Todos os produtos
Search
Central de documentação

VPN Gateway:IPsec-VPN e CEN: Rede global de alta velocidade

Última atualização: Sep 16, 2026

Este artigo descreve como usar o IPsec-VPN (uma conexão IPsec em uma instância de VPN Gateway) e o CEN (Cloud Enterprise Network) para construir uma rede empresarial global de alta qualidade e custo-benefício. Essa solução permite a comunicação any-to-any entre data centers on-premises (IDCs) e VPCs em várias regiões.

Cenário

Nota
  • Se sua conta Alibaba Cloud não tiver uma instância pública de VPN Gateway, recomendamos associar as conexões IPsec-VPN a um Transit Router para obter conectividade global any-to-any.

  • Caso já possua uma instância pública de VPN Gateway, este tópico explica como alcançar a conectividade global any-to-any usando conexões IPsec-VPN associadas ao gateway.

Uma empresa implanta múltiplos data centers e VPCs ao redor do mundo. Após conectar os data centers às VPCs por meio de conexões IPsec-VPN associadas a instâncias de VPN Gateway, cada data center comunica-se apenas com sua VPC associada. Por padrão, VPCs e data centers em regiões diferentes não se comunicam entre si. Nesse cenário, a conectividade dos sites ocorre da seguinte forma:

image
  • A VPC1 e a VPC2 não conseguem se comunicar entre si.

  • O data center 1 comunica-se com a VPC1 e também com o data center 2, pois ambos estão conectados à mesma instância de VPN Gateway via conexão IPsec-VPN. No entanto, o data center 1 não consegue se comunicar com o data center 3, data center 4 ou VPC2.

  • O data center 2 comunica-se com a VPC1 e com o data center 1, já que ambos compartilham a mesma instância de VPN Gateway através de uma conexão IPsec-VPN. Contudo, o data center 2 não estabelece comunicação com o data center 3, data center 4 ou VPC2.

  • O data center 3 tem conectividade com a VPC2 e com o data center 4, uma vez que ambos utilizam a mesma instância de VPN Gateway via conexão IPsec-VPN. Entretanto, não há comunicação entre o data center 3 e o data center 1, data center 2 ou VPC1.

  • O data center 4 conecta-se à VPC2 e ao data center 3 devido à conexão compartilhada na mesma instância de VPN Gateway. Porém, ele não consegue trocar tráfego com o data center 1, data center 2 ou VPC1.

Para ative a comunicação any-to-any em todos os seus sites globais, use o CEN. O CEN estabelece conexões privadas de alta qualidade e baixa latência entre VPCs, além de suportar propagação e aprendizado automático de rotas. Isso simplifica as configurações de roteamento e agiliza a conectividade de VPCs em diferentes regiões. Tal arquitetura interliga data centers de diversas regiões por meio das VPCs interconectadas, criando uma rede global totalmente integrada.

image
Importante

Recomendamos o uso de roteamento estático ao estabelecer conexões IPsec-VPN entre data centers e instâncias de VPN Gateway.

Cenário de exemplo

Este exemplo demonstra como combinar IPsec-VPN e CEN para permitir comunicação any-to-any entre sites globais. Uma empresa multinacional possui dois data centers na região China (Shanghai) e dois na região US (Silicon Valley). A empresa também dispõe da VPC1 na região China (Shanghai) e da VPC2 na região US (Silicon Valley), com aplicações implantadas em instâncias ecs em ambas as VPCs. Com a expansão dos negócios, surge a necessidade de conectividade entre os seis sites: data center 1 e data center 2 em China (Shanghai), data center 3 e data center 4 em US (Silicon Valley), além da VPC1 e VPC2.

image

Planejamento de blocos CIDR

Importante

Ao planejar seus blocos CIDR, garanta que não haja sobreposição entre os sites que precisam se comunicar.

VPC

Nome da VPC

Região da VPC

Bloco CIDR da VPC

Endereço IP da ecs

VPC1

China (Shanghai)

  • Bloco CIDR da VPC: 192.168.0.0/16

  • Bloco CIDR do vSwitch 1: 192.168.99.0/24, na zona E

  • Bloco CIDR do vSwitch 2: 192.168.100.0/24, na zona F

Endereço IP da ecs1: 192.168.99.48

VPC2

US (Silicon Valley)

  • Bloco CIDR da VPC: 10.0.0.0/16

  • Bloco CIDR do vSwitch 1: 10.0.10.0/24, na zona A

  • Bloco CIDR do vSwitch 2: 10.0.20.0/24, na zona B

Endereço IP da ecs2: 10.0.10.33

Data center on-premises

Nome do data center

Região do data center

Bloco CIDR on-premises

IP público do gateway

Endereço IP do cliente

Data center 1

China (Shanghai)

172.16.10.0/24

  • IP público 1: 47.XX.XX.23

  • IP público 2: 47.XX.XX.32

172.16.10.207

Data center 2

China (Shanghai)

172.16.40.0/24

  • IP público 1: 47.XX.XX.69

  • IP público 2: 47.XX.XX.71

172.16.40.60

Data center 3

US (Silicon Valley)

10.10.10.0/24

  • IP público 1: 57.XX.XX.11

  • IP público 2: 57.XX.XX.191

10.10.10.201

Data center 4

US (Silicon Valley)

10.30.66.0/24

  • IP público 1: 57.XX.XX.22

  • IP público 2: 57.XX.XX.234

10.30.66.11

Antes de começar

  • crie a VPC1 na região China (Shanghai) e a VPC2 na região US (Silicon Valley), implantando serviços em instâncias ecs em ambas as VPCs. Para mais informações, consulte Create a VPC with an IPv4 CIDR block.

  • crie uma instância pública de VPN Gateway nas regiões China (Shanghai) e US (Silicon Valley) e ative o recurso IPsec-VPN em ambas. Para mais informações, consulte Enable IPsec-VPN.

    Nota

    Este tópico utiliza instâncias de VPN Gateway que suportam conexões IPsec-VPN em modo dual-tunnel. Caso sua instância suporte apenas o modo single-tunnel, recomendamos atualizá-la. Conexões IPsec-VPN em modo dual-tunnel oferecem recuperação de desastres no nível de zona de disponibilidade. Para mais informações, consulte Upgrade an IPsec-VPN connection to dual-tunnel mode.

    A tabela abaixo lista informações sobre as instâncias de VPN Gateway, suas instâncias de VPC associadas e os endereços IP alocados pelo sistema. Você precisará dos endereços IP das instâncias de VPN Gateway para crie as conexões IPsec-VPN.

    Nome da instância

    Região

    Gateway Type

    Tipo de rede

    Tunnels

    Instância de VPC associada

    Endereços IP

    VPN Gateway 1

    China (Shanghai)

    Standard

    Public

    Dual-tunnel

    VPC1

    • Endereço IPsec 1: 47.XX.XX.87

    • Endereço IPsec 2: 47.XX.XX.78

    VPN Gateway 2

    US (Silicon Valley)

    Standard

    Public

    Dual-tunnel

    VPC2

    • Endereço IPsec 1: 47.XX.XX.207

    • Endereço IPsec 2: 47.XX.XX.15

Procedimento

Etapa 1: Criar customer gateways

crie customer gateways para registrar os endereços IP públicos dos seus dispositivos de gateway on-premises no Alibaba Cloud. Um VPN Gateway exige um customer gateway registrado para estabelecer uma conexão IPsec-VPN com um data center on-premises.

  1. Faça login no console do VPN Gateway.

  2. No painel de navegação à esquerda, escolha Interconnections > VPN > Customer Gateways.

  3. Na barra de navegação superior, selecione a região onde deseja crie os customer gateways.

    Nota

    O customer gateway e o VPN Gateway devem estar na mesma região.

  4. Na página Customer Gateway, clique em Create Customer Gateway.

  5. No painel Create Customer Gateway, configure os customer gateways com as definições abaixo e clique em OK.

    crie oito customer gateways para registrar os endereços IP públicos dos quatro dispositivos de gateway on-premises. A tabela a seguir descreve as configurações necessárias. Mantenha os valores padrão para todos os outros parâmetros. Para mais informações, consulte customer gateways.

    Região

    Parâmetro

    Endereço IP

    China (Shanghai)

    CustomerGateway1

    Primeiro endereço IP público do dispositivo de gateway on-premises 1: 47.XX.XX.23

    CustomerGateway2

    Segundo endereço IP público do dispositivo de gateway on-premises 1: 47.XX.XX.32

    CustomerGateway3

    Primeiro endereço IP público do dispositivo de gateway on-premises 2: 47.XX.XX.69

    CustomerGateway4

    Segundo endereço IP público do dispositivo de gateway on-premises 2: 47.XX.XX.71

    US (Silicon Valley)

    CustomerGateway5

    Primeiro endereço IP público do dispositivo de gateway on-premises 3: 57.XX.XX.11

    CustomerGateway6

    Segundo endereço IP público do dispositivo de gateway on-premises 3: 47.XX.XX.191

    CustomerGateway7

    Primeiro endereço IP público do dispositivo de gateway on-premises 4: 57.XX.XX.22

    CustomerGateway8

    Segundo endereço IP público do dispositivo de gateway on-premises 4: 47.XX.XX.234

Etapa 2: Criar conexões IPsec

crie duas conexões IPsec-VPN para cada VPN Gateway. Ao criar uma conexão IPsec-VPN, especifique as configurações de criptografia do túnel e o data center par. Cada conexão corresponde a um único data center.

