All Products
Search
Document Center

Express Connect:Migrate a TR connection to an ECR connection

Last Updated:Sep 20, 2026

For private access to Alibaba Cloud with lower latency and higher bandwidth without advanced networking features, use an Express Connect Router (ECR) to deploy your hybrid cloud.

Scenario

Important
  • Since the migration involves an active/standby switchover, before the migration, ensure that the peak bandwidth level of a single circuit does not exceed 50% of the overall circuit bandwidth. Otherwise, packet loss will occur.

  • During the migration, you need to migrate your multiple Express Connect circuits one by one. Make sure that a successfully migrated circuit has started forwarding traffic normally before you migrate the next circuit.

This topic uses the scenario in which a VPC uses a Transit Router to interconnect an on-premises IDC with cloud resources as an example for the migration. As shown in the following figure, after the migration, VPC1 and VPC2 can communicate with each other through the Transit Router, and VPC1 and VBR1 and VBR2, as well as VPC2 and VBR1 and VBR2, can communicate with each other through the Express Connect Router (ECR). Configuration flowchart of migration operations:

image

The following table describes the CIDR block allocation in this example. You can plan CIDR blocks based on your business requirements. Make sure that the CIDR blocks do not overlap.

Network

CIDR block

Data center

10.10.10.0/24

VPC

192.168.1.0/24

VBR1

Alibaba Cloud-side IPv4 interconnect IP address: 10.0.0.1

Customer-side IPv4 interconnect IP address: 10.0.0.2

IPv4 subnet mask: 255.255.255.252

VBR2

Alibaba Cloud-side IPv4 interconnect IP address: 10.0.0.5

Customer-side IPv4 interconnect IP address: 10.0.0.6

IPv4 subnet mask: 255.255.255.252

Prerequisites

Step 1: Redirect traffic to the primary VBR (VBR1)

Use a routing policy in Cloud Enterprise Network (CEN) to redirect all traffic to VBR1, making it the primary path for all inbound and outbound traffic.

  1. Log on to the .CEN console

  2. On the CEN Instance page, click the ID of the CEN instance that you want to manage.

  3. Go to the Basic Information > Transit Router tab and click the ID of the transit router that you want to manage.

  4. On the details page of the transit router, click the Route Table tab.

  5. In the left-side navigation pane, click the ID of the route table.

  6. On the route table details page, click the Route Maps tab.

  7. On the Route Maps tab, click Add Route Map.

  8. On the Add Route Map page, configure a routing policy to set VBR2 as the standby VBR and deny traffic via VBR2.

    This section describes only the key parameters. For more information, see Use routing policies.

    • Deny outbound traffic from VBR2

      Parameter

      Description

      Policy Priority

      A smaller value indicates a higher priority. The priority of the policy for VBR2 must be lower (a larger number) than the priority of the policy for VBR1.

      In this example, enter 30.

      Policy Direction

      Select RegionIn.

      Match Condition

      Select Source Instance IDs, and set the value to the ID of the VBR2 instance. This matches all routes that originate from the VBR2 network instance.

      Policy Action

      Set Policy Action to Deny.

    • Deny inbound traffic from VBR2

      Parameter

      Description

      Policy Priority

      In this example, enter 30.

      Policy Direction

      Select RegionOut.

      Match Condition

      Select Source Instance IDs, and set the value to the ID of the VBR2 instance. This matches all routes that originate from the VBR2 network instance.

      Policy Action

      Set Policy Action to Deny.

Step 2: Add route entries to the VPCs

Repeat this operation to add detailed route entries for accessing the on-premises IDC to VPC1 and VPC2 respectively. Make sure that the configured static route is more specific than the BGP route CIDR block advertised by the IDC through the ECR.

  1. Log on to the VPC console.

  2. In the left-side navigation pane, click Route Tables.

  3. In the top navigation bar, select the region to which the route table belongs.

  4. On the Route Tables page, find the route table that you want to manage and click its ID.

  5. On the route table details page, perform the following operations:

    1. Turn off the Propagate Routes switch. This stops the route table from receiving dynamically propagated routes.

    2. Select Route Entry List > Custom Route, and click Add Route.

      Parameter

      Description

      Name

      Enter a name for the custom route entry.

      Resource Group

      Select the resource group to which the next hop belongs.

      Destination CIDR Block

      Select the destination CIDR block type and enter the destination CIDR block to which traffic is forwarded. In this example, select IPv4 CIDR and enter the CIDR block 10.10.10.0/24.

      Next Hop Type

      Select the next hop type. In this example, select Transit Router.

      Transit Router

      Select the target TR instance.

      Description

      Enter a description for the custom route entry.

Step 3: Create and start a failure drill for express connect circuit 2

Create and start a failure drill for express connect circuit 2, which is associated with VBR2. This simulates a link failure for the express connect circuit and VBR2. For more information, see Create a failure drill task and Start a failure drill task.

Step 4: Delete the route propagation from VBR2 to the TR

Delete the route propagation from VBR2 to the TR.

  1. On the Route Table Association tab of the destination TR route table, find the destination network instance connection, and click Delete in the Actions column.

  2. In the Delete route association dialog box, confirm the information, and then click Confirm.

Step 5: Verify the removal of route propagation for VBR2

Verify that the route propagation from VBR2 is successfully deleted.

  1. On the Route Table Association tab of the destination TR route table, find the destination network instance connection, and click Delete in the Actions column.

