All Products
Search
Document Center

Cloud Enterprise Network:ModifyCenRouteMap

Last Updated:Aug 12, 2026

Modifies a routing policy by calling the ModifyCenRouteMap operation.

Operation description

The ModifyCenRouteMap operation is asynchronous. After you send a request, the system returns a RequestId but the routing policy has not been modified yet. The modification task is still running in the background. You can call the DescribeCenRouteMaps operation to query the status of the routing policy.

  • If the routing policy is in the Modifying state, the routing policy is being modified. In this state, you can only perform query operations.

  • If the routing policy is in the Active state, the routing policy has been modified.

Try it now

Try this API in OpenAPI Explorer, no manual signing needed. Successful calls auto-generate SDK code matching your parameters. Download it with built-in credential security for local usage.

Test

RAM authorization

The table below describes the authorization required to call this API. You can define it in a Resource Access Management (RAM) policy. The table's columns are detailed below:

  • Action: The actions can be used in the Action element of RAM permission policy statements to grant permissions to perform the operation.

  • API: The API that you can call to perform the action.

  • Access level: The predefined level of access granted for each API. Valid values: create, list, get, update, and delete.

  • Resource type: The type of the resource that supports authorization to perform the action. It indicates if the action supports resource-level permission. The specified resource must be compatible with the action. Otherwise, the policy will be ineffective.

    • For APIs with resource-level permissions, required resource types are marked with an asterisk (*). Specify the corresponding Alibaba Cloud Resource Name (ARN) in the Resource element of the policy.

    • For APIs without resource-level permissions, it is shown as All Resources. Use an asterisk (*) in the Resource element of the policy.

  • Condition key: The condition keys defined by the service. The key allows for granular control, applying to either actions alone or actions associated with specific resources. In addition to service-specific condition keys, Alibaba Cloud provides a set of common condition keys applicable across all RAM-supported services.

  • Dependent action: The dependent actions required to run the action. To complete the action, the RAM user or the RAM role must have the permissions to perform all dependent actions.

Action

Access level

Resource type

Condition key

Dependent action

cen:ModifyCenRouteMap

update

*CenInstance

acs:cen:*:{#accountId}:ceninstance/{#ceninstanceId}

None None

Request parameters

Parameter

Type

Required

Description

Example

CenId

string

Yes

The instance ID of the Cloud Enterprise Network (CEN) instance.

cen-7qthudw0ll6jmc****

CenRegionId

string

Yes

The ID of the region where the routing policy is applied.

You can call the DescribeChildInstanceRegions operation to query region IDs.

cn-hangzhou

RouteMapId

string

Yes

The ID of the routing policy.

cenrmap-abcdedfghij****

Description

string

No

The description of the routing policy.

The description can be empty or 1 to 256 characters in length and cannot start with http:// or https://.

desctest

MapResult

string

Yes

The action to perform on a route that matches all the match conditions. Valid values:

  • Permit: permits the route.

  • Deny: denies the route.

Valid values:

  • Permit :

    Permit.

  • Deny :

    Deny.

Permit

NextPriority

integer

No

Policy priority of the next associated routing policy.

  • You can set policy priority of the next associated routing policy only when MapResult is set to Permit. Only routes that are permitted continue to match the next associated routing policy.

  • The next associated routing policy must have the same region and direction as the current routing policy.

  • Policy priority of the next associated routing policy must be lower than (a number greater than) policy priority of the current routing policy.

20

CidrMatchMode

string

No

The match mode of the prefix list. Valid values:

  • Include: fuzzy match. A match is successful if the route prefix in the match condition contains the route prefix of the route being matched.

For example: A policy that defines 10.10.0.0/16 can fuzzy match the route 10.10.1.0/24.

  • Complete: exact match. A match is successful only if the route prefix in the match condition is the same as the route prefix of the route being matched.

For example: A policy that defines 10.10.0.0/16 can only exactly match the route 10.10.0.0/16.

Valid values:

  • Complete :

    Exact match.

  • Include :

    Fuzzy match.

Include

AsPathMatchMode

string

No

The match mode of the AS path list. Valid values:

  • Include: fuzzy match. A match is successful if the AS path in the match condition overlaps with the AS path of the route being matched.

  • Complete: exact match. A match is successful only if the AS path in the match condition is the same as the AS path of the route being matched.

Valid values:

  • Complete :

    Exact match.

  • Include :

    Fuzzy match.

Include

CommunityMatchMode

string

No

The match mode of the Community. Valid values:

  • Include: fuzzy match. A match is successful if the Community in the match condition overlaps with the Community of the route being matched.

  • Complete: exact match. A match is successful only if the Community in the match condition is the same as the Community of the route being matched.

  • Contain: contains match. A match is successful only if the Community of the route being matched contains all the Communities specified in the match condition.