  1. acesse a página de Conexões IPsec-VPN no console do VPN Gateway, clique em Bind VPN Gateway e configure os seguintes parâmetros.

  2. A tabela abaixo lista os principais parâmetros para as conexões IPsec-VPN. Mantenha os valores padrão para todos os outros parâmetros. Para mais informações, consulte IPsec-VPN connection (Bind VPN Gateway).

    Parâmetro

    Conexão IPsec 1

    Conexão IPsec 2

    Conexão IPsec 3

    Conexão IPsec 4

    Name

    insira IPsec-VPN Connection 1.

    insira IPsec-VPN Connection 2.

    insira IPsec-VPN Connection 3.

    insira IPsec-VPN Connection 4.

    Region

    selecione China (Shanghai).

    selecione China (Shanghai).

    selecione US (Silicon Valley).

    selecione US (Silicon Valley).

    Bind VPN Gateway

    selecione VPN Gateway 1.

    selecione VPN Gateway 1.

    selecione VPN Gateway 2.

    selecione VPN Gateway 2.

    Routing Mode

    selecione Destination Routing. Neste cenário, esse modo de roteamento permite a comunicação entre múltiplos segmentos de rede.

    Effective Immediately

    Mantenha o valor padrão Yes. Isso permite que a negociação IPsec inicie imediatamente após a conclusão da configuração.

    Tunnel 1

    Customer Gateway

    selecione Customer Gateway 1.

    selecione Customer Gateway 3.

    selecione Customer Gateway 5.

    selecione Customer Gateway 7.

    Pre-Shared Key

    Importante

    A chave pré-compartilhada da conexão IPsec-VPN deve ser idêntica à chave pré-compartilhada do dispositivo de gateway par. Caso contrário, a conexão IPsec-VPN não será estabelecida.

    insira fddsFF111****.

    insira fddsFF333****.

    insira fddsFF555****.

    insira fddsFF777****.

    Encryption Settings

    Mantenha os valores padrão para os demais parâmetros, exceto pelos seguintes:

    • Na seção IKE Settings, defina DH Group como group14.

    • Na seção IPsec Settings, defina DH Group como group14.

    Nota

    selecione os parâmetros de criptografia com base no dispositivo de gateway on-premises para garantir que as configurações de criptografia da conexão IPsec sejam idênticas às do dispositivo local.

    Tunnel 2

    Customer Gateway

    selecione Customer Gateway 2.

    selecione Customer Gateway 4.

    selecione Customer Gateway 6.

    selecione Customer Gateway 8.

    Pre-Shared Key

    insira fddsFF222****.

    insira fddsFF444****.

    insira fddsFF666****.

    insira fddsFF888****.

    Encryption Settings

    Mantenha os valores padrão para os demais parâmetros, exceto pelos seguintes:

    • Na seção IKE Settings, defina DH Group como group14.

    • Na seção IPsec Settings, defina DH Group como group14.

    Nota

    selecione os parâmetros de criptografia com base no dispositivo de gateway on-premises para garantir que as configurações de criptografia da conexão IPsec sejam idênticas às do dispositivo local.

  3. Na caixa de diálogo Created, clique em Cancel.

  4. Permaneça na página IPsec-VPN Connection, localize a conexão IPsec-VPN criada e clique em Generate Peer Configuration na coluna Actions.

    A configuração par contém as definições que você precisa aplicar aos seus dispositivos de gateway locais.

  5. Na caixa de diálogo IPsec-VPN Connection Configuration, copie a configuração e salve-a localmente. Você precisará dessas informações para configure seus dispositivos de gateway locais posteriormente.

    Após concluir a configuração, a tabela abaixo mostra o mapeamento entre VPCs, instâncias de VPN Gateway, conexões IPsec-VPN, instâncias de Customer Gateway e data centers.

    VPC

    VPN Gateway

    Conexão IPsec

    Túnel

    Customer Gateway

    Data center par

    VPC1

    VPN Gateway 1

    IPsec-VPN Connection 1

    túnel ativo

    Customer Gateway 1

    Data Center 1

    túnel standby

    Customer Gateway 2

    IPsec-VPN Connection 2

    túnel ativo

    Customer Gateway 3

    Data Center 2

    túnel standby

    Customer Gateway 4

    VPC2

    VPN Gateway 2

    IPsec-VPN Connection 3

    túnel ativo

    Customer Gateway 5

    Data Center 3

    túnel standby

    Customer Gateway 6

    IPsec-VPN Connection 4

    túnel ativo

    Customer Gateway 7

    Data Center 4

    túnel standby

    Customer Gateway 8

Etapa 3: Configurar rotas do VPN Gateway

Após crie as conexões IPsec-VPN, adicione rotas para os data centers nas instâncias de VPN Gateway. Este tópico usa rotas baseadas em destino como exemplo. Para mais informações sobre outros métodos de roteamento, consulte route configuration.

  1. No painel de navegação à esquerda, escolha Interconnections > VPN > VPN Gateways.

  2. Na barra de navegação superior, selecione a região onde reside a instância de VPN Gateway.

  3. Na página VPN Gateway, localize a instância de VPN Gateway desejada e clique em no seu ID de instância.

  4. clique em na aba Destination-based Route Table e, em seguida, clique em Add Route Entry.

  5. No painel Add Route Entry, configure as rotas baseadas em destino e clique em OK.

    No VPN Gateway 1, adicione rotas para o data center 1 e data center 2. No VPN Gateway 2, adicione rotas para o data center 3 e data center 4.

    Parâmetro

    VPN Gateway 1

    VPN Gateway 2

    Destination CIDR Block

    insira 172.16.10.0/24 para o data center 1.

    insira 172.16.40.0/24 para o data center 2.

    insira 10.10.0.0/16 para o data center 3.

    insira 10.30.0.0/16 para o data center 4.

    Next Hop Type

    selecione IPsec-VPN Connection.

    selecione IPsec-VPN Connection.

    selecione IPsec-VPN Connection.

    selecione IPsec-VPN Connection.

    Next Hop

    selecione a conexão IPsec-VPN 1.

    selecione a conexão IPsec-VPN 2.

    selecione a conexão IPsec-VPN 3.

    selecione a conexão IPsec-VPN 4.

    Advertise to VPC

    Mantenha o valor padrão Yes.

    Após adicionar a entrada de rota baseada em destino, o VPN Gateway anuncia automaticamente as rotas para o data center 1 e data center 2 na tabela de rotas do sistema da VPC1.

    Mantenha o valor padrão Yes.

    Após adicionar a entrada de rota baseada em destino, o VPN Gateway anuncia automaticamente as rotas para o data center 3 e data center 4 na tabela de rotas do sistema da VPC2.

Etapa 4: Configurar os dispositivos de gateway on-premises

Após concluir as etapas anteriores, adicione configurações de VPN e roteamento aos seus dispositivos de gateway on-premises para estabelecer uma conexão IPsec-VPN com o VPN Gateway. Isso garante que o tráfego dos seus data centers para outros sites seja roteado preferencialmente pelo túnel ativo e faça failover automático para o túnel standby caso o túnel ativo falhe.

Nota

Neste exemplo, utiliza-se o software Adaptive Security Appliance (ASA) 9.19.1 para descrever a configuração de um firewall Cisco. Os comandos podem variar conforme a versão do software. Consulte a documentação ou seu fornecedor com base no seu ambiente real durante as operações. Para mais informações, consulte Configure local gateways.

O conteúdo a seguir contém informações sobre products de terceiros, servindo apenas como referência. O Alibaba Cloud não oferece garantias ou qualquer outro tipo de compromisso quanto ao desempenho e confiabilidade de products de terceiros, ou sobre possíveis impactos decorrentes de operações realizadas com esses products.

Dispositivo de gateway on-premises 1

  1. Faça login na janela de linha de comando do firewall Cisco e entre no modo de configuração.

    ciscoasa> enable
    Password: ********             #Enter the password for enable mode.
    ciscoasa# configure terminal   #Enter configuration mode.
    ciscoasa(config)#     
  2. visualize as configurações de interface e rotas públicas.

