All Products
Search
Document Center

Elastic Desktop Service:Connect to on-premises networks via virtual private line

Last Updated:Aug 27, 2026

EDS virtual private line is a lightweight, low-cost solution that connects your cloud computers' office network to your on-premises network with minimal configuration.

Capabilities

Virtual private line provides bidirectional connectivity between cloud computers and your on-premises network. Access databases, NAS, OA systems, and network printers through private encrypted tunnels — no changes to existing network architecture. Use cases: hybrid cloud offices, cross-region collaboration, and isolated access to sensitive data. Build a low-cost, high-availability hybrid network.

Key advantages

Advantage

Description

Security and compliance

Encrypts data through private tunnels to prevent public internet exposure. Supports source IP tracing for enterprise data compliance.

Cost optimization

Eliminates the need for Express Connect circuits. Activate an EDS bandwidth plan to enable the feature.

Quick configuration

Set up in under 15 minutes through the console and your device once your on-premises device is ready.

Traffic control

Routes traffic through global return or split tunneling based on IP CIDR blocks, domains, or applications.

High availability

Bind multiple on-premises devices in the same network environment for active-active disaster recovery and load balancing.

Configure a virtual private line

Prerequisites

Limitations

Virtual private line throughput is limited by:

  • Downloads to cloud computer: limited by the lesser of the office network's downstream bandwidth and the on-premises network's upstream bandwidth.

  • Downloads to on-premises network: limited by the lesser of the office network's upstream bandwidth and the on-premises network's downstream bandwidth.

Procedure

  1. Activate the virtual private line and configure split tunneling rules.

    1. Log on to the EDS enterprise console.

    2. In the left-side navigation pane, choose Networks & Storage > Office Network.

    3. In the top navigation bar, select a region.

    4. On the Office Network page, click the office network ID of the target office network.

    5. On the details page of the office network, in the Network Information section, find the Virtual Private Line section and click Enable Now.

    6. On the Enable Virtual Private Line page, in the On-premises Network Device section, click Generate Binding Code, and then click Copy. Save the code for later use.

      Note
      • Use this code to bind your on-premises device to the virtual private line.

      • The binding code expires after one hour. If it expires, generate a new one.

    7. In the Configure Bypass Rule section, turn on the Bypass Rule switch and configure the Bypass Mode.

      Split tunneling mode

      Description

      Global return

      All cloud computer traffic routes through the tunnel to your on-premises device for forwarding.

      Whitelist return (multiple selections allowed)

      IP CIDR block

      • Routes traffic to specified destination IP ranges (IPv4 or IPv6) through the virtual private line.

      • Example: 10.0.0.1/24

      Domain

      • Routes requests for specified domains through the virtual private line via DNS resolution. Three matching patterns:

      • Examples:

        • Full match: aliyun.com

        • String match: aliyun

        • Wildcard match: *.aliyun.com

      Application

      • Routes traffic by transport protocol (TCP/UDP) and port, or by application-layer protocol signature.

      • Example: explorer.exe

    8. Click OK.

  1. Configure your on-premises device and bind it to the Premium office network:

    Device model

    Configuration guide

    iKuai AL88 series

    Virtual Private Line Device-side Configuration Guide (EDS x iKuai)

    Panabit AL88 series

    Virtual Private Line Device-side Configuration Guide (EDS x Panabit)

Manage on-premises network devices

Device information

  1. Log on to the EDS enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage > Office Network.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, click the office network ID of the target office network.

  5. On the details page of the office network, in the Network Information section, find the Virtual Private Line section and click Edit.

  6. On the Edit Virtual Private Line page, view device ID, brand and model, status, binding time, and remarks.

Delete a device

  1. Log on to the EDS enterprise console.

  2. In the left-side navigation pane, choose Networks & Storage > Office Network.

  3. In the top navigation bar, select a region.

  4. On the Office Network page, click the office network ID of the target office network.

  5. On the details page of the office network, in the Network Information section, find the Virtual Private Line section and click Edit.

  6. In the On-premises Network Device section, find the device that you want to delete and click Delete in the Actions column.

  7. In the confirmation dialog box, click OK.