Common questions about Express Connect circuits, organized by topic.
Capabilities and specifications — 6 questions
Networking and connectivity — 5 questions
Setup and configuration — 4 questions
Billing — 1 question
Troubleshooting — 8 questions
Capabilities and specifications
Can I access VPCs in different regions after connecting my data center through an Express Connect circuit?
Yes. After connecting your data center to Alibaba Cloud through an Express Connect circuit, you can access virtual private clouds (VPCs) in all regions. To connect to a VPC in a different region than your access point, use Cloud Enterprise Network (CEN).
What types of physical connections does Alibaba Cloud support?
Alibaba Cloud access devices support optical ports. By default, Alibaba Cloud provides single-mode optical transceivers at 1 Gbit/s, 10 Gbit/s, 40 Gbit/s, and 100 Gbit/s. These transceivers support a maximum transmission distance of 10 kilometers.
What is the maximum bandwidth for an Express Connect circuit?
The maximum bandwidth you can apply for in the console is 10 Gbit/s. For higher bandwidth, contact your customer manager.
Do Express Connect circuits support dynamic routing protocols?
Yes. Express Connect circuits support Border Gateway Protocol (BGP).
Can I configure multiple Express Connect circuits for disaster recovery?
Yes. Express Connect Router (ECR) networking supports up to 32 Express Connect circuits, which enables equal-cost multi-path routing (ECMP).
Do Express Connect circuits support network address translation (NAT)?
No. Configure NAT in your data center if needed.
Networking and connectivity
Can I use one Express Connect circuit to connect my data center to multiple VPCs?
Yes. Use CEN to connect the VPCs, which lets your data center communicate with each VPC over private connections.
Can I extend a VLAN from my data center to a VPC?
No. Alibaba Cloud supports only Layer 3 interconnections with external networks.
If one Express Connect circuit connects to multiple VPCs, are the connections isolated?
Assign a unique VLAN ID to each connection to isolate them. For details, see Create and manage a VBR.
What is the relationship between zones and access points?
Both zones and access points are scoped to regions. From one access point, you can reach all zones in the same region. To connect to a VPC in a different region, use CEN.
How do I achieve high availability?
Use Express Connect circuits to establish active/active or active/standby connections between your data center and Alibaba Cloud. For architecture guidance, see:
Setup and configuration
How do I connect a data center to Alibaba Cloud through an Express Connect circuit?
Read the Express Connect user guide.
Choose an access point.
Apply for an Express Connect circuit and pay the initial installation fee in the console.
Apply for a Letter of Authorization (LOA).
Contact your connectivity provider to install the Express Connect circuit.
After installation is complete, update the progress in the console and wait for Alibaba Cloud to install the pigtail (1–2 business days for access points in the Chinese mainland; 3 business days for access points outside China).
Pay the resource usage fee. The circuit status changes to Enabled.
Create a virtual border router (VBR).
Attach the VBR to a CEN instance, or create a peering connection.
Configure routes.
Run a ping test to verify connectivity between your data center and the VPC.
How do I plan the IP address for the physical connection?
Follow these rules when assigning IP addresses for your Express Connect circuit:
The Alibaba Cloud-side gateway IP address and data center-side gateway IP address must not conflict with each other. Only private IP addresses are allowed. If your data center uses public IP addresses, submit a ticketsubmit a ticket to configure IP address mapping.
CIDR blocks in your data center must not include
100.64.0.0/10, as this range is reserved for cloud service addresses.
What does the VLAN ID on a VBR control?
The VLAN ID determines how the VBR's switch port operates:
VLAN ID = 0: The switch port uses Layer 3 router interface mode. Each Express Connect circuit maps to one VBR, and the circuit can only connect to VPCs under the same account.
VLAN ID 1–2999: The switch port uses Layer 3 VLAN subinterface mode. Each VLAN ID maps to one VBR, and the circuit can connect to VPCs across different Alibaba Cloud accounts.
