Compute
Elastic Cloud Server
Huawei Cloud Flexus
Bare Metal Server
Auto Scaling
Image Management Service
Dedicated Host
FunctionGraph
Cloud Phone Host
Huawei Cloud EulerOS
Networking
Virtual Private Cloud
Elastic IP
Elastic Load Balance
NAT Gateway
Direct Connect
Virtual Private Network
VPC Endpoint
Cloud Connect
Enterprise Router
Enterprise Switch
Global Accelerator
Management & Governance
Cloud Eye
Identity and Access Management
Cloud Trace Service
Resource Formation Service
Tag Management Service
Log Tank Service
Config
OneAccess
Resource Access Manager
Simple Message Notification
Application Performance Management
Application Operations Management
Organizations
Optimization Advisor
IAM Identity Center
Cloud Operations Center
Resource Governance Center
Migration
Server Migration Service
Object Storage Migration Service
Cloud Data Migration
Migration Center
Cloud Ecosystem
KooGallery
Partner Center
User Support
My Account
Billing Center
Cost Center
Resource Center
Enterprise Management
Service Tickets
HUAWEI CLOUD (International) FAQs
ICP Filing
Support Plans
My Credentials
Customer Operation Capabilities
Partner Support Plans
Professional Services
Analytics
MapReduce Service
Data Lake Insight
CloudTable Service
Cloud Search Service
Data Lake Visualization
Data Ingestion Service
GaussDB(DWS)
DataArts Studio
Data Lake Factory
DataArts Lake Formation
IoT
IoT Device Access
Others
Product Pricing Details
System Permissions
Console Quick Start
Common FAQs
Instructions for Associating with a HUAWEI CLOUD Partner
Message Center
Security & Compliance
Security Technologies and Applications
Web Application Firewall
Host Security Service
Cloud Firewall
SecMaster
Anti-DDoS Service
Data Encryption Workshop
Database Security Service
Cloud Bastion Host
Data Security Center
Cloud Certificate Manager
Edge Security
Managed Threat Detection
Blockchain
Blockchain Service
Web3 Node Engine Service
Media Services
Media Processing Center
Video On Demand
Live
SparkRTC
MetaStudio
Storage
Object Storage Service
Elastic Volume Service
Cloud Backup and Recovery
Storage Disaster Recovery Service
Scalable File Service Turbo
Scalable File Service
Volume Backup Service
Cloud Server Backup Service
Data Express Service
Dedicated Distributed Storage Service
Containers
Cloud Container Engine
SoftWare Repository for Container
Application Service Mesh
Ubiquitous Cloud Native Service
Cloud Container Instance
Databases
Relational Database Service
Document Database Service
Data Admin Service
Data Replication Service
GeminiDB
GaussDB
Distributed Database Middleware
Database and Application Migration UGO
TaurusDB
Middleware
Distributed Cache Service
API Gateway
Distributed Message Service for Kafka
Distributed Message Service for RabbitMQ
Distributed Message Service for RocketMQ
Cloud Service Engine
Multi-Site High Availability Service
EventGrid
Dedicated Cloud
Dedicated Computing Cluster
Business Applications
Workspace
ROMA Connect
Message & SMS
Domain Name Service
Edge Data Center Management
Meeting
AI
Face Recognition Service
Graph Engine Service
Content Moderation
Image Recognition
Optical Character Recognition
ModelArts
ImageSearch
Conversational Bot Service
Speech Interaction Service
Huawei HiLens
Video Intelligent Analysis Service
Developer Tools
SDK Developer Guide
API Request Signing Guide
Terraform
Koo Command Line Interface
Content Delivery & Edge Computing
Content Delivery Network
Intelligent EdgeFabric
CloudPond
Intelligent EdgeCloud
Solutions
SAP Cloud
High Performance Computing
Developer Services
ServiceStage
CodeArts
CodeArts PerfTest
CodeArts Req
CodeArts Pipeline
CodeArts Build
CodeArts Deploy
CodeArts Artifact
CodeArts TestPlan
CodeArts Check
CodeArts Repo
Cloud Application Engine
MacroVerse aPaaS
KooMessage
KooPhone
KooDrive
On this page

Show all

Help Center/ Enterprise Router/ Best Practices/ Summary on Enterprise Router Best Practices

Summary on Enterprise Router Best Practices

Updated on 2025-02-27 GMT+08:00

An enterprise router is a high-specification, high-bandwidth, and high-performance router that connects virtual private clouds (VPCs) and on-premises networks to build a central hub network. Enterprise routers use the Border Gateway Protocol (BGP) to learn, dynamically select, or switch between routes, thereby significantly improving the network scalability and O&M efficiency and ensuring the service continuity.

You can use enterprise routers together with other Huawei Cloud services to flexibly construct different networks. This document provides best practices of typical networking for your reference.

