Creates a routing policy. A routing policy filters routing information and facilitates network management.
Operation description
Routing policies are sorted by priority. A smaller value indicates a higher priority. Each routing policy is a collection of conditional statements and execution statements. Starting from the routing policy with the highest priority, the system matches routes against the match conditions specified by routing policies. If a route meets all the match conditions of a routing policy, the system permits or denies the route based on the action specified in the routing policy. You can also modify the attributes of permitted routes. By default, the system permits routes that meet none of the match conditions. For more information, see Routing policy overview.
CreateCenRouteMap
is an asynchronous operation. After you send a request, the routing policy ID is returned but the operation is still being performed in the system background. You can call DescribeCenRouteMaps
to query the status of a routing policy.
- If a routing policy is in the Creating state, the routing policy is being created. In this case, you can query the routing policy but cannot perform other operations.
- If a routing policy is in the Active state, the routing policy is created.
Debugging
Authorization information
The following table shows the authorization information corresponding to the API. The authorization information can be used in the Action
policy element to grant a RAM user or RAM role the permissions to call this API operation. Description:
- Operation: the value that you can use in the Action element to specify the operation on a resource.
- Access level: the access level of each operation. The levels are read, write, and list.
- Resource type: the type of the resource on which you can authorize the RAM user or the RAM role to perform the operation. Take note of the following items:
- The required resource types are displayed in bold characters.
- If the permissions cannot be granted at the resource level,
All Resources
is used in the Resource type column of the operation.
- Condition Key: the condition key that is defined by the cloud service.
- Associated operation: other operations that the RAM user or the RAM role must have permissions to perform to complete the operation. To complete the operation, the RAM user or the RAM role must have the permissions to perform the associated operations.
Operation | Access level | Resource type | Condition key | Associated operation |
---|---|---|---|---|
cen:CreateCenRouteMap | create |
|
| none |
Request parameters
Parameter | Type | Required | Description | Example |
---|---|---|---|---|
CenId | string | Yes | The ID of the CEN instance. | cen-7qthudw0ll6jmc**** |
CenRegionId | string | Yes | The ID of the region in which the routing policy is applied. You can call the DescribeChildInstanceRegions operation to query the most recent region list. | cn-hangzhou |
TransmitDirection | string | Yes | The direction in which the routing policy is applied. Valid values:
For example, routes are advertised from network instances deployed in the current region or other regions to the gateway deployed in the current region.
For example, routes are advertised from the gateway deployed in the current region to network instances deployed in the same region, or to gateways deployed in other regions. | RegionIn |
Description | string | No | The description of the routing policy. This parameter is optional. If you enter a description, it must be 1 to 256 characters in length and cannot start with http:// or https://. | desctest |
Priority | integer | Yes | The priority of the routing policy. Valid values: 1 to 100. A smaller value indicates a higher priority. Note
You cannot specify the same priority for routing policies that apply in the same region and direction. The system matches routes against the match conditions of routing policies in descending order of priority. A smaller value indicates a higher priority. You must set the priorities to proper values.
| 3 |
MapResult | string | Yes | The action to be performed on a route that meets all the match conditions. Valid values:
| Permit |
NextPriority | integer | No | The priority of the routing policy that you want to associate with the current one.
| 20 |
CidrMatchMode | string | No | The match method that is used to match routes against the prefix list. Valid values:
For example, if you set the match condition to 1.1.0.0/16 and fuzzy match is applied, the route whose prefix is 1.1.1.0/24 meets the match condition.
For example, if you set the match condition to 1.1.0.0/16 and exact match is applied, only the route whose prefix is 1.1.0.0/16 meets the match condition. | Include |
AsPathMatchMode | string | No | The match method that is used to match routes based on the AS path. Valid values:
| Include |
CommunityMatchMode | string | No | The match method that is used to match routes based on the community. Valid values:
| Include |
CommunityOperateMode | string | No | The action to be performed on the community. Valid values:
This parameter specifies the action to be performed when a route meets the match condition. | Additive |
Preference | integer | No | The new priority of the route. Valid values: 1 to 100. The default priority is 50. A smaller value indicates a higher priority. This parameter specifies the action to be performed when a route meets the match condition. | 50 |
SourceInstanceIdsReverseMatch | boolean | No | Specifies whether to exclude source instance IDs. Valid values:
| false |
DestinationInstanceIdsReverseMatch | boolean | No | Specifies whether to exclude destination instance IDs. Valid values:
| false |
MatchAddressType | string | No | The type of IP address in the match condition. Valid values:
This parameter can be empty. If no value is specified, all types of IP address are a match. | IPv4 |
TransitRouterRouteTableId | string | No | The ID of the route table of the transit router. If you do not specify a route table ID, the routing policy is automatically associated with the default route table of the transit router. | vtb-gw8nx3515m1mbd1z1**** |
SourceInstanceIds | array | No | The IDs of the source network instances to which the routes belong. The following network instance types are supported:
You can enter at most 32 IDs. | |
string | No | The IDs of the source network instances to which the routes belong. The following network instance types are supported:
You can enter at most 32 IDs. | vpc-adeg3544fdf34vf**** | |
DestinationInstanceIds | array | No | The IDs of the destination network instances to which the routes belong. The following network instance types are supported:
You can enter at most 32 IDs. Note
The destination instance IDs take effect only when Direction is set to Export from Regional Gateway and the destination instances are deployed in the current region.
