An Express Connect Router (ECR) provides high-performance, high-capacity, and low-latency connections between a Virtual Private Cloud and a data center.
Limitations
When you add a virtual border router (VBR) to an ECR, the ASN of the VBR's BGP group must match the ECR's ASN. If the ASN of your ECR is not 45104, associate the VBR with the ECR before you configure BGP settings for the VBR.
You cannot add a VBR that does not support MPBGP to an ECR. To check if your VBR supports MPBGP, go to its details page and find Advanced features of ports: in the Basic Information section.
Prerequisites
You have created a virtual border router (VBR) instance.
If you plan to associate a VPC with the ECR, ensure that you have created the required Virtual Private Cloud (VPC).
NoteA VPC can receive dynamic routes from only one source at a time. If the VPC is already associated with a transit router (TR) and has route synchronization enabled, you cannot associate the VPC with an ECR. For more information, see the description of dynamic routes in the route table topic.
If you plan to associate a transit router (TR) instance with the ECR, ensure that you have created the required transit router (TR) instance.
Create an ECR
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click Create ECR.
In the Create ECR dialog box, set the parameters, select I have read and understand the billing rules, and then click OK.
Parameter
Description
Name
Enter a name for the ECR.
ASN
Enter an ASN. The value can be 45104 (default), a number from 64512 to 65534, or a number from 4200000000 to 4294967294. 65025 is reserved by Alibaba Cloud.
Resource Group
Select the resource group to which the ECR belongs.
Description
Enter a description for the ECR.
Associate a VBR
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.
On the VBR tab, click Associate VBR.
In the Associate VBR dialog box, set the following parameters and click OK.
Parameter
Description
Resource Owner
The account that owns the VBR. Valid values:
Current Account.
Another Account: To add a VBR from another Alibaba Cloud account, the VBR's owner must first authorize your ECR to access it. For more information, see Authorize a VBR instance in another account.
Region
Select the region where the VBR resource is deployed.
Peer Account UID
Enter the UID of the peer Alibaba Cloud account.
NoteThis parameter is required when Resource Owner is set to Another Account.
Network Instance
Select the target VBR instance.
Allow Business Access Between Data Centers
Select whether to allow traffic between data centers.
NoteThis feature is disabled by default. To enable it, contact your Alibaba Cloud account manager.
Associate a VPC
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.
On the VPC tab, click Associate VPC.
In the Associate VPC dialog box, set the following parameters and click OK.
Parameter
Description
Resource Owner
The account that owns the VPC. Valid values:
Current Account.
Another Account: To associate a VPC from another Alibaba Cloud account, the VPC's owner must first authorize your ECR to access it. For more information, see Authorize a VPC instance in another account.
Region
Select the region where the target VPC is deployed.
Peer Account UID
Enter the UID of the peer Alibaba Cloud account.
NoteThis parameter is required when Resource Owner is set to Another Account.
VPC ID
Select the ID of the target VPC.
Allowed Route Prefixes
Enter the route prefixes that you want to advertise from the ECR to the data center. You can select Matching Mode or Incremental Mode to configure the route prefixes.
NoteAn ECR supports both IPv4 and IPv6 route prefixes.
When you configure route prefixes, you can select or switch between the following modes:
Matching Mode: Express Connect advertises the configured route prefixes to the data center and withdraws the specific routes that have been advertised.
Incremental Mode: Express Connect withdraws advertised specific routes that fall within the configured route prefixes. Specific routes outside this range remain advertised.
Switching from Matching Mode to Incremental Mode: Express Connect re-advertises the specific routes that are outside the range of the route prefixes to the data center. The configured route prefixes remain advertised.
Switching from Incremental Mode to Matching Mode: Express Connect withdraws the specific routes that have been advertised to the data center and are outside the range of the route prefixes. The configured route prefixes remain advertised.
If you do not configure any route prefixes or clear all existing route prefixes, Express Connect automatically advertises specific routes to the data center.
