Updated on 2023-12-11 GMT+08:00

VPC Peering Connection Overview

What Is a VPC Peering Connection?

A VPC peering connection is a networking connection that connects two VPCs for them to communicate using private IP addresses. The VPCs to be peered can be in the same account or different accounts, but must be in the same region.
Figure 1 shows an application scenario of VPC peering connections.
  • There are two VPCs (VPC-A and VPC-B) in region A that are not connected.
  • Service servers (ECS-A01 and ECS-A02) are in VPC-A, and database servers (RDS-B01 and RDS-B02) are in VPC-B. The service servers and database servers cannot communicate with each other.
  • You need to create a VPC peering connection (peering-AB) between VPC-A and VPC-B so the service servers and database servers can communicate with each other.
Figure 1 VPC peering connection network diagram

Currently, VPC peering connections are free of charge.

VPC Peering Connection Creation Process

A VPC peering connection can only connect VPCs in the same region.

  • If two VPCs are in the same account, the process of creating a VPC peering connection is shown in Figure 2.
    For details about how to create a VPC peering connection, see Creating a VPC Peering Connection with Another VPC in Your Account.
    Figure 2 Process of creating a VPC peering connection between VPCs in the same account
  • If two VPCs are in different accounts, the process of creating a VPC peering connection is shown in Figure 3.

    For details about how to create a VPC peering connection, see Creating a VPC Peering Connection with a VPC in Another Account.

    If account A initiates a request to create a VPC peering connection with a VPC in account B, the VPC peering connection takes effect only after account B accepts the request.
    Figure 3 Process of creating a VPC peering connection between VPCs in different accounts

Notes and Constraints

  • A VPC peering connection can only connect VPCs in the same region.
    • A VPC peering connection can enable a VPC created on the Huawei Cloud Chinese Mainland website and the other created on the Huawei Cloud International website to communicate, but the VPCs must be in the same region. For example, one VPC on the Chinese Mainland website is in CN-Hong Kong region, and the other VPC on the International website is also in CN-Hong Kong region.
    • If you want to connect VPCs in different regions, you can use Cloud Connect.
    • If you only need few ECSs in different regions to communicate with each other, you can assign and bind EIPs to the ECSs.
  • If the local and peer VPCs have overlapping CIDR blocks, the VPC peering connection may not take effect.

    In this case, you can refer to networking configuration examples.

  • By default, if VPC A is peered with VPC B that has EIPs, VPC A cannot use EIPs in VPC B to access the Internet. To enable this, you can use the NAT Gateway service or configure an SNAT server. For details, see Enabling Internet Connectivity for an ECS Without an EIP.