Help Center/ Cloud Bastion Host/ User Guide/ Managing Instances/ Binding or Unbinding an EIP to or from a Bastion Host
Updated on 2026-05-22 GMT+08:00

Binding or Unbinding an EIP to or from a Bastion Host

Scenarios

Elastic IP (EIP) enables your cloud resources to communicate with the Internet using static public IP addresses and scalable bandwidths. A resource with an EIP can access the Internet directly. A resource with only a private IP address cannot.

  • Binding an EIP
    • To access a bastion host over the Internet, you need to bind an EIP to the bastion host.
    • An EIP must be bound to a bastion host instance if you want to perform any of the following operations (the minimum EIP bandwidth is 5 Mbit/s):
      • Use a web browser to log in to the bastion host system. Login address: https://<EIP-of-the-bastion-host-instance>. for example, https://10.10.10.10.
      • If the mobile SMS login is configured, you need to obtain the verification code through the mobile phone. If the EIP is not configured, you cannot receive SMS messages.
      • Interconnect with LTS to send logs. For details, see Configuring LTS.
      • In V3.3.2.0 and earlier versions, if no EIPs are bound to a bastion host instance, operations such as changing the version specifications, upgrading the version, and starting or restarting the instance will fail.
  • Unbinding an EIP
    • If your CBH instance does not need to use an EIP, you can unbind the EIP.
    • If you want to bind an EIP to another CBH instance, unbind the EIP from the original instance first.

Constraints

  • An EIP can be bound to only one cloud resource. A CBH instance cannot share an EIP with other cloud resources.
  • When binding an EIP to a bastion host instance, the operation can be done on the CBH console only. Otherwise, you cannot log in to the CBH instance using IAM.

Prerequisites

To bind an EIP to a CBH instance, ensure that at least one EIP has been created and the EIP and the CBH instance are created under the same account in the same region. For details about how to create an EIP, see Assigning an EIP.

Binding an EIP

  1. Log in to the CBH console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. Locate the row containing the instance to which you want to bind an EIP. In the Operation column, choose More > Configure Network > Bind EIP.
  4. In the displayed dialog box, select an EIP in the Unbound status and click OK.

    After the EIP is bound, you can view it in the EIP column of the instance list. The Login button in the Operation column becomes available.

Unbinding an EIP

Precautions

If you unbind the EIP from the instance, you cannot use the EIP to log in to the bastion host. Exercise caution when performing this operation.

Procedure

  1. Log in to the CBH console.
  2. Click in the upper left corner on the displayed page and select a region.
  3. Locate the row containing the instance from which you want to unbind an EIP. In the Operation column, choose More > Configure Network > Unbind EIP.
  4. In the displayed dialog box, click OK.

    After the unbinding is successful, no IP address is displayed in the EIP column of the instance. The Log in button in the Operation column becomes unavailable.