Valid values:

  • Complete :

    Exact match.

  • Include :

    Fuzzy match.

  • Contain :

    Contains match.

Include

CommunityOperateMode

string

No

The action to perform on the Community. Valid values:

  • Additive: adds the Community to the route.

  • Replace: replaces the original Community of the route.

This parameter specifies the action to perform on a route after the route matches the match conditions.

Valid values:

  • Replace :

    Replace.

  • Additive :

    Add.

Additive

Preference

integer

No

The priority of the route to be modified.

Valid values: 1 to 100. The default priority of a route is 50. A smaller value indicates a higher priority.

This parameter specifies the action to perform on a route after the route matches the match conditions.

22

Priority

integer

Yes

Policy priority of the routing policy. Valid values: 1 to 100. A smaller value indicates a higher priority.

Note

Policy priority of routing policies in the same region and with the same direction must be unique. When the system executes routing policies, it starts matching conditional statements from the routing policy with the smallest priority number. Specify policy priority based on the expected matching order.

10

SourceInstanceIdsReverseMatch

boolean

No

Specifies whether to use the reverse match mode for the source instance ID list. Valid values:

  • false (default): no. A match is successful if the source instance ID of the route is in SourceInstanceIds.N.

  • true: yes. A match is successful if the source instance ID of the route is not in SourceInstanceIds.N.

false

DestinationInstanceIdsReverseMatch

boolean

No

Specifies whether to use the reverse match mode for the destination instance ID list. Valid values:

  • false (default): no. A match is successful if the destination instance ID of the route is in DestinationInstanceIds.N.

  • true: yes. A match is successful if the destination instance ID of the route is not in DestinationInstanceIds.N.

false

MatchAddressType

string

No

The IP address type that the route must match. Valid values:

  • IPv4: matches only IPv4 routes.

  • IPv6: matches only IPv6 routes.

This parameter can be left empty, which indicates that all types of routes are matched.

IPv4

SourceInstanceIds

array

No

The list of source instance IDs that the route must match. The following instance types are supported:

  • Virtual Private Cloud (VPC) instance ID

  • Virtual Border Router (VBR) instance ID

  • Cloud Connect Network (CCN) instance ID

  • Smart Access Gateway instance ID

  • IPsec connection ID

A maximum of 64 instance IDs can be specified.

vpc-afsfdf5435vcvc****

string

No

The list of source instance IDs that the route must match. The following instance types are supported:

  • Virtual Private Cloud (VPC) instance ID

  • Virtual Border Router (VBR) instance ID

  • Cloud Connect Network (CCN) instance ID

  • Smart Access Gateway instance ID

  • IPsec connection ID

A maximum of 64 instance IDs can be specified.

vpc-afsfdf5435vcvc****

DestinationInstanceIds

array

No

The list of destination instance IDs that the route must match. The following instance types are supported:

  • Virtual Private Cloud (VPC) instance ID

  • Virtual Border Router (VBR) instance ID

  • Cloud Connect Network (CCN) instance ID

  • Smart Access Gateway instance ID

  • IPsec connection ID

A maximum of 64 instance IDs can be specified.

Note

The destination instance ID list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination instance IDs are in the local region.

vpc-avcdsg34ds****

string

No

The list of destination instance IDs that the route must match. The following instance types are supported:

  • Virtual Private Cloud (VPC) instance ID

  • Virtual Border Router (VBR) instance ID

  • Cloud Connect Network (CCN) instance ID

  • Smart Access Gateway instance ID

  • IPsec connection ID

A maximum of 64 instance IDs can be specified.

Note

The destination instance ID list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination instance IDs are in the local region.

vpc-avcdsg34ds****

SourceRouteTableIds

array

No

The list of source route table IDs that the route must match. A maximum of 64 route table IDs can be specified.

vtb-acdbvtbr342cd****

string

No

The list of source route table IDs that the route must match. A maximum of 64 route table IDs can be specified.

vtb-acdbvtbr342cd****

DestinationRouteTableIds

array

No

The list of destination route table IDs that the route must match. A maximum of 64 route table IDs can be specified.

Note

The destination route table ID list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination route table IDs are route table IDs of network instances in the local region.

vtb-adfg53c322v****

string

No

The list of destination route table IDs that the route must match. A maximum of 64 route table IDs can be specified.

Note

The destination route table ID list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination route table IDs are route table IDs of network instances in the local region.

vtb-adfg53c322v****

SourceRegionIds

array

No

The list of source region IDs that the route must match. A maximum of 64 region IDs can be specified.

You can call the DescribeChildInstanceRegions operation to query region IDs.

cn-beijing

string

No

The list of source region IDs that the route must match. A maximum of 64 region IDs can be specified.

