All Products
Search
Document Center

Cloud Enterprise Network:CreateTransitRouterCidr

Last Updated:Jun 10, 2026

Blok CIDR Router transit adalah Blok CIDR kustom yang dapat Anda buat untuk Router transit. Blok CIDR ini mirip dengan Blok CIDR yang digunakan untuk menetapkan alamat IP ke antarmuka loopback router. Panggil operasi CreateTransitRouterCidr untuk membuat Blok CIDR untuk Router transit.

Deskripsi operasi

A transit router CIDR block is a custom CIDR block that you can create for a transit router. It is similar to a CIDR block used to assign an IP address to a router's loopback interface. A transit router CIDR block is used to allocate IP addresses to network instance connections. For more information, see Transit router CIDR blocks.

The CreateTransitRouterCidr operation is used to add a CIDR block to a transit router only after the transit router is created.

Before you create a transit router CIDR block, note the following information:

  • Only Enterprise Edition transit routers support CIDR blocks.

  • For more information about the limits on transit router CIDR blocks, see Limits on transit router CIDR blocks.

  • A transit router supports up to five CIDR blocks. The subnet mask of each CIDR block must be 16 to 24 bits in length.

  • You cannot create CIDR blocks that are within 100.64.0.0/10, 224.0.0.0/4, 127.0.0.0/8, or 169.254.0.0/16, or their subnets.

  • Each CIDR block must not conflict with the CIDR blocks of interconnected network instances in the Cloud Enterprise Network (CEN) instance.

  • Each CIDR block must be unique within the same CEN instance.

  • After you add a CIDR block to a transit router and create the first VPN connection on it, the system automatically allocates three CIDR blocks from the specified CIDR block. These three CIDR blocks are reserved by the system for creating VPN connections. The system then allocates IP addresses to IPsec connections from the remaining CIDR blocks.

    You can call the ListTransitRouterCidrAllocation operation to query the CIDR blocks that are reserved by the system or allocated to IPsec connections.

Coba sekarang

Coba API ini di OpenAPI Explorer tanpa perlu penandatanganan manual. Panggilan yang berhasil akan secara otomatis menghasilkan contoh kode SDK sesuai dengan parameter Anda. Unduh kode tersebut dengan kredensial bawaan yang aman untuk penggunaan lokal.

Test

RAM authorization

Tabel berikut menjelaskan otorisasi yang diperlukan untuk memanggil API ini. Anda dapat menentukannya dalam kebijakan Resource Access Management (RAM). Kolom pada tabel dijelaskan sebagai berikut:

  • Action: Aksi yang dapat digunakan dalam elemen Action pada pernyataan kebijakan izin RAM untuk memberikan izin guna melakukan operasi tersebut.

  • API: API yang dapat Anda panggil untuk melakukan aksi tersebut.

  • Access level: Tingkat akses yang telah ditentukan untuk setiap API. Nilai yang valid: create, list, get, update, dan delete.

  • Resource type: Jenis resource yang mendukung otorisasi untuk melakukan aksi tersebut. Ini menunjukkan apakah aksi tersebut mendukung izin tingkat resource. Resource yang ditentukan harus kompatibel dengan aksi tersebut. Jika tidak, kebijakan tersebut tidak akan berlaku.

    • Untuk API dengan izin tingkat resource, jenis resource yang diperlukan ditandai dengan tanda bintang (*). Tentukan Nama Sumber Daya Alibaba Cloud (ARN) yang sesuai dalam elemen Resource pada kebijakan.

    • Untuk API tanpa izin tingkat resource, ditampilkan sebagai All Resources. Gunakan tanda bintang (*) dalam elemen Resource pada kebijakan.

  • Condition key: Kunci kondisi yang didefinisikan oleh layanan. Kunci ini memungkinkan kontrol granular, berlaku baik hanya untuk aksi maupun untuk aksi yang terkait dengan resource tertentu. Selain kunci kondisi spesifik layanan, Alibaba Cloud menyediakan serangkaian common condition keys yang berlaku di semua layanan yang didukung RAM.

  • Dependent action: Aksi dependen yang diperlukan untuk menjalankan aksi tersebut. Untuk menyelesaikan aksi tersebut, pengguna RAM atau role RAM harus memiliki izin untuk melakukan semua aksi dependen.

Action

Access level

Resource type

Condition key

Dependent action

cen:CreateTransitRouterCidr

create

*TransitRouter

acs:cen:*:{#accountId}:centransitrouter/{#centransitrouterId}

None None

Parameter permintaan

Parameter

Type

Required

Description

Example

ClientToken

string

No

Token Klien yang digunakan untuk memastikan idempotensi permintaan.

