This topic describes how to use Enterprise Edition transit routers to enable communication between on-premises and cloud networks.
Regions and zones that support Enterprise Edition transit routers
Area | Region | Zone |
---|---|---|
Chinese mainland | China (Hangzhou) | Zone H and Zone I |
China (Shanghai) | Zone F and Zone G | |
China (Nanjing - Local Region) | Zone A | |
China (Shenzhen) | Zone D and Zone E | |
China (Heyuan) | Zone A and Zone B | |
China (Guangzhou) | Zone A and Zone B | |
China (Qingdao) | Zone B and Zone C | |
China (Beijing) | Zone H and Zone G | |
China (Zhangjiakou) | Zone A and Zone C | |
China (Hohhot) | Zone A and Zone B | |
China (Ulanqab) | Zone A and Zone B | |
China (Chengdu) | Zone A and Zone B | |
Asia Pacific | Singapore (Singapore) | Zone B and Zone C |
China (Hong Kong) | Zone B and Zone C | |
Malaysia (Kuala Lumpur) | Zone A and Zone B | |
India (Mumbai) | Zone A and Zone B | |
Indonesia (Jakarta) | Zone A and Zone B | |
Philippines (Manila) | Zone A | |
Japan (Tokyo) | Zone A and Zone B | |
Europe | Germany (Frankfurt) | Zone A and Zone B |
UK (London) | Zone A and Zone B | |
North America | US (Virginia) | Zone A and Zone B |
US (Silicon Valley) | Zone A and Zone B | |
Australia | Australia (Sydney) | Zone A and Zone B |
Scenario
A company has a data center in Hangzhou. The data center is connected to Alibaba Cloud through Express Connect circuits and virtual border routers (VBRs). The company has deployed two virtual private clouds (VPCs) named VPC1 and VPC2 in the China (Hangzhou) region. Elastic Compute Service (ECS) instances are deployed in the VPCs. The data center, VPC1, and VPC2 cannot communicate with each other. Due to business growth, the company wants to enable network communication among the data center, VPC1, and VPC2.
In this case, the company can use CEN to connect VPC1, VPC2, and the VBR to the transit router in the China (Hangzhou) region. This enables network communication among the data center, VPC1, and VPC2.

Prerequisites
- The data center is connected to Alibaba Cloud through Express Connect circuits and VBRs. For more information, see Connect to an ECS instance from a data center by using an Express Connect circuit.
- Two VPCs are deployed in the China (Hangzhou) region. ECS instances are deployed in
the VPCs. For more information, see Create an IPv4 VPC.
At least one vSwitch is deployed for each VPC in the zones supported by Enterprise Edition transit routers. Each vSwitch must have at least one idle IP address.
For example, if you create one VPC in the China (Hangzhou) region, you must create at least one vSwitch in zone H and one vSwitch in zone I. Each vSwitch must have at least one idle IP address.Note Enterprise Edition transit routers associate elastic network interfaces (EIPs) with the vSwitches in the zones. The ENIs function as ingresses that forward network traffic from VPCs to the transit routers. Each ENI occupies one IP address.The following table shows the CIDR blocks allocated to VPC1, VPC2, the VBR, and the data center. Make sure that the CIDR blocks do not overlap.Item VPC1 VPC2 VBR Data center The region where the network instance is deployed. China (Hangzhou) China (Hangzhou) China (Hangzhou) Hangzhou Network instance CIDR block - VPC CIDR block: 192.168.0.0/16
- vSwitch 1 CIDR block: 192.168.20.0/24
- vSwitch 2 CIDR block: 192.168.21.0/24
- VPC CIDR block: 10.0.0.0/16
- vSwitch 1 CIDR block: 10.0.0.0/24
- vSwitch 2 CIDR block: 10.0.1.0/24
- VLAN ID: 0
- IPv4 CIDR block at the Alibaba Cloud side: 172.16.1.2/30
- IPv4 CIDR block at the customer side: 172.16.1.1/30
On-premises network CIDR block: 172.16.0.0/16 vSwitch zone - vSwitch 1 in zone H
- vSwitch 2 in zone I
- vSwitch 1 in zone H
- vSwitch 2 in zone I
N/A N/A Server IP address ECS1 IP address: 192.168.20.161 ECS2 IP address: 10.0.0.33 N/A On-premises server IP address: 172.16.0.89 - You must be aware of the security group rules that are applied to the ECS instances in the VPCs. Make sure that the security group rules allow the VPCs to communicate with each other and with the data center. For more information, see Query security group rules and Add security group rules.
Procedure

Step 1: Create a CEN instance
CEN is used to create and manage network resources. Before you can connect networks, you must create a CEN instance.
Step 2: Connect the VPCs to the transit router
Connect VPC1 and VPC2 to the transit router in the China (Hangzhou) region.
Step 3: Connect the VBR to the transit router
Step 4: Test network connectivity
After you complete the preceding steps, VPC1, VPC2, and the data center can communicate with each other.
- Test the network connectivity between VPC1 and VPC2.
- Test the network connectivity between VPC1 and the data center.
- Test the network connectivity between VPC2 and the data center.
Route descriptions
- The transit router in the China (Hangzhou) region automatically learns routes from VPC1, VPC2, and the VBR.
- The VBR uses the transit router to learn routes from VPC1 and VPC2.
- The CEN instance automatically adds the following route entries to the route tables
of VPC1 and VPC2: 10.0.0.0/8, 172.16.0.0/12, and 192.168.0.0/16. The next hops are
the transit router.
Network traffic from VPC1 and VPC2 is routed to the transit router. The transit router enables the VPCs and the data center to communicate with each other.
The following table describes the route entries of VPC1 and VPC2. You can check route entries in the console. For more information, see View routes of an Enterprise Edition transit router and View routes of network instances.



