Adds a destination-based route for an IPsec-VPN connection.
Usage notes
- You cannot create a destination-based route whose destination CIDR block is 0.0.0.0/0.
- Do not add a route whose destination CIDR block is 100.64.0.0/10, a subset of 100.64.0.0/10, or a CIDR block that contains 100.64.0.0/10. If such a route is added, the status of the IPsec-VPN connection cannot be displayed in the console or IPsec negotiations fail.
- CreateVcoRouteEntry is an asynchronous operation. After a request is sent, the system returns a request ID and runs the task in the background. You can call the DescribeVpnConnection operation to query the status of the task.
- If the IPsec-VPN connection is in the updating state, the route is being created.
- If the IPsec-VPN connection is in the attached state, the route is created.
- You cannot repeatedly call CreateVcoRouteEntry within a specific time period.
Debugging
Request parameters
Parameter |
Type |
Required |
Example |
Description |
Action | String | Yes | CreateVcoRouteEntry | The operation that you want to perform. Set the value to CreateVcoRouteEntry. |
RegionId | String | Yes | ap-southeast-2 | The region ID of the IPsec-VPN connection. You can call the DescribeRegions operation to query the most recent list of regions. |
VpnConnectionId | String | Yes | vco-p0w2jpkhi2eeop6q6**** | The ID of the IPsec-VPN connection. |
RouteDest | String | Yes | 192.168.10.0/24 | The destination CIDR block of the destination-based route. |
Weight | Integer | Yes | 100 | The weight of the destination-based route. Valid values:
|
NextHop | String | Yes | vco-p0w2jpkhi2eeop6q6**** | The next hop of the destination-based route. |
Description | String | No | desctest | The description of the destination-based route. |
OverlayMode | String | No | Ipsec | The tunneling protocol. Set the value to Ipsec, which specifies the IPsec tunneling protocol. |
ClientToken | String | No | 123e4567-e89b-12d3-a456-4266**** | The client token that is used to ensure the idempotence of the request. You can use the client to generate the token, but you must make sure that the token is unique among different requests. The token can contain only ASCII characters. Note
If you do not specify this parameter, the system automatically uses the request ID as the client token. The request ID may be different for each request. |
Response parameters
Parameter |
Type |
Example |
Description |
VpnConnectionId | String | vco-p0w2jpkhi2eeop6q6**** | The ID of the IPsec-VPN connection. |
RouteDest | String | 192.168.10.0/24 | The destination CIDR block of the destination-based route. |
NextHop | String | vco-p0w2jpkhi2eeop6q6**** | The next hop of the destination-based route. |
Weight | Integer | 100 | The weight of the destination-based route.
|
OverlayMode | String | Ipsec | The tunneling protocol. The value is set to Ipsec, which indicates the IPsec tunneling protocol. |
State | String | published | The status of the destination-based route. Only published is returned, which indicates that the current route is published to the transit router. |
CreateTime | Long | 1658387202664 | The timestamp when the destination-based route was created. Unit: milliseconds. This value is a UNIX timestamp representing the number of milliseconds that have elapsed since the epoch time January 1, 1970, 00:00:00 UTC. |
RequestId | String | CFC4D13B-E680-3985-95B1-87AA155481DF | The request ID. |
Description | String | desctest | The description of the destination-based route. |
Examples
Sample requests
http(s)://[Endpoint]/?Action=CreateVcoRouteEntry
&RegionId=ap-southeast-2
&VpnConnectionId=vco-p0w2jpkhi2eeop6q6****
&RouteDest=192.168.10.0/24
&Weight=100
&NextHop=vco-p0w2jpkhi2eeop6q6****
&Description=desctest
&OverlayMode=Ipsec
&ClientToken=123e4567-e89b-12d3-a456-4266****
&Common request parameters
Sample success responses
XML
format
HTTP/1.1 200 OK
Content-Type:application/xml
<CreateVcoRouteEntryResponse>
<VpnConnectionId>vco-p0w2jpkhi2eeop6q6****</VpnConnectionId>
<RouteDest>192.168.10.0/24</RouteDest>
<NextHop>vco-p0w2jpkhi2eeop6q6****</NextHop>
<Weight>100</Weight>
<OverlayMode>Ipsec</OverlayMode>
<State>published</State>
<CreateTime>1658387202664</CreateTime>
<RequestId>CFC4D13B-E680-3985-95B1-87AA155481DF</RequestId>
<Description>desctest</Description>
</CreateVcoRouteEntryResponse>
JSON
format
HTTP/1.1 200 OK
Content-Type:application/json
{
"VpnConnectionId" : "vco-p0w2jpkhi2eeop6q6****",
"RouteDest" : "192.168.10.0/24",
"NextHop" : "vco-p0w2jpkhi2eeop6q6****",
"Weight" : 100,
"OverlayMode" : "Ipsec",
"State" : "published",
"CreateTime" : 1658387202664,
"RequestId" : "CFC4D13B-E680-3985-95B1-87AA155481DF",
"Description" : "desctest"
}
Error codes
HttpCode |
Error code |
Error message |
Description |
400 | Resource.QuotaFull | The quota of resource is full | The resource quota is exhausted. |
400 | VpnConnection.Configuring | The specified service is configuring. | The operation is not allowed when the specified service is being configured. Try again later. |
400 | VpnConnection.FinancialLocked | The specified service is financial locked. | The service is locked due to overdue payments. |
400 | VpnRouteEntry.AlreadyExists | The specified route entry is already exist. | The route already exists. |
400 | VpnRouteEntry.Conflict | The specified route entry has conflict. | The specified route conflicts with an existing route. |
400 | VpnRouteEntry.ConflictSSL | The specified route entry has conflict with SSL client. | The route conflicts with the SSL client. |
400 | VpnRouteEntry.BackupRoute | Validate backup route entry failed. | Active/standby routes failed authentication. |
400 | InvalidNextHop.NotFound | The specified NextHop does not exist. | The specified next hop does not exist. |
400 | IllegalParam.RouteDest | The specified RouteDest is invalid | The destination address is invalid. |
400 | OperationFailed.InvalidCidrBlock | Operation failed because the specified network block is invalid. | The CIDR block is invalid. |
400 | QuotaExceeded.VpnRouteEntry | The number of route entries to the VPN gateway in the VPC routing table has reached the quota limit. | The number of routes that point to the VPN gateway in the VPC route table reaches the quota. |
400 | TaskConflict | The operation is too frequent, please wait a moment and try again. | Your requests are too frequent. Try again later. |
403 | Forbbiden.SubUser | User not authorized to operate on the specified resource. | You do not have the permissions to manage the resource. |
403 | Forbidden | User not authorized to operate on the specified resource. | You are unauthorized to perform this operation on the specified resource. You can apply for the required permissions and try again. |
404 | InvalidVpnConnectionInstanceId.NotFound | The specified vpn connection instance id does not exist. | The specified IPsec connection does not exist. Check whether the ID of the IPsec connection is valid. |
For a list of error codes, see Service error codes.