For example, a company with multiple subsidiaries — each with a separate Alibaba Cloud account and VPC — assigns a unique VLAN ID per subsidiary. When creating VBRs, each subsidiary's VBR gets a different VLAN ID.
What are the Alibaba Cloud-side and data center-side IP addresses on a VBR?
The Alibaba Cloud-side IP address is the IP address of the VBR itself. The data center-side IP address is the IP address of the gateway device in your data center. Both addresses must belong to the same CIDR block and are used to establish communication between your data center and the VPC.
Billing
How much does it cost to connect a data center to Alibaba Cloud through an Express Connect circuit?
You are charged by both Alibaba Cloud and your connectivity provider. For a full breakdown, see Billing overview.
Troubleshooting
How do I verify the network connectivity of an Express Connect circuit?
After your connectivity provider completes installation, confirm delivery in the console:
Log on to the Express Connect console.
In the top navigation bar, select your region, then click Physical Connection in the left-side navigation pane.
On the Physical Connections page, click Confirm Delivery. The circuit status changes to Waiting for Pigtail Installation.
Alibaba Cloud completes pigtail installation within 1–2 business days for access points in the Chinese mainland and within 3 business days for access points outside China. When installation is complete, the LOA Status column changes to Pending For Payment.
The status of your connectivity provider's installation is not shown in the console. Contact your connectivity provider's installation team for updates on their progress. All other statuses can be viewed in the LOA Status column on the Physical Connection page.
Pay the resource usage fee. The circuit status changes to Enabled.
Create a VBR and configure routes.
Run
pingto verify connectivity between your data center and the VPC.
How do I check if Alibaba Cloud has completed the installation of an Express Connect circuit?
To check whether Alibaba Cloud has completed the pigtail installation, follow these steps:
Log on to the Express Connect console and select your region from the top navigation bar.
Find the target physical port instance and check the LOA Status column.
When the LOA Status changes to Pending For Payment, Alibaba Cloud has completed the pigtail installation.
The status of your connectivity provider's installation is not shown in the console. Contact your connectivity provider's installation team for updates on their progress. All other statuses can be viewed in the LOA Status column on the Physical Connection page.
How do I connect a data center to an internal OSS endpoint in a VPC?
Internal Object Storage Service (OSS) endpoints belong to 100.64.0.0/10, which is reserved by Alibaba Cloud. You cannot add a 100.64.0.0/10 route directly to a VBR.
Split the block into smaller subnets — for example, 100.64.0.0/11 and 100.96.0.0/11 — then add these routes to the VBR route table with the next hop set to the VPC.
What do I do if my data center cannot access an Elastic Compute Service (ECS) instance after installing the Express Connect circuit?
See Troubleshooting for a full diagnostic guide.
What do I do if my Express Connect circuit goes down?
Ping the VBR IP address from your data center's gateway device. If the ping fails, contact your connectivity provider to report the issue. You can also submit a ticketsubmit a ticket for Alibaba Cloud to check the access device connected to your circuit.
If the Alibaba Cloud access device is operating normally but the issue persists, work with your connectivity provider to resolve it.
What do I do if the bandwidth is not reaching the configured limit?
The steps depend on your router interface bandwidth:
Below 1 Gbit/s: Use iPerf3 to measure the actual bandwidth. If the result is below 10 Mbit/s, check whether half-duplex mode is enabled on one of the ports. Ask your connectivity provider to switch the negotiation mode to adaptive.
Above 1 Gbit/s: When traffic is distributed across multiple resources, each data stream is limited to 130 Mbit/s or 250 Mbit/s. This is expected behavior.
What do I do if I get an error when adding or deleting routes for a VBR?
VBR hardware can process a limited number of requests at the same time. Wait for any ongoing tasks to complete, then retry the route change.
What do I do if I see a token error when adding routes?
Your browser cookie has timed out. Log out and log back in, then try again.