All Products
Search
Document Center

Express Connect:Add a cross-account VBR to a VPC

Last Updated:Jun 17, 2026
Important

VBR-to-VPC connections are no longer available for purchase. We recommend that you use ECR (Express Connect Router). ECR is a forwarding service component for global hybrid cloud networks. It provides features such as global private network interconnection, fully dynamic routing, and unified route publishing and management.

To create a peering connection between a VBR and a Virtual Private Cloud in different Alibaba Cloud accounts, you must use the cross-account authorization feature of the VPC to grant permissions to the VBR.

Use case

You can create a VBR-to-VPC connection between instances in the same region or in different regions. This topic uses a same-region connection as an example.

An enterprise uses Alibaba Cloud account A to create a VBR in the China (Hangzhou) region and Alibaba Cloud account B to create a VPC in the same region. The enterprise wants to use the cross-account VBR authorization feature of the VPC to establish a private connection between the VBR and the VPC.

Limitations

  • For security and compliance reasons, cross-account VBR connectivity is not enabled by default. If you want to connect your VBR to a Cloud Enterprise Network (CEN) instance or a VPC that belongs to a different Alibaba Cloud account, you must provide a document to prove that the main accounts of these Alibaba Cloud accounts belong to the same entity. Then, contact your account manager to request this feature.

    The following figure shows a sample proof of affiliation:

    image
  • A VBR instance that is created on the Alibaba Cloud China site can connect only to a VPC instance on the China site. A VBR instance that is created on the Alibaba Cloud International site can connect only to a VPC instance on the International site.

Prerequisites

  • You have created a VBR instance in the China (Hangzhou) region under Alibaba Cloud account A.

  • You have created a VPC instance in the China (Hangzhou) region under Alibaba Cloud account B.

  • You have the UID of Alibaba Cloud account B, which owns the VPC instance, and the UID of Alibaba Cloud account A, which owns the VBR instance.

Procedure

  1. Step 1: Apply for the privilege to connect a VBR to a cross-account CEN or VPC

  2. Step 2: Grant authorization from the VPC instance

  3. Step 3: Create the cross-account VBR-to-VPC connection

  4. (Optional) Step 4: Revoke the VPC instance authorization

Step 1: Apply for the cross-account connection privilege

Note
  • You can apply for the privilege to connect a VBR to a cross-account CEN or VPC in the Quota Center console or the Express Connect console. This topic uses the Quota Center console as an example. For information about how to apply in the Express Connect console, see Increase quotas.

  • Before you apply for the privilege, contact your account manager and provide the required documents. Then, submit an application in Quota Center. Alibaba Cloud reviews the application based on the documents you provide. For more information about the required documents, see Limitations.

  1. Log on to the Quota Center console.

  2. In the left-side navigation pane, choose Products > Privileges and Quotas.

  3. On the Products with Privileges page, click Express Connect in the Network section.

  4. On the Privileges page, find the target privilege (Privilege name: Allow VBR to load CEN or VPC across accounts, Quota ID: vbr_cross_account_conn/allow), and then click Request in the Actions column.

  5. In the Apply for Privileges dialog box, configure the following parameters and click Confirm.

    Parameter

    Description

    Quota ID

    The system automatically displays the quota ID.

    Description

    The system automatically displays the description of the quota ID.

    Requested Value

    Select a value for the quota.

    • Effective

    • Invalid

    This example uses Effective.

    Time

    Set the effective and expiration times for the privilege.

    Note
    • This parameter is required only when Requested Value is set to Effective.

    • The privilege is valid for one day and takes effect on the day of application.

    Application Reason

    Enter the reason for the application. The following is a sample reason:

    Customer XX: YYYY (customer name + Alibaba Cloud primary account UID) needs to apply for the privilege to connect a VBR to a cross-account CEN or VPC.

    Note

    The Alibaba Cloud primary account UIDs you provide for the cross-account scenario must belong to the same enterprise or entity.

    Notify Result

    Select whether to receive a notification about the result.

    • Yes

    • No

Step 2: Grant authorization from the VPC

You need to grant cross-account authorization to the VBR of Alibaba Cloud account A from the VPC of Alibaba Cloud account B. After authorization, the VPC instance of account B can establish a peering connection with the VBR instance of account A.

