All Products
Search
Document Center

NAT Gateway:Use a transit router to share a NAT gateway across multiple VPCs

Last Updated:Sep 21, 2026

You can use a transit router to route traffic from multiple Virtual Private Clouds (VPCs) to the internet through a single Internet NAT gateway. This setup centralizes internet egress and removes the need to create a separate NAT gateway for each VPC.

Background

Cloud Enterprise Network (CEN) is a highly available network built on Alibaba Cloud's private global network. CEN uses a transit router (TR) to establish private communication channels between VPCs in different regions, or between VPCs and on-premises data centers.

A transit router instance is a core forwarding component within a region. It forwards traffic between network instances in the same or different regions and supports flexible routing policies. Within a CEN instance, you can create one transit router instance in each region. You can connect network instances to an Enterprise Edition transit router. After the connection is established, the Enterprise Edition transit router stores the routes of the network instances and forwards traffic by looking up entries in its route table.

For more information, see How a transit router works.

Example scenario

A company has two VPCs, VPC-A and VPC-B, in the China (Chengdu) region. In VPC-A, vSwitch-A1 and vSwitch-A2 are created. An Internet NAT gateway is created in vSwitch-A1 and an ECS instance named ECS1 is created in vSwitch-A2. In VPC-B, vSwitch-B1 and vSwitch-B2 are created, and an ECS instance named ECS2 is created in vSwitch-B1. For business purposes, both VPC-A and VPC-B require internet access.

The company can use a transit router and its route table feature to meet this requirement. By creating an Internet NAT gateway in VPC-A and configuring SNAT entries for the gateway, both VPC-A and VPC-B can access the internet through the shared NAT gateway.

image

Prerequisites

  • You have created the VPCs and vSwitches as described in the following table. For more information, see Create and manage a VPC.

    VPC

    Region

    vSwitch

    Zone and CIDR block

    VPC-A

    China (Chengdu)

    vSwitch-A1

    Chengdu zone A, 192.168.10.0/24

    vSwitch-A2

    Chengdu zone B, 192.168.20.0/24

    VPC-B

    vSwitch-B1

    Chengdu zone A, 172.16.10.0/24

    vSwitch-B2

    Chengdu zone B, 172.16.20.0/24

  • You have created an ECS instance named ECS1 in vSwitch-A2 and an ECS instance named ECS2 in vSwitch-B1. For more information, see Create an instance on the Custom Launch tab.

  • You have created a CEN instance. For more information, see Create a CEN instance.

  • You have created an Enterprise Edition transit router in the region where your VPC is located. For more, see Create transit routers。

Procedure

Step 1: Create an Internet NAT gateway

  1. Log on to the NAT Gateway console.

  2. On the Internet NAT Gateway page, click Create Internet NAT Gateway.

  3. On the NAT Gateway page, configure the following parameters and click Buy Now.

    Parameter

    Description

    Region

    Select the region where you want to create the Internet NAT gateway.

    Network and Zone

    Select the VPC and vSwitch to which the NAT gateway belongs. After the NAT gateway is created, you cannot change the VPC or vSwitch.

    Network Type

    In this example, Internet NAT Gateway is selected.

    • Internet NAT Gateway: provides Network Address Translation capabilities and can be associated with EIPs to allow ECS instances to access the Internet, enabling communication between private and public networks.

    • VPC NAT Gateway: also provides Network Address Translation capabilities but cannot be associated with EIPs. It can only provide address translation within private networks for ECS instances, suitable for scenarios such as hiding internal addresses and avoiding address conflicts.

    EIP

    In this example, Purchase EIP is selected.

    • Select EIP

      EIP: Select an EIP that is not associated with an instance.

    • Purchase EIP: By default, a pay-by-traffic BGP (Multi-ISP) EIP is created. You can select a Maximum Bandwidth based on your business requirements.

      Note
      • If you want to associate an EIP with a different line type or billing method, first Apply for EIPs, and then Select EIP to associate.

