Connecting to Salesforce Express Connect

Salesforce Express Connect lets you access Salesforce applications and services directly with a private, dedicated connection. When you create a Salesforce Express Connect through the Megaport Portal:

  • Express Connect is delivered as a Layer 3 routed service.
  • You access Salesforce services using public IPs and are required to run BGP to receive Salesforce routes.
  • Megaport allocates a /31 public IP range for each Salesforce peering.

Express Connect offers two IP addressing options:

  • You can source NAT your LAN traffic to use the /31 public IP space provided by Megaport.
    or
  • You can advertise your own public IP address space to Salesforce. (Salesforce will not accept RFC1918 routes.)

Deployment considerations:

  • Provisioning – One Virtual Cross Connect (VXC) provisions two logical connections to Salesforce using a Megaport Cloud Router (MCR). Salesforce has redundant routers which provide guaranteed uptime for both service locations.
  • Timeframe – Salesforce can take up to two business days for approval once a VXC is deployed from the Portal.
  • IP Addresses and ASN – Customers can use their own publicly registered IP space or Megaport will allocate a public /31 for the end user to peer directly with Salesforce. RFC 1918 private space is not allowed. Private and public ASNs are accepted.
  • Internet Backup – Although we always recommend two Ports for redundancy, an Express Connect over Megaport can be used for the primary connection to Salesforce and if you use publicly routed IP space and the single Port fails, routing to Salesforce can revert to the public Internet.

This figure shows a common Express Connect deployment:

Express Connect deployment

To create a connection to Salesforce Express Connect

  1. In the Megaport Portal, go to the Services page and select the Port you want to use.
    If you haven’t already created a Port, see Creating a Port.
  2. Add a VXC connection for the Port.
    If this is the first connection for the Port, click the Salesforce tile. The tile is a shortcut to the configuration page. Alternatively, click +Connection, click Cloud, and click Salesforce.
    VXC connection

  3. Select Salesforce.com as the provider.
    Salesforce as provider

  4. Select your destination Port and click Next.

  5. Specify these connection details:

    • Connection Name – The name of your VXC to be shown in the Megaport Portal.

    • Service Level Reference (optional) – Specify a unique identifying number for the VXC to be used for billing purposes, such as a cost center number or a unique customer ID. The service level reference number appears for each service under the Product section of the invoice. You can also edit this field for an existing service.

    • Rate Limit – This is the speed of your connection in Mbps. The rate limit can be any value between 1Mb and 5GB.

    • Preferred A-End VLAN – Optionally, specify a VLAN ID for this connection. This must be a unique VLAN ID on this Port and can range from 2 to 4093. If you specify a VLAN ID that is already in use, the system displays the next available VLAN number. The VLAN ID must be unique to proceed with the order. If you don’t specify a value, Megaport will assign one.

      You can click Untag to remove the VLAN tagging for this connection. The untagged option limits you to only one VXC deployed on this Port.
      Connection details

  6. Click Next.

  7. Provide the connection details for the Salesforce service. Provide these values:

    • ASN – Enter a private or public ASN.

    • BGP Password – Optionally, specify the BGP Auth Key.

    • Prefixes – Enter prefixes to announce to Salesforce — RIR assigned IPv4 address ranges only. If you do not have public IP ranges, you can source NAT to the /31s IP provided by Megaport. If you are going to use the /31s IP provided by Megaport, you can leave this field blank.
      Note: RFC 1918 space is not permitted.
      Once configured, you cannot add new prefixes to the VXC.
      SFDC connection details

  8. Click Next.
    A summary page appears that includes the monthly cost. Click Back to make changes or click Add VXC to move this configuration to your cart. Once you have finished this configuration, you can configure additional VXCs or proceed through the checkout process.

    After you complete the check out process, Salesforce can take up to two business days to approve the connection request. The VXC status will be Deployable until Salesforce accepts the connection.
    VXC status
    When Salesforce accepts the request, two logical and redundant connections are created from Salesforce.

    You can view and edit the details of your SEC connection by clicking the VXC and selecting Details.

  9. Configure one BGP peering connection using the /31 IP addresses assigned by Megaport (outlined in red in the image below).
    It is important to configure the IP address that has been assigned to you for the local interface as it has been automatically whitelisted on the SEC side. You will still be able to configure your own public prefixes for advertising across this link using the Megaport specific peering IP address.

    BGP details for SFDC

Helpful resources


Last update: