El contenido no se encuentra disponible en el idioma seleccionado. Estamos trabajando continuamente para agregar más idiomas. Gracias por su apoyo.

Compute
Elastic Cloud Server
Huawei Cloud Flexus
Bare Metal Server
Auto Scaling
Image Management Service
Dedicated Host
FunctionGraph
Cloud Phone Host
Huawei Cloud EulerOS
Networking
Virtual Private Cloud
Elastic IP
Elastic Load Balance
NAT Gateway
Direct Connect
Virtual Private Network
VPC Endpoint
Cloud Connect
Enterprise Router
Enterprise Switch
Global Accelerator
Management & Governance
Cloud Eye
Identity and Access Management
Cloud Trace Service
Resource Formation Service
Tag Management Service
Log Tank Service
Config
OneAccess
Resource Access Manager
Simple Message Notification
Application Performance Management
Application Operations Management
Organizations
Optimization Advisor
IAM Identity Center
Cloud Operations Center
Resource Governance Center
Migration
Server Migration Service
Object Storage Migration Service
Cloud Data Migration
Migration Center
Cloud Ecosystem
KooGallery
Partner Center
User Support
My Account
Billing Center
Cost Center
Resource Center
Enterprise Management
Service Tickets
HUAWEI CLOUD (International) FAQs
ICP Filing
Support Plans
My Credentials
Customer Operation Capabilities
Partner Support Plans
Professional Services
Analytics
MapReduce Service
Data Lake Insight
CloudTable Service
Cloud Search Service
Data Lake Visualization
Data Ingestion Service
GaussDB(DWS)
DataArts Studio
Data Lake Factory
DataArts Lake Formation
IoT
IoT Device Access
Others
Product Pricing Details
System Permissions
Console Quick Start
Common FAQs
Instructions for Associating with a HUAWEI CLOUD Partner
Message Center
Security & Compliance
Security Technologies and Applications
Web Application Firewall
Host Security Service
Cloud Firewall
SecMaster
Anti-DDoS Service
Data Encryption Workshop
Database Security Service
Cloud Bastion Host
Data Security Center
Cloud Certificate Manager
Edge Security
Situation Awareness
Managed Threat Detection
Blockchain
Blockchain Service
Web3 Node Engine Service
Media Services
Media Processing Center
Video On Demand
Live
SparkRTC
MetaStudio
Storage
Object Storage Service
Elastic Volume Service
Cloud Backup and Recovery
Storage Disaster Recovery Service
Scalable File Service Turbo
Scalable File Service
Volume Backup Service
Cloud Server Backup Service
Data Express Service
Dedicated Distributed Storage Service
Containers
Cloud Container Engine
Software Repository for Container
Application Service Mesh
Ubiquitous Cloud Native Service
Cloud Container Instance
Databases
Relational Database Service
Document Database Service
Data Admin Service
Data Replication Service
GeminiDB
GaussDB
Distributed Database Middleware
Database and Application Migration UGO
TaurusDB
Middleware
Distributed Cache Service
API Gateway
Distributed Message Service for Kafka
Distributed Message Service for RabbitMQ
Distributed Message Service for RocketMQ
Cloud Service Engine
Multi-Site High Availability Service
EventGrid
Dedicated Cloud
Dedicated Computing Cluster
Business Applications
Workspace
ROMA Connect
Message & SMS
Domain Name Service
Edge Data Center Management
Meeting
AI
Face Recognition Service
Graph Engine Service
Content Moderation
Image Recognition
Optical Character Recognition
ModelArts
ImageSearch
Conversational Bot Service
Speech Interaction Service
Huawei HiLens
Video Intelligent Analysis Service
Developer Tools
SDK Developer Guide
API Request Signing Guide
Terraform
Koo Command Line Interface
Content Delivery & Edge Computing
Content Delivery Network
Intelligent EdgeFabric
CloudPond
Intelligent EdgeCloud
Solutions
SAP Cloud
High Performance Computing
Developer Services
ServiceStage
CodeArts
CodeArts PerfTest
CodeArts Req
CodeArts Pipeline
CodeArts Build
CodeArts Deploy
CodeArts Artifact
CodeArts TestPlan
CodeArts Check
CodeArts Repo
Cloud Application Engine
MacroVerse aPaaS
KooMessage
KooPhone
KooDrive
Help Center/ Cloud Connect/ Best Practices/ Connecting On-Premises Data Centers and VPCs/ Using Cloud Connect and Direct Connect to Connect an On-premises Data Center to a VPC

Using Cloud Connect and Direct Connect to Connect an On-premises Data Center to a VPC

Updated on 2025-01-15 GMT+08:00

Scenarios

If you have more than one on-premises data center and VPC, you can use Direct Connect and a cloud connection to connect all your on-premises data centers to the VPCs in different regions.

