Membuat gerbang NAT Internet enhanced atau gerbang NAT VPC dengan memanggil operasi CreateNatGateway.
Deskripsi operasi
Sebelum memanggil operasi ini, perhatikan informasi berikut:
-
Saat pertama kali membuat gerbang NAT, sistem secara otomatis membuat peran tertaut layanan bernama AliyunServiceRoleForNatgw dan melampirkan kebijakan izin bernama AliyunServiceRolePolicyForNatgw ke peran tersebut untuk memberikan akses gerbang NAT ke sumber daya cloud lainnya. Untuk informasi lebih lanjut, lihat Service-linked roles.
-
Setelah gerbang NAT Internet enhanced dibuat, sistem secara otomatis menambahkan entri rute ke tabel rute VPC. Blok CIDR tujuan entri rute adalah 0.0.0.0/0 dan lompatan berikutnya adalah gerbang NAT. Entri rute digunakan untuk merutekan Trafik ke gerbang NAT.
-
Operasi CreateNatGateway bersifat asinkron. Sistem pertama kali mengembalikan ID instans gerbang NAT (gerbang NAT Internet atau gerbang NAT VPC), tetapi instans gerbang NAT belum dibuat. Tugas pembuatan terus berjalan di latar belakang. Anda dapat memanggil operasi DescribeNatGateways untuk mengkueri status gerbang NAT.
-
Saat gerbang NAT berada dalam status Creating, gerbang NAT sedang dibuat. Dalam status ini, Anda hanya dapat melakukan operasi kueri dan tidak dapat melakukan operasi lainnya.
-
Saat gerbang NAT berada dalam status Available, gerbang NAT telah dibuat.
-
Pembuatan gerbang NAT biasanya memakan waktu 1 hingga 3 menit. Harap tunggu.
Coba sekarang
Test
RAM authorization
Parameter permintaan
|
Parameter |
Type |
Required |
Description |
Example |
| RegionId |
string |
Yes |
ID wilayah tempat gerbang NAT diterapkan. Anda dapat memanggil operasi DescribeRegions untuk mengkueri ID wilayah. |
cn-hangzhou |
| VpcId |
string |
Yes |
ID VPC tempat Anda ingin membuat gerbang NAT. |
vpc-bp1di7uewzmtvfuq8**** |
| Name |
string |
No |
Nama gerbang NAT. Panjang nama harus 2 hingga 128 karakter, dan dapat berisi angka, garis bawah (_), dan tanda hubung (-). Nama harus diawali dengan huruf atau karakter Tionghoa. Jika parameter ini tidak ditentukan, sistem akan membuat nama default untuk gerbang NAT. |
fortest |
| Description |
string |
No |
Deskripsi gerbang NAT. Deskripsi dapat kosong, atau memiliki panjang 2 hingga 256 karakter. Deskripsi tidak dapat diawali dengan |
testnat |
| ClientToken |
string |
No |
Token klien yang digunakan untuk memastikan idempotensi permintaan. Anda dapat menggunakan klien untuk menghasilkan nilai ini, tetapi Anda harus memastikan nilainya unik di antara permintaan yang berbeda. Catatan
Jika Anda tidak menentukan parameter ini, sistem secara otomatis menggunakan RequestId dari permintaan API sebagai ClientToken. Nilai RequestId mungkin berbeda untuk setiap permintaan API. |
5A2CFF0E-5718-45B5-9D4D-70B3FF3898 |
| Spec |
string |
No |
Gerbang NAT Internet berlangganan tidak lagi tersedia untuk dibeli. Parameter ini tidak lagi digunakan. |
无效参数 |
| InstanceChargeType |
string |
No |
Metode penagihan gerbang NAT. Nilai valid: PostPaid (default): pay-as-you-go. Untuk informasi lebih lanjut, lihat Billing of Internet NAT gateways dan Billing of VPC NAT gateways. |
PostPaid |
| PricingCycle |
string |
No |
Gerbang NAT Internet berlangganan tidak lagi tersedia untuk dibeli. Parameter ini tidak lagi digunakan. |
无效参数 |
| Duration |
string |
No |
Gerbang NAT Internet berlangganan tidak lagi tersedia untuk dibeli. Parameter ini tidak lagi digunakan. |
无效参数 |
| AutoPay |
boolean |
No |
Gerbang NAT Internet berlangganan tidak lagi tersedia untuk dibeli. Parameter ini tidak lagi digunakan. |
无效参数 |
| VSwitchId |
string |
No |
ID vSwitch tempat gerbang NAT berada. Saat membuat gerbang NAT, Anda harus menentukan vSwitch tempat gerbang NAT berada. Sistem menetapkan alamat IP privat yang tidak terpakai di dalam vSwitch ke gerbang NAT.
