{"componentChunkName":"component---src-templates-acg-portal-intl-template-tsx","path":"/fm5aqhghr-intl","result":{"data":{"markdownRemark":{"html":"<h2 id=\"概览\"><a href=\"#%E6%A6%82%E8%A7%88\" aria-label=\"概览 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>概览</h2>\n<p>VPC（Virtual Private Cloud）内支持创建多张自定义路由表，可与云智能网的TGW（Transit Gateway）绑定，使得TGW到VPC方向的流量匹配自定义路由表，可以满足用户更多场景的使用，如实现多VPC间的安全防护。</p>\n<h2 id=\"需求场景\"><a href=\"#%E9%9C%80%E6%B1%82%E5%9C%BA%E6%99%AF\" aria-label=\"需求场景 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>需求场景</h2>\n<p>安全VPC：多个VPC之间的互访流量需要经过安全VPC进行防护。</p>\n<p>说明：</p>\n<ul>\n<li>安全VPC是一个特定的虚拟私有云（VPC）配置，它在多个VPC之间的互访流量以及VPC访问公网的流量路径上，部署了第三方的防火墙进行安全防护。</li>\n<li>第三方防火墙配置不在此赘述，用户可根据实际情况自行配置。</li>\n</ul>\n<h2 id=\"方案概述\"><a href=\"#%E6%96%B9%E6%A1%88%E6%A6%82%E8%BF%B0\" aria-label=\"方案概述 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>方案概述</h2>\n<h3 id=\"两个vpc之间的互访流量经过安全vpc\"><a href=\"#%E4%B8%A4%E4%B8%AAvpc%E4%B9%8B%E9%97%B4%E7%9A%84%E4%BA%92%E8%AE%BF%E6%B5%81%E9%87%8F%E7%BB%8F%E8%BF%87%E5%AE%89%E5%85%A8vpc\" aria-label=\"两个vpc之间的互访流量经过安全vpc permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>两个VPC之间的互访流量经过安全VPC</h3>\n<p>请求流量从源VPC发出之后，先经过安全VPC中的第三方防火墙实例，再到达目的VPC；回向流量从目的VPC发出之后，同样先经过安全VPC中的第三方防火墙实例，再回到源VPC。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/1%E6%94%B9_a14f242.png\" alt=\"1改.png\"></p>\n<p>按以下方式配置路由表（详见配置步骤）：</p>\n<ul>\n<li>业务 VPC 路由设定：对于 VPC-A 与 VPC-B，系统默认路由表已能满足基础通信需求。在其接入云智能网（CSN）的过程中，系统将自动把指向这两个 VPC 的三大私网段路由信息同步至中转网关（TGW），无需额外复杂操作，确保最简捷的连通基础构建。</li>\n<li>路由表分类与关联：CSN中将默认路由表定义为不可信路由表，手动创建一张自定义路由表定义为可信路由表，VPC-A与VPC-B关联不可信路由表，安全VPC关联可信路由表。</li>\n<li>安全 VPC 流量导向精细化：安全VPC自定义路由表绑定至中转网关（TGW），将安全VPC入向流量导流至防火墙；安全VPC系统路由表引流至TGW。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/2.3%E6%94%B9_c5e6596.png\" alt=\"2.3改.png\"></p>\n<h2 id=\"配置步骤\"><a href=\"#%E9%85%8D%E7%BD%AE%E6%AD%A5%E9%AA%A4\" aria-label=\"配置步骤 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>配置步骤</h2>\n<h3 id=\"环境准备\"><a href=\"#%E7%8E%AF%E5%A2%83%E5%87%86%E5%A4%87\" aria-label=\"环境准备 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>环境准备</h3>\n<p>创建VPC-A、VPC-B和安全VPC三个VPC。由于当前在VPC路由表中，子网直连路由优先级高于自定义路由，VPC尽量选择不同网段，为了避免出现流量被直连路由导走情况。本示例中，VPC-A网段为192.168.0.0/16，VPC-B网段为172.16.0.0/16，安全VPC网段为10.0.0.0/16。</p>\n<p>具体操作方法参考<a href=\"https://cloud.baidu.com/doc/VPC/s/qjwvyu0at#%E5%88%9B%E5%BB%BAvpc%E3%80%82\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">创建VPC</a> </p>\n<p>在安全VPC中创建一台虚机，模拟第三方防火墙；在VPC-A和VPC-B中各创建一台虚机，用于两VPC间互访流量的连通性测试。</p>\n<p>具体操作方法参考<a href=\"https://cloud.baidu.com/doc/BCC/s/8kbbkwg4p\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">创建云服务器实例</a>。</p>\n<p>合理设置三台虚机的安全组，使得三台实例之间可以相互通信。</p>\n<p>具体操作方法参考<a href=\"https://cloud.baidu.com/doc/VPC/s/Vjwvyu1sh\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">安全组</a>。</p>\n<h3 id=\"配置流程\"><a href=\"#%E9%85%8D%E7%BD%AE%E6%B5%81%E7%A8%8B\" aria-label=\"配置流程 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>配置流程</h3>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/%E6%B5%81%E7%A8%8B%E5%9B%BE-202412191611_f3abde8.png\" alt=\"流程图-202412191611.png\"></p>\n<p>步骤一：创建CSN实例并加载VPC</p>\n<ul>\n<li>登录到<a href=\"https://console.bce.baidu.com/csn\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">百度智能云控制台</a>，创建一个CSN实例。</li>\n</ul>\n<p>具体操作方法参考<a href=\"https://cloud.baidu.com/doc/CSN/s/Uklrk4o7b#%E5%88%9B%E5%BB%BA%E4%BA%91%E6%99%BA%E8%83%BD%E7%BD%91%E5%AE%9E%E4%BE%8B\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">创建云智能网实例</a>。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/3_8d2f191.png\" alt=\"3.png\"></p>\n<ul>\n<li>点击创建好的实例名称，进入实例基本信息页面。点击左侧边栏中的“网络实例管理”按钮，进入网络实例管理页面，依次添加VPC-A、VPC-B和安全VPC三个VPC到CSN中。</li>\n</ul>\n<p>具体操作方法参考<a href=\"https://cloud.baidu.com/doc/CSN/s/Uklrk4o7b#%E6%B7%BB%E5%8A%A0%E7%BD%91%E7%BB%9C%E5%AE%9E%E4%BE%8B\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">添加网络实例</a>。</p>\n<ul>\n<li>注意在添加时，\"路由学习粒度”选择VPC；“关联至默认路由表”和“被学习至默认路由表”两个功能均选择关闭，在后续步骤中单独配置；“自动为实例配置指向TGW的路由”功能选择开启。