This topic describes how to migrate an Elastic Compute Service (ECS) instance of the Virtual Private Cloud (VPC) type from its current VPC to a different one. If the VPC that you selected when you created an ECS instance does not meet your business requirements or if you want to re-plan the network of an ECS instance, you can use this feature to change the VPC of the instance.


  • The instance is in the Stopped state. For more information about how to stop an ECS instance, see Stop an instance.
    Note If the instance has not been restarted after it is created, you must restart it before you stop it.
  • The instance is not added as a backend server of a Server Load Balancer (SLB) instance. For more information about how to remove a backend server from an SLB instance, see Add an ECS instance to the default server group.
  • The secondary elastic network interfaces (ENIs) attached to the instance are detached. Multiple secondary private IP addresses assigned to the ENIs are revoked. For more information, see Unbind an ENI and Unassign secondary private IP addresses.
  • The instance is not remotely connected over the private network. If the ECS instance is remotely connected over the private network, a private link is generated. In this case, the instance cannot be migrated from the current VPC. To change the VPC of the ECS instance, release the private link.
  • The destination VPC, vSwitch, and security groups are created and available.

Use scenarios

  • You want to re-plan the VPCs of your ECS instances because the original VPCs are unable to keep up with the growing needs of your business.
  • In the early business stage, only one VPC was planned. Different projects and usage environments shared this VPC, which resulted in risks stemming from data operations. You want to use different VPCs for different projects and environments.
  • Your ECS instances are deployed in the default VPCs of different accounts. Instances that reside in different VPCs cannot connect to each other across Alibaba Cloud accounts due to IP address conflicts. To ensure that the instances within different Alibaba Cloud accounts can connect to each other, you must change the VPCs of the instances and resolve the IP address conflicts.


  • The instance cannot be used in other cloud services. For example, the instance cannot be in the process of migration or having its VPC changed, or the databases deployed on the instance cannot be managed by Data Transmission Service (DTS).
  • After the VPC is changed, the new vSwitch of the instance must reside within the same zone as the original vSwitch.
  • When you change the VPC of an instance, you must select one to five security groups of the same type (basic or advanced) for the instance.
  • Instances of specific instance families do not support VPC changes to VPCs on which advanced features are enabled. For more information, see Instance families that do not support advanced VPC features.
  • You can change the VPCs of up to 20 instances at a time.
  • After you change the VPC of an instance, the instance can no longer communicate with other instances in the original VPC. For information about how to communicate with other instances, see What is Express Connect?
  • The cut-through mode or the multi-EIP-to-ENI mode cannot be enabled for the instance.
  • The instance cannot be associated with a high-availability virtual IP address (HAVIP).
  • The vSwitch of the instance cannot be associated with a custom route table.
  • The instance cannot have Global Accelerator (GA) activated.
  • The instance cannot have secondary ENIs bound.
  • The instance cannot have IPv6 addresses assigned.
  • The primary ENI of the instance cannot be associated with multiple IP addresses.


  1. Log on to the ECS console.
  2. In the left-side navigation pane, choose Instances & Images > Instances.
  3. In the top navigation bar, select a region.
  4. Change the VPCs of one or more ECS instances at a time.
    • Change the VPC of a single instance

      Find the ECS instance for which you want to change the VPC. In the Actions column, choose More > Network and Security Group > Change VPC.

    • Change the VPCs of multiple ECS instances at a time

      Select the instances for which you want to change the VPCs and choose More > Network and Security Group > Change VPC in the lower part of the page.

  5. In the Change VPC wizard, follow the instructions to change the VPC of the ECS instance.
    Change VPC
    1. In the Prepare step, check the network information and precautions and click Next.
    2. In the Select VPC step, configure the Destination VPC, Destination VSwitch, and Destination Security Group parameters and click Next.
    3. Optional:In the Configure Primary Private IP Address step, specify a primary private IP address for the selected instance to use in the destination VPC.
      • The primary private IP address must be within the CIDR block of the destination vSwitch.
      • If you do not manually set the primary private IP address, the system assigns one automatically.
    4. Click OK.

After you change the VPC of the instance, you can click the instance ID to view the new VPC and vSwitch in the Network Information section on the Instance Details page.