You can call the DescribeChildInstanceRegions operation to query region IDs.

cn-beijing

SourceChildInstanceTypes

array

No

The list of source instance types that the route must match. The following instance types are supported:

  • VPC: VPC instance.

  • VBR: virtual border router instance.

  • CCN: CCN instance.

  • VPN: VPN gateway instance or IPsec connection.

    • If the IPsec connection or SSL server is attached to a VPN gateway instance, the VPC associated with the VPN gateway instance must be connected to the transit router instance, and the VPN gateway instance must run the BGP dynamic routing protocol for this parameter to take effect.

    • If the IPsec connection is directly attached to the transit router instance, this parameter takes effect.

VPC

string

No

The list of source instance types that the route must match. The following instance types are supported:

  • VPC: VPC instance.

  • VBR: virtual border router instance.

  • CCN: CCN instance.

  • VPN: VPN gateway instance or IPsec connection.

    • If the IPsec connection or SSL server is attached to a VPN gateway instance, the VPC associated with the VPN gateway instance must be connected to the transit router instance, and the VPN gateway instance must run the BGP dynamic routing protocol for this parameter to take effect.

    • If the IPsec connection is directly attached to the transit router instance, this parameter takes effect.

VPC

DestinationChildInstanceTypes

array

No

The list of destination instance types that the route must match. The following instance types are supported:

  • VPC: VPC instance.

  • VBR: VBR instance.

  • CCN: CCN instance.

  • VPN: IPsec connection.

    Note

    If the IPsec connection or SSL server is bindded to a VPN gateway instance and is connected to the transit router instance through the VPC associated with the VPN gateway instance, this parameter does not take effect. This parameter takes effect only when the IPsec connection is directly bindded to the transit router instance.

The destination instance type list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination instance types are instance types in the local region.

VPC

string

No

The list of destination instance types that the route must match. The following instance types are supported:

  • VPC: VPC instance.

  • VBR: VBR instance.

  • CCN: CCN instance.

  • VPN: IPsec connection.

    Note

    If the IPsec connection or SSL server is bindded to a VPN gateway instance and is connected to the transit router instance through the VPC associated with the VPN gateway instance, this parameter does not take effect. This parameter takes effect only when the IPsec connection is directly bindded to the transit router instance.

The destination instance type list takes effect only when the routing policy is applied in the outbound direction from the regional gateway and the destination instance types are instance types in the local region.

VPC

DestinationCidrBlocks

array

No

The prefix list that the route must match.

IP address ranges in the prefix list are in CIDR format. A maximum of 64 IP address ranges can be specified.

10.10.10.0/24

string

No

The prefix list that the route must match.

IP address ranges in the prefix list are in CIDR format. A maximum of 64 IP address ranges can be specified.

10.10.10.0/24

RouteTypes

array

No

The list of routing types that the route must match. The following routing types are supported:

  • System: system routes that are automatically generated by the system.

  • Custom: custom routes that are manually added by users.

  • BGP: BGP routes that are propagated through the BGP routing protocol.

System

string

No

The list of routing types that the route must match. The following routing types are supported:

  • System: system routes that are automatically generated by the system.

  • Custom: custom routes that are manually added by users.

  • BGP: BGP routes that are propagated through the BGP routing protocol.

System

MatchAsns

array

No

The AS path list that the route must match.

Note

Only AS SEQUENCE is supported. AS SET, AS CONFED SEQUENCE, and AS CONFED SET are not supported. This means that only AS number lists are supported, and sets and sublists are not supported.

65501

integer

No

The AS path list that the route must match.

Note

Only AS SEQUENCE is supported. AS SET, AS CONFED SEQUENCE, and AS CONFED SET are not supported. This means that only AS number lists are supported, and sets and sublists are not supported.

65501

MatchCommunitySet

array

No

The Community set that the route must match.

Each Community is in the n:m format, where the value range of both n and m is 1 to 65535. Communities must comply with RFC 1997. Large Communities (RFC 8092) are not supported.

A maximum of 64 Communities can be specified.

Note

Incorrect Community configurations may cause routes to fail to be advertised to on-premises data centers.

65501:1

string

No

The Community set that the route must match.

Each Community is in the n:m format, where the value range of both n and m is 1 to 65535. Communities must comply with RFC 1997. Large Communities (RFC 8092) are not supported.

A maximum of 64 Communities can be specified.

Note

Incorrect Community configurations may cause routes to fail to be advertised to on-premises data centers.

65501:1

OperateCommunitySet

array

No

The Community set to be executed.

Each Community is in the n:m format, where the value range of both n and m is 1 to 65535. Communities must comply with RFC 1997. Large Communities (RFC 8092) are not supported.

A maximum of 32 Communities can be specified.

Note

Incorrect Community configurations may cause routes to fail to be advertised to on-premises data centers.

65501:1

string

No

The Community set to be executed.