Table 1 Scenarios

Networking

Scenario

Cloud Service

Description

Cross-region network

Connecting VPCs Across Regions Using Enterprise Router and Central Network

  • Enterprise Router
  • Cloud Connect (central network)
  • VPC
  • ECS
For nearby access, an enterprise runs workloads in regions A, B, and C. The VPCs in each region need to communicate with each other. To achieve this, you can:
  1. Create an enterprise router in each region: ER-A in region A, ER-B in region B, and ER-C in region C.
  2. Create a central network and add ER-A, ER-B, and ER-C to the central network as attachments so that the three enterprise routers can communicate with each other.
  3. In region A, attach VPC-A01 and VPC-A02 to ER-A so that the two VPCs can communicate with each other. Perform the same operations in regions B and C. In this way, the VPCs in the three regions can communicate with each other over the central network.

Intra-region network

Using Enterprise Router to Isolate VPCs in the Same Region

  • Enterprise Router
  • VPC
  • ECS
There are four VPCs in a region of Huawei Cloud, with service A, service B, and service C respectively in VPC 1, VPC 2, and VPC 3, and common service in VPC 4. The network requirements are as follows:
  1. VPC 1, VPC 2, and VPC 3 need to be isolated from each other.
  2. VPC 1, VPC 2, and VPC 3 need to communicate with VPC 4.

Intra-region network

Using a Third-Party Firewall to Protect VPCs Connected by Enterprise Routers

  • Enterprise Router
  • VPC
  • ECS

There are three VPCs in a region of Huawei Cloud, with service A and service B respectively in VPC 1 and VPC 2, and the third-party firewall in VPC 3. For security purposes, the traffic to service A and service B must be filtered by the firewall in VPC 3.

Hybrid cloud network

Using Enterprise Router and a Transit VPC to Allow an On-Premises Data Center to Access Service VPCs

  • Enterprise Router
  • Direct Connect (virtual gateway)
  • VPN
  • VPC
  • ECS

You can use enterprise routers to build a central network and to simplify the network architecture. There are two typical networking schemes. One is to attach the service VPCs to the enterprise router. The other is to use a transit VPC to build a network, together with VPC Peering and Enterprise Router. Compared with scheme 1, scheme 2 costs less and eliminates some restrictions.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router and Direct Connect Global DC Gateway

  • Enterprise Router
  • Direct Connect (global DC gateway)
  • VPC
  • ECS

Suppose your enterprise has deployed two VPCs in a region. The two VPCs need to communicate with each other and communicate with your on-premises data center through a global DC gateway.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router and a Pair of Direct Connect Connections (Global DC Gateway)

  • Enterprise Router
  • Direct Connect (global DC gateway)
  • VPC
  • ECS

Direct Connect establishes a dedicated, secure, stable, and high-speed network connection between your on-premises data center and VPCs. Direct Connect now provides global DC gateways that allow you to build a large-scale hybrid cloud network globally.

To improve the performance and reliability of the hybrid cloud network, your enterprise uses two Direct Connect connections to connect your on-premises data center to the VPCs. The two Direct Connect connections work in load balancing mode. When both connections are working normally, network transmission is greatly improved. If one connection is faulty, the other connection ensures the normal running of the hybrid cloud network and thereby prevents service interruptions caused by a single connection
  • The two VPCs can communicate with each other and communicate with the on-premises data center over two Direct Connect connections and an enterprise router.
  • When one Direct Connect connection is faulty, the two VPCs can communicate with the on-premises data center over the normal connection.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router and a Pair of Active/Standby Direct Connect Connections (Global DC Gateway)

  • Enterprise Router
  • Direct Connect (global DC gateway)
  • VPC
  • ECS

Direct Connect establishes a dedicated, secure, stable, and high-speed network connection between your on-premises data center and VPCs. Direct Connect now provides global DC gateways that allow you to build a large-scale hybrid cloud network globally.

To improve the reliability of the hybrid cloud network and reduce costs, your enterprise uses a pair of active/standby Direct Connect connections to connect your on-premises data center to the VPCs. Both connections are associated with one enterprise router for automatic switchover. If the active connection becomes faulty, the standby one automatically takes over, which minimizes service interruptions.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router, VPN, and Direct Connect (Global DC Gateway)

  • Enterprise Router
  • Direct Connect (global DC gateway)
  • VPN
  • VPC
  • ECS

Direct Connect establishes a dedicated, secure, stable, and high-speed network connection between your on-premises data center and VPCs. Direct Connect now provides global DC gateways that allow you to build a large-scale hybrid cloud network globally.

VPN establishes a secure, encrypted communication tunnel between your on-premises data center and your VPC. Compared with Direct Connect, VPN is cost-effective and can be quickly deployed.

