to access a resource on Alibaba Cloud, you can create Ethernet point-to-point connections or multiprotocol label switching (MPLS) VPN connections for tenants to access the cloud resource. You can associate a virtual border router (VBR) with each connection and set a bandwidth limit from 50 Mbit/s to 500 Mbit/s for each VBR. This topic describes how to create a hosted connection over an Express Connect circuit pre-installed by an Express Connect partner. Then, the tenant can access Alibaba Cloud through the hosted connection.
Before you create a hosted connection for a tenant, make sure that the following prerequisites are met:
- Two or more Express Connect circuits are connected to different access points of Alibaba Cloud. Permissions to access a resource on Alibaba Cloud are acquired. To apply for permissions to access a resource on Alibaba Cloud, contact your customer business manager from Alibaba Cloud.
- The service terms in Limits on networks are met.
- The switch that connects to the tenant supports bandwidth adjustment and traffic monitoring. Traffic monitoring is enabled for the switch to collect statistics about bandwidth (bit/s), packet loss rate (bit/s), packet forwarding rate (pps), and data transfer (bytes).
- The following traffic throttling features are configured on the customer-premises equipment (CPE): Quality of Service (QoS) policies and Address Resolution Protocol (ARP) throttling. In most cases, the limit is set to one ARP packet per second per tenant.
- The CIDR block 100.64.0.0/10 must not be used to connect the VBR with the gateway device in the data center.
- If Internet Control Message Protocol (ICMP) throttling is configured, the limit on ICMP echo requests must be set to a value greater than 500 pps.
- A bandwidth limit is set for the VBR. The sum of bandwidth limits that you set for all VBRs on an Express Connect circuit cannot be greater than the bandwidth limit of the Express Connect circuit.
- For tenants that require high availability, they can connect VBRs to different Express Connect circuits.
- The network typology is planned. For example, you must specify basic network information such as virtual LAN (VLAN) IDs, peer IP addresses, and CIDR blocks.
Create a hosted connection
- Log on to the Express Connect console.
- In the top navigation bar, select the region and click Virtual Border Routers (VBRs) in the left-side navigation pane.
- On the Virtual Border Routers (VBRs) page, click Create VBR.
- In the Create VBR panel, set the following parameters and click OK.
Parameter Description Account Specify whether to create a VBR for the current account or another account. Valid values:
Note To create a VBR for another Alibaba Cloud account, Submit a ticket.
- Current account: Create a VBR for the account that you use to log on to the console. This is the default value.
- For others account create: Create a VBR for another account.
Name This parameter is required only when Account is set to Current account.
Enter a name for the VBR. The name must be 2 to 128 characters in length and can contain digits, periods (.), underscores (_), and hyphens (-). It must start with a letter but cannot start with
Owner Account This parameter is required only when Account is set to For others account create.
Enter the ID of the account for which you want to create the VBR.
Physical Connection Interface Select an Express Connect circuit. The Express Connect circuit must be enabled and work as expected. VLAN ID Enter the VLAN ID of the VBR. Valid values: 0 to 2999.
- If the VLAN ID is set to 0, the switch port on the VBR uses a Layer 3 router interface instead of a VLAN interface. When a Layer 3 router interface is used, an Express Connect circuit is associated with a VBR.
- If the VLAN ID is set to a value from 1 to 2999, the switch port on the VBR uses a Layer 3 subinterface (VLAN). When a Layer 3 subinterface (VLAN) is used, each VLAN ID corresponds to a VBR. In this case, the Express Connect circuit with which the VBR is associated can be used to connect to VPCs that belong to different Alibaba Cloud accounts. VBRs that correspond to different VLAN IDs are isolated from each other at Layer 2.
For example, a company has multiple subdivisions or subsidiaries. Each subdivision or subsidiary has a separate Alibaba Cloud account. Each Alibaba Cloud account has a separate VPC. If the company applies for an Express Connect circuit, the company must assign a VLAN ID to each subdivision or subsidiary. When the company creates router interfaces, the VLAN IDs are used to identify the subsidiaries or subdivisions that use the Express Connect circuit. In this case, the subsidiaries or subdivisions are isolated at Layer 2.
Gateway IP Address on Alibaba Cloud Side The peer IP address on the Alibaba Cloud side. Enter the IPv4 address of the VBR. IPv4 Address of Gateway at Customer Side The peer IP address on the client side. Enter the IPv4 address of the network device that routes traffic from the data center to the VPC. Subnet Mask Enter the subnet mask of the peer IPv4 addresses on the Alibaba Cloud side and on the client side. You can enter a long subnet mask because only two IP addresses are required.
- Click OK.
- Contact the tenant of the hosted connection to Log on to the Express Connect console and confirm the VBR configurations. Then, connect a virtual private cloud (VPC) and the data center.
For more information about how to connect a VPC and a data center, see Connect to an ECS instance from a data center by using an Express Connect circuit.
What to do next
After you create a hosted connection, you can modify the parameters that you specified for the associated VBR. For example, you can change the bandwidth limit of the VBR.
- Log on to the Express Connect console.
- In the top navigation bar, select the region and click Exclusive Physical Connection in the left-side navigation pane.
- In the top navigation bar, select the region to which the Express Connect circuit belongs, and click Exclusive Physical Connection.
- On the Exclusive Physical Connection page, click the ID of the connection to navigate to the details page.
- In the Actions column of the VBR that you want to manage, choose . You can change the bandwidth limit as prompted. After you change the bandwidth limit of the VBR, you must update the traffic throttling configuration on the CPE.
- In the Actions column of the VBR that you want to manage, choose . You can modify the configurations as prompted. After you modify the configurations, inform the tenant and verify network connectivity.