Cloud Enterprise Network (CEN) is a highly available network built on the global private network of Alibaba Cloud. CEN uses transit routers to establish inter-region connections between virtual private clouds (VPCs). This enables VPCs to communicate with data centers and builds flexible, stable, enterprise-class networks in the cloud.


Introduction to CEN - August 2022
CEN instanceCEN instances are the basic resources that are used to create and manage cloud networks. Transit routers are deployed on CEN instances.

A CEN instance can contain one or more transit routers. You can purchase bandwidth plans and create inter-region connections on transit routers to enable communication between network instances in different regions.

Transit router

Transit routers are the core network element that forwards network traffic within or across regions. Transit routers are region-specific and support custom routing policies. For a CEN instance, you can create only one transit router in each region.

Network instance
You can use transit routers to connect the following network instances. This way, you can enable communication between cloud resources, communication between resources in different regions, and communication between cloud resources and on-premises resources.
  • Virtual private clouds (VPCs)
  • Virtual border routers (VBRs)
  • Cloud Connect Network (CCN) instances
  • IPsec-VPN connections
  • Transit routers
Network instance attachment
A network instance attachment refers to the connection between a transit router and a network instance. Network instance attachments can be classified into the following types:
  • VPC attachments
  • VBR attachments
  • CCN attachments
  • VPN attachments

    VPN attachments refer to the connections between IPsec-VPN connections and transit routers.

  • Inter-region connection

    An inter-region connection refers to a connection between transit routers that are deployed in different regions. You can purchase a bandwidth plan to connect network instances across regions. Network instances in the same region can communicate with each other through transit routers. You do not need to create inter-region connections or purchase bandwidth plans for network instances in the same region.

Transit router route tableNetwork instances that are connected through a transit router forward traffic by using the route tables of the transit router. Each transit router has a default route table. You can create custom route tables and configure communication, isolation, and traffic redirection policies by using the associated forwarding and route learning features.
  • Default route table

    The system automatically creates a default route table for each transit router.

  • Custom route table

    You can manually create custom route tables. Custom route tables are similar to virtual routing and forwarding (VRF) used by traditional routers. A custom route table is isolated from the default route table and other custom route tables.

  • Associated forwarding

    You can create an associated forwarding correlation between a network instance attachment and a route table of a transit router. After you enable associated forwarding, the transit router forwards traffic based on the route table that is associated with the network instance.

  • Route learning

    You can enable route learning between a network instance attachment and a route table of a transit router. After you create a route learning correlation, the route table can automatically learn routes from the network instance.

Bandwidth plan

A bandwidth plan provides bandwidth resources to enable inter-region communication. You can purchase bandwidth plans and create inter-region connections on transit routers to enable communication between network instances in different regions.f For more information, see Work with a bandwidth plan.

Transit router editions

Transit routers are available in two editions: Basic Edition and Enterprise Edition. Enterprise Edition is an upgraded version of Basic Edition and supports all features of Basic Edition. In addition, Enterprise Edition supports custom routing policies. For more information, see How transit routers work.

The following table lists the regions and zones that support Basic Edition and Enterprise Edition.

Table 1. Regions and zones that support Enterprise Edition transit routers
Chinese mainlandChina (Hangzhou)Zone H, Zone I, Zone J, and Zone K
China (Shanghai)Zone F, Zone G, Zone E, Zone B, Zone N, Zone M, and Zone L
China (Nanjing - Local Region)Zone A
China (Fuzhou - Local Region)Zone A
China (Shenzhen)Zone D, Zone E, Zone F, and Zone A
China (Heyuan)Zone A and Zone B
China (Guangzhou)Zone A and Zone B
China (Qingdao)Zone B and Zone C
China (Beijing)Zone H, Zone G, Zone J, Zone K, Zone I, and Zone L
China (Zhangjiakou)Zone A, Zone B, and Zone C
China (Hohhot)Zone A and Zone B
China (Ulanqab)Zone A, Zone B, and Zone C
China (Chengdu)Zone A and Zone B
Asia PacificSingapore (Singapore)Zone A, Zone B, and Zone C
China (Hong Kong) Zone B, Zone C, and Zone D
Malaysia (Kuala Lumpur)Zone A and Zone B
India (Mumbai)Zone A and Zone B
Indonesia (Jakarta)Zone A, Zone B, and Zone C
Philippines (Manila)Zone A
Japan (Tokyo)Zone A and Zone B
South Korea (Seoul)Zone A
Thailand (Bangkok)Zone A
EuropeGermany (Frankfurt)Zone A and Zone B
UK (London)Zone A and Zone B
North AmericaUS (Virginia)Zone A and Zone B
US (Silicon Valley)Zone A and Zone B
AustraliaAustralia (Sydney)Zone A and Zone B
Middle EastSAU (Riyadh)Zone A and Zone B
Table 2. Regions that support Basic Edition transit routers
Chinese mainlandChinese mainland CCN
Asia PacificJapan CCN, Singapore CCN, Hong Kong CCN, Malaysia CCN, and Indonesia CCN
EuropeFrankfurt CCN
AustraliaAustralia CCN


  • Worldwide Network Communication
    You can use transit routers and bandwidth plans to connect VPCs in different regions to data centers. This allows networks to communicate on a global scale. In the same region, a transit router can connect to at most 1000 VPCs. This allows you to expand networks.
  • Low Latency and High Speed
    CEN provides low-latency and high-speed network transmission. In the same region, the data transfer rate can reach the maximum rate supported by the device port. Resources can communicate with each other on a global scale. Compared with data transmission over the Internet, network latency is greatly reduced.
  • High Reliability and High Quality
    Transit routers can be deployed in active/standby mode. Network traffic is automatically switched between the active and standby transit routers to ensure service availability. Multiple sets of high-quality connections exist between any two nodes in the network established by CEN. When Layer 2 connections are interrupted, the network automatically converges in case your workloads are interrupted.
  • Secure and Flexible Enterprise-class Networking
    Transit routers support custom routing policies to meet the requirements for enterprise-class networking. For example, you can create a network topology that supports security zones, demilitarized zones, and service chaining.
  • Convenience with Pay-As-You-Go
    Transit routers support the pay-as-you-go billing method. For network communication within the same region, you are charged only for the connected network instances and data transfer processed by the transit routers. You can also create inter-region connections without device or ISP line deployment, and adjust connection settings as needed. This reduces networking costs.
  • One-stop O&M
    The CEN console displays your network resources in different regions. You can query intra-region and inter-region network typologies and check network status in the console. The CEN console supports visualized management that improves O&M efficiency.

Notes on network transmission

Alibaba Cloud offers a private network with high performance and low latency. This private network provides a secure cloud computing environment to meet your networking requirements. Packet loss during network transmission may be caused by many factors, such as network stream collisions, Layer 2 network errors, and other network errors. Alibaba Cloud aims to provide network services with an hourly packet loss rate of less than 0.0001% for 99% of packets.

When you use CEN, take note of the following rules:
  • Only network traffic transmitted over CEN passes through the Alibaba Cloud transmission network. CEN can minimize the packet loss rate in inter-region transmission when bandwidth resources are sufficient.
  • Express Connect circuits that connect the Chinese mainland to regions outside the Chinese mainland are provided by China Unicom. These Express Connect circuits are optimized and maintained in the same way as the Alibaba Cloud transmission network to minimize packet loss.