All Products
Search
Document Center

Bastionhost:Purchase an instance and log on to the console

Last Updated:Jul 13, 2026

This topic walks you through purchasing a Bastionhost Basic Edition instance, enabling it with the correct network settings, and accessing its console.

Step 1: Purchase an instance

  1. Go to the Bastionhost buy page.

  2. On the Bastionhost buy page, configure the following parameters, and then click Buy Now to complete the payment.

    Parameter

    Example

    Description

    Region

    China (Hangzhou)

    The region where you want to deploy the Bastionhost instance. We recommend selecting the same region as your assets. If the Bastionhost instance and assets are not in the same region, internal network communication is generally unavailable. You need to use Cloud Enterprise Network (CEN) or the network domain feature to implement cross-region internal network access.

    Warning

    The region of a Bastionhost instance cannot be changed after purchase. Select the region with caution.

    Version

    Basic Edition

    The edition of the instance. For a comparison of editions, see Selection guide.

    Assets

    50 assets

    The plan of the instance, which specifies the maximum number of assets that can be added and managed.

    Extra Bandwidth

    0

    An additional public bandwidth beyond the default included in your plan.

    Valid values: 0 to 200. Unit: Mbit/s. The value must be a multiple of 10.

    Extended Storage Plans

    0

    An additional storage space beyond the default included in your plan.

    Resource Group

    Default Resource Group

    The resource group to which the Bastionhost instance belongs.

    Quantity

    1

    The number of Bastionhost instances to purchase.

    Duration

    1 Month

    The subscription period of the Bastionhost instance. We recommend selecting the Auto-renewal Recommended checkbox to prevent service disruption caused by instance expiration. Auto-renewal charges your account monthly at the current price.

Note

For billing details, see Billing methods.

Step 2: Enable and log on to the bastion host

  1. Log on to the Bastionhost console.

    If this is your first time logging on, create the service-linked role as prompted. This role is required to enable Bastionhost features.

  2. In the top navigation bar, select the region where your instance resides. In the instance list, find the instance and click Run.

  3. In the Enable Bastion Host panel, configure the following parameters.

    The configuration for the Basic Edition differs from other editions. If you purchased another edition, see Enable a Bastionhost instance for configuration guidance.

    Parameter

    Description

    Select Network

    Select a VPC and vSwitch. The VPC cannot be changed after the Bastionhost instance is enabled. Choose the VPC that contains the asset you want to manage, such as an ECS or ApsaraDB RDS instance. The vSwitch must have at least three available IP addresses. If the selected vSwitch lacks sufficient resources, select another one or create a new one.

    ECS Security Groups

    Add the Bastionhost instance to at least one basic security group. A security group rule is automatically generated to allow the Bastionhost instance to access all ECS instances in that group. You cannot use an advanced security group or a managed security group. If your ECS instances belong to an advanced security group, create a basic security group to proceed.

    After enabling the Bastionhost instance, you can change its security group. If ECS instances in an advanced security group need to communicate with Bastionhost, add the Bastionhost instance's egress IP addresses to that security group's inbound rules.
    For the Basic Edition, you can manually switch the vSwitch zone after enabling the bastion host.
  4. Click Next. After the startup check passes, click Enable.

    The Bastionhost instance starts successfully and enters initialization, which takes about 10 to 15 minutes. After initialization is complete, the instance enters the Running state, which indicates that it is successfully enabled.

  5. After the instance is successfully enabled, click Manage to log on to the Bastionhost console.