  1. Log on to the VPC console with Alibaba Cloud account B.

  2. In the top navigation bar, select the region of the target VPC instance. This example uses China (Hangzhou).

  3. On the VPC page, find the target VPC instance and click its ID.

  4. On the details page of the VPC instance, click the Cross-Account VBR Authorization tab and then click Cross-Account VBR Authorization.

  5. In the Cross-Account VBR Authorization dialog box, configure the parameters and click OK.

    Parameter

    Description

    Peer Account UID

    Enter the UID for Alibaba Cloud account A, which owns the VBR instance.

    Region

    Select the region of the VBR instance. This example uses China (Hangzhou).

    VBR ID

    Select the VBR instance in Alibaba Cloud account A that you want to authorize.

    • Grant Permissions to Specified VBRs: Authorizes one or more specified VBR instances in the selected region under Alibaba Cloud account A to connect to this VPC instance.

      If you select Grant Permissions to Specified VBRs, enter the ID of a VBR instance. To authorize multiple VBR instances, click + Add to enter multiple VBR instance IDs.

      Note

      If you add multiple VBR instance IDs, make sure the IDs are unique.

    • Grant Permissions to All VBRs: Authorizes all VBR instances in the selected region under Alibaba Cloud account A to connect to this VPC instance.

    After you complete the configuration, the authorization takes effect. You can view the created authorization on the Cross-Account VBR Authorization tab.

    Note

    Note the UID of Alibaba Cloud account B and the VPC instance ID. You will need them to create the VBR-to-VPC connection.

Step 3: Create the cross-account VBR-to-VPC connection

After creating a cross-account VBR-to-VPC connection, you can use it to enable private network connectivity between VBRs and VPCs that belong to different Alibaba Cloud accounts.

  1. Use Alibaba Cloud account A and log on to the Express Connect console.

  2. In the left-side navigation pane, choose Peering Connections > VBR-to-VPC.

  3. On the VBR-to-VPC page, click Create Peering Connection.

  4. On the Establish VBR-VPC Interconnection page, configure the following parameters.

    Parameter

    Description

    Initiator Region

    Select the region of the initiator VBR instance. This example uses China (Hangzhou).

    Initiator VBR

    Select the initiator VBR instance from the drop-down list.

    Acceptor Region Type

    Select the region type of the acceptor VPC instance. This example uses Intra-Region.

    Acceptor Account Type

    Select the account type of the acceptor VPC instance. This example uses Another Account.

    Acceptor Account ID

    If you select Another Account as the account type, you must specify the acceptor account ID.

    Select the acceptor account ID from the drop-down list. In this example, select the UID of Alibaba Cloud account B.

    Acceptor VPC

    Select the ID of the authorized acceptor VPC instance.

    Fee Details

    The system automatically displays the Bandwidth Fee.

  5. Read and select the terms of service, and then click OK.

    Note

    If the connection is cross-border, which means one region is in the Chinese mainland and the other is outside the Chinese mainland, you must also select the corresponding cross-border declaration to create the connection.

    After the connection is established, the status of both the initiator and the acceptor changes to Activated.

(Optional) Step 4: Revoke the VPC instance authorization

If you no longer need the cross-account VBR-to-VPC connection, you can revoke the authorization granted by the VPC instance. Revoking the authorization does not interrupt existing cross-account VBR-to-VPC connections.

  1. Log on to the VPC console with Alibaba Cloud account B.

  2. In the top navigation bar, select the region of the target VPC instance. This example uses China (Hangzhou).

  3. On the VPC page, find the target VPC instance and click its ID.

  4. On the details page of the VPC instance, click the Cross-Account VBR Authorization tab. Find the authorization to remove, and then click Revoke Authorization in the Actions column.

  5. In the dialog box that appears, click OK.

API reference

  • GrantInstanceToVbr: Authorizes a VBR instance from another account to connect to a VPC instance.

  • RevokeInstanceFromVbr: Revokes the permissions granted to a VBR for connecting to a VPC in a cross-account VBR-to-VPC connection scenario.

  • DescribeEcGrantRelation: Queries the authorization relationship between a VPC instance and a VBR instance in a cross-account VBR-to-VPC connection scenario.