Yandex Cloud
Search
Discuss with expertTry it for free
  • Customer Stories
  • Documentation
  • Blog
  • All Services
    • Cloud Interconnect
    • Cloud Backup
    • Cloud Registry
    • Yandex AI Studio
    • Compute Cloud
    • Object Storage
    • Managed Service for Kubernetes®
    • Yandex BareMetal
    • Smart Web Security
    • Security Deck
    • Managed Service for PostgreSQL
    • Managed Service for ClickHouse®
    • Monium
    • Cloud CDN
    • Network Load Balancer
    • Virtual Private Cloud
    • Cloud DNS
    • Application Load Balancer
    • Yandex Cloud Video
    • Stackland
    • Yandex Cloud Router
    • Yandex Managed Service for Trino
    • Managed Service for MySQL®
    • Managed Service for Valkey™
    • Managed Service for Apache Spark™
    • Yandex StoreDoc
    • Managed Service for OpenSearch
    • Managed Service for Apache Kafka®
    • Data Transfer
    • Yandex MPP Analytics Engine for PostgreSQL
    • Yandex Managed Service for Apache Airflow®
    • Data Processing
    • Yandex MetaData Hub
    • Managed Service for YDB
    • Managed Service for Sharded PostgreSQL
    • Managed Service for YTsaurus
    • Yandex WebSQL
    • DataLens
    • Yandex Search API
    • SpeechSense
    • SpeechKit
    • DataSphere
    • Vision OCR
    • Translate
    • Yandex Identity Hub
    • Key Management Service
    • Certificate Manager
    • Yandex Lockbox
    • Audit Trails
    • SmartCaptcha
    • Cloud Desktop
    • Yandex SIEM
    • SourceCraft Code Assistant
    • Container Registry
    • Managed Service for GitLab
    • Managed Service for Prometheus®
    • Cloud Functions
    • API Gateway
    • Yandex Cloud Postbox
    • Message Queue
    • Serverless Integrations
    • IoT Core
    • Data Streams
    • Serverless Containers
    • Cloud Notification Service
    • Yandex Query
    • Identity and Access Management
    • Yandex Cloud Console
    • Resource Manager
    • Yandex Cloud Billing
    • Yandex Cloud Quota Manager
    • Cloud Apps
  • System Status
  • Marketplace
    • Featured
    • Infrastructure & Network
    • Data Platform
    • AI for business
    • Security
    • DevOps tools
    • Serverless
    • Monitoring & Resources
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
    • Price calculator
    • Pricing plans
  • Customer Stories
  • Documentation
  • Blog
© 2026 Direct Cursus Technology L.L.C.
Tutorials
    • All tutorials
      • Setting up network connectivity between multiple virtual networks using VPC Stitching
      • Configuring Cloud Interconnect access to cloud networks behind NGFWs

In this article:

  • Getting started
  • Create a trunk
  • Create a private connection
  • Create a virtual router
  • Contact support to enable VPC Stitching
  • Add cloud networks and IP prefixes
  • Add stitching announcements
  • Test network connectivity
  1. Architecture and networking
  2. Cloud Interconnect
  3. Setting up network connectivity between multiple virtual networks using VPC Stitching

Setting up network connectivity between multiple virtual networks using VPC Stitching

Written by
Yandex Cloud
Updated at September 30, 2026
View in Markdown
  • Getting started
  • Create a trunk
  • Create a private connection
  • Create a virtual router
  • Contact support to enable VPC Stitching
  • Add cloud networks and IP prefixes
  • Add stitching announcements
  • Test network connectivity

Warning

This function is only available if Cloud Interconnect is activated with a traffic volume of at least 300 TB.

With VPC Stitching, you can set up IP connectivity between two or more Virtual Private Cloud networks that are located in different folders or clouds.

Alert

You can only configure VPC Stitching for cloud networks belonging to clouds within the same organization. Cross-organization network connectivity is not supported.