Catatan
Anda dapat memanggil operasi ListEnhanhcedNatGatewayAvailableZones untuk mengkueri zona yang mendukung gerbang NAT, dan memanggil operasi DescribeVSwitches untuk mengkueri jumlah alamat IP yang tersedia di vSwitch. |
vsw-bp1e3se98n9fq8hle**** |
| NatType |
string |
No |
Tipe gerbang NAT. Nilai valid: Enhanced, yang menunjukkan gerbang NAT enhanced. |
Enhanced |
| InternetChargeType |
string |
No |
Metode penagihan gerbang NAT. Nilai valid: PayByLcu, yang menunjukkan metode pengukuran pay-by-LCU. |
PayByLcu |
| NetworkType |
string |
No |
Tipe gerbang NAT yang akan dibuat. Nilai valid:
|
internet |
SecurityProtectionEnabled
deprecated
|
boolean |
No |
Apakah akan mengaktifkan fitur firewall. Nilai valid:
|
false |
| IcmpReplyEnabled |
boolean |
No |
Apakah akan mengaktifkan fitur balasan ICMP. Nilai valid:
|
true |
| PrivateLinkEnabled |
boolean |
No |
Apakah akan mengaktifkan PrivateLink. Nilai valid:
|
false |
| EipBindMode |
string |
No |
Mode pengikatan EIP gerbang NAT. Nilai valid:
|
MULTI_BINDED |
| Tag |
array<object> |
No |
Daftar tag. |
MULTI_BINDED |
|
object |
No |
|||
| Key |
string |
No |
Kunci tag. Gunakan Tag.N.Key dalam panggilan API, di mana N berkisar dari 1 hingga 20. Setelah ditentukan, nilai tidak boleh berupa string kosong. Panjang kunci tag dapat mencapai 128 karakter, tidak dapat diawali dengan aliyun atau acs:, dan tidak dapat mengandung http:// atau https://. |
TestKey |
| Value |
string |
No |
Nilai tag. Gunakan Tag.N.Value dalam panggilan API, di mana N berkisar dari 1 hingga 20. Setelah ditentukan, nilai tidak boleh berupa string kosong. Panjang nilai tag dapat mencapai 128 karakter, tidak dapat diawali dengan aliyun atau acs:, dan tidak dapat mengandung http:// atau https://. |
TestValue |
| AccessMode |
object |
No |
Mode akses untuk akses terbalik ke gerbang NAT VPC. |
MULTI_BINDED |
| ModeValue |
string |
No |
Mode akses. Nilai valid:
Catatan
Saat bidang ini memiliki nilai, PrivateLinkEnabled harus diatur ke true. |
route |
| TunnelType |
string |
No |
Tipe mode saluran data:
Catatan
Nilai ini valid saat mode akses adalah mode saluran data. |
geneve |
| NatIp |
string |
No |
Alamat IP privat yang ditempati oleh gerbang NAT. Gunakan alamat IP yang belum dialokasikan di Blok CIDR vSwitch tempat gerbang NAT berada. Jika parameter ini dikosongkan, sistem akan mengalokasikan alamat IP secara acak. |
192.168.0.2 |
| Ipv4Prefix |
string |
No |
Blok CIDR awalan IP yang digunakan untuk membuat alamat IP NAT secara massal. Gunakan Blok CIDR cadangan yang belum dialokasikan dari vSwitch tempat gerbang NAT berada. |
192.168.0.0/28 |
| AvailabilityMode |
string |
No |
Elemen respons
|
Element |
Type |
Description |
Example |
|
object |
Struktur data yang dikembalikan. |
||
| NatGatewayId |
string |
ID instans gerbang NAT yang dibuat. |
ngw-112za33e4**** |
| RequestId |
string |
ID permintaan. |
2315DEB7-5E92-423A-91F7-4C1EC9AD97C3 |
| ForwardTableIds |
object |
||
| ForwardTableId |
array |
Daftar tabel DNAT. |
|
|
string |
Daftar tabel DNAT. |
ftb-11tc6xgmv**** |
|
| SnatTableIds |
object |
||
| SnatTableId |
array |
Daftar tabel SNAT. |
|
|
string |
Daftar tabel SNAT. |
stb-SnatTableIds**** |
|
| FullNatTableIds |
object |
||
| FullNatTableId |
array |
