Alibaba Cloud VPC Networking: VSwitches, Routes and Peering - 夜莺博客

Alibaba Cloud VPC Networking: VSwitches, Routes and Peering

Alibaba Cloud networking is organised around the VPC, and a VPC is deliberately simple: one CIDR block, one or more vSwitches (the equivalent of subnets), route tables per vSwitch, and internet access through NAT gateways or elastic IPs. The design work is almost entirely about address planning and about deciding which gateway goes where, because a wrong CIDR choice is expensive to reverse once workloads are running.

Address Planning First

  • Pick a VPC CIDR from private space (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) and reserve room for peering with on-premises and other VPCs.
  • Keep vSwitch CIDR blocks at /24 or larger for growth; a vSwitch cannot overlap another vSwitch in the same VPC or in a peered VPC.
  • Reserve one CIDR block per environment (production, staging, shared services) so route tables stay readable.
  • Never allocate the same CIDR in two VPCs you intend to peer - overlapping ranges break peering and cannot be worked around inside the peering itself.

Core Objects and Their Roles

# aliyun CLI: create a VPC and two vSwitches
aliyun vpc CreateVpc --CidrBlock 10.10.0.0/16 --VpcName prod-vpc
aliyun vpc CreateVSwitch --CidrBlock 10.10.1.0/24 --VpcId vpc-xxxx \
  --ZoneId cn-hangzhou-h --VSwitchName prod-web
aliyun vpc CreateVSwitch --CidrBlock 10.10.2.0/24 --VpcId vpc-xxxx \
  --ZoneId cn-hangzhou-i --VSwitchName prod-db

Spreading vSwitches across zones is the availability decision: an ECS instance lives in one zone, but the VPC spans the region, so multi-zone vSwitch placement is what makes a multi-zone load balancer or RDS deployment possible.

Internet Access: NAT, EIP and Route Tables

  • NAT gateway - outbound-only internet access for private ECS instances. One NAT gateway per zone for resilience.
  • Elastic IP (EIP) - a public address bound to an instance, NAT gateway or SLB. Use it for inbound services only.
  • Route tables - a custom route table with 0.0.0.0/0 -> NAT gateway gives private instances outbound access without public addresses.
aliyun vpc CreateNatGateway --VpcId vpc-xxxx --NatType Enhanced \
  --VSwitchId vsw-public --Name prod-nat
aliyun vpc CreateRouteEntry --RouteTableId vtb-xxxx \
  --DestinationCidrBlock 0.0.0.0/0 --NextHopId ngw-xxxx \
  --NextHopType NatGateway

The classic mistake is attaching an EIP to every instance so that management access is easy, which turns a private subnet into a directly attacked surface. Keep instances private, reach them over a VPN or bastion host, and let the NAT gateway handle egress.

Connecting VPCs and On-Premises

# VPC peering between two regions
aliyun vpc CreateVpcPeerConnection --RegionId cn-hangzhou \
  --VpcId vpc-a --AcceptingRegionId cn-beijing --AcceptingVpcId vpc-b \
  --Name hz-to-bj

# routes are required on both sides
aliyun vpc CreateRouteEntry --RouteTableId vtb-a \
  --DestinationCidrBlock 10.20.0.0/16 --NextHopId pcc-xxxx --NextHopType VpcPeer

Peering is not transitive: if A peers with B and B peers with C, A cannot reach C through B. For that topology use a transit router (Cloud Enterprise Network) rather than chaining peerings.

Security Groups and Network ACLs

aliyun ecs CreateSecurityGroup --VpcId vpc-xxxx --SecurityGroupName web-sg \
  --Description web-tier
aliyun ecs AuthorizeSecurityGroup --SecurityGroupId sg-xxxx --IpProtocol tcp \
  --PortRange 443/443 --SourceCidrIp 0.0.0.0/0
aliyun ecs AuthorizeSecurityGroup --SecurityGroupId sg-xxxx --IpProtocol tcp \
  --PortRange 3306/3306 --SourceGroupId sg-db-xxxx

Referencing a security group as the source instead of a CIDR is the cleanest way to express tier-to-tier policy, and it survives subnet renumbering. Network ACLs add a stateless subnet-level filter; use them for broad deny rules and security groups for stateful per-instance policy.

Bring-Up Checklist

  • VPC and vSwitch CIDRs documented and non-overlapping with on-premises.
  • NAT gateway per zone, route tables referencing them, no stray EIPs.
  • Security groups grouped by tier, not by instance.
  • Flow logs enabled on the vSwitches you care about before you need them.
  • Peering and CEN attachments verified with a ping between two instances, in both directions.

Compare designs across providers with AWS Transit Gateway route tables, AWS Direct Connect private VIF and BGP, Azure VNet peering and gateway transit and Google Cloud Interconnect VLAN attachments.

原文链接:https://www.alibabacloud.com/help/en/vpc/product-overview/what-is-vpc