You can see the solution architecture in the diagram below:

This tutorial uses the following configuration:

  • Net-1 cloud network with multiple subnets.
  • Net-2 cloud network with multiple subnets.
  • vpc-stitching private connection that routes traffic between cloud networks.
  • ri-1 virtual router with the private connection, cloud networks, and the IP prefixes of their subnets added to it.
  • Stitching announcements aggregating the IP prefixes of the subnets in each cloud network.

Warning

No SLA is provided for VPC Stitching. The amount of traffic transmitted through VPC Stitching cannot be monitored. Data transmission beyond the trunk capacity is possible but not guaranteed.

To set up VPC Stitching:

  1. Create a trunk if you do not have an appropriate Cloud Interconnect connection yet.
  2. Create a private connection.
  3. Create a virtual router.
  4. Contact support to enable VPC Stitching.
  5. Add cloud networks and IP prefixes to the virtual router.
  6. Add stitching announcements to the private connection.
  7. Test network connectivity.

Getting startedGetting started

Make sure that:

  • The cloud networks to set up connectivity between belong to clouds within the same organization.
  • The subnet IP prefixes of these networks do not overlap.
  • You have the cic.editor and cloud-router.editor roles for the folders containing Cloud Interconnect and Cloud Router resources, respectively.
  • The Yandex Cloud CLI is installed and configured if you intend to use it.

VPC Stitching requires the following:

  • Trunk with at least 300 TB of data, equivalent to a capacity of 1 Gbit/s.
  • Private connection created in the trunk with a special VPC Stitching configuration.
  • Virtual router with the private connection and cloud networks added to it.

If you already have a trunk with at least 300 TB of data, proceed to creating a private connection. If the amount of data is less than 300 TB, change the connection capacity and wait for support to confirm.

If the private connection and virtual router with the required configuration have already been created and support has confirmed that VPC Stitching is enabled, proceed to configuring IP prefixes.

Create a trunkCreate a trunk

Create a support ticket to create a Cloud Interconnect trunk with 300 TB of data.

Use the following ticket template:

Subject: [CIC] Creating a new trunk to enable VPC Stitching.

Text of request:
Please create a new Cloud Interconnect trunk for VPC Stitching
with 300 TB of data in the <folder_ID> folder.

Wait for support to confirm. After the trunk is created, get its ID, as you will need it when creating your private connection.

Create a private connectionCreate a private connection

Create a private connection with the following configuration:

Parameter

Value

Name

vpc-stitching

VLAN ID

4095

Subnet for BGP peering

172.31.255.0/30

IP address of the customer-premises equipment

172.31.255.1

IP address of the Yandex Cloud equipment

172.31.255.2

BGP ASN on the customer-premises equipment

65534

Management console
CLI
  1. In the management console, select the folder containing the trunk.

  2. Navigate to Cloud Interconnect.

  3. In the left-hand panel, select Private connections and click Create private connection.

  4. In the window that opens:

    1. In the Trunk connection ID field, select the previously created trunk.
    2. In the VLAN ID field, specify 4095.
    3. In the Peering subnet field, specify 172.31.255.0/30.
    4. In the Peer IP field, specify 172.31.255.1.
    5. In the Cloud IP field, specify 172.31.255.2.
    6. In the BGP ASN field, specify 65534.
    7. Under General information, specify vpc-stitching in the Name field.
    8. Click Create.
  5. Get the ID of the private connection you created.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.

If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. View the description of the CLI command to create a private connection:

    yc cic private-connection create --help
    
  2. Create a private connection:

    yc cic private-connection create \
      --name vpc-stitching \
      --trunk-id <trunk_ID> \
      --vlan-id 4095 \
      --ipv4-peering 'peering-subnet=172.31.255.0/30,peer-ip=172.31.255.1,cloud-ip=172.31.255.2,peer-bgp-asn=65534' \
      --async
    

    Where:

    • --name: Private connection name.
    • --trunk-id: Trunk ID.
    • --vlan-id: Private connection VLAN ID.
    • --ipv4-peering: Comma-separated BGP peering parameters in key=value format.
    • --async: Optional parameter for running the operation asynchronously.
  3. Wait for the operation to complete and get information about the private connection:

    yc cic private-connection get --name vpc-stitching
    

    Save the id field value, as you will need it later.