Daftar tabel FULLNAT. |
|
|
string |
Daftar tabel FULLNAT. |
fulltb-gw88z7hhlv43rmb26**** |
Contoh
Respons sukses
JSONformat
{
"NatGatewayId": "ngw-112za33e4****",
"RequestId": "2315DEB7-5E92-423A-91F7-4C1EC9AD97C3",
"ForwardTableIds": {
"ForwardTableId": [
"ftb-11tc6xgmv****"
]
},
"SnatTableIds": {
"SnatTableId": [
"stb-SnatTableIds****"
]
},
"FullNatTableIds": {
"FullNatTableId": [
"fulltb-gw88z7hhlv43rmb26****"
]
}
}
Kode kesalahan
|
HTTP status code |
Error code |
Error message |
Description |
|---|---|---|---|
| 400 | Forbidden.NatPayBySpec | Pay-by-specification NAT is no longer supported. Newly purchased pay-as-you-go NAT gateways only support the pay-by-CU metering method. | |
| 400 | DependencyViolation.FullNatEntry | The specified resource of %s depends on %s, so the operation cannot be completed. | |
| 400 | UnsupportedFeature.InternetChargeType | The feature of InternetChargeType is not supported. | |
| 400 | InvalidVPCStatus | vpc incorrect status. | |
| 400 | InvalidNatGatewayName.MalFormed | NatGateway name is not valid. | |
| 400 | InvalidNatGatewayDescription.MalFormed | NatGateway description is not valid. | |
| 400 | MissingParameter.BandwidthPackage | only support one BandwidthPackage be created with NatGateway. | |
| 400 | OperationDenied | The user cannot allow to create natgw, please call PD to authorize | |
| 400 | RouterEntryConflict.Duplicated | A route entry already exists, which CIDR is '0.0.0.0/0' | |
| 400 | MissingParameter | Miss mandatory parameter. | |
| 400 | QuotaExceeded.BandwidthPackageIps | The specified ipCount exceeded quota. | |
| 400 | AllocateIpFailed | Alloc bandwidthPackage ips failed, maybe no available ip. | |
| 400 | InvalidParameter.Name.Malformed | The specified Name is not valid. | |
| 400 | InvalidParameter.Description.Malformed | The specified Description is not valid. | |
| 400 | ZONE_NO_AVAILABLE_IP | The Zone have no available ip. | |
| 400 | ParameterIllegal | ipCount,bandwidth parameter invalid | |
| 400 | InvalidParameter.BandwidthPackage.n.ISP.ValueNotSupport | The specified ISP of BandwidthPackage is not valid. | |
| 400 | InvalidNatGatewayId.NotFound | The NatGatewayId not exist. | |
| 400 | VpcStatusError | The Vpc is creating . | |
| 400 | InvalidParameter.Spec.ValueNotSupported | The specified Spec is not valid. | |
| 400 | TaskConflict | The operation is too frequent, TaskConflict. | |
| 400 | COMMODITY.INVALID_COMPONENT | The instance component is invalid. | |
| 400 | CreateNatGateway.RouteConflict.DynamicRoute | Route conflict exists in routing table. | |
| 400 | OperationUnsupported.MultiNatGateway | More than one natGateway per vpc is unsupported. | |
| 400 | Forbidden.CheckEntryRuleQuota | Route entry quota rule check error. | |
| 400 | OperationFailed.UnpaidBillsExist | The account has unpaid bills. Please pay your overdue bill first. | |
| 400 | IncorrectStatus.RouteEntry | Specified routeEntry status error. | |
| 400 | OperationFailed.RiskControl | Risk control check failed. | |
| 400 | OperationFailed.TokenVerfiy | Token verify failed. | |
| 400 | IllegalParam.Name | The specified Name is invalid, shorter than 2 characters. | |
| 400 | OperationFailed.EnhancedQuotaExceed | Enhanced nat gateway per vpc quota is exceeded | |
