This topic describes how to acquire permissions to attach network instances under other accounts to a Cloud Enterprise Network (CEN) instance.

Prerequisites

Before you begin, you must obtain the following information:
  • The ID of the account to which the CEN instance belongs.
  • The ID of the CEN instance.

VPC authorization

This section describes how to acquire the permissions to attach a virtual private cloud (VPC) created by Account A to a CEN instance created by Account B. After the VPC owner grants the permissions to the CEN instance owner, the VPC under Account A can be attached to the CEN instance under Account B.

Notice After Account A grants the permissions to Account B, Account B can attach network instances under Account A to the CEN instance under Account B. This means that Account B can access the network of Account A. Proceed with caution.
  1. Log on to the VPC console with Account A.
  2. In the top menu bar, select the region where the VPC is created.
  3. On the VPCs page, find the VPC that you want to manage and click its ID.
  4. Click the Authorize Cross Account Attach CEN tab. On the tab, click Authorize Cross Account Attach CEN.
  5. In the Attach to CEN dialog box, enter the UID of Account B and the ID of the CEN instance, and then click OK.
    After you complete the configuration, you can view information about the authorization on the Authorize Cross Account Attach CEN tab. VPC authorization
  6. Record the ID of the VPC under Account A and the ID of Account A. You can navigate to the Account Management page to view the account ID.
    View the account ID

VBR authorization

This section describes how to acquire the permissions to attach a virtual border router (VBR) created by Account A to a CEN instance created by Account B. After the VBR owner grants the permissions to the CEN instance owner, the VBR under Account A can be attached to the CEN instance under Account B.
Notice
  • Starting November 1, 2019, you are no longer allowed to attach VBRs under other accounts to your CEN instances by default. To use this feature,submit a ticket.
  • After Account A grants the permissions to Account B, Account B can attach network instances under Account A to the CEN instance under Account B. This means that Account B can access the network of Account A. Proceed with caution.
  1. Log on to the Express Connect console with Account A.
  2. In the left-side navigation pane, click Virtual Border Routers (VBRs).
  3. In the top menu bar, select the region where the VBR is created.
  4. On the Virtual Border Routers (VBRs) page, click the ID of the VBR that you want to manage.
  5. On the page that appears, click the CEN Authorization tab and click Authorize CEN of Another Account to Load Instance.
  6. On the Authorize CEN of Another Account to Load Instance page, enter the UID of Account B and the ID of the CEN instance under Account B, and click OK.
    After you complete the configuration, you can view information about the authorization on the Authorize CEN of Another Account to Load Instance tab. VBR authorization
  7. Record the ID of the VBR under Account A and the ID of Account A. You can navigate to the Account Management page to view the account ID.
    View the account ID

CCN instance authorization

This section describes how to acquire the permissions to attach a Cloud Connect Network (CCN) instance created by Account A to a CEN instance created by Account B. After the CCN instance owner grants the permissions to the CEN instance owner, the CCN instance under Account A can be attached to the CEN instance under Account B.

Notice After Account A grants the permissions to Account B, Account B can attach network instances under Account A to the CEN instance under Account B. This means that Account B can access the network of Account A. Proceed with caution.
  1. Log on to the SAG console with Account A.
  2. In the left-side navigation pane, click CCN.
  3. In the top menu bar, select the region where the CCN instance is created.
  4. On the CCN page, click the ID of the CCN instance that you want to connect.
  5. On the page that appears, click the CEN Cross Account Authorization Information tab. On the tab, click CEN Cross Account Authorization.
  6. In the Attach to CEN dialog box, enter the UID of Account B and the ID of the CEN instance under Account B and click OK.
    After you complete the configuration, you can view information about the authorization on the CEN Cross Account Authorization Information tab. CCN instance authorization
  7. Record the ID of the CCN instance under Account A and the ID of Account A. You can navigate to the Account Management page to view the account ID.
    View the account ID

What to do next

After you acquire permissions from network instances that are created by other accounts, you can attach the network instances to a CEN instance under your account. To perform this task, use the IDs of the network instances and IDs of the accounts that you recorded to create connections in the CEN console. For more information, see