Figure 1 shows an example.

NOTE:

For details about the regions where cloud connections are available, see Region Availability.

Figure 1 Connecting on-premises data centers and VPCs
NOTE:

When you configure a cloud connection, note that:

  • Subnet CIDR blocks of the VPCs cannot overlap or conflict with each other.
  • The routes for the subnets in the VPCs cannot conflict with existing routes, including those added for VPC Peering, Direct Connect, or VPN.

Prerequisites

  • You have a Huawei Cloud account, and the Huawei Cloud account has been configured with operation permissions of related services.
  • The account balance is sufficient to purchase the required resources, such as Direct Connect connections, bandwidth packages, and ECSs.
  • Direct Connect locations have been determined and the site survey of on-premises data centers have been completed together with the carrier. For details, see Preparations.
  • The VPCs and subnets that need to communicate with each other across regions have been created.
  • All VPC subnets have been configured for your on-premises data centers.

Procedure

  1. Configure Direct Connect. In this example, two Direct Connect connections are required to connect each on-premises data center to the cloud.

    1. Create a Direct Connect connection.
      1. Log in to the Direct Connect console.
      2. On the console homepage, click in the upper left corner and select the desired region and project.
      3. Click to display Service List and choose Networking > Direct Connect.
      4. In the navigation pane on the left, choose Direct Connect > Connections.
      5. Click Create Connection.
      6. On the Create Connection page, configure the parameters based on Table 1.
        Table 1 Parameters required for creating a connection

        Parameter

        Description

        Region

        Specifies the region where the connection is deployed. You can change the region here, or use the region selector in the upper left corner of the console.

        Connection Name

        Specifies the connection name. Enter a desired name.

        Location

        Specifies the location where your leased line can connect to Huawei Cloud.

        Carrier

        Specifies the carrier that provides the leased line.

        Port Type

        Specifies the type of the port used by the connection. There are four types of ports: 1GE, 10GE, 40GE, and 100GE.

        Leased Line Bandwidth

        Specifies the bandwidth of the connection, in Mbit/s. Select a value from the drop-down list. This is the bandwidth of the leased line you have purchased from the carrier.

        Your Equipment Room Address

        Specifies the address of your equipment room. The address must be specific to the floor on which your equipment room is located, for example, Equipment Room XX, Building XX, No. XX, Huajing Road, Fengdong District, Shanghai.

        Tag

        Identifies the connection. A tag consists of a key and a value. You can add 20 tags to a connection.

        NOTE:

        If a predefined tag has been created on TMS, you can directly select the corresponding tag key and value.

        For details about predefined tags, see Predefined Tags.

        Description

        Provides supplementary information about the connection.

        Billing Mode

        Specifies how you are charged. Currently, only Yearly/Monthly is supported.

        Required Duration

        Specifies the duration for which you require the connection.

        Auto-renew

        Specifies whether to automatically renew the connection to ensure service continuity.

        It is recommended that you set the auto-renewal period to be the same as the required duration. If the required duration is three months, the system automatically renews the subscription for every three months.

        Enterprise Project

        Provides a cloud resource management mode, in which cloud resources and members are centrally managed by project.

        Contact Person/Phone Number/Contact Email

        Specifies information about the person who is responsible for your connection.

        If you do not provide the contact information, your account information will be used. This will prolong the review.

      7. Click Next
      8. Confirm the order and click Pay.
      9. Click OK.
    2. Connect your data center to the location you select.
      1. After you have paid for the order, the system automatically allocates a connection ID for you, and the connection information is displayed on the management console. The connection status is Creating, when you will be contacted to confirm the construction plan and relevant information (including your company name, constructor, expected construction time, and construction workers).
      2. After having confirmed the construction plan, you can arrange the carrier to deploy the dedicated line and connect it to your equipment room based on your construction plan.
      3. In normal cases, Huawei resident engineers will connect the dedicated line to the Huawei Cloud gateway port within two working days.
      4. After the construction is complete, the connection status becomes Normal, indicating that the connection is ready.
    3. Create a virtual gateway.

      Create a virtual gateway to associate it with the VPC in CN South-Guangzhou.