| |
string | No | The IDs of the destination network instances to which the routes belong. The following network instance types are supported:
You can enter at most 32 IDs. Note
The destination instance IDs take effect only when Direction is set to Export from Regional Gateway and the destination instances are deployed in the current region.
| vpc-afrfs434465fdf**** | |
SourceRouteTableIds | array | No | The IDs of the source route tables from which routes are evaluated. You can enter at most 32 route table IDs. | |
string | No | The IDs of the source route tables from which routes are evaluated. You can enter at most 32 route table IDs. | vtb-adfr233vf34rvd4**** | |
DestinationRouteTableIds | array | No | The IDs of the destination route tables to which routes are evaluated. You can enter at most 32 route table IDs. Note
The destination route table IDs take effect only when Direction is set to Export from Regional Gateway and the destination route tables belong to network instances deployed in the current region.
| |
string | No | The IDs of the destination route tables to which routes are evaluated. You can enter at most 32 route table IDs. Note
The destination route table IDs take effect only when Direction is set to Export from Regional Gateway and the destination route tables belong to network instances deployed in the current region.
| vtb-adefrgtr144vf**** | |
SourceRegionIds | array | No | The IDs of the source regions from which routes are evaluated. You can enter at most 32 region IDs. You can call the DescribeChildInstanceRegions operation to query the most recent region list. | |
string | No | The IDs of the source regions from which routes are evaluated. You can enter at most 32 region IDs. You can call the DescribeChildInstanceRegions operation to query the most recent region list. | cn-beijing | |
SourceChildInstanceTypes | array | No | The types of source network instance to which the routes belong. The following types of network instances are supported:
You can specify one or more network instance types. | |
string | No | The types of source network instance to which the routes belong. The following types of network instances are supported:
You can specify one or more network instance types. | VPC | |
DestinationChildInstanceTypes | array | No | The types of destination network instance to which the routes belong. The following types of network instances are supported:
You can specify one or more network instance types. Note
The destination network instance types are valid only if the routing policy is applied to scenarios where routes are advertised from the gateway in the current region to network instances in the current region.
| |
string | No | The types of destination network instance to which the routes belong. The following types of network instances are supported:
You can specify one or more network instance types. Note
The destination network instance types are valid only if the routing policy is applied to scenarios where routes are advertised from the gateway in the current region to network instances in the current region.
| VPC | |
DestinationCidrBlocks | array | No | The prefix list against which routes are matched. Specify IP addresses in CIDR notations. You can specify at most 32 CIDR blocks. IPv4 and IPv4 addresses are supported. | |
string | No | The prefix list against which routes are matched. Specify IP addresses in CIDR notations. You can specify at most 32 CIDR blocks. IPv4 and IPv4 addresses are supported. | 10.10.10.0/24 | |
RouteTypes | array | No | The type of route to be compared. Valid values: The following route types are supported:
You can specify multiple route types. | |
string | No | The type of route to be compared. Valid values: The following route types are supported:
You can specify multiple route types. | System | |
MatchAsns | array | No | The AS paths based on which routes are compared. You can specify at most 32 AS numbers. Note
Only the AS-SEQUENCE parameter is supported. The AS-SET, AS-CONFED-SEQUENCE, and AS-CONFED-SET parameters are not supported. In other words, only the AS number list is supported. Sets and sub-lists are not supported.
| |
long | No | The AS paths based on which routes are compared. You can specify at most 32 AS numbers. Note
Only the AS-SEQUENCE parameter is supported. The AS-SET, AS-CONFED-SEQUENCE, and AS-CONFED-SET parameters are not supported. In other words, only the AS number list is supported. Sets and sub-lists are not supported.
| 65501 | |
MatchCommunitySet | array | No | The community set based on which routes are compared. Specify the community in the format of n:m. Valid values of n and m: 1 to 65535. Each community must comply with the RFC 1997 standard. The RFC 8092 standard that defines Border Gateway Protocol (BGP) large communities is not supported. You can specify at most 32 communities. Note
If the configurations of the communities are incorrect, routes may fail to be advertised to your data center.
