All Products
Search
Document Center

Express Connect:Create and manage an ECR

Last Updated:Nov 08, 2024

You can use an Express Connect Router (ECR) to connect a data center to a virtual private cloud (VPC). The ECR connection provides higher performance, supports high specifications, and reduces latency.

Limits

The local autonomous system number (ASN) of the Border Gateway Protocol (BGP) group of the virtual border router (VBR) associated with the ECR must be the same as the ASN of the ECR. If the ASN of the ECR is not 45104, you must associate a VBR with the ECR and configure BGP for the VBR.

Prerequisites

  • A virtual border router (VBR) to be associated with an ECR is created. For more information, see Create and manage a VBR.

  • A VPC is created before you associate an ECR with the VPC. For more information, see Create and manage a VPC.

  • A transit router (TR) is created before you associate an ECR with the TR. For more information, see the "Create a transit router" section of the Transit routers topic.

Create an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, click Create ECR.

  3. In the Create ECR dialog box, configure the parameters that are described in the following table, select I have read and understand the billing rules, and then click OK.

    Parameter

    Description

    Name

    The name of the ECR.

    ASN

    The ASN of the ECR. Default value: 45104. Valid values: 45104, 64512 to 65534, and 4200000000 to 4294967294. The value of 65025 is reserved by Alibaba Cloud.

    Resource Group

    Select the resource group to which the ECR belongs.

    Tag Key

    Select or enter a tag key.

    Tag Value

    Select or enter a tag value.

    Description

    The description of the ECR.

Associate a VBR with an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

  3. Click the VBR tab. On the VBR tab, click Associate VBR.

  4. In the Associate VBR dialog box, configure the parameters described in the following table and click OK.

    Parameter

    Description

    Resource Owner

    The type of the account to which the VBR belongs. Valid values:

    • Current Account: The VBR and the ECR belong to the same account.

    • Another Account: If you want to associate a VBR with the ECR across accounts, you must authorize the ECR that belongs to the current Alibaba Cloud account to access the VBR that belongs to another Alibaba Cloud account. For more information, see the "Grant permissions to the ECR by using the VBR" section of the Grant permissions to an ECR across Alibaba Cloud accounts topic.

    Region

    The region in which the VBR resides.

    Peer Account UID

    The ID of the Alibaba Cloud account to which the VPC belongs.

    Note

    This parameter is required if you set the Resource Owner parameter to Another Account.

    Network Instance

    The name or ID of the VBR.

    Allow Business Access Between Data Centers

    Specifies whether to allow data centers to access each other.

    Note

    By default, this feature is disabled. If you want to use the feature, contact your Alibaba Cloud account manager to apply for enabling the feature.

Associate a VPC with an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

  3. Click the VPC tab. On the VPC tab, click Associate VPC.

  4. In the Associate VPC dialog box, configure the parameters described in the following table and click OK.

    Parameter

    Description

    Resource Owner

    The type of the account to which the VPC belongs. Valid values:

    • Current Account: The VPC and the ECR belong to the same account.

    • Another Account: If you want to associate a VPC with the ECR across accounts, you must authorize the ECR that belongs to the current Alibaba Cloud account to access the VPC that belongs to another Alibaba Cloud account For more information, see the "Grant permissions to the ECR by using the VPC" section of the Grant permissions to an ECR across Alibaba Cloud accounts topic.

    Region

    The region in which the VPC resides.

    Peer Account UID

    The ID of the Alibaba Cloud account to which the VPC belongs.

    Note

    This parameter is required if you set the Resource Owner parameter to Another Account.

    VPC ID

    The ID of the VPC.

    Allowed Route Prefixes

    The route prefixes that you want to advertise to the local network by using the ECR. After you specify a CIDR block, the route of the VPC is not advertised to the local network.

    Important
    • You can add IPv4 and IPv6 route prefixes to an ECR.

    • After you configure allowed route prefixes, Express Connect withdraws the routes that are advertised to a data center, and advertises the configured route prefixes to the data center. If you delete the allowed route prefixes, Express Connect advertises the specific routes to the data center again.

Associate a TR with an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

  3. Click the TR tab. On the TR tab, click Associate TR.

  4. In the Associate TR dialog box, configure the parameters that are described in the following table and click OK.

    Parameter

    Description

    CEN ID

    The ID of the CEN instance to which the TR belongs.

