- What's New
- Function Overview
- Product Bulletin
- Service Overview
- Billing
- Getting Started
- User Guide
-
Best Practices
- Direct Connect Best Practices
- Connecting an On-Premises Data Center to a VPC over a Single Connection and Using Static Routing to Route Traffic
- Connecting an On-Premises Data Center to a VPC over a Single Connection and Using BGP Routing to Route Traffic
- Connecting an On-Premises Data Center to a VPC over Two Connections in Load Balancing Mode (Virtual Gateway)
- Connecting an On-Premises Data Center to a VPC over Two Connections in an Active/Standby Pair (Virtual Gateway)
- Connecting an On-Premises Data Center to Multiple VPCs that Do Not Need to Communicate with Each Other
- Connecting an On-Premises Data Center to Multiple VPCs in the Same Region Using Direct Connect and VPC Peering
- Using a Public NAT Gateway and Direct Connect to Accelerate Internet Access
- Allowing On-Premises Servers to Access Cloud Services Using Direct Connect and VPC Endpoint
-
API Reference
- Before You Start
- API Overview
- Calling APIs
-
API
- Connections
- Virtual Gateways
-
Virtual Interfaces
- Creating a Virtual Interface
- Querying the Virtual Interface List
- Querying Details About a Virtual Interface
- Updating a Virtual Interface
- Deleting a Virtual Interface
- Creating a Virtual Interface Peer
- Updating a Virtual Interface Peer
- Deleting a Virtual Interface Peer
- Performing a Virtual Interface Switchover Test
- Querying the List of Virtual Interface Switchover Test Records
- Tag Management
- Quota Management
- Global DC Gateways
- Peer Links
- Connect Gateways
- Global EIPs
- Global DC Gateway Route Tables
- Public Parameters
- Appendix
- SDK Reference
- Troubleshooting
-
FAQs
-
Popular Questions
- What Are the Network Requirements for Connections?
- What Locations Are Available for Direct Connect?
- How Do I Select a Carrier When Purchasing a Connection?
- How Will I Be Billed for Direct Connect?
- How Do I Submit a Service Ticket?
- How Do I Test the Network Connectivity Between a Location and the Cloud?
- What Do I Do If I Select the Wrong Carrier When Creating a Connection?
-
Product Consultation
- What Are the Network Requirements for Connections?
- What Are 1GE and 10GE?
- What Locations Are Available for Direct Connect?
- Is BGP Routing Supported in Direct Connect?
- What Is Full-Service Installation Statement?
- How Do I Submit a Service Ticket?
- What Are the Network Latency and Packet Loss Rate of a Connection?
- Are the Uplink and Downlink Bandwidths of a Direct Connect Connection the Same?
- What Do I Do If I Select the Wrong Carrier When Creating a Connection?
- How Do I Plan the VPCs for a New Connection?
- What Are Local and Remote Gateways (Interconnection IP Addresses)?
- How Do I Configure BFD for a Connection?
- Leased Line
-
Interconnection with the Cloud
- Can I Access the Same VPC over Multiple Connections?
- How Do I Plan the CIDR Blocks for a Connection?
- What Should I Consider When I Use Direct Connect to Access the Cloud?
- Does Direct Connect Support NAT?
- Can the VLAN of the On-premises Network Be Used in the VPC Through Direct Connect?
- Can My On-Premises Data Center Access Multiple VPCs Through One Connection?
- Can Direct Connect Be Used with Similar Services of Other Cloud Service Providers?
-
Networking and Scenarios
- Can Multiple Connections Access the Same VPC?
- Can My On-Premises Data Center Access Multiple VPCs Through One Connection?
- Can Direct Connect Be Used with Similar Services of Other Cloud Service Providers?
- Can I Limit the Bandwidth Available on Each Hosted Connection?
- How Do I Plan the VPCs for a New Connection?
-
Related Console Operations
- How Do I Submit a Service Ticket?
- How Can I Unsubscribe from Direct Connect?
- What Parameters Can Be Modified After I Have Created a Virtual Interface?
- Do I Need to Delete the Virtual Gateway and Virtual Interface Before Deleting a Hosted Connection?
- How Do I Change the Routing Mode of a Connection?
- How Do I Delete a Hosted Connection?
- What Is the BGP ASN Used by Huawei Cloud?
- What Are Local and Remote Gateways (Interconnection IP Addresses)?
- Troubleshooting
- Billing
- Resource Monitoring
- Quota
-
Popular Questions
-
More Documents
- User Guide (ME-Abu Dhabi Region)
- User Guide (Paris Region)
- eu-west-0-api
- User Guide (Kuala Lumpur Region)
-
API Reference (Kuala Lumpur Region)
- Before You Start
- API Overview
- Calling APIs
- API Usage
-
API
- Connection
- Virtual Gateway
-
Virtual Interface
- Querying Details About a Virtual Interface
- Updating a Virtual Interface
- Deleting a Virtual Interface
- Querying the Virtual Interface List
- Creating a Virtual Interface
- Updating a Virtual Interface Peer
- Deleting a Virtual Interface Peer
- Creating a Virtual Interface Peer
- Performing a Virtual Interface Switchover Test
- Querying the Switchover Test Records of a Virtual Interface
- Tag management
- Quota Management
- Public Parameters
- Appendixes
- Change History
- General Reference
Copied.
Identity Authentication and Access Control
Identity Authentication
You can use Identity and Access Management (IAM) to control access to your Direct Connect resources. IAM permissions define which actions on your cloud resources are allowed or denied. After creating an IAM user, the administrator needs to add it to a user group and grant the permissions required by Direct Connect to the user group. Then, all users in this group automatically inherit the granted permissions.
For details, see Permissions.
Access Control
A security group is a collection of access control rules for cloud resources, such as cloud servers, containers, and databases, that have the same security protection requirements and that are mutually trusted within a VPC. After a security group is created, you can create various access rules for the security group, and these rules will apply to all cloud resources added to this security group.
Your account automatically comes with a default security group. The default security group allows all outbound traffic, denies all inbound traffic, and allows all traffic between cloud resources in the group. Your cloud resources in this security group can communicate with each other already without adding additional rules. For details about the default security group rules, see Default Security Groups and Security Group Rules.
In addition, Huawei Cloud allows you to manage security groups and security group rules, including
- Creating, viewing, deleting, modifying, cloning, and adding security groups
- Adding, copying, modifying, deleting, importing, and exporting security group rules
- Quickly adding multiple security group rules
- Viewing and changing security groups of ECSs
- Adding cloud resources to or removing cloud resources from security groups
You can define access control rules for a security group. Then ECSs that will be added to this security group will be protected. For details, see Security Group.
Feedback
Was this page helpful?
Provide feedbackThank you very much for your feedback. We will continue working to improve the documentation.See the reply and handling status in My Cloud VOC.
For any further questions, feel free to contact us through the chatbot.
Chatbot