You can use a transit router to route traffic from multiple Virtual Private Clouds (VPCs) to the internet through a single Internet NAT gateway. This setup centralizes internet egress and removes the need to create a separate NAT gateway for each VPC.
Background
Cloud Enterprise Network (CEN) is a highly available network built on Alibaba Cloud's private global network. CEN uses a transit router (TR) to establish private communication channels between VPCs in different regions, or between VPCs and on-premises data centers.
A transit router instance is a core forwarding component within a region. It forwards traffic between network instances in the same or different regions and supports flexible routing policies. Within a CEN instance, you can create one transit router instance in each region. You can connect network instances to an Enterprise Edition transit router. After the connection is established, the Enterprise Edition transit router stores the routes of the network instances and forwards traffic by looking up entries in its route table.
For more information, see How a transit router works.
Example scenario
A company has two VPCs, VPC-A and VPC-B, in the China (Chengdu) region. In VPC-A, vSwitch-A1 and vSwitch-A2 are created. An Internet NAT gateway is created in vSwitch-A1 and an ECS instance named ECS1 is created in vSwitch-A2. In VPC-B, vSwitch-B1 and vSwitch-B2 are created, and an ECS instance named ECS2 is created in vSwitch-B1. For business purposes, both VPC-A and VPC-B require internet access.
The company can use a transit router and its route table feature to meet this requirement. By creating an Internet NAT gateway in VPC-A and configuring SNAT entries for the gateway, both VPC-A and VPC-B can access the internet through the shared NAT gateway.
Prerequisites
You have created the VPCs and vSwitches as described in the following table. For more information, see Create and manage a VPC.
VPC
Region
vSwitch
Zone and CIDR block
VPC-A
China (Chengdu)
vSwitch-A1
Chengdu zone A, 192.168.10.0/24
vSwitch-A2
Chengdu zone B, 192.168.20.0/24
VPC-B
vSwitch-B1
Chengdu zone A, 172.16.10.0/24
vSwitch-B2
Chengdu zone B, 172.16.20.0/24
You have created an ECS instance named ECS1 in vSwitch-A2 and an ECS instance named ECS2 in vSwitch-B1. For more information, see Create an instance on the Custom Launch tab.
You have created a CEN instance. For more information, see Create a CEN instance.
You have created an Enterprise Edition transit router in the region where your VPC is located. For more, see Create transit routers。
Procedure
Step 1: Create an Internet NAT gateway
Log on to the NAT Gateway console.
On the Internet NAT Gateway page, click Create Internet NAT Gateway.
On the NAT Gateway page, configure the following parameters and click Buy Now.
Parameter
Description
Region
Select the region where you want to create the Internet NAT gateway.
Network and Zone
Select the VPC and vSwitch to which the NAT gateway belongs. After the NAT gateway is created, you cannot change the VPC or vSwitch.
Network Type
In this example, Internet NAT Gateway is selected.
Internet NAT Gateway: provides Network Address Translation capabilities and can be associated with EIPs to allow ECS instances to access the Internet, enabling communication between private and public networks.
VPC NAT Gateway: also provides Network Address Translation capabilities but cannot be associated with EIPs. It can only provide address translation within private networks for ECS instances, suitable for scenarios such as hiding internal addresses and avoiding address conflicts.
EIP
In this example, Purchase EIP is selected.
Select EIP
EIP: Select an EIP that is not associated with an instance.
Purchase EIP: By default, a pay-by-traffic BGP (Multi-ISP) EIP is created. You can select a Maximum Bandwidth based on your business requirements.
NoteIf you want to associate an EIP with a different line type or billing method, first Apply for EIPs, and then Select EIP to associate.
Each EIP that you associate with a NAT gateway occupies a private IP address of the vSwitch to which the NAT gateway belongs. Make sure that the vSwitch has sufficient available private IP addresses. Otherwise, you cannot associate new EIPs with the NAT gateway.
Configure Later: The created NAT gateway will not have Internet access capabilities. You need to manually associate an EIP with the NAT gateway.
You can find the Internet NAT gateway on the Internet NAT Gateway page.

Step 2: Create VPC connections and configure routes
Create connections for VPC-A and VPC-B to the transit router in the China (Chengdu) region, and then configure routes for the transit router.
Log on to the CEN console, find the CEN instance that you want to manage, and then click its ID.
On the Basic Information page, go to the tab, and find the transit router in the destination region. In the Actions column, click Create Connection.
Create VPC connections for VPC-A and VPC-B.
NoteFor information about the regions and zones that support Enterprise Edition transit routers, see Transit router editions.
The following example uses the VPC-A connection. For [CONFIRM-LABEL-2], select vpc-2 | VPC-A. In the vSwitch section, select a vSwitch in each of two zones for disaster recovery:
Chengdu Zone B: vsw-2*** | vSwitch-A2
Chengdu Zone A: vsw-*** | vSwitch-A1
In [CONFIRM-LABEL-1], select [CONFIRM-LABEL-3], [CONFIRM-LABEL-4], and [CONFIRM-LABEL-5].
On the Route Table tab, click Add Route Entry.
Add a route entry for 0.0.0.0/0 and point it to the VPC-A connection to forward IPv4 traffic to VPC-A.
Step 3: Configure the VPC route table
Add a 0.0.0.0/0 route entry to the route table and set the next hop to the transit router to forward IPv4 traffic to it.
Log on to the VPC console.
In the left-side navigation pane, click Route Tables.
On the Route Tables page, find the system route table of VPC-B and click its ID.