    Abaixo está um exemplo de configuração de interface habilitada no firewall Cisco.

    ciscoasa(config)# show running-config interface 
    !
    interface GigabitEthernet0/0
     nameif outside1                            #Name of the GigabitEthernet0/0 interface.
     security-level 0
     ip address 47.XX.XX.23 255.255.255.255     #public IP address configured for the GigabitEthernet0/0 interface.
    !
    interface GigabitEthernet0/1                #The interface that connects to the on-premises data center.
     nameif private                             #Name of the GigabitEthernet0/1 interface.
     security-level 100                         #Specify a security level for the private interface that is higher than that of the public interfaces.
     ip address 172.16.10.217 255.255.255.0       #IP address configured for the GigabitEthernet0/1 interface.
    !
    interface GigabitEthernet0/2                
     nameif outside2                            #Name of the GigabitEthernet0/2 interface.
     security-level 0
     ip address 47.XX.XX.32 255.255.255.255    #public IP address configured for the GigabitEthernet0/2 interface.
    !
    route outside1 47.XX.XX.87 255.255.255.255 192.XX.XX.172   #Configure a route to the public IP address of Tunnel 1 on the Alibaba Cloud side. The next hop is a public IP address.
    route outside2 47.XX.XX.78 255.255.255.255 192.XX.XX.158   #Configure a route to the public IP address of Tunnel 2 on the Alibaba Cloud side. The next hop is a public IP address.
    route private 172.16.10.0 255.255.255.0 172.16.10.216           #Configure a route to the on-premises data center.
  3. Habilite o IKEv2 nas interfaces públicas.

    crypto ikev2 enable outside1
    crypto ikev2 enable outside2
  4. crie uma Política IKEv2 e especifique o algoritmo de autenticação, algoritmo de criptografia, grupo DH e tempo de vida da SA para a fase IKE. Essas configurações devem ser consistentes com as do lado do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IKE Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ikev2 policy 10     
     encryption aes             #Specify the encryption algorithm.
     integrity sha              #Specify the authentication algorithm.
     group 14                   #Specify the DH group.
     prf sha                    #The prf value must be the same as the integrity value. On the Alibaba Cloud side, prf defaults to the same value as the authentication algorithm.
     lifetime seconds 86400     #Specify the SA lifetime.
  5. crie uma proposta e um perfil IPsec. Especifique o algoritmo de criptografia, algoritmo de autenticação, grupo DH e tempo de vida da SA para a fase IPsec. Essas configurações devem corresponder às do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IPsec Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ipsec ikev2 ipsec-proposal ALIYUN-PROPOSAL    #Create an IPsec proposal.
     protocol esp encryption aes                         #Specify the encryption algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
     protocol esp integrity sha-1                        #Specify the authentication algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
    crypto ipsec profile ALIYUN-PROFILE                  
     set ikev2 ipsec-proposal ALIYUN-PROPOSAL            #Create an IPsec profile and apply the created proposal. 
     set ikev2 local-identity address                    #Set the local ID format to IP address to match the RemoteId format on the Alibaba Cloud side.
     set pfs group14                                     #Specify PFS and the DH group.
     set security-association lifetime seconds 86400     #Specify the time-based SA lifetime.
     set security-association lifetime kilobytes unlimited #Disable the traffic-based SA lifetime.
  6. crie grupos de túnel e especifique as chaves pré-compartilhadas para os túneis. As chaves devem corresponder à configuração no Alibaba Cloud.

    tunnel-group 47.XX.XX.87 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 1 as L2L.
    tunnel-group 47.XX.XX.87 ipsec-attributes             
     ikev2 remote-authentication pre-shared-key fddsFF111****  #Specify the pre-shared key of the peer for Tunnel 1. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF111****   #Specify the local pre-shared key for Tunnel 1. This must match the key configured on Alibaba Cloud.
    !
    tunnel-group 47.XX.XX.78 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 2 as L2L.
    tunnel-group 47.XX.XX.78 ipsec-attributes
     ikev2 remote-authentication pre-shared-key fddsFF222****  #Specify the pre-shared key of the peer for Tunnel 2. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF222****   #Specify the local pre-shared key for Tunnel 2. This must match the key configured on Alibaba Cloud.
    !
  7. crie as interfaces de túnel.

    interface Tunnel1                                  #Create an interface for Tunnel 1.
     nameif ALIYUN1
     ip address 169.254.10.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside1                  #Specify the source interface for Tunnel 1 as the public interface GigabitEthernet0/0.
     tunnel destination 47.XX.XX.87                    #Specify the tunnel destination as the public IP address of Tunnel 1 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 1.
     no shutdown                                       #Enable the Tunnel 1 interface.
    !
    interface Tunnel2                                  #Create an interface for Tunnel 2.
     nameif ALIYUN2                
     ip address 169.254.20.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside2                  #Specify the source interface for Tunnel 2 as the public interface GigabitEthernet0/2.
     tunnel destination 47.XX.XX.78                    #Specify the tunnel destination as the public IP address of Tunnel 2 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4                            
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 2.
     no shutdown                                       #Enable the Tunnel 2 interface.
    !
  8. configure rotas estáticas para outros sites.

    Configure a high-priority route for traffic from data center 1 to other sites through the Tunnel 1 interface.
    route ALIYUN1 172.16.40.0 255.255.255.0 47.XX.XX.87 4  #Configure a route to data center 2.
    route ALIYUN1 10.30.0.0 255.255.0.0 47.XX.XX.87 4      #Configure a route to data center 4.
    route ALIYUN1 10.10.0.0 255.255.0.0 47.XX.XX.87 4      #Configure a route to data center 3.
    route ALIYUN1 10.0.0.0 255.255.0.0 47.XX.XX.87 4       #Configure a route to VPC2.
    route ALIYUN1 192.168.99.0 255.255.255.0 47.XX.XX.87 4 #Configure a route to VPC1.
    Configure a low-priority route for traffic from data center 1 to other sites through the Tunnel 2 interface.
    route ALIYUN2 172.16.40.0 255.255.255.0 47.XX.XX.78 5   
    route ALIYUN2 10.30.0.0 255.255.0.0 47.XX.XX.78 5       
    route ALIYUN2 10.10.0.0 255.255.0.0 47.XX.XX.78 5       
    route ALIYUN2 10.0.0.0 255.255.0.0 47.XX.XX.78 5        
    route ALIYUN2 192.168.99.0 255.255.255.0 47.XX.XX.78 5  
  9. Dependendo do seu ambiente de rede, adicione rotas no data center 1 para permitir que seus clientes acessem outros sites através do firewall Cisco.

Dispositivo de gateway on-premises 2

  1. Faça login na janela de linha de comando do firewall Cisco e entre no modo de configuração.

    ciscoasa> enable
    Password: ********             #Enter the password for enable mode.
    ciscoasa# configure terminal   #Enter configuration mode.
    ciscoasa(config)#     
  2. visualize as configurações de interface e rotas públicas.

    Abaixo está um exemplo de configuração de interface habilitada no firewall Cisco.

    ciscoasa(config)# show running-config interface 
    !
    interface GigabitEthernet0/0
     nameif outside1                            #Name of the GigabitEthernet0/0 interface.
     security-level 0
     ip address 47.XX.XX.69 255.255.255.255     #public IP address configured for the GigabitEthernet0/0 interface.
    !
    interface GigabitEthernet0/1                #The interface that connects to the on-premises data center.
     nameif private                             #Name of the GigabitEthernet0/1 interface.
     security-level 100                         #Specify a security level for the private interface that is higher than that of the public interfaces.
     ip address 172.16.40.217 255.255.255.0       #IP address configured for the GigabitEthernet0/1 interface.
    !
    interface GigabitEthernet0/2                
     nameif outside2                            #Name of the GigabitEthernet0/2 interface.
     security-level 0
     ip address 47.XX.XX.71 255.255.255.255    #public IP address configured for the GigabitEthernet0/2 interface.
    !
    route outside1 47.XX.XX.87 255.255.255.255 192.XX.XX.172   #Configure a route to the public IP address of Tunnel 1 on the Alibaba Cloud side. The next hop is a public IP address.
    route outside2 47.XX.XX.78 255.255.255.255 192.XX.XX.158   #Configure a route to the public IP address of Tunnel 2 on the Alibaba Cloud side. The next hop is a public IP address.
    route private 172.16.40.0 255.255.255.0 172.16.40.216           #Configure a route to the on-premises data center.
  3. Habilite o IKEv2 nas interfaces públicas.

