Help Center/ Direct Connect/ Best Practices/ Connecting an On-Premises Data Center to a VPC over a Single Connection and Using BGP Routing to Route Traffic
Updated on 2024-12-16 GMT+08:00

Connecting an On-Premises Data Center to a VPC over a Single Connection and Using BGP Routing to Route Traffic

Overview

Connect your on-premises network to the cloud network and use BGP routes to route traffic between your on-premises network and the VPC.

Prerequisites

  • Your on-premises network must use a single-mode fiber with a 1GE, 10GE, 40GE, or 100GE optical module to connect to the access device in the cloud.
  • Auto-negotiation for the port must be disabled. Port speed and full-duplex mode must be manually configured.
  • 802.1Q VLAN encapsulation is supported on your on-premises network.
  • On-premises devices must support BGP and cannot use ASN 64512, which is used by Huawei Cloud.

Typical Topology

Your on-premises network is connected to a VPC over a single connection.

For details on how to create a VPC, see the Creating a VPC.

The following table lists the CIDR blocks used in this example:
Table 1 CIDR blocks

Item

CIDR Block

Your on-premises network

10.1.123.0/24

Local and remote gateways (addresses for interconnection)

10.0.0.0/30

VPC

192.168.0.0/16

Figure 1 Accessing a VPC over a connection though BGP routes

Procedure

  1. Create a connection.

    1. Go to the Connections page.
    2. In the upper left corner of the page, click and select a region and project.
    3. In the upper right corner, click Create Connection.
    4. On the Create Connection page, enter the equipment room details and select the Direct Connect location and port based on Table 2.
      Figure 2 Creating a connection
      Table 2 Parameters for creating a connection

      Parameter

      Example Value

      Description

      Billing Mode

      Yearly/Monthly

      Specifies how you will be billed for the connection. Currently, only Yearly/Monthly is supported.

      Region

      EU-Dublin

      Specifies the region where the connection resides. You can also change the region in the upper left corner of the console.

      Connection Name

      dc-123

      Specifies the name of your connection.

      Location

      Dublin

      Specifies the Direct Connect location where your leased line can be connected to.

      Carrier

      China Telecom

      Specifies the carrier that provides the leased line.

      Port Type

      1GE single-mode optical port

      Specifies the type of the port that the leased line is connected to. The options are as follows: 1GE, 10GE.

      Leased Line Bandwidth (Mbit/s)

      100

      Specifies the bandwidth of the line you need to lease from the carrier.

      Equipment Room Address

      Room xx, xx building, xx road, xx district, xx city

      Specifies the address of your equipment room. The address must be specific to the floor your equipment room is on.

      Tag

      example_key1

      example_value1

      Adds tags to help you identify your connection. You can change them after the connection is created.

      Description

      -

      Provides supplementary information about the connection.

      Required Duration

      5

      Specifies how long the connection will be used for.

      Auto-renew

      5

      Specifies whether to automatically renew the subscription to ensure service continuity.

      For example, if you select this option and the required duration is three months, the system automatically renews the subscription for another three months.

      Enterprise Project

      default

      Specifies the enterprise project by which connections are centrally managed. Select an existing enterprise project.

    5. Click Confirm Configuration.
    6. Confirm the configuration and click Pay Now.
    7. Confirm the order, select a payment method, and click Confirm.
    8. After you have paid for the order, a connection ID is allocated to you automatically, and the connection information is displayed on the management console. You will be contacted to confirm the construction plan and relevant information (including your company name, constructor, expected construction time, and construction workers).
    9. After having confirmed the construction plan, you can arrange the carrier to deploy the dedicated line and connect it to your equipment room based on your construction plan.
    10. In normal cases, Huawei onsite engineers will connect the dedicated line to the Huawei Cloud gateway port within two working days.
    11. Verify that the connection is in the Normal state, which means that the connection is ready, and the billing starts.

  2. Create a virtual gateway.

    1. In the navigation pane on the left, choose Direct Connect > Virtual Gateways.
    2. Click Create Virtual Gateway.
    3. Configure the parameters based on Table 3.
      Figure 3 Creating a virtual gateway
      Table 3 Parameters required for creating a virtual gateway

      Parameter

      Example Value

      Description

      Name

      vgw-123

      Specifies the virtual gateway name.

      The name can contain 1 to 64 characters.

      Enterprise Project

      default

      Specifies the enterprise project by which virtual gateways are centrally managed. Select an existing enterprise project.

      VPC

      VPC-001

      Specifies the VPC to be associated with the virtual gateway.

      Local Subnet

      192.168.0.0/16

      Specifies the CIDR blocks of the subnets in the VPC to be accessed using Direct Connect.