      1. Log in to the management console.
      2. On the console homepage, click in the upper left corner and select the desired region and project.
      3. Click to display Service List and choose Networking > Direct Connect.
      4. In the navigation pane on the left, choose Direct Connect > Virtual Gateways.
      5. Click Create Virtual Gateway.
      6. Configure the parameters based on Table 2.
        Figure 2 Create Virtual Gateway
        Table 2 Parameters required for creating a virtual gateway

        Parameter

        Description

        Name

        Specifies the virtual gateway name.

        The name can contain 1 to 64 characters.

        VPC

        Specifies the VPC associated with the virtual gateway.

        Local Subnet

        Specifies the CIDR blocks of subnets in the VPC to connect to the on-premises network.

        Description

        Provides supplementary information about the virtual gateway.

        The description can contain a maximum of 128 characters.

        NOTE:

        Add CIDR blocks of all VPC subnets that will communicate with each on-premises data center to ensure normal communication.

      7. Click OK.

        When the virtual gateway status changes Normal, the virtual gateway has been created.

    4. Create a virtual interface.

      Create a virtual interface over which the on-premises data center connects to Huawei Cloud so that the on-premises data center can access the VPC in CN South-Guangzhou.

      1. Log in to the management console.
      2. On the console homepage, click in the upper left corner and select the desired region and project.
      3. Click to display Service List and choose Networking > Direct Connect.
      4. In the navigation pane on the left, choose Direct Connect > Virtual Interfaces.
      5. Click Create Virtual Interface.
      6. Configure the parameters based on Table 3.
        Figure 3 Create Virtual Interface
        Table 3 Parameters required for creating a virtual interface

        Parameter

        Description

        Region

        Specifies the region where the connection is deployed. You can change the region here, or use the region selector in the upper left corner of the console.

        Name

        Specifies the virtual interface name.

        The name can contain 1 to 64 characters.

        Connection

        Specifies the connection you use to connect your data center to the cloud.

        Virtual Gateway

        Specifies the virtual gateway to which the virtual interface will connect.

        VLAN

        Specifies the VLAN of the virtual interface.

        You need to configure the VLAN if you buy a self-service connection.

        The VLAN for a hosted connection will be allocated by the carrier or partner. In this scenario, you do not need to configure the VLAN.

        Enterprise Project

        Provides a cloud resource management mode, in which cloud resources and members are centrally managed by project.

        Bandwidth

        Specifies the bandwidth that can be used by the virtual interface, in Mbit/s. The bandwidth cannot exceed that of the connection.

        Local Gateway

        Specifies the IP address for connecting to the cloud.

        Remote Gateway

        Specifies the IP address for connecting to the on-premises network.

        The IP address of the remote gateway must be in the same network segment as that of the local gateway, and it is recommended that both IP addresses use a 30-bit mask.

        Remote Subnet

        Specifies the subnets and masks of the on-premises data center. If there are multiple subnets, use commas (,) to separate them.

        Routing Mode

        Specifies the routing mode. Two options are available, static routing and BGP routing.

        If there are two or more connections, select BGP routing.

        BGP ASN

        Specifies the ASN of the BGP peer. Enter a value from 1 to 65535, excluding 64512, which is reserved by Huawei Cloud.

        This parameter is required if you select BGP routing.

        BGP MD5 Authentication Key

        Specifies the password used to authenticate the BGP peer using MD5.

        This parameter is mandatory if you select BGP routing, and you must ensure that the parameter values on both gateways are the same.

        The value contains 8 to 255 characters and must contain at least two types of the following characters:

        • Uppercase letters
        • Lowercase letters
        • Digits
        • Special characters ~!, .:;-_"(){}[]/@#$ %^&*+\|=

        Description

        Provides supplementary information about the virtual interface.

        The description can contain a maximum of 128 characters.

      7. Click Submit. When the status of the virtual interface changes Normal, the virtual interface has been created.
      8. Ping a server in on-premises data center 1 from an ECS in the VPC in CN South-Guangzhou (VPC 1) to test network connectivity.
    5. Repeat 1.a to 1.d to establish network connectivity between on-premises data center 2 and the VPC in CN East-Shanghai1 (VPC 2).

  2. Create a cloud connection.

    1. Create a cloud connection.
      1. Go to the Cloud Connections page.
      2. In the upper right corner of the page, click Create Cloud Connection.
      3. Configure the parameters based on Table 4.
        Table 4 Parameters for creating a cloud connection

        Parameter

        Description

        Name

        Specifies the cloud connection name.

        Enterprise Project

        Specifies the enterprise project for managing the cloud connection.