    crypto ikev2 enable outside1
    crypto ikev2 enable outside2
  4. crie uma Política IKEv2 e especifique o algoritmo de autenticação, algoritmo de criptografia, grupo DH e tempo de vida da SA para a fase IKE. Essas configurações devem ser consistentes com as do lado do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IKE Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ikev2 policy 10     
     encryption aes             #Specify the encryption algorithm.
     integrity sha              #Specify the authentication algorithm.
     group 14                   #Specify the DH group.
     prf sha                    #The prf value must be the same as the integrity value. On the Alibaba Cloud side, prf defaults to the same value as the authentication algorithm.
     lifetime seconds 86400     #Specify the SA lifetime.
  5. crie uma proposta e um perfil IPsec. Especifique o algoritmo de criptografia, algoritmo de autenticação, grupo DH e tempo de vida da SA para a fase IPsec. Essas configurações devem corresponder às do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IPsec Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ipsec ikev2 ipsec-proposal ALIYUN-PROPOSAL    #Create an IPsec proposal.
     protocol esp encryption aes                         #Specify the encryption algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
     protocol esp integrity sha-1                        #Specify the authentication algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
    crypto ipsec profile ALIYUN-PROFILE                  
     set ikev2 ipsec-proposal ALIYUN-PROPOSAL            #Create an IPsec profile and apply the created proposal. 
     set ikev2 local-identity address                    #Set the local ID format to IP address to match the RemoteId format on the Alibaba Cloud side.
     set pfs group14                                     #Specify PFS and the DH group.
     set security-association lifetime seconds 86400     #Specify the time-based SA lifetime.
     set security-association lifetime kilobytes unlimited #Disable the traffic-based SA lifetime.
  6. crie grupos de túnel e especifique as chaves pré-compartilhadas para os túneis. As chaves devem corresponder à configuração no Alibaba Cloud.

    tunnel-group 47.XX.XX.87 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 1 as L2L.
    tunnel-group 47.XX.XX.87 ipsec-attributes             
     ikev2 remote-authentication pre-shared-key fddsFF333****  #Specify the pre-shared key of the peer for Tunnel 1. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF333****   #Specify the local pre-shared key for Tunnel 1. This must match the key configured on Alibaba Cloud.
    !
    tunnel-group 47.XX.XX.78 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 2 as L2L.
    tunnel-group 47.XX.XX.78 ipsec-attributes
     ikev2 remote-authentication pre-shared-key fddsFF444****  #Specify the pre-shared key of the peer for Tunnel 2. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF444****   #Specify the local pre-shared key for Tunnel 2. This must match the key configured on Alibaba Cloud.
    !
  7. crie as interfaces de túnel.

    interface Tunnel1                                  #Create an interface for Tunnel 1.
     nameif ALIYUN1
     ip address 169.254.11.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside1                  #Specify the source interface for Tunnel 1 as the public interface GigabitEthernet0/0.
     tunnel destination 47.XX.XX.87                    #Specify the tunnel destination as the public IP address of Tunnel 1 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 1.
     no shutdown                                       #Enable the Tunnel 1 interface.
    !
    interface Tunnel2                                  #Create an interface for Tunnel 2.
     nameif ALIYUN2                
     ip address 169.254.21.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside2                  #Specify the source interface for Tunnel 2 as the public interface GigabitEthernet0/2.
     tunnel destination 47.XX.XX.78                    #Specify the tunnel destination as the public IP address of Tunnel 2 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4                            
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 2.
     no shutdown                                       #Enable the Tunnel 2 interface.
    !
  8. configure rotas estáticas para outros sites.

    Configure a high-priority route for traffic from data center 2 to other sites through the Tunnel 1 interface.
    route ALIYUN1 172.16.10.0 255.255.255.0 47.XX.XX.87 4  #Configure a route to data center 1.
    route ALIYUN1 10.30.0.0 255.255.0.0 47.XX.XX.87 4      #Configure a route to data center 4.
    route ALIYUN1 10.10.0.0 255.255.0.0 47.XX.XX.87 4      #Configure a route to data center 3.
    route ALIYUN1 10.0.0.0 255.255.0.0 47.XX.XX.87 4       #Configure a route to VPC2.
    route ALIYUN1 192.168.99.0 255.255.255.0 47.XX.XX.87 4 #Configure a route to VPC1.
    Configure a low-priority route for traffic from data center 2 to other sites through the Tunnel 2 interface.
    route ALIYUN2 172.16.10.0 255.255.255.0 47.XX.XX.78 5   
    route ALIYUN2 10.30.0.0 255.255.0.0 47.XX.XX.78 5       
    route ALIYUN2 10.10.0.0 255.255.0.0 47.XX.XX.78 5       
    route ALIYUN2 10.0.0.0 255.255.0.0 47.XX.XX.78 5        
    route ALIYUN2 192.168.99.0 255.255.255.0 47.XX.XX.78 5  
  9. Dependendo do seu ambiente de rede, adicione rotas no data center 2 para permitir que seus clientes acessem outros sites através do firewall Cisco.

Dispositivo de gateway on-premises 3

  1. Faça login na janela de linha de comando do firewall Cisco e entre no modo de configuração.

    ciscoasa> enable
    Password: ********             #Enter the password for enable mode.
    ciscoasa# configure terminal   #Enter configuration mode.
    ciscoasa(config)#     
  2. visualize as configurações de interface e rotas públicas.

    Abaixo está um exemplo de configuração de interface habilitada no firewall Cisco.

    ciscoasa(config)# show running-config interface 
    !
    interface GigabitEthernet0/0
     nameif outside1                            #Name of the GigabitEthernet0/0 interface.
     security-level 0
     ip address 57.XX.XX.11 255.255.255.255     #public IP address configured for the GigabitEthernet0/0 interface.
    !
    interface GigabitEthernet0/1                #The interface that connects to the on-premises data center.
     nameif private                             #Name of the GigabitEthernet0/1 interface.
     security-level 100                         #Specify a security level for the private interface that is higher than that of the public interfaces.
     ip address 10.10.10.217 255.255.255.0       #IP address configured for the GigabitEthernet0/1 interface.
    !
    interface GigabitEthernet0/2                
     nameif outside2                            #Name of the GigabitEthernet0/2 interface.
     security-level 0
     ip address 57.XX.XX.191 255.255.255.255    #public IP address configured for the GigabitEthernet0/2 interface.
    !
    route outside1 47.XX.XX.207 255.255.255.255 192.XX.XX.172   #Configure a route to the public IP address of Tunnel 1 on the Alibaba Cloud side. The next hop is a public IP address.
    route outside2 47.XX.XX.15 255.255.255.255 192.XX.XX.158   #Configure a route to the public IP address of Tunnel 2 on the Alibaba Cloud side. The next hop is a public IP address.
    route private 10.10.10.0 255.255.255.0 10.10.10.216           #Configure a route to the on-premises data center.
  3. Habilite o IKEv2 nas interfaces públicas.

    crypto ikev2 enable outside1
    crypto ikev2 enable outside2
  4. crie uma Política IKEv2 e especifique o algoritmo de autenticação, algoritmo de criptografia, grupo DH e tempo de vida da SA para a fase IKE. Essas configurações devem ser consistentes com as do lado do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IKE Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ikev2 policy 10     
     encryption aes             #Specify the encryption algorithm.
     integrity sha              #Specify the authentication algorithm.
     group 14                   #Specify the DH group.
     prf sha                    #The prf value must be the same as the integrity value. On the Alibaba Cloud side, prf defaults to the same value as the authentication algorithm.
     lifetime seconds 86400     #Specify the SA lifetime.
  5. crie uma proposta e um perfil IPsec. Especifique o algoritmo de criptografia, algoritmo de autenticação, grupo DH e tempo de vida da SA para a fase IPsec. Essas configurações devem corresponder às do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IPsec Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ipsec ikev2 ipsec-proposal ALIYUN-PROPOSAL    #Create an IPsec proposal.
     protocol esp encryption aes                         #Specify the encryption algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
     protocol esp integrity sha-1                        #Specify the authentication algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
    crypto ipsec profile ALIYUN-PROFILE                  
     set ikev2 ipsec-proposal ALIYUN-PROPOSAL            #Create an IPsec profile and apply the created proposal. 
     set ikev2 local-identity address                    #Set the local ID format to IP address to match the RemoteId format on the Alibaba Cloud side.
     set pfs group14                                     #Specify PFS and the DH group.
     set security-association lifetime seconds 86400     #Specify the time-based SA lifetime.
     set security-association lifetime kilobytes unlimited #Disable the traffic-based SA lifetime.
  6. crie grupos de túnel e especifique as chaves pré-compartilhadas para os túneis. As chaves devem corresponder à configuração no Alibaba Cloud.

    tunnel-group 47.XX.XX.207 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 1 as L2L.
    tunnel-group 47.XX.XX.207 ipsec-attributes             
     ikev2 remote-authentication pre-shared-key fddsFF555****  #Specify the pre-shared key of the peer for Tunnel 1. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF555****   #Specify the local pre-shared key for Tunnel 1. This must match the key configured on Alibaba Cloud.
    !
    tunnel-group 47.XX.XX.15 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 2 as L2L.
    tunnel-group 47.XX.XX.15 ipsec-attributes
     ikev2 remote-authentication pre-shared-key fddsFF666****  #Specify the pre-shared key of the peer for Tunnel 2. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF666****   #Specify the local pre-shared key for Tunnel 2. This must match the key configured on Alibaba Cloud.
    !
  7. crie as interfaces de túnel.

    interface Tunnel1                                  #Create an interface for Tunnel 1.
     nameif ALIYUN1
     ip address 169.254.12.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside1                  #Specify the source interface for Tunnel 1 as the public interface GigabitEthernet0/0.
     tunnel destination 47.XX.XX.207                    #Specify the tunnel destination as the public IP address of Tunnel 1 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 1.
     no shutdown                                       #Enable the Tunnel 1 interface.
    !
    interface Tunnel2                                  #Create an interface for Tunnel 2.
     nameif ALIYUN2                
     ip address 169.254.22.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside2                  #Specify the source interface for Tunnel 2 as the public interface GigabitEthernet0/2.
     tunnel destination 47.XX.XX.15                   #Specify the tunnel destination as the public IP address of Tunnel 2 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4                            
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 2.
     no shutdown                                       #Enable the Tunnel 2 interface.
    !
  8. configure rotas estáticas para outros sites.

