Setting up network connectivity between multiple virtual networks using VPC Stitching
Warning
This function is only available if Cloud Interconnect is activated with a traffic volume of at least 300 TB.
With VPC Stitching, you can set up IP connectivity between two or more Virtual Private Cloud networks that are located in different folders or clouds.
Alert
You can only configure VPC Stitching for cloud networks belonging to clouds within the same organization. Cross-organization network connectivity is not supported.
You can see the solution architecture in the diagram below:
This tutorial uses the following configuration:
Net-1cloud network with multiple subnets.Net-2cloud network with multiple subnets.vpc-stitchingprivate connection that routes traffic between cloud networks.ri-1virtual router with the private connection, cloud networks, and the IP prefixes of their subnets added to it.- Stitching announcements aggregating the IP prefixes of the subnets in each cloud network.
Warning
No SLA is provided for VPC Stitching. The amount of traffic transmitted through VPC Stitching cannot be monitored. Data transmission beyond the trunk capacity is possible but not guaranteed.
To set up VPC Stitching:
- Create a trunk if you do not have an appropriate Cloud Interconnect connection yet.
- Create a private connection.
- Create a virtual router.
- Contact support to enable VPC Stitching.
- Add cloud networks and IP prefixes to the virtual router.
- Add stitching announcements to the private connection.
- Test network connectivity.
Getting started
Make sure that:
- The cloud networks to set up connectivity between belong to clouds within the same organization.
- The subnet IP prefixes of these networks do not overlap.
- You have the cic.editor and cloud-router.editor roles for the folders containing Cloud Interconnect and Cloud Router resources, respectively.
- The Yandex Cloud CLI is installed and configured if you intend to use it.
VPC Stitching requires the following:
- Trunk with at least 300 TB of data, equivalent to a capacity of 1 Gbit/s.
- Private connection created in the trunk with a special VPC Stitching configuration.
- Virtual router with the private connection and cloud networks added to it.
If you already have a trunk with at least 300 TB of data, proceed to creating a private connection. If the amount of data is less than 300 TB, change the connection capacity and wait for support to confirm.
If the private connection and virtual router with the required configuration have already been created and support has confirmed that VPC Stitching is enabled, proceed to configuring IP prefixes.
Create a trunk
Create a support ticket
Use the following ticket template:
Subject: [CIC] Creating a new trunk to enable VPC Stitching.
Text of request:
Please create a new Cloud Interconnect trunk for VPC Stitching
with 300 TB of data in the <folder_ID> folder.
Wait for support to confirm. After the trunk is created, get its ID, as you will need it when creating your private connection.
Create a private connection
Create a private connection with the following configuration:
|
Parameter |
Value |
|
Name |
|
|
VLAN ID |
|
|
Subnet for BGP peering |
|
|
IP address of the customer-premises equipment |
|
|
IP address of the Yandex Cloud equipment |
|
|
BGP ASN on the customer-premises equipment |
|
-
In the management console
, select the folder containing the trunk. -
Navigate
to Cloud Interconnect. -
In the left-hand panel, select
Private connections and click Create private connection. -
In the window that opens:
- In the Trunk connection ID field, select the previously created trunk.
- In the VLAN ID field, specify
4095. - In the Peering subnet field, specify
172.31.255.0/30. - In the Peer IP field, specify
172.31.255.1. - In the Cloud IP field, specify
172.31.255.2. - In the BGP ASN field, specify
65534. - Under General information, specify
vpc-stitchingin the Name field. - Click Create.
-
Get the ID of the private connection you created.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
View the description of the CLI command to create a private connection:
yc cic private-connection create --help -
Create a private connection:
yc cic private-connection create \ --name vpc-stitching \ --trunk-id <trunk_ID> \ --vlan-id 4095 \ --ipv4-peering 'peering-subnet=172.31.255.0/30,peer-ip=172.31.255.1,cloud-ip=172.31.255.2,peer-bgp-asn=65534' \ --asyncWhere:
--name: Private connection name.--trunk-id: Trunk ID.--vlan-id: Private connection VLAN ID.--ipv4-peering: Comma-separated BGP peering parameters inkey=valueformat.--async: Optional parameter for running the operation asynchronously.
-
Wait for the operation to complete and get information about the private connection:
yc cic private-connection get --name vpc-stitchingSave the
idfield value, as you will need it later.
Create a virtual router
Create a virtual router named ri-1 and add the vpc-stitching private connection to it.
- In the management console
, select the folder where you want to create a virtual router. - Navigate
to Cloud Router. - Click Create routing instance.
- Enter the virtual router name:
ri-1. - In the Private connections field, select the
vpc-stitchingconnection or specify its ID. - Click Create.
- Get the ID of the virtual router you created.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
See the description of the CLI command for creating a virtual router:
yc cloudrouter routing-instance create --help -
Create a virtual router and add your private connection to it:
yc cloudrouter routing-instance create \ --name ri-1 \ --folder-id <folder_ID> \ --cic-prc <private_connection_ID> \ --asyncWhere:
--name: Virtual router name.--folder-id: ID of the folder where you are creating your virtual router.--cic-prc:vpc-stitchingprivate connection ID.--async: Optional parameter for running the operation asynchronously.
-
Wait for the operation to complete and get information about the virtual router:
yc cloudrouter routing-instance get --name ri-1Save the value of the
idfield.
Contact support to enable VPC Stitching
Create a support ticket
Use the following ticket template:
Subject: [CloudRouter] Enabling VPC Stitching.