Each Community is in the n:m format, where the value range of both n and m is 1 to 65535. Communities must comply with RFC 1997. Large Communities (RFC 8092) are not supported.

A maximum of 32 Communities can be specified.

Note

Incorrect Community configurations may cause routes to fail to be advertised to on-premises data centers.

65501:1

PrependAsPath

array

No

The AS path that is prepended when the regional gateway receives or advertises route entries.

The requirements for configuring the prepended AS path vary based on the direction of the routing policy:

  • When configuring the prepended AS path in the inbound direction to the regional gateway, you must configure the source instance ID list and source region in the match conditions, and the source region must be the same as the region where the routing policy is applied.

  • When configuring the prepended AS path in the outbound direction from the regional gateway, you must configure the destination instance ID list in the match conditions.

This parameter specifies the action to execute on a route after the route matches the match conditions.

65501

integer

No

The AS path that is prepended when the regional gateway receives or advertises route entries.

The requirements for configuring the prepended AS path vary based on the direction of the routing policy:

  • When configuring the prepended AS path in the inbound direction to the regional gateway, you must configure the source instance ID list and source region in the match conditions, and the source region must be the same as the region where the routing policy is applied.

  • When configuring the prepended AS path in the outbound direction from the regional gateway, you must configure the destination instance ID list in the match conditions.

This parameter specifies the action to execute on a route after the route matches the match conditions.

65501

DestinationRegionIds

array

No

The list of destination region IDs that the route must match. A maximum of 64 region IDs can be specified.

string

No

The list of destination region IDs that the route must match. A maximum of 64 region IDs can be specified.

cn-beijing

Response elements

Element

Type

Description

Example

object

The response parameters.

RequestId

string

The request ID.

54B48E3D-DF70-471B-AA93-08E683A1B457

Examples

Success response

JSON format

{
  "RequestId": "54B48E3D-DF70-471B-AA93-08E683A1B457\t"
}

Error codes

HTTP status code

Error code

Error message

Description

400 InvalidOperation.NoEffictiveAction No effective action be configured. The error message returned because the specified action is invalid.
400 InvalidOperation.CenRouteMapExist Operation is invalid because an route map config exist. The error message returned because this operation is not supported when a routing policy exists.
400 Invid.Parameter When using GatewayRegionId, SourceRegionId must not be null The error message returned because the GatewayRegionId and SourceRegionId parameters must be set.
400 InvalidName Name is invalid. The error message returned because the specified name is invalid.
400 InvalidDescription Description is invalid. The error message returned because the description is invalid.
400 InvalidParam.DestinationInstanceIds When using "PrependAsPath" in the "RegionOut", "DestinationInstanceIds" must be local region instances. When using the PrependAsPath option in a RegionOut configuration, the DestinationInstanceIds target instance should be within the local domain.
400 Forbidden.NoMedAuthorized Med operation is unauthorized. Unable to operate on the specified Med routing policy.
400 InvalidOperation.MedRouteMapExist Operation is invalid because the default med route map already exist. The operation is invalid because there is already a med routeMap with the next hop destination for this Ecr instance.
400 InvalidOperation.MedRouteMapNotAllowedOtherAction Operation is invalid because the default med not allowed other action. the med policy does not allow to configure other policies.
400 InvalidOperation.MedRouteMapActionMustPermit Operation is invalid because the default med map result must be permit. Operation is invalid because the default med map result must be permit.
400 InvalidParameter.MedRouteMapDestInstanceIds Param DestInstanceIds must be ecr instance id. The destination instance list of med routeMap must be ECR instance.
400 InvalidParameter.MedRouteMapDestInstanceType Param DestChildInstanceTypes must be ecr. The destination instance type of the med routeMap must be ECR.
400 InvalidOperation.PrependAsPathWithInvalidSourceRegionId When using PrependAsPath in the RegionIn direction, SourceRegionId must be local region ID. When using PrependAsPath in the RegionIn direction, SourceRegionId must be local region ID.
400 InvalidOperation.PrependAsPathWithInvalidSourceInstanceIds When using PrependAsPath in the RegionIn direction, SourceInstanceIds must be local instance ids. When using PrependAsPath in the RegionIn direction, SourceInstanceIds must be local instance ids.
400 InvalidOperation.TransitRouterNotExist Operation is invalid because the transit router not exist. The error message returned because the specified transit router does not exist.
400 InvalidParameter Invalid parameter. The error message returned because the parameter is set to an invalid value.
400 Unauthorized The AccessKeyId is unauthorized. The error message returned because you do not have the permissions to perform this operation.
400 InvalidParameter.RouteMapId The specified parameter RouteMapId is invalid.
400 InvalidParameter.CenId The specified parameter CenId is invalid.

See Error Codes for a complete list.

Release notes

See Release Notes for a complete list.