You have activated the CCN service, and all VPCs in your organization have been interconnected through CCN. By default, network instances added to CCN are interconnected.
In certain scenarios, you may want to restrict your partner's network instances from directly accessing your organization's internal network zone without affecting the interconnection between internal VPC network instances. This can be implemented through the custom route table feature of CCN. Specifically, you can plan different custom route tables for CCN and create an interconnection VPC, through which your partner's VPC can access your internal network zone.
The custom route table feature is currently in beta test. To try it out, please submit a ticket.
The network instances associated with CCN are divided into an internal zone, a peering zone, and an external partner zone. Network instances in the internal zone are interconnected, while the partner VPC access the internal zone through the interconnection VPC.
As shown below, create three custom route tables for the CCN instance: the internal route table, the interconnection route table, and the external route table.
According to the conditions of network zones, three custom route tables need to be planned: the internal route table, the interconnection route table, and the external route table.
The routing plan of the custom route table is as follows:
|Item||Internal Route Table||Connection Route Table||External Route Table|
|Route reception policy||Receive the routes of the network instances in the internal network zone, i.e., routes of the internal VPCs.||Receive the routes of the network instances in the internal network zone and partner network zone, i.e., routes of the internal VPCs and partner VPC.||Receive the routes of the network instances in the interconnection network zone, i.e., routes of the interconnection VPC.|
|Bound network instance||Bind network instances in the internal network zone, i.e., internal VPCs.||Bind network instances in the interconnection network zone, i.e., the interconnection VPC.||Bind network instances in the partner network zone, i.e., the partner VPC.|
Please set according to the route table reception policy in the route plan.