      • Each EIP that you associate with a NAT gateway occupies a private IP address of the vSwitch to which the NAT gateway belongs. Make sure that the vSwitch has sufficient available private IP addresses. Otherwise, you cannot associate new EIPs with the NAT gateway.

    • Configure Later: The created NAT gateway will not have Internet access capabilities. You need to manually associate an EIP with the NAT gateway.

    You can find the Internet NAT gateway on the Internet NAT Gateway page.

    image

Step 2: Create VPC connections and configure routes

Create connections for VPC-A and VPC-B to the transit router in the China (Chengdu) region, and then configure routes for the transit router.

  1. Log on to the CEN console, find the CEN instance that you want to manage, and then click its ID.

  2. On the Basic Information page, go to the Transit Router tab, and find the transit router in the destination region. In the Actions column, click Create Connection.

    Create VPC connections for VPC-A and VPC-B.

    Note

    For information about the regions and zones that support Enterprise Edition transit routers, see Transit router editions.

    The following example uses the VPC-A connection. For [CONFIRM-LABEL-2], select vpc-2 | VPC-A. In the vSwitch section, select a vSwitch in each of two zones for disaster recovery:

    • Chengdu Zone B: vsw-2*** | vSwitch-A2

    • Chengdu Zone A: vsw-*** | vSwitch-A1

    In [CONFIRM-LABEL-1], select [CONFIRM-LABEL-3], [CONFIRM-LABEL-4], and [CONFIRM-LABEL-5].

  3. On the Route Table tab, click Add Route Entry.

    Add a route entry for 0.0.0.0/0 and point it to the VPC-A connection to forward IPv4 traffic to VPC-A.

Step 3: Configure the VPC route table

Add a 0.0.0.0/0 route entry to the route table and set the next hop to the transit router to forward IPv4 traffic to it.

  1. Log on to the VPC console.

  2. In the left-side navigation pane, click Route Tables.

  3. On the Route Tables page, find the system route table of VPC-B and click its ID.

  4. On the route table details page, click the Route Entry List > Custom Route tab and then click Add Route Entry.

  5. In the Add Route Entry panel, configure the following parameters and click OK.

    Parameter

    Description

    Name

    Enter a name for the route entry.

    Destination CIDR Block

    Select IPv4 CIDR Block and then enter 0.0.0.0/0.

    Next Hop Type

    Select the instance type for the next hop.

    In this example, select Transit Router.

    Forwarding Router

    Select the VPC-B connection.

    You can view the created route entry that points to the VPC-B connection on the Custom Route tab.

Step 4: Create an SNAT entry

Configure an SNAT entry on the NAT gateway to allow specified resources to access the internet through the associated EIP.

  1. On the Internet NAT Gateway page, find the NAT gateway that you want to manage and click Configure SNAT in the Actions column.

  2. On the SNAT tab, click Create SNAT Entry.

  3. On the Create SNAT Entry page, configure the following parameters and click OK.

    Parameter

    Description

    SNAT Entry

    In this example, VPC Granularity is selected. You can select an SNAT entry granularity based on your business requirements.

    • VPC Granularity: All ECS instances in the VPC, as well as ECS instances in other VPCs or on-premises data centers that are connected through CEN or Express Connect and have a 0.0.0.0/0 route pointing to this VPC, share the same EIP for Internet access.

    • Specify vSwitch: Provides fine-grained control. Only ECS instances in the specified vSwitches can access the Internet through the NAT gateway.

      Note

      If you select multiple vSwitches or ECS instances/ENIs, the system creates multiple SNAT entries that use the same EIP.

    • Specify ECS Instance/ENI: Provides fine-grained control. Only the specified ECS instances or elastic network interfaces (ENIs) can access the Internet through the NAT gateway.

    • Specify Custom CIDR Block: Allows you to flexibly specify any IP CIDR block for Internet access through the NAT gateway. This option covers scenarios such as cross-VPC and cross-IDC network environments.

    Select EIP

    Select one or more EIPs that provide Internet access. In this example, select the EIP that was purchased and associated with the Internet NAT gateway during creation in Step 1.