    Configure a high-priority route for traffic from data center 3 to other sites through the Tunnel 1 interface.
    route ALIYUN1 172.16.40.0 255.255.255.0 47.XX.XX.207 4  #Configure a route to data center 2.
    route ALIYUN1 10.30.0.0 255.255.0.0 47.XX.XX.207 4      #Configure a route to data center 4.
    route ALIYUN1 172.16.10.0 255.255.255.0 47.XX.XX.207 4  #Configure a route to data center 1.
    route ALIYUN1 10.0.0.0 255.255.0.0 47.XX.XX.207 4       #Configure a route to VPC2.
    route ALIYUN1 192.168.99.0 255.255.255.0 47.XX.XX.207 4 #Configure a route to VPC1.
    Configure a low-priority route for traffic from data center 3 to other sites through the Tunnel 2 interface.
    route ALIYUN2 172.16.40.0 255.255.255.0 47.XX.XX.15 5   
    route ALIYUN2 10.30.0.0 255.255.0.0 47.XX.XX.15 5       
    route ALIYUN2 172.16.10.0 255.255.255.0 47.XX.XX.15 5      
    route ALIYUN2 10.0.0.0 255.255.0.0 47.XX.XX.15 5        
    route ALIYUN2 192.168.99.0 255.255.255.0 47.XX.XX.15 5  
  9. Dependendo do seu ambiente de rede, adicione rotas no data center 3 para permitir que seus clientes acessem outros sites através do firewall Cisco.

Dispositivo de gateway on-premises 4

  1. Faça login na janela de linha de comando do firewall Cisco e entre no modo de configuração.

    ciscoasa> enable
    Password: ********             #Enter the password for enable mode.
    ciscoasa# configure terminal   #Enter configuration mode.
    ciscoasa(config)#     
  2. visualize as configurações de interface e rotas públicas.

    Abaixo está um exemplo de configuração de interface habilitada no firewall Cisco.

    ciscoasa(config)# show running-config interface 
    !
    interface GigabitEthernet0/0
     nameif outside1                            #Name of the GigabitEthernet0/0 interface.
     security-level 0
     ip address 57.XX.XX.22 255.255.255.255     #public IP address configured for the GigabitEthernet0/0 interface.
    !
    interface GigabitEthernet0/1                #The interface that connects to the on-premises data center.
     nameif private                             #Name of the GigabitEthernet0/1 interface.
     security-level 100                         #Specify a security level for the private interface that is higher than that of the public interfaces.
     ip address 10.30.66.217 255.255.255.0       #IP address configured for the GigabitEthernet0/1 interface.
    !
    interface GigabitEthernet0/2                
     nameif outside2                            #Name of the GigabitEthernet0/2 interface.
     security-level 0
     ip address 57.XX.XX.234 255.255.255.255    #public IP address configured for the GigabitEthernet0/2 interface.
    !
    route outside1 47.XX.XX.207 255.255.255.255 192.XX.XX.172   #Configure a route to the public IP address of Tunnel 1 on the Alibaba Cloud side. The next hop is a public IP address.
    route outside2 47.XX.XX.15 255.255.255.255 192.XX.XX.158   #Configure a route to the public IP address of Tunnel 2 on the Alibaba Cloud side. The next hop is a public IP address.
    route private 10.30.66.0 255.255.255.0 10.30.66.216           #Configure a route to the on-premises data center.
  3. Habilite o IKEv2 nas interfaces públicas.

    crypto ikev2 enable outside1
    crypto ikev2 enable outside2
  4. crie uma Política IKEv2 e especifique o algoritmo de autenticação, algoritmo de criptografia, grupo DH e tempo de vida da SA para a fase IKE. Essas configurações devem ser consistentes com as do lado do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IKE Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ikev2 policy 10     
     encryption aes             #Specify the encryption algorithm.
     integrity sha              #Specify the authentication algorithm.
     group 14                   #Specify the DH group.
     prf sha                    #The prf value must be the same as the integrity value. On the Alibaba Cloud side, prf defaults to the same value as the authentication algorithm.
     lifetime seconds 86400     #Specify the SA lifetime.
  5. crie uma proposta e um perfil IPsec. Especifique o algoritmo de criptografia, algoritmo de autenticação, grupo DH e tempo de vida da SA para a fase IPsec. Essas configurações devem corresponder às do Alibaba Cloud.

    Importante

    No Alibaba Cloud, é possível especifique apenas um valor para os parâmetros Encryption Algorithm, Authentication Algorithm e DH Group na fase IPsec Configurations. Recomendamos fazer o mesmo no seu firewall Cisco e garantir que os valores correspondam à configuração do Alibaba Cloud.

    crypto ipsec ikev2 ipsec-proposal ALIYUN-PROPOSAL    #Create an IPsec proposal.
     protocol esp encryption aes                         #Specify the encryption algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
     protocol esp integrity sha-1                        #Specify the authentication algorithm. The protocol is ESP, which is required on the Alibaba Cloud side.
    crypto ipsec profile ALIYUN-PROFILE                  
     set ikev2 ipsec-proposal ALIYUN-PROPOSAL            #Create an IPsec profile and apply the created proposal. 
     set ikev2 local-identity address                    #Set the local ID format to IP address to match the RemoteId format on the Alibaba Cloud side.
     set pfs group14                                     #Specify PFS and the DH group.
     set security-association lifetime seconds 86400     #Specify the time-based SA lifetime.
     set security-association lifetime kilobytes unlimited #Disable the traffic-based SA lifetime.
  6. crie grupos de túnel e especifique as chaves pré-compartilhadas para os túneis. As chaves devem corresponder à configuração no Alibaba Cloud.

    tunnel-group 47.XX.XX.207 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 1 as L2L.
    tunnel-group 47.XX.XX.207 ipsec-attributes             
     ikev2 remote-authentication pre-shared-key fddsFF777****  #Specify the pre-shared key of the peer for Tunnel 1. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF777****   #Specify the local pre-shared key for Tunnel 1. This must match the key configured on Alibaba Cloud.
    !
    tunnel-group 47.XX.XX.15 type ipsec-l2l                    #Specify the encapsulation mode for Tunnel 2 as L2L.
    tunnel-group 47.XX.XX.15 ipsec-attributes
     ikev2 remote-authentication pre-shared-key fddsFF888****  #Specify the pre-shared key of the peer for Tunnel 2. This is the pre-shared key on the Alibaba Cloud side.
     ikev2 local-authentication pre-shared-key fddsFF888****   #Specify the local pre-shared key for Tunnel 2. This must match the key configured on Alibaba Cloud.
    !
  7. crie as interfaces de túnel.

    interface Tunnel1                                  #Create an interface for Tunnel 1.
     nameif ALIYUN1
     ip address 169.254.13.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside1                  #Specify the source interface for Tunnel 1 as the public interface GigabitEthernet0/0.
     tunnel destination 47.XX.XX.207                   #Specify the tunnel destination as the public IP address of Tunnel 1 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 1.
     no shutdown                                       #Enable the Tunnel 1 interface.
    !
    interface Tunnel2                                  #Create an interface for Tunnel 2.
     nameif ALIYUN2                
     ip address 169.254.23.2 255.255.255.252           #Specify the IP address of the interface.
     tunnel source interface outside2                  #Specify the source interface for Tunnel 2 as the public interface GigabitEthernet0/2.
     tunnel destination 47.XX.XX.15                    #Specify the tunnel destination as the public IP address of Tunnel 2 on the Alibaba Cloud side.
     tunnel mode ipsec ipv4                            
     tunnel protection ipsec profile ALIYUN-PROFILE    #Apply the ALIYUN-PROFILE IPsec profile to Tunnel 2.
     no shutdown                                       #Enable the Tunnel 2 interface.
    !
  8. configure rotas estáticas para outros sites.