On the route table details page, click the tab and then click Add Route Entry.
In the Add Route Entry panel, configure the following parameters and click OK.
Parameter
Description
Name
Enter a name for the route entry.
Destination CIDR Block
Select IPv4 CIDR Block and then enter 0.0.0.0/0.
Next Hop Type
Select the instance type for the next hop.
In this example, select Transit Router.
Forwarding Router
Select the VPC-B connection.
You can view the created route entry that points to the VPC-B connection on the Custom Route tab.
Step 4: Create an SNAT entry
Configure an SNAT entry on the NAT gateway to allow specified resources to access the internet through the associated EIP.
On the Internet NAT Gateway page, find the NAT gateway that you want to manage and click Configure SNAT in the Actions column.
On the SNAT tab, click Create SNAT Entry.
On the Create SNAT Entry page, configure the following parameters and click OK.
Parameter
Description
SNAT Entry
In this example, VPC Granularity is selected. You can select an SNAT entry granularity based on your business requirements.
VPC Granularity: All ECS instances in the VPC, as well as ECS instances in other VPCs or on-premises data centers that are connected through CEN or Express Connect and have a 0.0.0.0/0 route pointing to this VPC, share the same EIP for Internet access.
Specify vSwitch: Provides fine-grained control. Only ECS instances in the specified vSwitches can access the Internet through the NAT gateway.
NoteIf you select multiple vSwitches or ECS instances/ENIs, the system creates multiple SNAT entries that use the same EIP.
Specify ECS Instance/ENI: Provides fine-grained control. Only the specified ECS instances or elastic network interfaces (ENIs) can access the Internet through the NAT gateway.
Specify Custom CIDR Block: Allows you to flexibly specify any IP CIDR block for Internet access through the NAT gateway. This option covers scenarios such as cross-VPC and cross-IDC network environments.
Select EIP
Select one or more EIPs that provide Internet access. In this example, select the EIP that was purchased and associated with the Internet NAT gateway during creation in Step 1.
Entry Name
Enter a name for the SNAT entry.
Verify the configuration
Log on to the ECS1 and ECS2 instances by using the Workbench console.
Run the command
ping 223.5.5.5.A successful ping response shows that the ECS1 and ECS2 instances can access the internet.
Verification result for ECS1 (IP address: 192.168.20.105):
[root@xxx ~]# ifconfig eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 192.168.20.105 netmask 255.255.255.0 broadcast 192.168.20.255 inet6 fe80::216:3eff:fe05:a16b prefixlen 64 scopeid 0x20<link> ether 00:16:3e:05:a1:6b txqueuelen 1000 (Ethernet) RX packets 201827 bytes 292016507 (278.4 MiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 24840 bytes 6379164 (6.0 MiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 127.0.0.1 netmask 255.0.0.0 inet6 ::1 prefixlen 128 scopeid 0x10<host> loop txqueuelen 1000 (Local Loopback) RX packets 136 bytes 10888 (10.6 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 136 bytes 10888 (10.6 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 [root@xxx ~]# ping 223.5.5.5 PING 223.5.5.5 (223.5.5.5) 56(84) bytes of data. 64 bytes from 223.5.5.5: icmp_seq=1 ttl=125 time=4.05 ms 64 bytes from 223.5.5.5: icmp_seq=2 ttl=125 time=3.61 ms 64 bytes from 223.5.5.5: icmp_seq=3 ttl=125 time=3.68 ms 64 bytes from 223.5.5.5: icmp_seq=4 ttl=125 time=3.60 ms ^C --- 223.5.5.5 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time 3003ms rtt min/avg/max/mdev = 3.601/3.732/4.046/0.197 msVerification result for ECS2 (IP address: 172.16.10.30):
[root@xxx ~]# ifconfig eth0: flags=4163<UP,BROADCAST,RUNNING,MULTICAST> mtu 1500 inet 172.16.10.30 netmask 255.255.255.0 broadcast 172.16.10.255 inet6 fe80::216:3eff:fe05:a187 prefixlen 64 scopeid 0x20<link> ether 00:16:3e:05:a1:87 txqueuelen 1000 (Ethernet) RX packets 203086 bytes 291677540 (278.1 MiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 27542 bytes 6764889 (6.4 MiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 lo: flags=73<UP,LOOPBACK,RUNNING> mtu 65536 inet 127.0.0.1 netmask 255.0.0.0 inet6 ::1 prefixlen 128 scopeid 0x10<host> loop txqueuelen 1000 (Local Loopback) RX packets 136 bytes 10888 (10.6 KiB) RX errors 0 dropped 0 overruns 0 frame 0 TX packets 136 bytes 10888 (10.6 KiB) TX errors 0 dropped 0 overruns 0 carrier 0 collisions 0 [root@xxx ~]# ping 223.5.5.5 PING 223.5.5.5 (223.5.5.5) 56(84) bytes of data. 64 bytes from 223.5.5.5: icmp_seq=1 ttl=124 time=3.81 ms 64 bytes from 223.5.5.5: icmp_seq=2 ttl=124 time=3.55 ms 64 bytes from 223.5.5.5: icmp_seq=3 ttl=124 time=3.56 ms 64 bytes from 223.5.5.5: icmp_seq=4 ttl=124 time=3.52 ms ^C --- 223.5.5.5 ping statistics --- 4 packets transmitted, 4 received, 0% packet loss, time 3004ms rtt min/avg/max/mdev = 3.520/3.609/3.809/0.123 ms