All Products
Search
Document Center

NAT Gateway:Create VPC peering connections to enable multiple VPCs to use the same Internet NAT gateway

Last Updated:Aug 28, 2026

This tutorial shows how to use virtual private cloud (VPC) peering connections to share a single Internet NAT gateway across multiple VPCs, so all connected VPCs can access the internet without deploying a separate NAT gateway in each VPC.

Why share a NAT gateway

Deploying an Internet NAT gateway in every VPC that needs internet access adds cost and operational overhead that scales with the number of VPCs. By connecting VPCs through peering connections and routing their outbound traffic through one centralized NAT gateway, you pay for a single gateway and manage a single set of elastic IP address (EIP) associations. The billable components of this architecture are:

  • The Internet NAT gateway (per hour)

  • EIP associations on the NAT gateway

  • Data transfer through the VPC peering connections

How it works

A VPC peering connection is a private network connection between two VPCs. Traffic between peered VPCs travels over the Alibaba Cloud backbone and does not traverse the public internet.

To share a NAT gateway across VPCs:

  1. Create an Internet NAT gateway in the hub VPC (the VPC that owns the NAT gateway).

  2. Create a VPC peering connection between the hub VPC and each spoke VPC.

  3. Add route entries so spoke VPCs forward their outbound traffic to the hub VPC through the peering connection.

  4. Create SNAT entries on the NAT gateway to cover the CIDR blocks of both the hub VPC and each spoke VPC.

To connect more than two VPCs, create a separate peering connection between each pair. For example, to connect VPC1, VPC2, and VPC3, create three peering connections: VPC1–VPC2, VPC2–VPC3, and VPC1–VPC3.

Example scenario

A company has two VPCs in the China (Chengdu) region:

  • VPC-A — the hub VPC. Contains vSwitch-A1 (where the NAT gateway is deployed) and vSwitch-A2 (where ECS-A runs).

  • VPC-B — the spoke VPC. Contains vSwitch-B1 (where ECS-B runs). CIDR block: 172.16.0.0/16.

Both ECS-A and ECS-B need to access the internet. The solution: peer VPC-A and VPC-B, configure routes, and create SNAT entries on the NAT gateway in VPC-A.

image

Prerequisites

Before you begin, make sure you have:

  • Two VPCs in the same region (this example uses China (Chengdu))

  • ECS instances in each VPC that need internet access

  • Sufficient permissions to create NAT gateways, VPC peering connections, route entries, and SNAT entries

Step 1: Create an Internet NAT gateway

Go to the NAT Gateway - Internet NAT Gateway purchase page and configure the following parameters.

  • Billing Method: Pay-as-you-go.

  • Region: Select the region where you want to create the Internet NAT gateway.

  • Network and Zone: Select the VPC and vSwitch for the Internet NAT gateway. The selected vSwitch is used to assign a private IP address to the NAT gateway. Associating an EIP consumes one private IP address from this vSwitch. You cannot change these settings after the gateway is created.

  • Disaster Recovery: Select a disaster recovery mode for the NAT gateway.

    • Cross-zone disaster recovery (Default): Deploys the gateway in a primary and a secondary zone. If the primary zone fails, traffic automatically fails over to the secondary zone.

    • Single-zone disaster recovery: Deploys the gateway within the selected zone, with high availability ensured through device-level redundancy. The instance fee is 50% of the cross-zone mode, and the CU fee is 80%.

  • EIP: Select an option based on whether you have an existing EIP.

    • Select EIP: Select an EIP that is not associated with an instance.

    • Purchase EIP: Select this option if you do not have an available EIP. By default, a pay-by-traffic BGP (Multi-ISP) EIP is created. You can set the Maximum Bandwidth based on your business requirements.

      To associate a BGP (Multi-ISP)_Premium EIP or an EIP with a different billing method, first apply for an EIP, and then select Select EIP during creation.
    • Configure Later: The NAT gateway is created without Internet access.

      After the NAT gateway is created, find the target instance and click Associate Now in the EIP column. You can then select an existing EIP or purchase and associate a new one.

Step 2: Create a VPC peering connection

  1. Log on to the VPC console.

  2. In the left-side navigation pane, click VPC Peering Connection.

  3. In the top navigation bar, select the region. In this example, select China (Chengdu).

  4. On the VpcPeer page, click Create VPC Peering Connection.

  5. Configure the following parameters and click OK.

    Parameter

    Description

    Name

    Enter a name for the connection.

