After you create a virtual border router (VBR), a route table is automatically created for it. You can add routes to this route table to manage its traffic forwarding.
Background
After you create a VBR, you must add routes pointing to an Express Connect circuit and a Virtual Private Cloud (VPC) to forward traffic between the VPC and your on-premises data center.
When you access an Object Storage Service (OSS) internal domain name by using Cloud Enterprise Network (CEN), Express Connect, Smart Access Gateway (SAG), or a VPN Gateway, you must configure routes for the address blocks in the corresponding region. Otherwise, network connectivity issues may occur. For more information, see Regions and endpoints.
A VBR supports three types of routes: custom, Border Gateway Protocol (BGP), and CEN.
You can add and delete custom routes. Each VBR supports up to 48 custom routes.
A VBR supports BGP routing for your on-premises data center. For more information, see Configure and manage BGP.
After a VBR is attached to a CEN instance, CEN automatically synchronizes routes for the VBR.
VBR does not support source address policy-based routing. If you need a specific ECS instance to access the internal network through a specified leased line, we recommend that you implement this through the CEN policy-based routing feature.
Add a custom route
Log on to the Express Connect console.
In the top menu bar, select the target region, and then in the left-side navigation pane, click Virtual Border Routers (VBRs).
On the Virtual Border Routers (VBRs) page, click the target VBR instance ID.
Click the Routes tab, and then click Add Route.
In the Add Route panel, configure the route and click OK.
Parameter
Description
Network Type
The network type for the route.
IPv4 Routing: an IPv4 route.
IPv6 Routing: an IPv6 route.
NoteThis parameter is required only if the VBR instance supports IPv6.
If you set Network Type to IPv6 Routing, the destination can be any IPv6 CIDR block except for 2403:28c0:200::/40.
Next Hop Type
The type of next hop.
VPC: forwards traffic destined for the specified CIDR block to the selected VPC.
Physical Connection Interfaces: forwards traffic destined for the specified CIDR block to the selected Express Connect interface.
NoteIf the VBR instance is attached to an Enterprise Edition transit router and you want to configure a static route from the VBR to the transit router, go to the Network Instance Route Table tab of the transit router, select the VBR instance as the network instance, and then click Add Route Entry to add the static route. For more information, see Add a route entry.
Destination CIDR Block
Enter the destination CIDR block to forward traffic to. If the CIDR format is invalid appears, check the IP range format: to access a single IP address, set the destination CIDR block to a 32-bit mask (such as 10.0.0.61/32). If you use a 30-bit or other subnet mask, you must specify a valid network address (such as 10.0.0.60/30). Do not directly use a host IP with a subnet mask (such as 10.0.0.61/30, which is an invalid format).
Next Hop
The instance to use as the next hop.
Description
A description for the route.
Delete a custom route
Log on to the Express Connect console.
In the top menu bar, select the target region, and then in the left-side navigation pane, click Virtual Border Routers (VBRs).
On the Virtual Border Routers (VBRs) page, click the target VBR instance ID.
Click the Routes tab, find the target route, and then click Delete in the Actions column.
In the dialog box that appears, click OK.
FAQ
Why are VBR and VPC still unable to communicate even though routes have been configured?
Check the following points:
Bidirectional routing principle: Network connectivity requires bidirectional routing. Even for one-way access, you must configure routes pointing to the peer CIDR block in the route tables of both the source and destination ends (including the VPC route table and the VBR route table), so that return traffic can be forwarded correctly.
Route learning and synchronization: If the VBR has been added to Cloud Enterprise Network (CEN), confirm that the Automatically advertise system routes to the default route table of the Transit Router and Automatically advertise routes to the VBR options are enabled. Alternatively, manually add a static route from the VBR to the Transit Router in the Enterprise Router to prevent the VPC route table from failing to learn the related routes.
Security group and ACL rules: In addition to route configuration, you also need to check whether the ECS security group, VBR ACL, or VPN Gateway policy allows the corresponding source/destination CIDR blocks and ports (such as ports 2222 and 18080). Even if the routes are correct, traffic blocked by security policies will still cause network connectivity failures.
API reference
CreateRouteEntry: Creates a custom route in a route table.
ModifyRouteEntry: Modifies the name and description of a custom route.
DescribeRouteEntryList: Lists the routes for a VBR. Before you delete a custom route, call this operation to retrieve the route's NextHopId.
DeleteRouteEntry: Deletes a custom route from the route table of a VBR.