This topic describes how to access an Apsara File Storage NAS file system from a local data center by configuring a VPN gateway.
Background information
You can only mount a file system on an ECS instance that resides in the same region as the file system. For example, an NFS or SMB file system that you create in China (Hangzhou) can only be mounted on an ECS instance that resides in China (Hangzhou). You cannot mount a file system that resides in China (Hangzhou) on a local data center or on an ECS instance that resides in a different region such as China (Qingdao). To resolve these issues, you can establish a connection over an Express Connect circuit. To enable a file system mount on a local data center, you can establish the connection between the data center and the Virtual Private Cloud (VPC) where the file system resides. To enable a cross-region file system mount, you can establish the connection between the VPC where the ECS instance resides and the VPC where the file system resides. However, high costs incur for establishing the connection.
- A server that resides in a local data center
- An ECS instance that resides in a different region different from the region of the
file system
If you have created a VPN gateway on an ECS instance in one VPC, you need to create another VPN gateway in the other VPC. Then, you need to establish a connection between the two VPN gateways. For more information about detailed operations, see Enable a cross-region mount (one VPN gateway available). If no VPN gateway exists in your environment, we recommend that you create VPN gateways in the two VPCs and connect the gateways. For more information about detailed operations, see Enable a cross-region mount (no VPN gateway available).
The following figure shows the topology that is adopted when VPN gateways are used.

- Advantages
- Fixes all connectivity issues.
- Provides secure access by using IPsec to encrypt data in transit.
- Compared with Express Connect, VPN Gateway helps you reduce a large number of costs.
- Disadvantages
The Internet bandwidth and latency between a local data center and a VPC or between VPCs restrict I/O performance of a file system over a VPN connection.
Mount a file system on a server that resides in a local data center
Enable a cross-region mount (one VPN gateway available)
The following example shows a practical scenario of two VPCs named VPC 1 and VPC 2 that reside in different regions.
Enable a cross-region mount (no VPN gateway available)
The following example shows a practical scenario of two VPCs named VPC 1 and VPC 2 that reside in different regions.