Benefits of Alibaba Express connections with MCR
- Enhanced security and higher network performance
- Scalable connectivity options
- API integration between Megaport and Alibaba which simplifies the provisioning of connections for a fast and seamless experience
- Connect to Alibaba Cloud on-ramp locations through any of the global Megaport-enabled locations
- Connect with the Alibaba Cloud Enterprise Network (CEN). For more information, see What is Cloud Enterprise Network? in the Alibaba documentation.
Creating a VXC to the Alibaba Cloud
Before you can create a connection to the Alibaba Cloud, you need to have an Alibaba account (you can create one in the Alibaba Console). Your account number is required to create your Megaport VXC.If you require a VXC to the Alibaba Cloud with a rate limit higher than 1 Gbps, contact your Alibaba and Megaport Account Managers to request a higher limit before proceeding. VXCs created with a higher rate limit without approval will not be deployed.
- Log in to the Alibaba Cloud Console and retrieve your account ID.
When logged in, click your avatar icon located in the top right corner and copy your Account ID.
-
In the , select the MCR to attach your VXC to and click +Connection.
If you haven’t already created an MCR, see Creating an MCR. - Click the Cloud tile and click Next.
- Select Alibaba Cloud as the provider.
- Select the target destination for your connection and click Next.
-
Specify the connection details:
- Connection Name — The name of your VXC to be shown in the .
- Service Level Reference (optional) — Specify a unique identifying number for your Megaport service to be used for billing purposes, such as a cost center number, unique customer ID, or purchase order number. The service level reference number appears for each service under the Product section of the invoice. You can also edit this field for an existing service.
- Rate Limit — The speed of your connection in Mbps.
-
VXC State — Select Enabled or Shut Down to define the initial state of the connection. For more information, see Shutting Down a VXC for Failover Testing.
If you select Shut Down, traffic will not flow through this service and it will behave as if it was down on the Megaport network. Billing for this service will remain active and you will still be charged for this connection.
- Minimum Term — Select No Minimum Term, 12 Months, 24 Months, 36 Months, 48 Months, or 60 Months. Longer terms result in a lower monthly rate. 12 Months is selected by default. Take note of the information on the screen to avoid early termination fees (ETF). Enable the Minimum Term Renewal option for services with a 12, 24, 36, 48 or 60-month term to automatically renew the contract at the same discounted price and term length at the end of the contract. If you don’t renew the contract, at the end of the term, the contract will automatically roll over to month-to-month contract for the following billing period, at the same price, without term discounts. For more information, see VXC Pricing and Contract Terms and VXC, Megaport Internet, and IX Billing.
-
Resource Tags — You can use resource tags to add your own reference metadata to a Megaport service.
To add a tag:- Click Add Tags.
- Click Add New Tag.
- Enter details into the fields:
- Key — string maximum length 128. Valid values are a-z 0-9 _ : . / \ -
- Value — string maximum length 256. Valid values are a-z A-Z 0-9 _ : . @ / + \ - (space)
- Click Save. If you already have resource tags for that service, you can manage them by clicking Manage Tags.
- Click Next.
-
Enter an IP address with the subnet mask, for example, 192.168.100.1/30.
Use the first available IP address to assign to the MCR. Alibaba uses the second available IP address for the BGP neighbor. This example uses 192.168.100.0/30. The first available IP address is 192.168.100.1/30, which is assigned to the MCR.
For more information, see Creating an MCR VXC. -
If the MCR has IPsec enabled, you can add IPsec tunnels.
Click + Add IPsec Tunnel Interface.
Add the IPsec tunnel details:- Description — Enter a description of the IPsec tunnel for your reference.
- Source IP Address — Click the box and select the address from the drop-down list.
This is a list of interface IP addresses defined on this VXC. - Destination IP Address — Add the destination IP address.
The destination IP address of the tunnel must not be an IP address configured on the same MCR. - Pre-shared key — Add a key that is common to both the IKE2 (Internet Key Exchange version 2) initiator and responder. The length must be between 8 and 100 characters.
- Local Identifier (optional) — Enter the identifier used for IKE authentication. This allows you to override the default source IP address with a non-IP address, which is required for some configurations. By default, the source IP address is used. Valid values include IPv4/IPv6 addresses, domain names, and email addresses (lowercase, 5-100 characters). For example,
megaport.comoruser@example.com. - Remote Identifier (optional) — Enter the identifier used for IKE authentication. This allows you to override the default destination IP address with a non-IP address, which is required for some configurations. By default, the destination IP address is used. Valid values include IPv4/IPv6 addresses, domain names, and email addresses (lowercase, 5-100 characters). For example,
megaport.comoruser@example.com. - Start Action — Select either active or passive. Passive indicates that the local MCR is an IPsec responder waiting for the remote to perform IKE2 initiation.
- Phase 1 Lifetime — Enter a value between 300 and 604800 seconds. This is the lifetime of IKE2 session in seconds. The default value is 28800 seconds (8 hours). When it expires, rekeying will occur.
- Phase 2 Lifetime — Enter a value between 300 and 86400 seconds. This is the lifetime in seconds of the IPsec Security Association (SA). The value must be less than the Phase 1 Lifetime. The default value is 3600 seconds (1 hour). When it expires, rekeying will occur.
