Updated on 2023-11-10 GMT+08:00



There are three VPCs in region A on Huawei Cloud, with service A and service B respectively in VPC 1 and VPC 2, and the third-party firewall in VPC 3. For security purposes, the traffic to service A and service B must be scrubbed by the firewall in VPC 3.

Figure 1 Traffic scrubbing for VPCs in the same region

You can share an enterprise router with different accounts to attach VPCs of these accounts to the same enterprise router for communications.

Operation Procedure

Figure 2 shows the procedure for using an enterprise router to scrub traffic for VPCs in the same region.

Figure 2 Flowchart for scrubbing traffic between VPCs in the same region
Planning Networks and Resources

Plan required CIDR blocks and the number of resources.


Creating Resources

  1. Create an enterprise router.
  2. Create three VPCs and three ECSs.


Configuring Networks

  1. Configure VPC attachments for the enterprise router:
    1. Attach the three VPCs to the enterprise router.
    2. Create two custom route tables for the enterprise router.
    3. Associate and propagate VPC attachments with the route tables of the enterprise router.
    4. Add routes to the route tables of the VPCs for traffic to route through the enterprise router.
  2. Configure kernel parameters and routes for ECS 3 to allow communications between NICs eth0 and eth1.


Verifying Network Connectivity and Traffic Scrubbing

Log in to an ECS and run the ping command to verify the network connectivity.