| 400 | NoPermission.CreateServiceLinkedRole | You are not authorized to create service linked role | |
| 400 | OperationFailed.EnhancedInventoryNotEnough | Operation failed because inventory is not enough. | |
| 400 | OperationFailed.VswNotBelongToVpc | Operation failed because the specified VSwitch is not bound to the same VPC with NAT gateway. | |
| 400 | OperationFailed.EnhancedUserIsUnAuthorized | Operation failed because the user is not authorized to create an enhanced NAT gateway. | |
| 400 | OperationUnsupported.PrePaidPyByLcu | The operation failed because the subscription NAT gateway does not support the pay-by-LCU billing method. | |
| 400 | OperationFailed.NormalInventoryNotEnough | Standard NAT gateways are no longer offered. You can create enhanced NAT gateways and set the correct natType. | |
| 400 | OperationFailed.VSwitchNoAvailableIp | Operation failed because the specified vswitch does not have availabe ip. | |
| 400 | UnsupportedFeature.IcmpReplyEnabled | The feature of IcmpReplyEnabled is not supported. | |
| 400 | UnsupportedFeature.SecurityProtectionEnabled | The feature of SecurityProtectionEnabled is not supported. | |
| 400 | OperationFailed.RegionConvert | Operation failed because do not find region info. | |
| 400 | UnsupportedFeature.VpcNat | The feature of VpcNat is not supported. | |
| 400 | InvalidVSWITCHID.NotFound | The specified resource of %s is not found. | |
| 400 | Forbidden.OperateShareResource | Operate share resource is forbidden. | |
| 400 | IncorrectStatus.VSWITCH | The status of VSWITCH is incorrect. | |
| 400 | OperationFailed.VpcNatGatewayInventoryNotEnough | The operation is failed because of inventory is not enough. | |
| 400 | OperationFailed.VpcNatGatewayCheckInventory | The operation is failed because of check inventory result is unexpected | |
| 400 | ExclusiveParam.%sAnd%s | The param of %s and %s are mutually exclusive. | |
| 400 | SecurityGroupType.NotSupported | The specified security group type is not supported. | |
| 400 | SecurityGroup.NotExist | The specified security group is not exist. | |
| 400 | OperationFailed.ContainForbiddenLabel | There is a label that prohibits ordering, please contact your distributor for processing. | |
| 400 | OperationDenied.PrePaidInstance | The operation is not allowed because prepaid instance is no longer supported. | |
| 400 | UnsupportedFeature.Geneve | The feature of Geneve is not supported. | |
| 400 | OperationFailed.NoAvailableResource | The Zone have no available resource. | |
| 400 | ExclusiveParam.AccessModeValueAndAccessTunnelType | The specified param AccessModeValue and AccessTunnelType are mutually exclusive. | |
| 400 | ExclusiveParam.PrivateLinkModeAndAccessMode | The specified param PrivateLinkMode and AccessMode are mutually exclusive. | |
| 400 | ExclusiveParam.PrivateLinkEnabledAndAccessMode | The specified paramPrivateLinkEnabled and AccessMode are mutually exclusive. | |
| 400 | UnsupportedFeature.AccessModeValue | The feature of AccessMode.ModeValue(%s) is not supported. | |
| 400 | IllegalParam.AccessTunnelType | The request parameter AccessMode.TunnelType is illegal. | |
| 400 | IllegalParam.AccessModeValue | The request parameter AccessMode.ModeValue is illegal. | |