Create a virtual routerCreate a virtual router

Create a virtual router named ri-1 and add the vpc-stitching private connection to it.

Management console
CLI
  1. In the management console, select the folder where you want to create a virtual router.
  2. Navigate to Cloud Router.
  3. Click Create routing instance.
  4. Enter the virtual router name: ri-1.
  5. In the Private connections field, select the vpc-stitching connection or specify its ID.
  6. Click Create.
  7. Get the ID of the virtual router you created.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.

If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. See the description of the CLI command for creating a virtual router:

    yc cloudrouter routing-instance create --help
    
  2. Create a virtual router and add your private connection to it:

    yc cloudrouter routing-instance create \
      --name ri-1 \
      --folder-id <folder_ID> \
      --cic-prc <private_connection_ID> \
      --async
    

    Where:

    • --name: Virtual router name.
    • --folder-id: ID of the folder where you are creating your virtual router.
    • --cic-prc: vpc-stitching private connection ID.
    • --async: Optional parameter for running the operation asynchronously.
  3. Wait for the operation to complete and get information about the virtual router:

    yc cloudrouter routing-instance get --name ri-1
    

    Save the value of the id field.

Contact support to enable VPC StitchingContact support to enable VPC Stitching

Create a support ticket to enable VPC Stitching for your private connection.

Use the following ticket template:

Subject: [CloudRouter] Enabling VPC Stitching.

Text of request:
Please enable VPC Stitching:
* Private connection ID (prc-id):
  bd6g2**********7c8sv (vpc-stitching).
* Virtual router ID (ri-id):
  fokrf**********ml058 (ri-1).

Wait for support to confirm that VPC Stitching is enabled before proceeding with the configuration.

Add cloud networks and IP prefixesAdd cloud networks and IP prefixes

Add Net-1 and Net-2 to your virtual router and configure subnet IP prefixes.

Use the following subnet names and IP prefixes for the cloud networks:

  • Net-1 (enpcfncr6uld********):

    • ru-central1-a zone:

      • subnet-a1: 10.10.12.0/24
      • subnet-a2: 10.10.13.0/24
    • ru-central1-b zone:

      • subnet-b1: 10.10.16.0/24
      • subnet-b2: 10.10.17.0/24
    • ru-central1-d zone:

      • subnet-d1: 10.10.20.0/24
      • subnet-d2: 10.10.21.0/24
  • Net-2 (enpt8ok6snlp********):

    • ru-central1-a zone:

      • subnet-a3: 172.16.11.0/24
      • subnet-a4: 172.16.25.0/24
    • ru-central1-b zone:

      • subnet-b3: 172.18.28.0/24
      • subnet-b4: 172.18.30.0/24
    • ru-central1-d zone:

      • subnet-d3: 10.10.42.0/24
      • subnet-d4: 10.10.69.0/24
Management console
CLI
  1. In the management console, select the folder containing the ri-1 virtual router.
  2. Navigate to Cloud Router.
  3. In the row with the ri-1 virtual router, click and select  Edit.
  4. Under Routed networks and prefixes, select Net-1 and Net-2.
  5. In the network sections that appear, select the subnets by name and add their IP prefixes for the matching availability zones using the values from the list above.
  6. Click Save.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.

If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. View the description of the CLI command for managing the networks and IP prefixes of a virtual router:

    yc cloudrouter routing-instance update-networks --help
    
  2. Add Net-1 and Net-2 and the IP prefixes of their subnets:

    yc cloudrouter routing-instance update-networks \
      <virtual_router_ID> \
      --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-a,ipv4-prefixes=[10.10.12.0/24,10.10.13.0/24]' \
      --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-b,ipv4-prefixes=[10.10.16.0/24,10.10.17.0/24]' \
      --add-vpc-net 'id=enpcfncr6uld********,zone=ru-central1-d,ipv4-prefixes=[10.10.20.0/24,10.10.21.0/24]' \
      --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-a,ipv4-prefixes=[172.16.11.0/24,172.16.25.0/24]' \
      --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-b,ipv4-prefixes=[172.18.28.0/24,172.18.30.0/24]' \
      --add-vpc-net 'id=enpt8ok6snlp********,zone=ru-central1-d,ipv4-prefixes=[10.10.42.0/24,10.10.69.0/24]' \
      --async
    

    Use the following format to specify each --add-vpc-net parameter: id=<network_ID>,zone=<availability_zone>,ipv4-prefixes=[<CIDR>,...].