If your ECR is currently advertising only one route prefix and you modify it, Alibaba Cloud temporarily reverts to advertising specific routes to ensure service stability. After the modified prefix is successfully advertised, the system reverts to advertising only the configured prefix. Pay close attention to how the advertisement of specific routes affects your on-premises network.
Associate a TR
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.
On the TR tab, click Associate TR.
In the Associate TR dialog box, set the following parameters and click OK.
Parameter
Description
CEN ID
Select the CEN instance that contains the target transit router.
Region
Select the region where the target transit router is deployed.
TR
Select the target transit router instance.
Allowed Route Prefixes
Enter the route prefixes that you want to advertise from the ECR to the data center. You can select Matching Mode or Incremental Mode to configure the route prefixes.
NoteAn ECR supports both IPv4 and IPv6 route prefixes.
When you configure route prefixes, you can select or switch between the following modes:
Matching Mode: Express Connect advertises the configured route prefixes to the data center and withdraws the specific routes that have been advertised.
Incremental Mode: Express Connect withdraws advertised specific routes that fall within the configured route prefixes. Specific routes outside this range remain advertised.
Switching from Matching Mode to Incremental Mode: Express Connect re-advertises the specific routes that are outside the range of the route prefixes to the data center. The configured route prefixes remain advertised.
Switching from Incremental Mode to Matching Mode: Express Connect withdraws the specific routes that have been advertised to the data center and are outside the range of the route prefixes. The configured route prefixes remain advertised.
If you do not configure any route prefixes or clear all existing route prefixes, Express Connect automatically advertises specific routes to the data center.
If your ECR is currently advertising only one route prefix and you modify it, Alibaba Cloud temporarily reverts to advertising specific routes to ensure service stability. After the modified prefix is successfully advertised, the system reverts to advertising only the configured prefix. Pay close attention to how the advertisement of specific routes affects your on-premises network.
Advanced Configurations
The system selects the following advanced settings by default. To change them, click Modify to go to the TR console and modify the configuration.
Associate with Default Route Table of Transit Router
If this feature is enabled, the ECR connection is automatically associated with the default route table of the transit router. The transit router uses this route table to forward traffic from the ECR.
Propagate System Routes to Default Route Table of Transit Router
If this feature is enabled, the ECR propagates the BGP routes that it learns from the VBR to the default route table of the transit router. This allows the network instances to communicate with each other.
Advertise Routes to ECR
If this feature is enabled, the TR automatically advertises routes to the ECR.
CEN authorization
If you grant permissions to an account, that account can attach your on-premises network instances to its Cloud Enterprise Network (CEN) instance. This connects their network to yours. Proceed with caution.
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.
On the CEN Authorization tab, click Authorize CEN of Another Account to Load Instance.
In the Join CEN dialog box, set the following parameters and click OK.
Parameter
Description
CEN Instance ID
Enter the ID of the peer CEN instance.
CEN Account
Enter the UID of the Alibaba Cloud account that owns the CEN instance.
Payer
Select which account pays for the cross-account connection. Valid values:
CEN Owner.
ECR Owner.
Disable and enable a route entry
You can disable a route entry to prevent it from taking effect. It can be re-enabled later.
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance.
On the Routes tab, find the target route entry. In the Actions column, click Disable or Enable. In the dialog box that appears, click OK.
Delete an ECR
Log on to the Express Connect Console.
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to delete and click Delete in the Actions column.
Other operations
In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click the target ECR instance. You can then perform the following operations as needed.
Actions | Procedure |
Disassociate a VBR instance | Note To disassociate a VBR that is part of a failover group, you must first disable the failover group. In the Failover Group ID column, set the status to Disabled. This action deletes the failover group. You can then disassociate the VBR instance.
|
Disassociate a TR instance |
|
Disassociate a VPC instance |
|
View and manage route entries |
|
Delete a CEN authorization |
|