Calls the CreateVcoRouteEntry operation to add a destination route entry to an IPsec-VPN connection.
Operation description
The IPsec-VPN connection must be associated with a transit router instance. For more information, see CreateTransitRouterVpnAttachment.
You cannot add a destination route with a destination CIDR block of 0.0.0.0/0.
Do not add a destination route with a destination CIDR block of 100.64.0.0/10, a subnet of 100.64.0.0/10, or a CIDR block that contains 100.64.0.0/10. Such route entries cause the console to fail to display the status of the IPsec-VPN connection or cause IPsec-VPN negotiation to fail.
- The CreateVcoRouteEntry operation is asynchronous. After you send a request, the system returns an instance ID, but the destination route entry has not been created. The creation task is still running in the background. You can call DescribeVpnConnection to query the creation status of the destination route entry:
If the IPsec-VPN connection is in the updating state, the destination route entry is being created.
If the IPsec-VPN connection is in the attached state, the destination route entry is created.
The CreateVcoRouteEntry operation does not support concurrent creation of destination route entries for the same IPsec-VPN connection.
Try it now
Test
RAM authorization
|
Action |
Access level |
Resource type |
Condition key |
Dependent action |
|
vpc:CreateVcoRouteEntry |
create |
*VpnConnections
|
None | None |
Request parameters
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
The region ID of the IPsec-VPN connection. You can call the DescribeRegions operation to query the region ID. |
cn-hangzhou |
| VpnConnectionId |
string |
Yes |
The ID of the IPsec-VPN connection. |
vco-p0w2jpkhi2eeop6q6**** |
| RouteDest |
string |
Yes |
The destination CIDR block of the destination route entry. |
192.168.10.0/24 |
| Weight |
integer |
Yes |
The weight of the destination route entry. Valid values:
|
100 |
| NextHop |
string |
Yes |
The next hop of the destination route entry. |
vco-p0w2jpkhi2eeop6q6**** |
| Description |
string |
No |
The description of the destination route entry. |
desctest |
| OverlayMode |
string |
No |
The tunneling protocol. Set the value to Ipsec (default), which specifies the IPsec tunnel protocol. |
Ipsec |
| ClientToken |
string |
No |
The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The client token can contain only ASCII characters. Note
If you do not specify this parameter, the system automatically uses the RequestId of the API request as the ClientToken. The RequestId may be different for each API request. |
123e4567-e89b-12d3-a456-4266**** |
| DryRun |
boolean |
No |
Specifies whether to perform a dry run. Valid values:
|
false |
Response elements
|
Element |
Type |
Description |
Example |
|
object |
The response parameters. |
||
| VpnConnectionId |
string |
The ID of the IPsec-VPN connection. |
vco-p0w2jpkhi2eeop6q6**** |
| RouteDest |
string |
The destination CIDR block of the destination route entry. |
192.168.10.0/24 |
| NextHop |
string |
The next hop of the destination route entry. |
vco-p0w2jpkhi2eeop6q6**** |
| Weight |
integer |
The weight of the destination route entry.
|
100 |
| OverlayMode |
string |
The tunneling protocol. The value is Ipsec, which specifies the IPsec tunnel protocol. |
Ipsec |
| State |
string |
The publish status of the destination route entry. The value is published, which indicates that the route entry is published to the transit router instance. |
published |
| CreateTime |
integer |
The timestamp when the destination route entry was created. Unit: milliseconds. The timestamp follows the UNIX timestamp format, which represents the number of milliseconds that have elapsed since January 1, 1970, 00:00:00 UTC. |
1658387202664 |
| RequestId |
string |
The request ID. |
CFC4D13B-E680-3985-95B1-87AA155481DF |
| Description |
string |
The description of the destination route entry. |
desctest |
Examples
Success response
JSON format
{
"VpnConnectionId": "vco-p0w2jpkhi2eeop6q6****",
"RouteDest": "192.168.10.0/24",
"NextHop": "vco-p0w2jpkhi2eeop6q6****",
"Weight": 100,
"OverlayMode": "Ipsec",
"State": "published",
"CreateTime": 1658387202664,
"RequestId": "CFC4D13B-E680-3985-95B1-87AA155481DF",
"Description": "desctest"
}
Error codes
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | Resource.QuotaFull | The quota of resource is full | |
| 400 | VpnConnection.Configuring | The specified service is configuring. | The service is being configured. Try again later. |
| 400 | VpnConnection.FinancialLocked | The specified service is financial locked. | The error message returned because the service is locked due to overdue payments. |
| 400 | VpnRouteEntry.AlreadyExists | The specified route entry is already exist. | The route already exists. |
| 400 | VpnRouteEntry.Conflict | The specified route entry has conflict. | Route conflicts exist. |
| 400 | VpnRouteEntry.ConflictSSL | The specified route entry has conflict with SSL client. | The route conflicts with the SSL client. |
| 400 | VpnRouteEntry.BackupRoute | Validate backup route entry failed. | Active/standby routes failed authentication. |
| 400 | InvalidNextHop.NotFound | The specified NextHop does not exist. | The specified next hop does not exist. |
| 400 | IllegalParam.RouteDest | The specified RouteDest is invalid | The destination address is invalid. |
| 400 | OperationFailed.InvalidCidrBlock | Operation failed because the specified network block is invalid. | The CIDR block is invalid. |
| 400 | QuotaExceeded.VpnRouteEntry | The number of route entries to the VPN gateway in the VPC routing table has reached the quota limit. | The number of route entries to the VPN gateway in the VPC routing table has reached the quota limit. |
| 400 | TaskConflict | The operation is too frequent, please wait a moment and try again. | Your requests are too frequent. Try again later. |
| 400 | Resource.PbrRouteQuotaFull | The quota of Policy-based route is full. | Policy routing quota exceeded |
| 400 | CreatePbrRoutesQuotaFull.QuotaFull | The number of policy routes exceeds the quota limit. | The number of policy routes exceeds the quota limit. |
| 400 | CreateDbrRoutesQuotaFull.QuotaFull | The number of created destination routes exceeds the quota limit. | The number of created destination routes exceeds the quota limit. |
| 400 | DryRunOperation | Request validation has been passed with DryRun flag set. | The request passed the dry run. |
| 403 | Forbbiden.SubUser | User not authorized to operate on the specified resource. | The error message returned because you do not have the permissions to manage the resource. |
| 403 | Forbidden | User not authorized to operate on the specified resource. | You do not have the permissions to manage the specified resource. Apply for the permissions and try again. |
| 404 | InvalidVpnConnectionInstanceId.NotFound | The specified vpn connection instance id does not exist. | The specified vpn connection instance id does not exist. |
See Error Codes for a complete list.
Release notes
See Release Notes for a complete list.