Buat token di Klien Anda untuk memastikan token tersebut unik di antara permintaan yang berbeda. Token hanya dapat berisi karakter ASCII.

Catatan

Jika Anda tidak menentukan parameter ini, sistem secara otomatis menggunakan ID permintaan sebagai token Klien. ID permintaan berbeda untuk setiap permintaan.

123e4567-e89b-12d3-a456-426****

TransitRouterId

string

Yes

ID Router transit.

tr-p0w3x8c9em72a40nw****

RegionId

string

Yes

ID Wilayah tempat Router transit di-deploy.

Panggil operasi DescribeChildInstanceRegions untuk mengkueri ID Wilayah.

cn-hangzhou

Name

string

No

Nama Blok CIDR Router transit.

Nama dapat kosong atau terdiri dari 1 hingga 128 karakter, dan tidak boleh diawali dengan http:// atau https://.

nametest

Description

string

No

Deskripsi Blok CIDR Router transit.

Deskripsi dapat kosong atau terdiri dari 1 hingga 256 karakter, dan tidak boleh diawali dengan http:// atau https://.

desctest

DryRun

boolean

No

Apakah akan menjalankan dry run. Nilai valid:

  • true: Menjalankan dry run. Sistem memeriksa parameter yang diperlukan, format permintaan, dan batasan layanan. Jika permintaan gagal dalam dry run, Paket kesalahan dikembalikan. Jika permintaan lolos dry run, kode kesalahan DryRunOperation dikembalikan.

  • false (default): Menjalankan dry run lalu mengirim permintaan. Jika permintaan lolos dry run, Blok CIDR Router transit dibuat.

false

Cidr

string

Yes

Blok CIDR Router transit.

192.168.10.0/24

PublishCidrRoute

boolean

No

Apakah akan mengizinkan sistem secara otomatis menambahkan entri rute yang mengarah ke Blok CIDR Router transit ke tabel rute Router transit.

  • true (default): Ya.

    Setelah Anda membuat Koneksi VPN yang menggunakan Gateway VPN privat dan mengaktifkan pembelajaran entri rute untuk Koneksi tersebut, sistem secara otomatis menambahkan entri rute blackhole ke tabel rute Router transit terkait. Tujuan entri rute ini adalah Blok CIDR Router transit. Blok CIDR Router transit adalah Blok CIDR tempat alamat IP gerbang dialokasikan ke Koneksi IPsec. Entri rute blackhole ini diadvertisasi hanya ke tabel rute virtual border router (VBR) yang terhubung ke Router transit.

    Entri rute blackhole yang Blok CIDR tujuannya adalah Blok CIDR Router transit, yang merujuk pada Blok CIDR tempat alamat IP gerbang dialokasikan ke Koneksi IPsec-VPN. Entri rute blackhole diadvertisasi hanya ke tabel rute virtual border router (VBR) yang terhubung ke Router transit.

  • false: Tidak.

true

Elemen respons

Element

Type

Description

Example

object

The response parameters.

TransitRouterCidrId

string

The ID of the transit router CIDR block.

cidr-0zv0q9crqpntzz****

RequestId

string

The request ID.

0876E54E-3E36-5C31-89F0-9EE8A9266F9A

Contoh

Respons sukses

JSONformat

{
  "TransitRouterCidrId": "cidr-0zv0q9crqpntzz****",
  "RequestId": "0876E54E-3E36-5C31-89F0-9EE8A9266F9A"
}

Kode kesalahan

HTTP status code

Error code

Error message

Description

400 OverLappingExist.Cidr The cidr overlapping exist. The error message returned because CIDR overlapping is already enabled.
400 OperationUnsupported.TransitRouterCidr Transit region does not support the operation. The error message returned because this operation is not supported in the specified region.
400 IllegalParam.Cidr The specified cidr is invalid. The error message returned because the specified CIDR block is invalid.
400 IllegalParam.RegionId The specified RegionId is illegal. The error message returned because the specified region is invalid.
400 InstanceNotExist The instance is not exist. The error message returned because the specified instance does not exist.
400 InvalidTransitRouterMode.NeedUpgrade TransitRouter need to upgrade. The error message returned because the specified transit router mode is not supported.
400 IncorrectStatus.TransitRouterInstance The status of TransitRouter is incorrect. The error message returned because the transit router is in an invalid state.
400 InvalidParameter Invalid parameter. The error message returned because the parameter is set to an invalid value.
400 Unauthorized The AccessKeyId is unauthorized. The error message returned because you do not have the permissions to perform this operation.

Lihat Error Codes untuk daftar lengkap.

Catatan rilis

Lihat Release Notes untuk daftar lengkap.