    Resource Group

    Select a resource group.

    Requester VPC

    Select the hub VPC. In this example, select VPC-A.

    Accepter account type

    Select Same-Account if both VPCs belong to the same Alibaba Cloud account.

    Accepter region type

    Select Intra-Region if both VPCs are in the same region.

    Accepter VPC

    Select the spoke VPC. In this example, select VPC-B.

  6. On the VpcPeer page, confirm the connection status is Activated. Once activated, you can view the VPC ID, region, CIDR block, and owner account for both the requester VPC and the accepter VPC.

Step 3: Configure routes

Add route entries to both VPCs so traffic flows correctly through the peering connection.

Expected route table state after this step:

VPC

Destination

Next hop

VPC-A (requester)

172.16.0.0/16 (VPC-B CIDR)

VPC peering connection

VPC-B (accepter)

0.0.0.0/0

VPC peering connection

The route in VPC-A sends traffic destined for VPC-B across the peering connection. The route in VPC-B sends all outbound traffic (including internet-bound traffic) to VPC-A, where the NAT gateway handles the translation.

Configure routes for VPC-A (requester):

  1. On the VPC Peering Connection page, find the peering connection you created.

  2. In the Requester VPC column, click Configure route.

  3. In the Configure route dialog, set the following and click OK.

    Parameter

    Value

    VPC

    Automatically filled with VPC-A.

    Requester route table

    Select a route table associated with VPC-A.

    Name

    Enter a name for the route entry.

    Destination CIDR Block

    Select IPv4 CIDR and enter 172.16.0.0/16 (VPC-B's CIDR block).

    Next Hop

    Automatically filled with the VPC peering connection.

Configure routes for VPC-B (accepter):

  1. In the Accepter column, click Configure route.

  2. In the Configure route dialog, set the following and click OK.

    Parameter

    Value

    VPC

    Automatically filled with VPC-B.

    Accepter route table

    Select a route table associated with VPC-B.

    Name

    Enter a name for the route entry.

    Destination CIDR Block

    Select IPv4 CIDR and enter 0.0.0.0/0 to forward all IPv4 traffic to VPC-A through the peering connection.

    Next Hop

    Automatically filled with the VPC peering connection.

Important

After you add a 0.0.0.0/0 route that points to the peering connection, all outbound internet traffic from VPC-B is forwarded to VPC-A. If the NAT gateway in VPC-A does not yet have an SNAT entry that covers VPC-B's CIDR block, instances in VPC-B will lose internet access. If VPC-B is already running workloads that depend on internet connectivity, we recommend that you complete Step 4 first to make sure the SNAT configuration is correct, and then add this default route.

To verify the routes were added, click the peering connection ID and check the Route Entry List tab.

Step 4: Create an SNAT entry

Create an SNAT entry for each vSwitch that contains instances needing internet access — including vSwitches in VPC-B, because VPC-B's traffic arrives at the NAT gateway in VPC-A and must be covered by an SNAT rule.

  1. On the Internet NAT Gateway page, find your NAT gateway and click Configure SNAT in the Actions column.

  2. On the SNAT Management tab, click Create SNAT Entry.

  3. Configure the following parameters and click OK.

    Parameter

    Description

    SNAT Entry

    Select Specify vSwitch, then choose the vSwitch whose instances need internet access. The CIDR block of the selected vSwitch is displayed automatically. To cover multiple vSwitches, select them all — the system creates one SNAT entry per vSwitch, all using the same EIP.

    Select EIP

    Select Use Single IP and choose the EIP associated with the NAT gateway.

    Entry Name

    Enter a name for the SNAT entry.

Verify the configuration

Verify that both instances can reach the internet.

  1. Log on to ECS-A and ECS-B through the Workbench console.

  2. Run the following command on each instance.

    ping 223.5.5.5

    A successful ping confirms that the instance can access the internet through the NAT gateway.

image

What's next

  • To connect additional VPCs to the same NAT gateway, repeat steps 2 through 4 for each new VPC: create a peering connection, configure routes in both VPCs, and add SNAT entries for the new VPC's vSwitches.

  • To learn more about VPC peering connections, see VPC peering connections.