    Region

    The region in which the TR resides.

    TR

    The ID or name of the TR.

    Allowed Route Prefixes

    The route prefixes that you want to advertise to the local network by using the ECR. After you specify a CIDR block, the routes in the route table of the TR are not advertised to the local network.

    Note

    After the allowed route prefixes are configured, Express Connect withdraws the routes in the route table of the TR that are advertised to a data center and advertises the allowed route prefixes to the data center. If the allowed route prefixes are deleted or not configured, Express Connect automatically advertises the routes in the route table of the TR to the data center.

    Advanced Settings

    The system selects the following settings by default. To modify the settings, click Edit. On the page that appears, modify the settings.

    • Associate with Default Route Table of Transit Router

      After this feature is enabled, the ECR is automatically associated with the default route table of the transit router. The transit router forwards network traffic from the ECR by querying the default route table.

    • Propagate System Routes to Default Route Table of Transit Router

      After this feature is enabled, the ECR advertises the BGP routes learned from the VBR to the default route table of the transit router for communication between network instances.

    • Advertise Routes to ECR

      After this feature is enabled, the transit router automatically advertises routes to the ECR.

Update route prefixes

To update route prefixes for the VPC and the TR that are associated with the ECR, perform the following operations:

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

    • Update the route prefixes for the VPC.

      1. On the VPC tab, find the VPC for which you want to update the route prefixes and click the edit.png icon in the Dynamic CIDR Block Propagation column.

      2. In the Update Prefix List dialog box, enter the allowed route prefixes.

      3. Agree to the agreement and click OK.

    • Update the route prefixes for the TR.

      1. On the TR tab, find the TR for which you want to update the route prefixes and click the edit.png icon in the Dynamic CIDR Block Propagation column.

      2. In the Update Prefix List dialog box, enter the allowed route prefixes.

      3. Agree to the agreement and click OK.

Grant permissions to a CEN instance

Important

If you authorize a CEN instance of another account to access your network instance, the CEN instance can connect to your network. Proceed with caution.

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

  3. On the CEN Authorization tab, click Authorize CEN of Another Account to Load Instance.

  4. In the Join CEN dialog box, configure the parameters that are described in the following table and click OK.

    Parameter

    Description

    CEN Instance ID

    The ID of the CEN instance of another Alibaba Cloud account.

    CEN Account

    The ID of the Alibaba Cloud account to which the CEN instance belongs.

    Payer

    The account that pays for fees generated for connecting the CEN instance to your network instance. Valid values:

    • CEN Owner

    • ECR Owner

Disable or enable a route

You can disable a route from taking effect. After a route is disabled, you can enable the route again.

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. The details page of the ECR appears.

  3. Click the Routes tab. On the Routes tab, find the route that you want to disable or enable and click Disable or Enable in the Actions column. In the message that appears, click OK.

Delete an ECR

  1. Log on to the Express Connect console.

  2. In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to delete and click Delete in the Actions column.

  3. In the dialog box that appears, confirm that your services are not affected after you delete the ECR, and click OK.

More operations

In the left-side navigation pane, click Express Connect Router (ECR). On the Express Connect Router (ECR) page, find the ECR that you want to manage and click the name of the ECR. On the details page of the ECR, you can perform operations based on your business requirements. The following table describes the operations.

Operation

Procedure

Detach a VBR from the ECR

  1. On the VBR tab, find the VBR that you want to detach from the ECR and click Disassociate in the Actions column.

  2. In the message that appears, click OK.

Detach a TR from the ECR

  1. On the TR tab, find the TR that you want to detach from the ECR and click Disassociate in the Actions column.

  2. In the message that appears, click OK.

Detach a VPC from the ECR

  1. On the VPC tab, find the VPC that you want to detach from the ECR and click Disassociate in the Actions column.

  2. In the message that appears, click OK.

View and manage routes

  1. Routes > Current Entry. On the Current Entry tab, view the current routes.

  2. In the Actions column, click Disable or Enable to disable or enable the route.

Revoke permissions from a CEN instance

  1. On the CEN Authorization tab, find the CEN instance from which you want to revoke permissions and click Delete in the Actions column.

  2. In the Revoke Authorization message, click OK.