This topic describes how to migrate a virtual border router (VBR) from a peering connection in Express Connect to a Cloud Enterprise Network (CEN) instance. You can use CEN to establish private connections between virtual private clouds (VPCs), and between VPCs and data centers. CEN supports automatic route distribution and learning, which speeds up network convergence, improves the quality and security of cross-network communications, and connects all network resources.


A CEN instance is created. For more information, see Create a CEN instance.


You can perform the following steps to migrate a VBR from a peering connection to a CEN instance:

Warning Before you freeze or delete the router interfaces of the peering connection, make sure that the routes for both the VBR and the connected VPC from the peering connection are migrated.
  1. If you have configured health checks for the VBR, delete the health check settings in the Express Connect console.
  2. Log on to CEN console.
  3. On the Instances page, find the CEN instance that you want to manage and click the ID of the instance.
  4. Find the section that displays the types of network instances and click the Add a network instance icon next to the network instance that you want to manage.
  5. On the Connection with Peer Network Instance page, set parameters for the instance, and connect the VPC and VBR instance that you want to migrate. For more information, see Attach network instances to a CEN instance.
  6. If you want to communicate across regions, purchase a bandwidth plan and configure bandwidth for the communication.
  7. If you have created route entries that point to Elastic Compute Service (ECS) instances, virtual private network (VPN) gateways, or high-availability virtual IP addresses (HAVIPs), publish these routes to the CEN instance in the VPC console based on your connection requirements.
    VPC migration-publish the routes
  8. If your data center needs to access Alibaba Cloud services, such as Object Storage Service (OSS) and Alibaba Cloud DNS PrivateZone, configure the connections in the CEN console.
  9. Log on to CEN console. On the details page of the transit router, click the Routing Information tab to view the configuration information of the instance. After you attach the VBR and VPC to the CEN instance, make sure that the routes do not conflict.

    The static routes of a peering connection have higher priorities than the dynamic routes of the CEN instance. If a static route is configured for a peering connection, CEN does not learn routes that are more specific than and have the same destination as the static route. We recommend that you split static routes of the peering connection and delete them after CEN learns the routes. This ensures a smooth migration.

    In the following figure, the route to in the CEN instance is more specific than the route to of a peering connection. Therefore, the two routes are in conflict.Conflict 1
    • If you can tolerate a transient connection error during the migration, delete the route to Then, the route in the CEN instance automatically takes effect.

      The duration of the disconnection varies based on the number of CEN routes. For important business scenarios, we recommend that you use the following method to smoothly migrate the VPC.

    • If you want to smoothly migrate the VBR, split the route of a peering connection into routes that are more specific than the route to in the CEN instance. For example, split the route to into routes to and
      1. On the details page of VBRs in the Express Connect console, find the required VBR, click its ID, and then click the Routes tab.
      2. Click Add Route to add two routes in which the destination CIDR blocks are and The next hops are the VPC to which the VBR is connected.Split the route
      3. If Border Gateway Protocol (BGP) is used, advertise the routes to and the route 1
      4. Delete the route to from the peering connection.Delete the route 1
      5. Click Refresh to check whether the routes in the CEN instance take effect.Refresh the route 1
      6. Delete the routes to and from the VBR route table, and delete the advertised BGP routes.
      7. In the CEN console, configure health checks for the VBR. For more information, see Configure health checks.