Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex Cloud Router
    • All use cases
    • On-premises without redundancy and one cloud network
    • On-premises without redundancy and multiple cloud networks
    • On-premises with redundancy and one cloud network
    • On-premises with redundancy and multiple cloud networks
    • Two separate route instances without on-premises redundancy
    • Even redistribution of on-premise traffic (Active-Active)
    • Prioritizing on-premise traffic based on direction (Active-Standby)
    • Reserving an on-premise connection via a VPN gateway (PRC)
    • Prioritizing a static VPC route over routes from PRC
    • Even traffic distribution for route 0.0.0.0/0
    • Prioritizing traffic by direction for route 0.0.0.0/0
    • Connectivity for two cloud networks
    • Connectivity for two cloud networks and on-premises
  • Access management
  • Release notes
  1. Use cases
  2. Reserving an on-premise connection via a VPN gateway (PRC)

Reserving an on-prem connection via a VPN gateway

Written by
Yandex Cloud
Updated at June 10, 2025

You can use a VPN gateway to make your Cloud Interconnect connection failsafe. For example, this might be an option when you cannot set up two physical circuits via two points of presence to ensure a fault-tolerant connection of the customer infrastructure to Yandex Cloud.

The customer edge router (R1) uses the M9 PoP to announce two long prefixes from the customer infrastructure, 10.0.0.0/9 and 10.128.0.0/9, over BGP towards Yandex Cloud.

Setting up a backup connection from Yandex Cloud to the customer infrastructure involves deploying an IPsec VPN gateway in the ru-central1-b availability zone and configuring static routing within the VPC.

Cloud resource subnets in all three availability zones share a single route table with the 10.0.0.0/8 via 172.16.2.10 static route (prefix). Since this /8 route (prefix) is shorter than the /9 prefixes announced over BGP, it will have a lower priority while the Cloud Interconnect connection is running.

If the Cloud Interconnect connection fails, the longer (/9) prefixes will be removed from the cloud network and the entire traffic towards the customer infrastructure will be automatically routed via the shorter (/8) prefix using a static route to the VPN gateway.

Was the article helpful?

Previous
Prioritizing on-premise traffic based on direction (Active-Standby)
Next
Prioritizing a static VPC route over routes from PRC
© 2025 Direct Cursus Technology L.L.C.