When a transit router has a connectivity issue, use the Instance Diagnostics feature to identify the root cause. CEN integrates with Network Intelligence Service (NIS) to run automated checks across configuration, routing, quota, and payment — and surfaces actionable suggestions without requiring you to inspect each item manually.
What diagnostics can detect:
-
Bandwidth caps on inter-region connections
-
Missing or misconfigured route learning and associated forwarding
-
Network ACL rules blocking VPC vSwitch traffic
-
Route conflicts between connected network instances
-
Route usage approaching quota limits
-
Packet loss caused by throttling on inter-region connections
-
Overdue payments or expiring bandwidth plans
Limitations
Instance diagnostics are supported only on Enterprise Edition transit routers.
Prerequisites
Before you begin, make sure you have:
-
An Enterprise Edition transit router in your CEN instance
-
NIS activated — if not yet activated, the Instance Diagnostics panel prompts you to accept the Terms of Service and activate NIS for free
Diagnostic items
The following table describes all diagnostic items, organized by category.
| Category | Item | What it checks |
|---|---|---|
| Configuration | Cross-region throttling check | Whether a bandwidth cap is set on inter-region connections |
| Route learning check | Whether route learning is enabled between network connections and the transit router route tables. If route learning is not required, a static route pointing to the network instance must exist in the route tables — otherwise the transit router cannot forward traffic to that network instance. For more information, see Route learning. | |
| Associated forwarding check | Whether associated forwarding is enabled between network connections and the transit router route tables. For more information, see Associated forwarding. | |
| Network ACL configuration check | Whether the ACL allows requests from the CIDR block of the VPC vSwitch used to connect to the transit router. For more information, see Network ACLs. | |
| Automatic route advertisement check | Whether automatic route advertisement is enabled between virtual border router (VBR) connections and inter-region connections. Enable this if you want VBRs to automatically learn routes from the local transit router, and the local transit router to learn routes from the peer transit router. | |
| Quota | Route usage check | Whether the number of routes in the transit router route tables has reached 80% of the route quota |
| Cross-region throttling check (QoS queue) | Whether each QoS queue of the inter-region connections has consumed 80% of the maximum bandwidth | |
| Cross-region throttling check (connection) | Whether inter-region connections have consumed 80% of the maximum bandwidth | |
| Inter-region connection packet loss check | Whether packets were dropped due to throttling on inter-region connections in the last 15 minutes | |
| QoS queue packet loss check | Whether packets were dropped due to throttling in QoS queues of inter-region connections in the last 15 minutes | |
| Payment | Overdue payment alert | Whether the bandwidth plan associated with the CEN instance has an overdue payment |
| Expiring bandwidth plan alert | Whether the bandwidth plan associated with the CEN instance expires within seven days | |
| Route | Route conflict check | Whether routes of network instances connected to the transit router overlap with each other |
| VPC routes check | Whether all destination CIDR blocks in the transit router route table fall within the destination CIDR blocks of VPC routes pointing to the transit router (applies to the transit router route table associated with the VPC connection) |
Run a diagnostic
-
Log on to the CEN console.
-
On the Instances page, click the ID of the CEN instance.
-
On the Basic Information > Transit Router tab, find the transit router and click Diagnose in the Instance Diagnostics column.
-
In the Instance Diagnostics panel, review the diagnosis results.
If NIS is not activated, select Terms of Service for Standard Edition NIS and click Activate NIS free of charge to diagnose instances. If this is the first time that you run a diagnostic, the system automatically creates the service-linked role AliyunServiceRoleForNis. For more information, see Service-linked roles.
The panel surfaces the following information:
| Callout | Description |
|---|---|
| ① | Anomalies detected by the diagnostic, with a description, affected resources, and suggested fixes |
| ② | The Diagnostic Items section — select Show All Diagnostic Items to view every item and its result |
| ③ | View Diagnostic History in NIS Console — opens the Overview page in the NIS console, where you can review past diagnostic reports. For more information, see Use features on the Overview page. |
What's next
For a deeper look at instance diagnostics capabilities in NIS, see Work with instance diagnostics.