EDS virtual private line is a lightweight, low-cost solution that connects your cloud computers' office network to your on-premises network with minimal configuration.
Capabilities
Virtual private line provides bidirectional connectivity between cloud computers and your on-premises network. Access databases, NAS, OA systems, and network printers through private encrypted tunnels — no changes to existing network architecture. Use cases: hybrid cloud offices, cross-region collaboration, and isolated access to sensitive data. Build a low-cost, high-availability hybrid network.
Key advantages
|
Advantage |
Description |
|
Security and compliance |
Encrypts data through private tunnels to prevent public internet exposure. Supports source IP tracing for enterprise data compliance. |
|
Cost optimization |
Eliminates the need for Express Connect circuits. Activate an EDS bandwidth plan to enable the feature. |
|
Quick configuration |
Set up in under 15 minutes through the console and your device once your on-premises device is ready. |
|
Traffic control |
Routes traffic through global return or split tunneling based on IP CIDR blocks, domains, or applications. |
|
High availability |
Bind multiple on-premises devices in the same network environment for active-active disaster recovery and load balancing. |
Configure a virtual private line
Prerequisites
-
Your on-premises network device and environment are ready per the configuration guide.
-
You have a Premium office network. Basic office networks do not support virtual private line. Deploy an office network (formerly workspace).
Limitations
Virtual private line throughput is limited by:
-
Downloads to cloud computer: limited by the lesser of the office network's downstream bandwidth and the on-premises network's upstream bandwidth.
-
Downloads to on-premises network: limited by the lesser of the office network's upstream bandwidth and the on-premises network's downstream bandwidth.
Procedure
-
Activate the virtual private line and configure split tunneling rules.
-
Log on to the EDS enterprise console.
-
In the left-side navigation pane, choose Networks & Storage > Office Network.
-
In the top navigation bar, select a region.
-
On the Office Network page, click the office network ID of the target office network.
-
On the details page of the office network, in the Network Information section, find the Virtual Private Line section and click Enable Now.
-
On the Enable Virtual Private Line page, in the On-premises Network Device section, click Generate Binding Code, and then click Copy. Save the code for later use.
Note-
Use this code to bind your on-premises device to the virtual private line.
-
The binding code expires after one hour. If it expires, generate a new one.
-
-
In the Configure Bypass Rule section, turn on the Bypass Rule switch and configure the Bypass Mode.
Split tunneling mode
Description
Global return
All cloud computer traffic routes through the tunnel to your on-premises device for forwarding.
Whitelist return (multiple selections allowed)
IP CIDR block
-
Routes traffic to specified destination IP ranges (IPv4 or IPv6) through the virtual private line.
-
Example:
10.0.0.1/24
Domain
-
Routes requests for specified domains through the virtual private line via DNS resolution. Three matching patterns:
-
Examples:
-
Full match:
aliyun.com -
String match:
aliyun -
Wildcard match:
*.aliyun.com
-
Application
-
Routes traffic by transport protocol (TCP/UDP) and port, or by application-layer protocol signature.
-
Example:
explorer.exe
-
-
Click OK.
-
-
Configure your on-premises device and bind it to the Premium office network:
Device model
Configuration guide
iKuai AL88 series
Virtual Private Line Device-side Configuration Guide (EDS x iKuai)
Panabit AL88 series
Virtual Private Line Device-side Configuration Guide (EDS x Panabit)