    Configure a high-priority route for traffic from data center 4 to other sites through the Tunnel 1 interface.
    route ALIYUN1 172.16.40.0 255.255.255.0 47.XX.XX.207 4  #Configure a route to data center 2.
    route ALIYUN1 10.10.0.0 255.255.0.0 47.XX.XX.207 4      #Configure a route to data center 3.
    route ALIYUN1 172.16.10.0 255.255.255.0 47.XX.XX.207 4  #Configure a route to data center 1.
    route ALIYUN1 10.0.0.0 255.255.0.0 47.XX.XX.207 4       #Configure a route to VPC2.
    route ALIYUN1 192.168.99.0 255.255.255.0 47.XX.XX.207 4 #Configure a route to VPC1.
    Configure a low-priority route for traffic from data center 4 to other sites through the Tunnel 2 interface.
    route ALIYUN2 172.16.40.0 255.255.255.0 47.XX.XX.15 5   
    route ALIYUN2 10.10.0.0 255.255.0.0 47.XX.XX.15 5       
    route ALIYUN2 172.16.10.0 255.255.255.0 47.XX.XX.15 5      
    route ALIYUN2 10.0.0.0 255.255.0.0 47.XX.XX.15 5        
    route ALIYUN2 192.168.99.0 255.255.255.0 47.XX.XX.15 5  
  9. Dependendo do seu ambiente de rede, adicione rotas no data center 4 para permitir que seus clientes acessem outros sites através do firewall Cisco.

Após configure os dispositivos de gateway on-premises, o data center 1, data center 2 e VPC1 poderão se comunicar entre si, assim como o data center 3, data center 4 e VPC2. No entanto, a comunicação entre esses dois grupos ainda não está estabelecida.

Etapa 5: Configurar o Cloud Enterprise Network (CEN)

Use o Cloud Enterprise Network (CEN) para conectar o data center 1, data center 2, VPC1, data center 3, data center 4 e VPC2.

  1. crie uma instância CEN. Para mais informações, consulte CEN instance.

  2. crie um Transit Router na região China (Shanghai) e outro na região US (Silicon Valley). Para mais informações, consulte Create a transit router instance.

    Use as configurações padrão ao criar os Transit Routers.

  3. crie anexos de VPC.

    Anexe a VPC1 ao Transit Router na região China (Shanghai) e a VPC2 ao Transit Router na região US (Silicon Valley).

    1. Na página de detalhes da instância CEN, acesse a aba Basic Settings > Transit Router. Localize o Transit Router na região China (Shanghai) e clique em Create Network Instance Connection na coluna Actions.

    2. configure os parâmetros conforme mostrado na tabela abaixo e clique em OK.

      Esta tabela lista os principais parâmetros para crie anexos de VPC. Use os valores padrão para todos os outros parâmetros. Para mais informações, consulte Use an Enterprise Edition transit router to create a VPC attachment.

      Parâmetro

      Anexo da VPC1

      Anexo da VPC2

      Network Type

      selecione VPC.

      Region

      selecione China (Shanghai).

      selecione US (Silicon Valley).

      Account

      selecione Same Account.

      Attachment Name

      insira VPC1 attachment.

      insira VPC2 attachment.

      Networks

      selecione VPC1.

      selecione VPC2.

      vSwitch

      selecione o vSwitch 1 na zona E e o vSwitch 2 na zona F.

      Certifique-se de que cada vSwitch selecionado possua um endereço IP livre. Se a VPC não tiver um vSwitch nas zonas suportadas pelo Transit Router, ou se os vSwitches não tiverem endereços IP livres, será necessário crie um vSwitch. Para mais informações, consulte Create and manage vSwitches.

      selecione o vSwitch 1 na zona A e o vSwitch 2 na zona B.

      Certifique-se de que cada vSwitch selecionado possua um endereço IP livre. Se a VPC não tiver um vSwitch nas zonas suportadas pelo Transit Router, ou se os vSwitches não tiverem endereços IP livres, será necessário crie um vSwitch. Para mais informações, consulte Create and manage vSwitches.

      Advanced Settings

      Mantenha as configurações padrão. Todas as opções avançadas estão habilitadas por padrão.

  4. crie uma conexão inter-regional.

    Como a VPC1 e a VPC2 estão em regiões diferentes, é necessário crie uma conexão inter-regional para permitir a comunicação entre elas.

    1. Na página de detalhes da instância CEN, acesse a aba Basic Settings > Bandwidth Package Management e clique em Set Inter-region Bandwidth.

    2. Na página Connect Network Instance, configure a conexão inter-regional conforme descrito abaixo e clique em OK.

      Parâmetro

      Descrição

      Network Type

      selecione Inter-region Connection.

      Region

      selecione China (Shanghai).

      Local Region

      selecione US (Silicon Valley).

      Bandwidth Allocation Mode

      selecione Pay-By-Data-Transfer. O Cloud Data Transfer (CDT) cobra as taxas referentes a esse método de faturamento.

      Bandwidth

      insira a largura de banda para a conexão inter-regional. Unidade: Mbit/s.

      Default Line Type

      Mantenha o tipo de link padrão, Gold.

      Advanced Settings

      Todas as opções avançadas estão selecionadas por padrão.

  5. Publique as rotas dos data centers no Transit Router.

    A conexão inter-regional permite apenas que a VPC1 e a VPC2 se comuniquem. Para ative a comunicação entre todos os data centers, também é necessário publicar suas rotas no Transit Router.

    1. Na página de detalhes da instância CEN, acesse a aba Basic Settings > Transit Router, localize o Transit Router na região China (Shanghai) e clique em no seu ID.

    2. Na página de detalhes do Transit Router, clique em na aba Network Instance Route Table.

    3. Na aba Network Instance Route Table, localize as entradas de rota da instância VPC1 que apontam para o data center 1 e data center 2.

    4. Na coluna Publishing Progress de uma entrada de rota, clique em Publish. Na caixa de diálogo PublishRoute, confirme as informações da rota e clique em OK.

    5. Repita o processo para o Transit Router na região US (Silicon Valley). Para a instância VPC2, publique as rotas que apontam para o data center 3 e data center 4.

    Data centers 1 e 2

    Na aba Network Instance Route Table do Transit Router, selecione a instância de rede VPC1 e sua tabela de rotas. verifique se o Publish status das duas entradas de rota VpnGateway, 172.16.10.0/24 e 172.16.40.0/24, está como Published.

    Data centers 3 e 4

    Na aba Network Instance Route Table do Transit Router, selecione a instância de rede VPC2 e sua tabela de rotas. verifique se o Publish status das duas entradas de rota personalizadas VpnGateway 10.10.0.0/16 e 10.30.0.0/16 está como Published.

Etapa 6: Testar a conectividade

As etapas anteriores habilitam a comunicação entre os data centers e VPCs em diferentes regiões. Esta seção descreve como testar a conectividade.

Nota

Antes de testar a conectividade, verifique se as regras de grupo de segurança das instâncias ecs e as regras de ACL dos data centers on-premises permitem o tráfego entre os data centers e as VPCs. Para mais informações sobre regras de grupo de segurança, consulte Query security group rules e Add security group rules.

Testar conectividade da VPC1 para VPC2, data center 1, data center 2, data center 3 e data center 4.

  1. Faça login na instância ecs1 na VPC1. Para mais informações, consulte Connection method overview.

  2. Na instância ecs1, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>
    [root@izbxxxbdZ ~]# ping 10.0.10.33
    PING 10.0.10.33 (10.0.10.33) 56(84) bytes of data.
    64 bytes from 10.0.10.33: icmp_seq=1 ttl=62 time=30.7 ms
    64 bytes from 10.0.10.33: icmp_seq=2 ttl=62 time=30.4 ms
    64 bytes from 10.0.10.33: icmp_seq=3 ttl=62 time=30.5 ms
    64 bytes from 10.0.10.33: icmp_seq=4 ttl=62 time=30.5 ms
    ^Z
    [5]+  Stopped                 ping 10.0.10.33
    [root@izbpxxxdZ ~]# ping 10.10.10.201
    PING 10.10.10.201 (10.10.10.201) 56(84) bytes of data.
    64 bytes from 10.10.10.201: icmp_seq=1 ttl=60 time=34.2 ms
    64 bytes from 10.10.10.201: icmp_seq=2 ttl=60 time=33.6 ms
    64 bytes from 10.10.10.201: icmp_seq=3 ttl=60 time=34.6 ms
    64 bytes from 10.10.10.201: icmp_seq=4 ttl=60 time=33.5 ms
    ^Z
    [6]+  Stopped                 ping 10.10.10.201
    [root@izbpxxxodZ ~]# ping 10.30.66.11
    PING 10.30.66.11 (10.30.66.11) 56(84) bytes of data.
    64 bytes from 10.30.66.11: icmp_seq=1 ttl=60 time=35.2 ms
    64 bytes from 10.30.66.11: icmp_seq=2 ttl=60 time=34.4 ms
    64 bytes from 10.30.66.11: icmp_seq=3 ttl=60 time=34.3 ms
    64 bytes from 10.30.66.11: icmp_seq=4 ttl=60 time=34.3 ms
    ^Z
    [7]+  Stopped                 ping 10.30.66.11
    [root@izbpxxxdZ ~]# ping 172.16.40.60
    PING 172.16.40.60 (172.16.40.60) 56(84) bytes of data.
    64 bytes from 172.16.40.60: icmp_seq=1 ttl=62 time=8.27 ms
    64 bytes from 172.16.40.60: icmp_seq=2 ttl=62 time=7.75 ms
    64 bytes from 172.16.40.60: icmp_seq=3 ttl=62 time=7.84 ms
    64 bytes from 172.16.40.60: icmp_seq=4 ttl=62 time=7.96 ms
    ^Z
    [8]+  Stopped                 ping 172.16.40.60
    [root@izbpxxxdZ ~]# ping 172.16.10.207
    PING 172.16.10.207 (172.16.10.207) 56(84) bytes of data.
    64 bytes from 172.16.10.207: icmp_seq=1 ttl=62 time=9.62 ms
    64 bytes from 172.16.10.207: icmp_seq=2 ttl=62 time=8.52 ms
    64 bytes from 172.16.10.207: icmp_seq=3 ttl=62 time=9.59 ms
    64 bytes from 172.16.10.207: icmp_seq=4 ttl=62 time=8.81 ms
    ^Z
    [9]+  Stopped                 ping 172.16.10.207

    Os pacotes de resposta echo na saída confirmam que a VPC1 está conectada aos outros sites.