        An enterprise project facilitates project-level management and grouping of cloud resources and users. The name of the default project is default.

        For details about creating and managing enterprise projects, see the Enterprise Management User Guide.

        Scenario

        Specifies whether the cloud connection is used to connect VPCs or enterprise routers.

        If you select VPC here, only VPCs or virtual gateways can use this cloud connection.

        Tag

        Identifies the cloud connection. A tag consists of a key and a value. You can add 20 tags to a cloud connection.

        NOTE:

        If you have configured tag policies for Cloud Connect, add tags to cloud connections based on the tag policies. If you add a tag that does not comply with the tag policies, cloud connections may fail to be created. Contact your administrator to learn more about tag policies.

        Description

        (Optional) Provides supplementary information about the cloud connection.

        The description can contain no more than 255 characters and cannot contain angle brackets (<>).

      4. Click OK.
    2. Load network instances.

      Load the VPCs in CN South-Guangzhou and CN East-Shanghai1 to the created cloud connection.

      1. In the cloud connection list, click the name (CloudConnect) of the cloud connection.
      2. On the Network Instances tab, click Load Network Instance.
      3. Configure the parameters.
        NOTE:

        To enable the on-premises data center to access the VPC, you need to add the subnet used in the on-premises data center as a custom CIDR block.

      4. Click OK. The VPC in CN South-Guangzhou has been loaded to the cloud connection.
      5. Repeat the preceding steps to load the VPC in CN East-Shanghai to the cloud connection.
        Figure 4 Loading the other VPC
        NOTE:
        After the VPCs are loaded, they are on the same network. You can view the routes of each VPC on the Route Information tab.
        Figure 5 Route Information
    3. Buy a bandwidth package.

      By default, Cloud Connect provides 10 kbit/s of bandwidth for testing cross-region network connectivity.

      To ensure normal communication, you need to purchase a bandwidth package and bind it to the cloud connection.

      1. In the cloud connection list, click the name (CloudConnect) of the cloud connection.
      2. On the Bandwidth Packages tab, click Buy Bandwidth Package.
      3. Configure the parameters.

        Because the two VPCs are in the Chinese mainland, select Single geographic region for Applicability and Chinese mainland for Geographic Region.

      4. Click Buy Now.
      5. Confirm the configuration and click Pay Now.
      6. Click OK.

        Go back to the bandwidth package list. If its status changes to Normal, you can bind the bandwidth package to the cloud connection.

        NOTE:

        In the navigation pane, choose Bandwidth Packages. On the displayed page, locate the bandwidth package you just purchased. You can view its details, such as the billing mode, order information, cloud connection bound to, used bandwidth, and remaining bandwidth. You can also modify, unbind, renew, and unsubscribe from the bandwidth package.

    4. Assign an inter-region bandwidth.
      1. In the cloud connection list, click the name (CloudConnect) of the cloud connection.
      2. On the Inter-Region Bandwidths tab, click Assign Inter-Region Bandwidth.
      3. Configure the parameters.

        Select CN South-Guangzhou and CN East-Shanghai1 for Regions. The system automatically displays the bandwidth package bound to the cloud connection. Set the bandwidth based on your requirements, for example, 1 Mbit/s.

      4. View the assigned bandwidth on the Inter-Region Bandwidths tab.
        NOTE:

        The default security group rules deny all the inbound traffic. Ensure that security group rules in both directions are correctly configured for resources in the regions to ensure normal communication.

  1. Configure local routes on the on-premises data centers.

    • In on-premises data center 1, add routes to the VPC in CN South-Guangzhou (192.168.3.0/24), to the VPC in CN East-Shanghai1 (192.168.1.0/24), and to on-premises data center 2 (192.168.5.0/24).
    • In on-premises data center 2, add routes to the VPC in CN East-Shanghai1 (192.168.1.0/24), to the VPC in CN South-Guangzhou (192.168.3.0/24), and to on-premises data center 1 (172.16.1.0/24).

Verification

  1. Ping an ECS in the VPC in CN East-Shanghai1 and a server in each data center from an ECS in the VPC in CN South-Guangzhou.

  2. Ping an ECS in the VPC in CN South-Guangzhou and a server in each data center from an ECS in the VPC in CN East-Shanghai1.

  3. View the routes.

Utilizamos cookies para mejorar nuestro sitio y tu experiencia. Al continuar navegando en nuestro sitio, tú aceptas nuestra política de cookies. Descubre más

Feedback

Feedback

Feedback

0/500

Selected Content

Submit selected content with the feedback