You can use IPsec-VPN to establish secure and reliable connections between data centers or office networks and virtual private clouds (VPCs) on Alibaba Cloud. You can associate IPsec-VPN connections with VPN gateways and transit routers. This topic describes the common scenarios in which IPsec-VPN connections are associated with transit routers.

Common scenarios of public IPsec-VPN connections

Connect a data center to VPCs

After you associate an IPsec-VPN connection with a transit router, the data center can communicate with all VPCs that are connected to the transit router.

Connect a data center to VPCs

Establish multiple IPsec-VPN connections between a data center and VPCs to implement equal-cost multi-path (ECMP) routing

You can associate multiple IPsec-VPN connections with a transit router. You can connect a data center to VPCs through multiple IPsec-VPN connections to implement load balancing.

Connect a data center to VPCs through multiple IPsec-VPN connections

Connect multiple office networks

If an enterprise has multiple offices in different regions, and the offices are connected to Alibaba Cloud by using IPsec-VPN or other methods, the offices can communicate with each other by using transit routers.

Connect multiple offices

Common scenarios of private IPsec-VPN connections

Encrypt private connections over Express Connect circuits

You can use IPsec-VPN to encrypt a private connection over an Express Connect circuit between a data center and a VPC. This ensures network security.

Common scenarios of private IPsec-VPN connections