Testar conectividade da VPC2 para VPC1, data center 1, data center 2, data center 3 e data center 4.

  1. Faça login na instância ecs2 na VPC2. Para mais informações, consulte Connection method overview.

  2. Na instância ecs2, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>

    [root@iZ2zeixxxsdZ ~]# ping 192.168.99.48 PING 192.168.99.48 (192.168.99.48) 56(84) bytes of data. 64 bytes from 192.168.99.48: icmp_seq=1 ttl=62 time=31,9 ms 64 bytes from 192.168.99.48: icmp_seq=2 ttl=62 time=31,6 ms 64 bytes from 192.168.99.48: icmp_seq=3 ttl=62 time=31,6 ms 64 bytes from 192.168.99.48: icmp_seq=4 ttl=62 time=31,7 ms ^Z [1]+ Stopped ping 192.168.99.48 [root@iZ2zeixxxsdZ ~]# ping 172.16.10.207 PING 172.16.10.207 (172.16.10.207) 56(84) bytes of data. 64 bytes from 172.16.10.207: icmp_seq=1 ttl=60 time=37,3 ms 64 bytes from 172.16.10.207: icmp_seq=2 ttl=60 time=36,4 ms 64 bytes from 172.16.10.207: icmp_seq=3 ttl=60 time=36,4 ms 64 bytes from 172.16.10.207: icmp_seq=4 ttl=60 time=36,3 ms ^Z [2]+ Stopped ping 172.16.10.207 [root@iZ2zeixxxsdZ ~]# ping 172.16.40.60 PING 172.16.40.60 (172.16.40.60) 56(84) bytes of data. 64 bytes from 172.16.40.60: icmp_seq=1 ttl=60 time=34,1 ms 64 bytes from 172.16.40.60: icmp_seq=2 ttl=60 time=33,1 ms 64 bytes from 172.16.40.60: icmp_seq=3 ttl=60 time=32,7 ms 64 bytes from 172.16.40.60: icmp_seq=4 ttl=60 time=32,7 ms ^Z [3]+ Stopped ping 172.16.40.60 [root@iZ2zxxxsdZ ~]# ping 10.30.66.11 PING 10.30.66.11 (10.30.66.11) 56(84) bytes of data. 64 bytes from 10.30.66.11: icmp_seq=1 ttl=62 time=7,29 ms 64 bytes from 10.30.66.11: icmp_seq=2 ttl=62 time=7,02 ms 64 bytes from 10.30.66.11: icmp_seq=3 ttl=62 time=6,88 ms 64 bytes from 10.30.66.11: icmp_seq=4 ttl=62 time=6,63 ms ^Z [6]+ Stopped ping 10.30.66.11 [root@iZ2zxxxsdZ ~]# ping 10.10.10.201 PING 10.10.10.201 (10.10.10.201) 56(84) bytes of data. 64 bytes from 10.10.10.201: icmp_seq=1 ttl=62 time=5,01 ms 64 bytes from 10.10.10.201: icmp_seq=2 ttl=62 time=4,68 ms 64 bytes from 10.10.10.201: icmp_seq=3 ttl=62 time=4,51 ms 64 bytes from 10.10.10.201: icmp_seq=4 ttl=62 time=4,58 ms ^Z [7]+ Stopped ping 10.10.10.201 [root@iZ2zeiyvn7mvzzdqy253sdZ ~]#

    Os pacotes de resposta echo na saída confirmam que a VPC2 está conectada aos outros sites.

Testar conectividade do data center 1 para VPC1, VPC2, data center 2, data center 3 e data center 4.

  1. Faça login na interface de linha de comando de um cliente no data center 1.

  2. No cliente, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>

    [root@iZbp1xxx5rZ ~]# ping 192.168.99.48 PING 192.168.99.48 (192.168.99.48) 56(84) bytes of data. 64 bytes from 192.168.99.48: icmp_seq=1 ttl=62 time=8,66 ms 64 bytes from 192.168.99.48: icmp_seq=2 ttl=62 time=8,71 ms 64 bytes from 192.168.99.48: icmp_seq=3 ttl=62 time=8,64 ms 64 bytes from 192.168.99.48: icmp_seq=4 ttl=62 time=8,51 ms ^Z [2]+ Stopped ping 192.168.99.48 [root@iZbp1xxx5rZ ~]# ping 172.16.40.60 PING 172.16.40.60 (172.16.40.60) 56(84) bytes of data. 64 bytes from 172.16.40.60: icmp_seq=1 ttl=61 time=17,0 ms 64 bytes from 172.16.40.60: icmp_seq=2 ttl=61 time=15,9 ms 64 bytes from 172.16.40.60: icmp_seq=3 ttl=61 time=16,2 ms 64 bytes from 172.16.40.60: icmp_seq=4 ttl=61 time=15,9 ms ^Z [3]+ Stopped ping 172.16.40.60 [root@iZxxx ~]# ping 10.30.66.11 PING 10.30.66.11 (10.30.66.11) 56(84) bytes of data. 64 bytes from 10.30.66.11: icmp_seq=1 ttl=58 time=49,3 ms 64 bytes from 10.30.66.11: icmp_seq=2 ttl=58 time=48,7 ms 64 bytes from 10.30.66.11: icmp_seq=3 ttl=58 time=48,6 ms 64 bytes from 10.30.66.11: icmp_seq=4 ttl=58 time=48,4 ms ^Z [4]+ Stopped ping 10.30.66.11 [root@iZxxx ~]# ping 10.10.10.201 PING 10.10.10.201 (10.10.10.201) 56(84) bytes of data. 64 bytes from 10.10.10.201: icmp_seq=1 ttl=58 time=39,1 ms 64 bytes from 10.10.10.201: icmp_seq=2 ttl=58 time=38,6 ms 64 bytes from 10.10.10.201: icmp_seq=3 ttl=58 time=38,6 ms 64 bytes from 10.10.10.201: icmp_seq=4 ttl=58 time=38,3 ms ^Z [5]+ Stopped ping 10.10.10.201 [root@iZxxx ~]# ping 10.0.10.33 PING 10.0.10.33 (10.0.10.33) 56(84) bytes of data. 64 bytes from 10.0.10.33: icmp_seq=1 ttl=60 time=37,5 ms 64 bytes from 10.0.10.33: icmp_seq=2 ttl=60 time=36,8 ms 64 bytes from 10.0.10.33: icmp_seq=3 ttl=60 time=37,1 ms 64 bytes from 10.0.10.33: icmp_seq=4 ttl=60 time=36,9 ms ^Z [6]+ Stopped ping 10.0.10.33

    Os pacotes de resposta echo na saída confirmam que o data center 1 está conectado aos outros sites.

Testar conectividade do data center 2 para VPC1, VPC2, data center 1, data center 3 e data center 4.