-
Click Add BGP Connection.
Add the local and peer IP addresses for this BGP connection. You must also add the correct autonomous system number (ASN) for the peer. The Alibaba Cloud ASN is 45104. As a best practice we recommend that you confirm the ASN when configuring the Megaport end. -
Specify the connection details:
- Local IP — Select the IP address assigned to the MCR from the drop-down list. In this example, the local IP address is 192.168.100.1/30.
- Peer IP — Select the second available IP address in the /30 CIDR. In this example, the peer IP address is 192.168.100.2/30.
- Peer ASN — Enter 45104, which is the peer ASN for Alibaba. The peer ASN is always 45104.
-
BGP Password (optional) — Specify a shared key to authenticate the BGP peer. You will need to use this key when you configure your BGP peer group in the Alibaba Console. The shared key length is from 1 to 25 characters. The key can include any of these characters:
a-z
A-Z
0-9
! @ # ? . $ % ^ & * + = - - Description (optional) — Enter a description for the connection.
- BGP State — Shuts down the connection without removing it. The initial setting will be taken from the setting on the A-End of the MCR. Enabling or shutting down the BGP state does not affect existing BGP sessions. The BGP state only affects new VXCs. This setting overrides the MCR state for an individual connection.
-
Click Add.
The details for the new connection are shown: - Click Next.
- Enter the Account ID copied from your Alibaba Console and click Next.
- Review your order details and click Add VXC.
- Configure more VXCs or click Review Order.
- Click Review Order to proceed through the checkout process, or click Save to save the configured services before placing the order.
-
Review the Important Information section and confirm agreement with the Service Agreements.
If you do not have a promotion code, skip to the Order Now step. If you do have a promotion code, enter it into the Enter discount code field then click Apply. Alternatively, if a code already appears in the Discounts field, verify it is correct and click Apply.
The promotional discount appears below the Standard Term discount. This discount is not reflected in the Monthly Rate shown here, it is applied at the time of billing. If an invalid or expired code causes an error with your order, contact your Megaport Account Manager for a replacement code.
If you entered an incorrect promotion code, you can remove it by clicking Remove.
In addition to entering a promotion code manually, there are two other ways to apply promotion codes.
- Auto-apply — Megaport automatically applies the promotion code to your order. It appears automatically on the Checkout page.
- Manual list — Eligible promotion codes appear at checkout for any applicable services in your cart. You can then select and apply them.
- Click Order Now.
- In the Alibaba Console, choose Express Connect > Physical Connections.
- Click Accept and Pay next to the new physical connection (the connection that was part of your VXC order).
- Click OK to accept the connection.
- Choose the duration of the contract and verify the other connection details.
- Click Buy Now.
- Select the payment method in the top right corner and click Pay. The process might vary depending on the chosen payment method.
- Verify the details and click Purchase.
- In the Alibaba Console, click the instance name of the physical connection.
- Click Create VBR.
-
Specify these VBR details:
- Name — Enter a name for the VBR.
- Physical Connection Information — Confirm the physical connection that this VRB will attach to.
- VLAN ID and Set VBR Bandwidth Value — VLAN ID and speed are preconfigured based on the physical connection you selected.
- Peer details — The peer details should match the MCR end of the connection from the Megaport Portal. Enter the correct IP address for the relevant peer.
-
Click OK.
The new VBR appears on the Connected VBRs tab and is attached to the physical connection. The Bandwidth Status of the VBR is Not Activated until you configure the BGP details that correspond with those configured on the MCR.You can also view the connection status in the MCR Looking Glass. The Megaport side of the connection will be down (red X) until BGP is configured. - Click the newly created VBR.
- In the BGP Groups tab, click Create BGP Group.
-
Specify these details:
- Name (optional) — Enter a name for the group.
- Peer ASN — Enter the ASN assigned to the MCR. The MCR ASN is typically 133937, unless you choose to override the ASN when creating the BGP peer in the Megaport Portal. If you have specified a local ASN to override the default ASN, enter it here.
- BGP Key — If you entered a BGP password in the Megaport Portal, enter the same password here.
- Description (optional) — Enter a group description.
- In the Alibaba Console, select the instance name of the physical connection.
- Select the BGP Peers tab and click Create BGP Peer.
- Select the new BGP peer group from the drop-down list (the peer group that maps to the MCR ASN).
-
Enter the MCR IP address as the BGP Peer IP (configured in step 7 of To create a VXC to your Alibaba Express Connect peer location).
Initially, when you complete the BGP Peer configuration the BGP Connection Status is Unestablished. It might take a few moments for the peers to start communicating. Once the BGP peers are exchanging data, the BGP status in the Alibaba Console changes to Established. In the MCR Looking Glass in the Megaport Portal, the BGP status changes to a green checkmark.
Additional notes when setting up BGP
- You can only specify the data center as the BGP peer of a VBR.
- VBRs support only BGP-4.
- You can create a maximum of eight BGP peers for each VBR.
- Each BGP peer supports at most 110 dynamic routes.
- Bidirectional Forwarding Detection (BFD) is disabled for VBRs by default. To enable BFD, submit a ticket to Alibaba.