All Products
Search
Document Center

:Why does the system prompt the following error message when I create a VPC firewall for my CEN instance: It is not allowed to be created because of the existing unauthorized network instance?

Last Updated:Jun 14, 2023

Issue

The following error message is prompted when I create a virtual private cloud (VPC) firewall for my Cloud Enterprise Network (CEN) instance in the Cloud Firewall console: It is not allowed to be created because of the existing unauthorized network instance.

Possible causes

This error message appears if a VPC that belongs to another Alibaba Cloud account is attached to your CEN instance, and Cloud Firewall does not have permissions on the VPC or the edition of Cloud Firewall is not Ultimate.

Solutions

We recommend that you grant permissions on the VPC to Cloud Firewall or upgrade Cloud Firewall to Ultimate Edition before you create a VPC firewall. To grant the permissions, use your Alibaba Cloud account to log on to the Cloud Firewall console. For more information, see Authorize Cloud Firewall to access other cloud resources and Upgrade and downgrade Cloud Firewall.

Usage notes

  • Before you create a VPC firewall for your CEN instance, we recommend that you have knowledge of the use scenarios, limits, and prerequisites of Cloud Firewall. For more information, see Configure a VPC firewall for an Enterprise Edition transit router and Configure a VPC firewall for a Basic Edition transit router.

  • If a VPC that belongs to another Alibaba Cloud account is attached to your CEN instance, and you have purchased Cloud Firewall Enterprise Edition or Ultimate Edition, the VPC supports firewalls created in Cloud Firewall even if the Alibaba Cloud account of the VPC has not purchased Cloud Firewall Enterprise Edition or Ultimate Edition. VPC firewalls are supported only if the Alibaba Cloud account of the CEN instance has purchased Cloud Firewall Enterprise Edition or Ultimate Edition.

Applicable scope

  • Cloud Firewall

  • CEN