  1. Faça login na interface de linha de comando de um cliente no data center 2.

  2. No cliente, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>
    [root@xxx ~]# ping 192.168.99.48
    PING 192.168.99.48 (192.168.99.48) 56(84) bytes of data.
    64 bytes from 192.168.99.48: icmp_seq=1 ttl=62 time=8.29 ms
    64 bytes from 192.168.99.48: icmp_seq=2 ttl=62 time=7.93 ms
    64 bytes from 192.168.99.48: icmp_seq=3 ttl=62 time=8.07 ms
    64 bytes from 192.168.99.48: icmp_seq=4 ttl=62 time=8.01 ms
    ^Z
    [1]+  Stopped                 ping 192.168.99.48
    [root@xxx ~]# ping 172.16.10.207
    PING 172.16.10.207 (172.16.10.207) 56(84) bytes of data.
    64 bytes from 172.16.10.207: icmp_seq=1 ttl=61 time=16.9 ms
    64 bytes from 172.16.10.207: icmp_seq=2 ttl=61 time=16.2 ms
    64 bytes from 172.16.10.207: icmp_seq=3 ttl=61 time=16.2 ms
    64 bytes from 172.16.10.207: icmp_seq=4 ttl=61 time=17.6 ms
    ^Z
    [2]+  Stopped                 ping 172.16.10.207
    [root@xxx ~]# ping 10.30.66.11
    PING 10.30.66.11 (10.30.66.11) 56(84) bytes of data.
    64 bytes from 10.30.66.11: icmp_seq=1 ttl=58 time=42.7 ms
    64 bytes from 10.30.66.11: icmp_seq=2 ttl=58 time=41.9 ms
    64 bytes from 10.30.66.11: icmp_seq=3 ttl=58 time=42.2 ms
    64 bytes from 10.30.66.11: icmp_seq=4 ttl=58 time=41.8 ms
    ^Z
    [3]+  Stopped                 ping 10.30.66.11
    [root@xxx ~]# ping 10.10.10.201
    PING 10.10.10.201 (10.10.10.201) 56(84) bytes of data.
    64 bytes from 10.10.10.201: icmp_seq=1 ttl=58 time=41.5 ms
    64 bytes from 10.10.10.201: icmp_seq=2 ttl=58 time=42.8 ms
    64 bytes from 10.10.10.201: icmp_seq=3 ttl=58 time=41.3 ms
    64 bytes from 10.10.10.201: icmp_seq=4 ttl=58 time=41.4 ms
    ^Z
    [6]+  Stopped                 ping 10.10.10.201
    [root@xxx ~]# ping 10.0.10.33
    PING 10.0.10.33 (10.0.10.33) 56(84) bytes of data.
    64 bytes from 10.0.10.33: icmp_seq=1 ttl=60 time=41.7 ms
    64 bytes from 10.0.10.33: icmp_seq=2 ttl=60 time=41.5 ms
    64 bytes from 10.0.10.33: icmp_seq=3 ttl=60 time=41.4 ms
    64 bytes from 10.0.10.33: icmp_seq=4 ttl=60 time=41.6 ms
    64 bytes from 10.0.10.33: icmp_seq=5 ttl=60 time=41.7 ms
    64 bytes from 10.0.10.33: icmp_seq=6 ttl=60 time=41.9 ms
    64 bytes from 10.0.10.33: icmp_seq=7 ttl=60 time=41.4 ms
    64 bytes from 10.0.10.33: icmp_seq=8 ttl=60 time=41.4 ms
    64 bytes from 10.0.10.33: icmp_seq=9 ttl=60 time=41.3 ms
    ^Z
    [7]+  Stopped                 ping 10.0.10.33
    [root@xxx ~]#

    Os pacotes de resposta echo na saída confirmam que o data center 2 está conectado aos outros sites.

Testar conectividade do data center 3 para VPC1, VPC2, data center 1, data center 2 e data center 4.

  1. Faça login na interface de linha de comando de um cliente no data center 3.

  2. No cliente, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>

    [root@xxx ~]# ping 192.168.99.48 PING 192.168.99.48 (192.168.99.48) 56(84) bytes of data. 64 bytes from 192.168.99.48: icmp_seq=1 ttl=61 time=34,4 ms 64 bytes from 192.168.99.48: icmp_seq=2 ttl=61 time=33,2 ms 64 bytes from 192.168.99.48: icmp_seq=3 ttl=61 time=33,8 ms 64 bytes from 192.168.99.48: icmp_seq=4 ttl=61 time=33,6 ms ^Z [1]+ Stopped ping 192.168.99.48 [root@xxx ~]# ping 172.16.10.207 PING 172.16.10.207 (172.16.10.207) 56(84) bytes of data. 64 bytes from 172.16.10.207: icmp_seq=1 ttl=59 time=43,3 ms 64 bytes from 172.16.10.207: icmp_seq=2 ttl=59 time=40,5 ms 64 bytes from 172.16.10.207: icmp_seq=3 ttl=59 time=40,7 ms 64 bytes from 172.16.10.207: icmp_seq=4 ttl=59 time=40,4 ms ^Z [2]+ Stopped ping 172.16.10.207 [root@xxx ~]# ping 172.16.40.60 PING 172.16.40.60 (172.16.40.60) 56(84) bytes of data. 64 bytes from 172.16.40.60: icmp_seq=1 ttl=59 time=40,3 ms 64 bytes from 172.16.40.60: icmp_seq=2 ttl=59 time=39,6 ms 64 bytes from 172.16.40.60: icmp_seq=3 ttl=59 time=39,3 ms 64 bytes from 172.16.40.60: icmp_seq=4 ttl=59 time=39,3 ms ^Z [3]+ Stopped ping 172.16.40.60 [root@xxx ~]# ping 10.30.66.11 PING 10.30.66.11 (10.30.66.11) 56(84) bytes of data. 64 bytes from 10.30.66.11: icmp_seq=1 ttl=62 time=11,6 ms 64 bytes from 10.30.66.11: icmp_seq=2 ttl=62 time=10,8 ms 64 bytes from 10.30.66.11: icmp_seq=3 ttl=62 time=11,3 ms 64 bytes from 10.30.66.11: icmp_seq=4 ttl=62 time=11,3 ms ^Z [4]+ Stopped ping 10.30.66.11 [root@xxx ~]# ping 10.0.10.33 PING 10.0.10.33 (10.0.10.33) 56(84) bytes of data. 64 bytes from 10.0.10.33: icmp_seq=1 ttl=63 time=4,81 ms 64 bytes from 10.0.10.33: icmp_seq=2 ttl=63 time=4,68 ms 64 bytes from 10.0.10.33: icmp_seq=3 ttl=63 time=4,71 ms 64 bytes from 10.0.10.33: icmp_seq=4 ttl=63 time=4,66 ms ^Z [5]+ Stopped ping 10.0.10.33

    Os pacotes de resposta echo na saída confirmam que o data center 3 está conectado aos outros sites.

Testar conectividade do data center 4 para VPC1, VPC2, data center 1, data center 2 e data center 3.

  1. Faça login na interface de linha de comando de um cliente no data center 4.

  2. No cliente, execute o comando ping para testar a conectividade com clientes em outros sites.

    ping <client_ip_address>

    [root@xxx ~]# ping 192.168.99.48 PING 192.168.99.48 (192.168.99.48) 56(84) bytes of data. 64 bytes from 192.168.99.48: icmp_seq=1 ttl=60 time=34,4 ms 64 bytes from 192.168.99.48: icmp_seq=2 ttl=60 time=37,3 ms 64 bytes from 192.168.99.48: icmp_seq=3 ttl=60 time=34,3 ms 64 bytes from 192.168.99.48: icmp_seq=4 ttl=60 time=34,3 ms ^Z [2]+ Stopped ping 192.168.99.48 [root@xxx ~]# ping 172.16.10.207 PING 172.16.10.207 (172.16.10.207) 56(84) bytes of data. 64 bytes from 172.16.10.207: icmp_seq=1 ttl=58 time=47,0 ms 64 bytes from 172.16.10.207: icmp_seq=2 ttl=58 time=43,0 ms 64 bytes from 172.16.10.207: icmp_seq=3 ttl=58 time=43,1 ms 64 bytes from 172.16.10.207: icmp_seq=4 ttl=58 time=43,1 ms ^Z [3]+ Stopped ping 172.16.10.207 [root@xxx ~]# ping 172.16.40.60 PING 172.16.40.60 (172.16.40.60) 56(84) bytes of data. 64 bytes from 172.16.40.60: icmp_seq=1 ttl=58 time=57,8 ms 64 bytes from 172.16.40.60: icmp_seq=2 ttl=58 time=52,5 ms 64 bytes from 172.16.40.60: icmp_seq=3 ttl=58 time=52,5 ms 64 bytes from 172.16.40.60: icmp_seq=4 ttl=58 time=52,2 ms ^Z [4]+ Stopped ping 172.16.40.60 [root@xxx ~]# ping 10.10.10.201 PING 10.10.10.201 (10.10.10.201) 56(84) bytes of data. 64 bytes from 10.10.10.201: icmp_seq=1 ttl=61 time=11,2 ms 64 bytes from 10.10.10.201: icmp_seq=2 ttl=61 time=10,4 ms 64 bytes from 10.10.10.201: icmp_seq=3 ttl=61 time=16,4 ms 64 bytes from 10.10.10.201: icmp_seq=4 ttl=61 time=12,8 ms ^Z [6]+ Stopped ping 10.10.10.201 [root@xxx ~]# ping 10.0.10.33 PING 10.0.10.33 (10.0.10.33) 56(84) bytes of data. 64 bytes from 10.0.10.33: icmp_seq=1 ttl=62 time=7,28 ms 64 bytes from 10.0.10.33: icmp_seq=2 ttl=62 time=7,09 ms 64 bytes from 10.0.10.33: icmp_seq=3 ttl=62 time=8,54 ms 64 bytes from 10.0.10.33: icmp_seq=4 ttl=62 time=6,89 ms ^Z [7]+ Stopped ping 10.0.10.33 [root@xxx ~]#

    Os pacotes de resposta echo na saída confirmam que o data center 4 está conectado aos outros sites.