Selecting a Networking Scheme
| Scheme | Networking Architecture | Network Path Description | Configuration Guide | Remarks |
|---|---|---|---|---|
| Scheme 1 | Two service VPCs (VPC-A and VPC-B) and the Direct Connect virtual gateway are attached to an enterprise router. |
|
| For details, see How Do I Select a Networking Scheme? |
| Scheme 2 | The two service VPCs (VPC-A and VPC-B) are not attached to the enterprise router. Instead, a transit VPC (VPC-Transit) is used. The transit VPC and the Direct Connect virtual gateway are attached to the enterprise router. |
| Using Enterprise Router and a Transit VPC to Allow an On-premises Data Center to Access Service VPCs |
How Do I Select a Networking Scheme?
- Scheme 2 uses less traffic and fewer attachments.
- Traffic between service VPCs is routed through VPC peering connections instead of enterprise routers, reducing traffic costs.
- Only the transit VPC is attached to the enterprise router. You can pay less for the attachments.
- Scheme 2 frees you from the following constraints that scheme 1 has on attaching service VPCs to an enterprise router:
- If a service VPC is used by a shared load balancer, VPC endpoint, private NAT gateway, or DCS resource, contact customer service to confirm the service compatibility and preferentially use a transit VPC for networking.
- Traffic cannot be forwarded from a VPC to its attached enterprise router if the destination of a route with an enterprise router as the next hop is set to 0.0.0.0/0 in the VPC route table and if:
- An ECS in the VPC has an EIP bound.
- The VPC is being used by ELB (either dedicated or shared load balancers), NAT Gateway, VPC Endpoint, or DCS.
- If a VPC attached to an enterprise router has a NAT gateway associated and Scenario of the SNAT or DNAT rules is set to Direct Connect, the network from the on-premises data center to the VPC is disconnected.
If you still want to use scheme 1 to attach service VPCs to an enterprise router, contact customer service to evaluate the feasibility.