Text of request:
Please enable VPC Stitching:
* Private connection ID (prc-id):
bd6g2**********7c8sv (vpc-stitching).
* Virtual router ID (ri-id):
fokrf**********ml058 (ri-1).
Wait for support to confirm that VPC Stitching is enabled before proceeding with the configuration.
Add cloud networks and IP prefixes
Add Net-1 and Net-2 to your virtual router and configure subnet IP prefixes.
Use the following subnet names and IP prefixes for the cloud networks:
-
Net-1(enpcfncr6uld********):-
ru-central1-azone:subnet-a1:10.10.12.0/24subnet-a2:10.10.13.0/24
-
ru-central1-bzone:subnet-b1:10.10.16.0/24subnet-b2:10.10.17.0/24
-
ru-central1-dzone:subnet-d1:10.10.20.0/24subnet-d2:10.10.21.0/24
-
-
Net-2(enpt8ok6snlp********):-
ru-central1-azone:subnet-a3:172.16.11.0/24subnet-a4:172.16.25.0/24
-
ru-central1-bzone:subnet-b3:172.18.28.0/24subnet-b4:172.18.30.0/24
-
ru-central1-dzone:subnet-d3:10.10.42.0/24subnet-d4:10.10.69.0/24
-
- In the management console
, select the folder containing theri-1virtual router. - Navigate
to Cloud Router. - In the row with the
ri-1virtual router, click and select Edit. - Under Routed networks and prefixes, select
Net-1andNet-2. - In the network sections that appear, select the subnets by name and add their IP prefixes for the matching availability zones using the values from the list above.
- Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
View the description of the CLI command for managing the networks and IP prefixes of a virtual router:
yc cloudrouter routing-instance update-networks --help -
Add
Net-1andNet-2and the IP prefixes of their subnets:yc cloudrouter routing-instance update-networks \ <virtual_router_ID> \ --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-a,ipv4-prefixes=[10.10.12.0/24,10.10.13.0/24]' \ --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-b,ipv4-prefixes=[10.10.16.0/24,10.10.17.0/24]' \ --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-d,ipv4-prefixes=[10.10.20.0/24,10.10.21.0/24]' \ --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-a,ipv4-prefixes=[172.16.11.0/24,172.16.25.0/24]' \ --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-b,ipv4-prefixes=[172.18.28.0/24,172.18.30.0/24]' \ --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-d,ipv4-prefixes=[10.10.42.0/24,10.10.69.0/24]' \ --asyncUse the following format to specify each
--add-vpc-netparameter:id=<network_ID>,zone=<availability_zone>,ipv4-prefixes=[<CIDR>,...].If a network has already been added to the virtual router, use
--update-vpc-netrather than--add-vpc-net. -
Wait for the operation to complete and check the virtual router configuration:
yc cloudrouter routing-instance get \ <virtual_router_ID>The
vpc_infosection should show both networks and all IP prefixes you configured.
Add stitching announcements
Add aggregated IP prefixes to your private connection to use them as stitching announcements:
-
For
Net-1:-
10.10.12.0/23 -
10.10.16.0/23 -
10.10.20.0/23
-
-
For
Net-2:-
172.16.10.0/23 -
172.16.24.0/23 -
172.18.28.0/22 -
10.10.42.0/23 -
10.10.68.0/23
-
Warning
Do not use the IP prefixes of the subnets themselves as stitching announcements. Each stitching announcement must consist of an aggregated prefix that includes the matching subnet prefixes.
- In the management console
, select the folder containing thevpc-stitchingprivate connection. - Navigate
to Cloud Interconnect. - In the left-hand panel, select
Private connections. - In the row with the
vpc-stitchingprivate connection, click and select Edit. - In the IPv4 StaticRoute prefix field, add all stitching announcement from the list above. To add another prefix, click Add prefix.
- Click Save.
If you do not have the Yandex Cloud CLI yet, install and initialize it.
The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.
If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.
-
See the description of the CLI command for adding static routes to a private connection:
yc cic private-connection upsert-static-routes --help -
Add stitching announcements:
yc cic private-connection upsert-static-routes \ <private_connection_ID> \ --ipv4-static-routes "10.10.12.0/23,10.10.16.0/23,10.10.20.0/23,172.16.10.0/23,172.16.24.0/23,172.18.28.0/22,10.10.42.0/23,10.10.68.0/23" \ --asyncThe first positional argument is the private connection ID or name. Use
--ipv4-static-routesto provide stitching announcements in CIDR format, as a comma-separated list with no spaces. The--asyncsetting is optional. -
Wait for the operation to complete and check the private connection configuration:
yc cic private-connection get \ <private_connection_ID>The
ipv4_static_routesfield should show all the prefixes you added.
Test network connectivity
Before testing, make sure that:
- Each network being interconnected has a running resource with an IP address from the configured prefix.
- Security groups and local resource firewalls allow ICMP traffic between the networks.
- The virtual router is
ACTIVE. - The virtual router configuration includes
Net-1andNet-2, their IP prefixes, and thevpc-stitchingprivate connection.
-
Connect to a resource in
Net-1and run this command:ping -c 5 <resource_internal_IP_address_in_Net-2> -
Connect to a resource in
Net-2and run this command:ping -c 5 <resource_internal_IP_address_in_Net-1>
Network connectivity is considered established if packets are transmitted in both directions. Report your test results in the ticket you opened to enable VPC Stitching.
If connectivity cannot be established, check the IP prefixes, stitching announcements, security group rules, and local firewall rules. If you cannot resolve the issue on your own, include the test results in your support ticket.