  2. In the Delete route association dialog box, confirm the information, and then click Confirm.

Step 6: Detach VBR2 from the TR

You must detach VBR2 from the TR instance before you can associate it with an ECR.

  1. Log on to the Cloud Enterprise Network console.

  2. On the CEN Instance page, find the target CEN instance and click its ID.

  3. On the Basic Settings > Transit Router tab, find the target transit router instance, and then click the ID of the target instance.

  4. On the Intra-Region Connections tab, find the connection for VBR2, and then click Disassociate in the Actions column.

  5. In the dialog box that appears, click OK.

Step 7: Associate the VPCs with the ECR

Associate VPC1 and VPC2 with the ECR.

  1. Log on to the Express Connect console.

  2. In the top navigation bar, select a region.

  3. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the ID of the target ECR instance.

  1. On the VPC tab, click Associate VPC.

  2. In the Associate VPC dialog box, configure the following parameters and click OK.

    Parameter

    Description

    Region

    The region where the target VPC is located.

    Resource Owner

    Select the type of account that owns the VPC. Valid values:

    • Your Account.

    • Another Account.

    VpcId

    Select the ID of the target VPC instance.

    Allowed Route Prefixes

    Enter the prefixes of the routes that you want to advertise from the ECR to your data center.

Step 8: Associate VBR2 with the ECR

  1. Log on to the Express Connect console.

  2. In the top navigation bar, select a region.

  3. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the ID of the target ECR instance.

  4. On the VBR tab, click Add VBR.

  5. In the Add VBR dialog box, configure the following parameters and click OK.

    Parameter

    Description

    Resource Owner

    Select the type of account that owns the VBR. Valid values:

    • Your Account.

    • Another Account.

    Region

    Select the region where the VBR is located.

    Networks

    Select the target VBR instance. In this example, select the VBR2 instance.

Step 9: End the fault drill task for Express Connect circuit 2

You must end the failure drill for express connect circuit 2 to restore its status and the status of the VBR2 instance. For more information, see End a failure drill task.

Step 10: Redirect traffic to VBR2

Refer to Step 1 and change the Action from Deny to Allow for the routing policies in both the RegionOut and RegionIn directions for VBR2.

Step 11: Delete the static route from the VPC to the TR

If the CIDR blocks configured for your VPCs are more specific than the received BGP routes, delete the static routes in VPC1 and VPC2 that point to the TR. This ensures that all inbound and outbound traffic is forwarded through VBR2.

  1. Log on to the VPC console.

  2. In the left-side navigation pane, click Route Tables.

  3. In the top navigation bar, select the region to which the route table belongs.

  4. On the Route Tables page, find the route table that you want to manage and click its ID.

  5. On the route table details page, select Route Entry List > Custom Route, find the route entry that you added in Step 7, click Delete in the Actions column, and in the dialog box that appears, click OK.

Step 12: Create and start a failure drill for express connect circuit 1

Create and start a failure drill for express connect circuit 1, which is associated with VBR1. This simulates a link failure for the express connect circuit and VBR1. For more information, see Create a failure drill task and Start a failure drill task.

Step 13: Delete the route propagation from VBR1 to the TR

Delete the route propagation from VBR1 to the TR.

  1. On the Route Table Association tab of the destination TR route table, find the destination network instance connection, and click Delete in the Actions column.

  2. In the Delete route association dialog box, confirm the information, and then click Confirm.

Step 14: Verify the removal of route propagation for VBR1

Verify that the route propagation from VBR1 is successfully deleted.

  1. On the Route Table Association tab of the destination TR route table, find the destination network instance connection, and click Delete in the Actions column.

  2. In the Delete route association dialog box, confirm the information, and then click Confirm.

Step 15: Detach VBR1 from the TR

You must detach VBR1 from the TR instance before you can associate it with an ECR.

  1. Log on to the Cloud Enterprise Network console.

  2. On the CEN Instance page, find the target CEN instance and click its ID.

  3. On the Basic Settings > Transit Router tab, find the target transit router instance, and then click the instance ID.

  4. On the Intra-Region Connections tab, find the connection for VBR1, and then click Disassociate in the Actions column.

  5. In the dialog box that appears, click OK.

Step 16: Associate VBR1 with the ECR

  1. Log on to the Express Connect console.

  2. In the top navigation bar, select a region.

  3. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the ID of the target ECR instance.

  4. On the VBR tab, click Add VBR.

  5. In the Add VBR dialog box, configure the following parameters and click OK.

    Parameter

    Description

    Resource Owner

    Select the type of account that owns the VBR. Valid values:

    • Your Account.

    • Another Account.

    Region

    Select the region where the VBR is located.

    Networks

    Select the target VBR instance. In this example, select the VBR1 instance.

Step 17: End the failure drill for express connect circuit 1

You must end the failure drill for express connect circuit 1 to restore its status and the status of the VBR1 instance. For more information, see End a failure drill task.

Step 18: Verify traffic monitoring

Verify that the migrated circuit is forwarding traffic by checking the monitoring data for VBR2. Once confirmed, the migration is complete. Inbound and outbound traffic is now load-balanced across both express connect circuits through the ECR.

  1. Log on to the Express Connect console.

  2. In the top menu bar, select the target region, and then in the left-side navigation pane, click Virtual Border Routers (VBRs).

  3. On the Virtual Border Routers (VBRs) page, find the target VBR and click the Monitoring icon in the Monitor column to view traffic monitoring information.