To improve the reliability of the hybrid cloud network, your enterprise uses both Direct Connect and VPN connections to connect your on-premises data center to the VPCs. The Direct Connect connection works as the active connection and a VPN connection works as the standby one. If the active connection becomes faulty, the standby connection automatically takes over, which eliminates network interruptions.
  • Two VPCs (VPC 1 and VPC 2) and a Direct Connect global DC gateway are attached to the enterprise router. VPC1 and VPC 2 can communicate with each other and communicate with the on-premises data center over the Direct Connect connection.
  • A VPN gateway is also attached to the enterprise router. If the Direct Connect connection becomes faulty, VPC 1 and VPC 2 can communicate with the on-premises data center over the VPN connection.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router and Direct Connect (Virtual Gateway)

  • Enterprise Router
  • Direct Connect (virtual gateway)
  • VPC
  • ECS

There are two VPCs in a region. The two VPCs need to access each other and share the same Direct Connect connection to communicate with an on-premises data center.

For this to work, you can create an enterprise router in the region, and attach the two VPCs and the virtual gateway of the Direct Connect connection to the enterprise router. The enterprise router can forward traffic among the attached VPCs and the virtual gateway, and the two VPCs can share the Direct Connect connection.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router and a Pair of Direct Connect Connections (Virtual Gateway)

  • Enterprise Router
  • Direct Connect (virtual gateway)
  • VPC
  • ECS
To improve the performance and reliability of the hybrid cloud network, your enterprise uses two Direct Connect connections to connect your on-premises data center to the VPCs. The two Direct Connect connections work in load balancing mode. When both connections are working normally, network transmission is greatly improved. If one connection is faulty, the other connection ensures the normal running of the hybrid cloud network and thereby prevents service interruption caused by a single connection.
  • The two VPCs can communicate with each other and communicate with the on-premises data center over two Direct Connect connections and an enterprise router.
  • When one Direct Connect connection is faulty, the two VPCs can communicate with the on-premises data center over the normal connection.

Hybrid cloud network

Setting Up a Hybrid Cloud Network Using Enterprise Router, VPN, and Direct Connect (Virtual Gateway)

  • Enterprise Router
  • Direct Connect (virtual gateway)
  • VPN
  • VPC
  • ECS
To improve the reliability of the hybrid cloud network, your enterprise uses both Direct Connect and VPN connections to connect your on-premises data center to the VPCs. The Direct Connect connection works as the active connection and a VPN connection works as the standby one. If the active connection becomes faulty, the standby connection automatically takes over, which eliminates network interruptions.
  • Two VPCs (VPC 1 and VPC 2), and the Direct Connect virtual gateway are attached to the enterprise router. VPC1 and VPC 2 can communicate with each other and communicate with the on-premises data center over the Direct Connect connection.
  • A VPN gateway is also attached to the enterprise router. If the Direct Connect connection becomes faulty, VPC 1 and VPC 2 can communicate with the on-premises data center over the VPN connection.

Access to the public network from the cloud network

Allowing VPCs to Share an EIP to Access the Internet Using Enterprise Router and NAT Gateway

  • Enterprise Router
  • NAT Gateway
  • Elastic IP
  • VPC
  • ECS

There are four VPCs in region A on Huawei Cloud. VPC 1, VPC 2, and VPC 3 need to communicate with each other, and share an EIP through an SNAT rule of a NAT gateway in VPC 4 to access the Internet.

Network migration

Using Enterprise Router to Migrate the Network Set Up Through VPC Peering

  • Enterprise Router
  • VPC
  • ECS

There are three VPCs (VPC-A, VPC-B, and VPC-C) in region A and connected over VPC peering connections. To improve network scalability and reduce O&M costs, you can use an enterprise router to connect the three VPCs.

Network migration

Using Enterprise Router to Migrate the Network Set Up Through Direct Connect (Global DC Gateway)

  • Enterprise Router
  • Direct Connect (global DC gateway)
  • VPC
  • ECS

Your on-premises data center is connected to the desired VPC (VPC-X) through Direct Connect, and VPC-X, virtual gateway VGW-A, and two virtual interfaces (VIF-A01 and VIF-A02) are in the same region. To improve the reliability of your hybrid cloud network and reduce O&M costs, you can use global DC gateways and Enterprise Router to migrate the network.

Network migration

Using Enterprise Router and Central Network to Migrate the Network Set Up Through a Cloud Connection

  • Enterprise Router
  • Cloud Connect (cloud connection)
  • Cloud Connect (central network)
  • VPC
  • ECS

As shown in Figure 1, the VPCs in three regions (region A, region B, and region C) are connected over a cloud connection. To improve the network scalability and simplify maintenance, you can attach the VPCs to enterprise routers and add the enterprise routers to a central network as attachments, so that these VPCs can communicate with each other.

NOTICE:

If you need to set up a hybrid cloud network, it is recommended that you use Enterprise Router and Direct Connect Global DC Gateway.

From May 2024, Enterprise Router and Direct Connect Virtual Gateway cannot be used together to set up a hybrid cloud network. Existing networks that are set up using Enterprise Router and Direct Connect Virtual Gateway are not affected.

We use cookies to improve our site and your experience. By continuing to browse our site you accept our cookie policy. Find out more

Feedback

Feedback

Feedback

0/500

Selected Content

Submit selected content with the feedback