    If a network has already been added to the virtual router, use --update-vpc-net rather than --add-vpc-net.

  3. Wait for the operation to complete and check the virtual router configuration:

    yc cloudrouter routing-instance get \
      <virtual_router_ID>
    

    The vpc_info section should show both networks and all IP prefixes you configured.

Add stitching announcementsAdd stitching announcements

Add aggregated IP prefixes to your private connection to use them as stitching announcements:

  • For Net-1:

    • 10.10.12.0/23

    • 10.10.16.0/23

    • 10.10.20.0/23

  • For Net-2:

    • 172.16.10.0/23

    • 172.16.24.0/23

    • 172.18.28.0/22

    • 10.10.42.0/23

    • 10.10.68.0/23

Warning

Do not use the IP prefixes of the subnets themselves as stitching announcements. Each stitching announcement must consist of an aggregated prefix that includes the matching subnet prefixes.

Management console
CLI
  1. In the management console, select the folder containing the vpc-stitching private connection.
  2. Navigate to Cloud Interconnect.
  3. In the left-hand panel, select  Private connections.
  4. In the row with the vpc-stitching private connection, click and select  Edit.
  5. In the IPv4 StaticRoute prefix field, add all stitching announcement from the list above. To add another prefix, click Add prefix.
  6. Click Save.

If you do not have the Yandex Cloud CLI yet, install and initialize it.

The folder used by default is the one specified when creating the CLI profile. To change the default folder, use the yc config set folder-id <folder_ID> command. You can also specify a different folder for any command using --folder-name or --folder-id.

If you access a resource by its name, the search will be limited to the default folder. If you access a resource by its ID, the search will be global, i.e., through all folders based on access permissions.

  1. See the description of the CLI command for adding static routes to a private connection:

    yc cic private-connection upsert-static-routes --help
    
  2. Add stitching announcements:

    yc cic private-connection upsert-static-routes \
      <private_connection_ID> \
      --ipv4-static-routes "10.10.12.0/23,10.10.16.0/23,10.10.20.0/23,172.16.10.0/23,172.16.24.0/23,172.18.28.0/22,10.10.42.0/23,10.10.68.0/23" \
      --async
    

    The first positional argument is the private connection ID or name. Use --ipv4-static-routes to provide stitching announcements in CIDR format, as a comma-separated list with no spaces. The --async setting is optional.

  3. Wait for the operation to complete and check the private connection configuration:

    yc cic private-connection get \
      <private_connection_ID>
    

    The ipv4_static_routes field should show all the prefixes you added.

Test network connectivityTest network connectivity

Before testing, make sure that:

  • Each network being interconnected has a running resource with an IP address from the configured prefix.
  • Security groups and local resource firewalls allow ICMP traffic between the networks.
  • The virtual router is ACTIVE.
  • The virtual router configuration includes Net-1 and Net-2, their IP prefixes, and the vpc-stitching private connection.
  1. Connect to a resource in Net-1 and run this command:

    ping -c 5 <resource_internal_IP_address_in_Net-2>
    
  2. Connect to a resource in Net-2 and run this command:

    ping -c 5 <resource_internal_IP_address_in_Net-1>
    

Network connectivity is considered established if packets are transmitted in both directions. Report your test results in the ticket you opened to enable VPC Stitching.

If connectivity cannot be established, check the IP prefixes, stitching announcements, security group rules, and local firewall rules. If you cannot resolve the issue on your own, include the test results in your support ticket.

Was the article helpful?

Previous
Deploying a web app on BareMetal servers with an L7 load balancer and Smart Web Security protection
Next
Configuring Cloud Interconnect access to cloud networks behind NGFWs
© 2026 Direct Cursus Technology L.L.C.