All Products
Search
Document Center

Secure Access Service Edge:Use other Alibaba Cloud network instances

Last Updated:Jul 17, 2026

If your business resources are deployed outside Alibaba Cloud and you already use an Alibaba Cloud Virtual Border Router (VBR), Cloud Connect Network (CCN), or VPN Gateway, you can use a SASE gateway to connect your on-premises network to those resources, allowing users to access them as internal resources.

Manage multi-account resources

To manage connector resources in a member account, first add the account. After the account is added, the SASE Network Settings > Services Outside Alibaba Cloud tab displays all VBR, IPsec-VPN, and Smart Access Gateway (SAG) resources from the management account and any added member accounts. If no member accounts are added, only resources from the management account are displayed. For more information, see multi-account management.

Network connection diagram

Enable network connection

Step 1: Synchronize cloud network instances

SASE automatically synchronizes your cloud network instances. The following table describes the fields displayed after synchronization:

Parameter

Description

Connector Type

SASE supports three types of connectors: Virtual Border Router (VBR), Cloud Connect Network (CCN), and VPN Gateway.

Instance ID/Name

The ID of the connector instance, such as a VBR, VPN Gateway, or CCN instance.

Owner Account

The account that owns the connector, either the management account or a member account.

Network Channel

The network channel used by the connector.

For VBR, the network channel is Leased Line; for CCN, the network channel is SAG; and for VPN Gateway, the network channel is IPsec-VPN.

Internal CIDR Block

The internal CIDR block of your on-premises network or the vSwitch CIDR block of your VPC.

  • For the SAG and IPsec-VPN channels, SASE can automatically retrieve the internal CIDR block. No action is required.

  • For the Leased Line channel, SASE cannot automatically retrieve the internal CIDR block. You must enter it manually.

Separate multiple CIDR blocks with a comma (,).

Step 2: Configure a back-to-origin VPC

A back-to-origin VPC is a VPC that is already connected to your on-premises network through a SAG instance, an IPsec-VPN connection, or a Leased Line. SASE routes traffic through this VPC back to your on-premises resources.

  • For an IPsec-VPN (VPN Gateway) connector, the back-to-origin VPC is fixed because only one VPC can be connected to the on-premises network.

  • For a VBR connector, you must manually set the back-to-origin address in the Back-to-origin VPC column.

  • For a CCN connector, click Select Back-to-origin VPC in the Operation column to configure the back-to-origin VPC.

    Note

    Although all VPCs within a CCN instance can technically connect to the on-premises network, you may have routing or security policies that restrict access. Select only the VPC permitted to reach the on-premises network.

Step 3: Enable network connection

On the Cloud Network Instance tab, find the target instance and turn on the Network Connection switch. This allows SASE users to access Services Outside Alibaba Cloud.

Disable network connection

If you no longer need a network channel, turn off its Network Connection switch.

Important

Turning off the Network Connection switch for a VBR, IPsec-VPN, or SAG connector will prevent users from accessing internal applications through the SASE App. Proceed with caution.

Next steps

After you enable network connection, configure which office applications users can access. For more information, see Configure an office application and Configure a zero trust policy.

Related documents