| |
string | No | The community set based on which routes are compared. Specify the community in the format of n:m. Valid values of n and m: 1 to 65535. Each community must comply with the RFC 1997 standard. The RFC 8092 standard that defines Border Gateway Protocol (BGP) large communities is not supported. You can specify at most 32 communities. Note
If the configurations of the communities are incorrect, routes may fail to be advertised to your data center.
| 65501:1 | |
OperateCommunitySet | array | No | The community set on which actions are performed. Specify the community in the format of n:m. Valid values of n and m: 1 to 65535. Each community must comply with RFC 1997. The RFC 8092 standard that defines BGP large communities is not supported. You can specify at most 32 communities. Note
If the configurations of the communities are incorrect, routes may fail to be advertised to your data center.
| |
string | No | The community set on which actions are performed. Specify the community in the format of n:m. Valid values of n and m: 1 to 65535. Each community must comply with RFC 1997. The RFC 8092 standard that defines BGP large communities is not supported. You can specify at most 32 communities. Note
If the configurations of the communities are incorrect, routes may fail to be advertised to your data center.
| 65501:1 | |
PrependAsPath | array | No | The AS paths that are prepended by using an action statement when regional gateways receive or advertise routes. The AS paths vary based on the direction in which the routing policy is applied:
This parameter specifies the action to be performed when a route meets the match condition. You can specify at most 32 AS numbers. | |
long | No | The AS paths that are prepended by using an action statement when regional gateways receive or advertise routes. The AS paths vary based on the direction in which the routing policy is applied:
This parameter specifies the action to be performed when a route meets the match condition. You can specify at most 32 AS numbers. | 65501 | |
DestinationRegionIds | array | No | The destination region IDs of the route. You can specify at most 32 region IDs. | |
string | No | The destination region IDs of the route. You can specify at most 32 region IDs. | cn-beijing |
Response parameters
Examples
Sample success responses
JSON
format
{
"RouteMapId": "cenrmap-w4yf7toozfol3q****",
"RequestId": "62172DD5-6BAC-45DF-8D44-56SDF467BAC"
}
Error codes
HTTP status code | Error code | Error message | Description |
---|---|---|---|
400 | Forbidden.CenRouteMapExist | The specified CEN route map ID already exists. | The specified CEN route map ID already exists. |
400 | Invid.Parameter | When using PrependAsPath in the RegionIn, SourceRegionId must be local region Id. | - |
400 | InvalidOperation.NoEffictiveAction | No effective action be configured. | The error message returned because the specified action is invalid. |
400 | Invid.Parameter | When using GatewayRegionId, SourceRegionId must not be null | The error message returned because the GatewayRegionId and SourceRegionId parameters must be set. |
400 | Invid.Parameter | When using GatewayRegionId, GatewayZoneId must not be null | The error message returned because the GatewayRegionId and GatewayZoneId parameters must be set. |
400 | Invid.Parameter | When using GatewayRegionId, SourceRegionId must not be the same with tr region id | The error message returned because the specified gateway region ID (GatewayRegionId) and source region ID (SourceRegionId) cannot be the same. |
400 | Invid.Parameter | GatewayRegionId is invalid | The error message returned because the gateway region ID (GatewayRegionId) is invalid. |
400 | Invid.Parameter | TransitRouter not exist. | The error message returned because the specified transit router does not exist. |
400 | Invid.Parameter | SourceInstanceId is invalid. | The error message returned because the specified source instance ID (SourceInstanceId) is invalid. |
400 | Invid.Parameter | DestinationInstanceId is invalid. | The error message returned because the specified destination instance ID (DestinationInstanceId) is invalid. |
400 | IncorrectStatus.TransitRouterInstance | The status of TransitRouter is incorrect. | The error message returned because the transit router is in an invalid state. |
400 | InvalidDescription | Description is invalid. | The error message returned because the description is invalid. |
400 | IllegalParam.ZoneId | The specified ZoneId is illegal. | The error message returned because the specified zone is invalid. |
400 | InvalidParameter | Invalid parameter. | The error message returned because the parameter is set to an invalid value. |
400 | Unauthorized | The AccessKeyId is unauthorized. | The error message returned because you do not have the permissions to perform this operation. |
For a list of error codes, visit the Service error codes.
Change history
Change time | Summary of changes | Operation |
---|---|---|
2024-09-18 | The Error code has changed. The request parameters of the API has changed | View Change Details |
2024-09-10 | The Error code has changed. The request parameters of the API has changed | View Change Details |
2024-09-10 | The Error code has changed. The request parameters of the API has changed | View Change Details |
2023-12-13 | The Error code has changed | View Change Details |
2022-07-19 | The Error code has changed. The request parameters of the API has changed | View Change Details |