      You can add one or more CIDR blocks. If there are multiple CIDR blocks, separate every entry with a comma (,).

      BGP ASN

      64512

      Specifies the BGP ASN of the virtual gateway.

      Tag

      -

      Adds tags to help you identify your virtual gateway. You can change them after the virtual gateway is created.

      Description

      -

      Provides supplementary information about the virtual gateway.

    4. Click OK.

  3. Create a virtual interface.

    1. In the navigation pane on the left, choose Direct Connect > Virtual Interfaces.
    2. In the upper right corner, click Create Virtual Interface.
    3. Configure the parameters based on Table 4.
      Figure 4 Creating a virtual interface for your own account
      Table 4 Parameters for creating a virtual interface

      Parameter

      Example Value

      Description

      Virtual Interface Owner

      Current account

      Specifies the account that this virtual interface will be created for.

      Region

      EU-Dublin

      Specifies the region where the connection resides. You can also change the region in the upper left corner of the console.

      Name

      vif-test

      Specifies the virtual interface name.

      The name can contain 1 to 64 characters.

      Virtual Interface Priority

      -

      Specifies whether the virtual interface will be used prior to other virtual interfaces. There are two options: Preferred and Standard.

      If multiple virtual interfaces are associated with one Direct Connect device, the load is balanced among virtual interfaces with the same priority, while virtual interfaces with different priorities are working in active/standby pairs.

      Connection

      dc-test12

      Specifies the connection you can use to connect your on-premises network to Huawei Cloud.

      Gateway

      vgw-test

      Specifies the gateway that the virtual interface connects to.

      You can select a virtual gateway or global DC gateway.

      In this example, select a virtual gateway.

      VLAN

      30

      Specifies the ID of the VLAN for the virtual interface.

      • Standard connections: You need to configure the VLAN.
      • Hosted connections: The VLAN will be allocated by the carrier or partner. You do not need to configure the VLAN.

      Bandwidth (Mbit/s)

      1000

      Specifies the bandwidth that can be used by the virtual interface. The bandwidth cannot exceed that of the connection.

      Enterprise Project

      default

      Specifies the enterprise project by which virtual interfaces are centrally managed. Select an existing enterprise project.

      Tag

      -

      Adds tags to help you identify your virtual interface. You can change them after the virtual interface is created.

      Local Gateway

      10.0.0.1/30

      Specifies the IP address used by the cloud to connect to your on-premises network. After you configure Local Gateway on the console, the configuration will be automatically delivered to the gateway used by the cloud.

      Remote Gateway

      10.0.0.2/30

      Specifies the IP address used by the on-premises data center to connect to the cloud. After you configure Remote Gateway on the console, you need to configure the IP address on the interface of the on-premises device.

      CAUTION:

      The IP addresses of the local gateway and remote gateway must be in the same IP address range. Generally, an IP address range with a 30-bit mask is used. The IP addresses you plan cannot conflict with IP addresses used on your on-premises network. Plan an IP address range that will be used at both ends of the connection for network communication between your on-premises data center and the cloud.

      Remote Subnet

      10.1.123.0/24

      Specifies the subnets and masks of your on-premises network. If there are multiple subnets, use commas (,) to separate them.

      Routing Mode

      BGP

      Specifies whether static routing or dynamic routing is used to route traffic between your on-premises network and the cloud network.

      If there are or will be two or more connections, select BGP routing for higher availability.

      BGP ASN

      64510

      Specifies the ASN of the BGP peer.

      This parameter is required when BGP routing is selected.

      BGP MD5 Authentication Key

      1234567

      Specifies the password used to authenticate the BGP peer using MD5.

      This parameter can be set when BGP routing is selected, and the parameter values on both gateways must be the same.

      The key contains 8 to 255 characters and must contain at least two types of the following characters:

      • Uppercase letters
      • Lowercase letters
      • Digits
      • Special characters ~!,.:;-_"(){}[]/@#$%^&*+\|=

      Description

      -

      Provides supplementary information about the virtual interface.

    4. Click Create Now.

      The default security group rule denies all the inbound traffic. Ensure that security group rules in both directions are correctly configured to ensure normal communications.

  4. Wait for route advertisement from the cloud.

    Direct Connect automatically delivers the routes after a connection is established between your on-premises network and the cloud network.

  5. Configure routes on your on-premises network device.

    Example route (A Huawei-developed device is used an example.)

    bgp 64510
    peer 10.0.0.1 as-number 64512
    peer 10.0.0.1 password simple 1234567
    network 10.1.123.0 255.255.255.0