tencent cloud

Feedback

Adding Routing Policy

Last updated: 2022-07-06 16:55:22

    Overview

    This document describes how to configure a routing rule in the CKafka console to enhance network access control in public/private network transfers. For more information on public network access, see Configuring ACL Policy.

    Route Type VPC Public Domain Name Access
    Access mode
  • PLAINTEXT
  • SASL_PLAINTEXT
  • SASL_SSL (only supported by Pro Edition instances)
  • SASL_SCRAM (only supported by instances on v2.4.1; for existing instances, you need to submit a ticket for application)
  • SASL_PLAINTEXT
  • SASL_SSL (only supported by Pro Edition instances)
  • Directions

    Note:

    Up to 5 routes can be created per instance. There is only one route if the SASL_PLAINTEXT access mode is selected. For example, if the SASL_PLAINTEXT access mode is selected for the route type of public domain access, the SASL_PLAINTEXT access mode cannot be selected when other routes are created.

    Operation scenario: When purchasing an instance, if you select VPC and choose a corresponding VPC environment (such as VPC A), then CKafka services (such as data production and consumption) can be accessed only from VPC A. If you subsequently find that you need to access the CKafka services in VPC A from other VPCs (such as VPC B), you can select an appropriate routing policy for VPC by configuring the access mode.

    Suggestion: To ensure security, this access mode provides user management and ACL policy configuration to manage user access permission. Configure as appropriate.

    Directions:

    1. Log in to the CKafka console.
    2. Click Instance List on the left sidebar and click the ID/Name of the target instance to enter the basic information page.
    3. On the instance's basic information page, click Add a routing policy in the Access Mode module.
    4. In the pop-up window, select VPC Network as the route type and select the access mode and network.

      Note

      If you select VPC access, you can specify the IP to keep it unchanged when changing the access mode.

    5. Click Submit to add the VPC network.
      Note

      The VPC access address provided in the console (such as 172.16.0.12:9092) represents the communication address used to obtain the backend service. There may be multiple ports in a real access address. Open all ports after 9092 to the internet on your server, so that the service can be accessed normally.

    Contact Us

    Contact our sales team or business advisors to help your business.

    Technical Support

    Open a ticket if you're looking for further assistance. Our Ticket is 7x24 avaliable.

    7x24 Phone Support