| 400 | OperationFailed.VSwitchStatusError | The vSwitch is creating . | |
| 400 | UnsupportedFeature.PrivateLinkMode | The feature of %s is not supported. | |
| 400 | OperationFailed.EcsNetworkInterfaceQuotaNotSatisfy | ECS network interface quota is not satisfy. | |
| 400 | OperationFailed.NoNameAuthentication | You have not passed the real name authentication and do not meet the purchase conditions. Please log in to the user center for real-name authentication. | |
| 400 | Mismatch.NatIpAndNatIpCidr | The %s and %s are mismatched. | |
| 400 | Mismatch.Ipv4PrefixAndNatIpCidr | The %s and %s are mismatched. | |
| 400 | ResourceAlreadyExist.NatIp | The specified resource of NatIp has already exist. | |
| 400 | Mismatch.Ipv4PrefixAndCidrReservations | The %s and %s are mismatched. | |
| 400 | ResourceAlreadyAssociated.Ipv4Prefix | %s is already associated. | |
| 400 | ResourceNotEnough.Ipv4Prefix | The resource of %s is not enough. | |
| 400 | ResourceNotFound.Ipv4Prefix | The resource of s% is not found. | |
| 400 | ResourceAlreadyAssociated.NatIp | The resource of %s was already associated. | |
| 400 | ResourceNotEnough.NatIp | The specified resource of NatIp is not enough. | |
| 400 | ResourceNotFound.NatIp | The specified resource of %s is not found. | |
| 400 | IllegalParam.Ipv4Prefix | The param of %s is illegal, must be /28 network segment. | |
| 400 | IllegalParam.NatIp | The param of %s is illegal. | |
| 400 | OperationUnsupported.EnhancedRegion | Region not support. | |
| 400 | IncorrectStatus.RouteTableStatus | The route table status is invaild. Please try again later. | |
| 400 | OperationUnsupported.User | The current user does not support this operation. | |
| 400 | OperationUnsupported.EnhancedCURegion | Operation failed because of this region not unsupported. | |
| 400 | OrderError.NoAvailablePaymentMethod | Order payment parameter is not available. | |
| 400 | OrderError.BasicInfoUncompleted | Order basic parameter is not completed. | |
| 400 | OperationUnsupported.Region | Operation unsupport this region parameter. | |
| 400 | InvalidParameter.SingleZone | Operation failed because current user not support create single zone nat. | |
| 500 | OrderError.NatGateway | The Account failed to create order. | |
| 500 | OperationFailed.AccessTunnelId | AccessTunnelId param do operation failed. | |
| 500 | OperationFailed.EnhancedCheckInventory | The NAT gateway in the current zone is not in service, or the resource inventory is insufficient. | |
| 404 | InvalidRegionId.NotFound | The specified RegionId does not exist in our records. | |
| 404 | InvalidVpcId.NotFound | Specified value of VpcId is not found in our record. | |
| 404 | InvalidZoneId.NotFound | Specified value of ZoneId is not exists. | |
| 404 | VPC_ONLY_CAN_CREATE_ONE_NAT_GATEWAY | NatGateway in one vpc support only one. | |
| 404 | OperationFailed.CrateEntryTimeOut | Operation failed because create custom routeEntry timeout. | |
| 404 | Forbidden.CreateSpecialSpecNatGateway | You are not authorized to create special spec nat gateway. | |
| 404 | UnsupportedZoneForFwNat | The zone is unsupported for FW NAT. |
Lihat Error Codes untuk daftar lengkap.
Catatan rilis
Lihat Release Notes untuk daftar lengkap.