All Products
Search
Document Center

Cloud Enterprise Network:Create an ECR connection

Last Updated:Sep 15, 2026

Connect an Express Connect Router (ECR) instance to a transit router so that the on-premises data center associated with the ECR instance can communicate with other networks connected to the transit router.

Background information

After you connect an on-premises data center to Alibaba Cloud through a physical connection, you can use an ECR for low-latency communication with a Virtual Private Cloud (VPC). However, an ECR instance alone does not support communication with networks connected by other methods, such as IPsec-VPN connections, or communication between cloud networks. For example, VPC instances cannot communicate with each other through an ECR. To enable full-mesh communication between your on-premises data center and multiple cloud networks, connect both the ECR and VPC instances to a transit router. The transit router provides comprehensive connectivity between your on-premises and cloud networks.

image

Limits

  • Only an Enterprise Edition transit router supports connections to ECR instances.

  • If a VPC instance is connected to both a transit router and an ECR instance, route synchronization cannot be enabled for the VPC connection on the transit router.

  • You can connect an ECR instance to only one transit router in each region.

    For example, if two Cloud Enterprise Network (CEN) instances each have a transit router in the China (Hangzhou) region, an ECR instance can connect to only one of those transit routers, not both.

  • For information about ECR quotas, see ECR quotas.

Route propagation limits

  • If an ECR instance is connected to both a VPC instance and a transit router, routes cannot propagate between the VPC and transit router through the ECR instance, so the two instances cannot communicate with each other through the ECR.

  • After you add a static route or a route prefix that points to an ECR instance in a transit router route table:

    • These routes are not propagated to the route table of the peer transit router over an inter-region connection. You can manually add a route to the ECR instance in the peer transit router's route table.

    • If the transit router is connected to a VPC instance and an IPsec-VPN connection with route synchronization enabled for both, these routes can propagate to the route tables of the VPC instance and the IPsec-VPN connection.

  • After you create an ECR connection, the system automatically adds a default route policy to all route tables of the transit router in the RegionOut direction. The policy has a Policy Priority of 5000 and an Policy Action of Deny. This route policy prevents routes from being propagated among IPsec-VPN connections, ECR instances, Virtual Border Router (VBR) instances, and Cloud Connect Network (CCN) instances.

    To allow route propagation among these network instances and enable communication between them, create a custom route policy with a higher priority. For more information, see Route policies.

Billing

Connecting a transit router to an ECR instance incurs a connection fee and a data processing fee for each ECR connection. For more information, see Billing.

Prerequisites

Before you connect a transit router to an ECR instance, make sure the following requirements are met:

Procedure

  1. Log on to the CEN console.

  2. On the CEN Instance page, click the ID of the CEN instance that you want to manage.

  3. On the Basic Settings > Transit Router tab, find the transit router instance in the target region. In the Actions column, click Create Connection.

  4. On the Connection with Peer Network Instance page, configure the ECR instance and click OK.

    Parameter

    Description

    Network Type

    Select Express Connect Router (ECR).

    Region

    Select the region of the transit router instance.

    Transit Router

    The system automatically displays the transit router instance ID in the current region.

    Account

    Select the account that owns the ECR instance.

    Select Current Account if the VPC belongs to the same Alibaba Cloud account. Select Different Account and enter the primary account ID if the VPC belongs to a different account.

    Attachment Name

    Enter a name for the ECR connection.

    Networks

    Select the ECR instance that you want to connect.

    Route Prefix

    Route prefixes specify the routes that a transit router is allowed to propagate to an ECR instance. You must configure route prefixes in the Express Connect console. After you specify a route prefix, the transit router propagates only the specified route prefix to the ECR instance instead of the detailed routes from its route table. You can manage route prefixes only in the Express Connect console. For more information, see Create and manage VBR ECRs.

    Advanced Settings

    When you create an ECR connection, the following advanced features are enabled by default:

    • Associate with Default Route Table of Transit Router

      When enabled, the system automatically associates the ECR connection with the default route table of the transit router. The transit router then forwards traffic from the ECR instance based on this route table.

    • Propagate system routes to transit router route table

      When enabled, the ECR instance advertises routes from your on-premises data center to the default route table of the transit router.

    • Automatically Advertise Routes to ECR

      When enabled, the system automatically advertises routes from the route table associated with the ECR connection to the ECR instance's route table.

      Important
      • The Automatically Advertise Routes to ECR feature is enabled by default and you cannot disable it.

      • If route prefixes are configured for the transit router instance in the Express Connect console, only the route prefixes are advertised to the ECR instance, not the routes from the transit router's route table.

    You can clear the selected advanced features and customize connectivity for the ECR instance by using transit router routing features such as route association and route learning. For more information, see Route management.

Change an ECR connection's associated route table

After you create an ECR connection, you can change the transit router route table associated with it.

Warning

After you change the associated route table, the system withdraws the previously synchronized routes and then synchronizes routes from the new route table to the ECR instance's route table.

  1. Log on to the CEN console.

  2. On the CEN Instance page, click the ID of the CEN instance that you want to manage.

  3. On the Basic Settings > Transit Router tab, click the ID of the transit router instance in the target region.

  4. On the Intra-Region Connections tab, find the ECR connection and click the ECR connection ID.

  5. In the Attachment Details pane, in the Basic Information section, click Associated Route Table next to Modify.

  6. In the Modify Route Table dialog box, select the target transit router route table and click OK.