    Entry Name

    Enter a name for the SNAT entry.

Verify the configuration

  1. Log on to the ECS1 and ECS2 instances by using the Workbench console.

  2. Run the command ping 223.5.5.5.

    A successful ping response shows that the ECS1 and ECS2 instances can access the internet.

    Verification result for ECS1 (IP address: 192.168.20.105):

    [root@xxx ~]# ifconfig
    eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
            inet 192.168.20.105  netmask 255.255.255.0  broadcast 192.168.20.255
            inet6 fe80::216:3eff:fe05:a16b  prefixlen 64  scopeid 0x20<link>
            ether 00:16:3e:05:a1:6b  txqueuelen 1000 (Ethernet)
            RX packets 201827  bytes 292016507 (278.4 MiB)
            RX errors 0  dropped 0  overruns 0  frame 0
            TX packets 24840  bytes 6379164 (6.0 MiB)
            TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
    
    lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
            inet 127.0.0.1  netmask 255.0.0.0
            inet6 ::1  prefixlen 128  scopeid 0x10<host>
            loop  txqueuelen 1000 (Local Loopback)
            RX packets 136  bytes 10888 (10.6 KiB)
            RX errors 0  dropped 0  overruns 0  frame 0
            TX packets 136  bytes 10888 (10.6 KiB)
            TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
    
    [root@xxx ~]# ping 223.5.5.5
    PING 223.5.5.5 (223.5.5.5) 56(84) bytes of data.
    64 bytes from 223.5.5.5: icmp_seq=1 ttl=125 time=4.05 ms
    64 bytes from 223.5.5.5: icmp_seq=2 ttl=125 time=3.61 ms
    64 bytes from 223.5.5.5: icmp_seq=3 ttl=125 time=3.68 ms
    64 bytes from 223.5.5.5: icmp_seq=4 ttl=125 time=3.60 ms
    ^C
    --- 223.5.5.5 ping statistics ---
    4 packets transmitted, 4 received, 0% packet loss, time 3003ms
    rtt min/avg/max/mdev = 3.601/3.732/4.046/0.197 ms

    Verification result for ECS2 (IP address: 172.16.10.30):

    [root@xxx ~]# ifconfig
    eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST>  mtu 1500
            inet 172.16.10.30  netmask 255.255.255.0  broadcast 172.16.10.255
            inet6 fe80::216:3eff:fe05:a187  prefixlen 64  scopeid 0x20<link>
            ether 00:16:3e:05:a1:87  txqueuelen 1000 (Ethernet)
            RX packets 203086  bytes 291677540 (278.1 MiB)
            RX errors 0  dropped 0  overruns 0  frame 0
            TX packets 27542  bytes 6764889 (6.4 MiB)
            TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
    
    lo: flags=73<UP,LOOPBACK,RUNNING>  mtu 65536
            inet 127.0.0.1  netmask 255.0.0.0
            inet6 ::1  prefixlen 128  scopeid 0x10<host>
            loop  txqueuelen 1000 (Local Loopback)
            RX packets 136  bytes 10888 (10.6 KiB)
            RX errors 0  dropped 0  overruns 0  frame 0
            TX packets 136  bytes 10888 (10.6 KiB)
            TX errors 0  dropped 0 overruns 0  carrier 0  collisions 0
    
    [root@xxx ~]# ping 223.5.5.5
    PING 223.5.5.5 (223.5.5.5) 56(84) bytes of data.
    64 bytes from 223.5.5.5: icmp_seq=1 ttl=124 time=3.81 ms
    64 bytes from 223.5.5.5: icmp_seq=2 ttl=124 time=3.55 ms
    64 bytes from 223.5.5.5: icmp_seq=3 ttl=124 time=3.56 ms
    64 bytes from 223.5.5.5: icmp_seq=4 ttl=124 time=3.52 ms
    ^C
    --- 223.5.5.5 ping statistics ---
    4 packets transmitted, 4 received, 0% packet loss, time 3004ms
    rtt min/avg/max/mdev = 3.520/3.609/3.809/0.123 ms