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/4_a896a15.png\" alt=\"4.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/5_6f8f9ac.png\" alt=\"5.png\"></p>\n<ul>\n<li>加载三个VPC完成后，网络实例管理页面如下图所示。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/6_723e3d9.png\" alt=\"6.png\"></p>\n<p>步骤二：配置CSN实例路由表</p>\n<ul>\n<li>点击左侧边栏的“路由管理按钮”，进入路由管理页面。此时路由表列表中有一个default路由表，将default路由表定义为不可信路由表。账户开通CSN多路由表白名单后，点击路由表列表中的“+创建”按钮，创建一张自定义路由表定义为可信路由表，名称设置为trusted。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/7_a9b350d.png\" alt=\"7.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/8_53a5c0b.png\" alt=\"8.png\"></p>\n<ul>\n<li>在不可信路由表（default）中，添加与VPC-A和VPC-B的关联关系，使得从VPC-A和VPC-B进入TGW的流量匹配不可信路由表。</li>\n</ul>\n<p>具体操作可参考<a href=\"https://cloud.baidu.com/doc/CSN/s/fkya1yv0g#%E5%88%9B%E5%BB%BA%E5%85%B3%E8%81%94%E5%85%B3%E7%B3%BB\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">关联关系创建方法</a>。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/9_0b09d84.png\" alt=\"9.png\"></p>\n<ul>\n<li>在不可信路由表（default）中，添加目标网段分别为VPC-A和VPC-B网段、下一跳实例为安全VPC的两条静态路由，将VPC-A和VPC-B的互访流量转发到安全VPC。</li>\n</ul>\n<p><a href=\"https://cloud.baidu.com/doc/CSN/s/fkya1yv0g#%E6%B7%BB%E5%8A%A0%E8%B7%AF%E7%94%B1\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">路由添加方法</a>可参考。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/10_d186b2e.png\" alt=\"10.png\"></p>\n<ul>\n<li>在可信路由表（trusted）中，创建与安全VPC的关联关系，使得从安全VPC进入TGW的流量匹配可信路由表。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/11_ba46f45.png\" alt=\"11.png\"></p>\n<ul>\n<li>在可信路由表（trusted）中，添加VPC-A和VPC-B的学习关系，将经过安全VPC的流量转发到VPC-A或VPC-B。</li>\n</ul>\n<p><a href=\"https://cloud.baidu.com/doc/CSN/s/fkya1yv0g#%E5%88%9B%E5%BB%BA%E5%AD%A6%E4%B9%A0%E5%85%B3%E7%B3%BB\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">学习关系创建方法</a>可参考。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/12_9dd495a.png\" alt=\"12.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/13_999316a.png\" alt=\"13.png\"></p>\n<ul>\n<li>配置完成后，CSN实例路由表信息如下表所示：</li>\n</ul>\n<table>\n    <thead>\n        <tr>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>路由表名称</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>路由表描述</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>关联VPC</p>\n            </th>\n            <th colspan=\"2\" rowspan=\"1\" style=\"text-align:center\">\n                <p>路由</p>\n            </th>\n        </tr>\n        <tr>\n            <th colspan=\"1\" rowspan=\"1\" style=\"border-radius:0;border-left:none;border-top:none;text-align:center\">\n                <p>目标网段</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"1\" style=\"border-radius:0;border-left:none;border-top:none;text-align:center\">\n                <p>下一跳</p>\n            </th>\n        </tr>\n    </thead>\n    <tbody>\n        <tr>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>default</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>不可信流量</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>VPC-A、VPC-B</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>安全VPC</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>安全VPC</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>trusted</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>可信流量</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"2\">\n                <p>安全VPC</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>VPC-A</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>VPC-B</p>\n            </td>\n        </tr>\n    </tbody>\n</table>\n<p>步骤三：配置安全VPC路由表</p>\n<ul>\n<li>登录到<a href=\"https://console.bce.baidu.com/network/#/vpc/instance/list\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">私有网络控制台</a>，点击左侧边栏的“路由表”按钮，进入路由表页面，点击“创建路由表”按钮，路由表名称设置为路由表A，所在网络选择安全VPC。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/14_1b84927.png\" alt=\"14.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/15_1554725.png\" alt=\"15.png\"></p>\n<ul>\n<li>创建完成后，点击路由表A右侧的“管理”按钮，进入路由表A详情页面。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/16_51f2bfb.png\" alt=\"16.png\"></p>\n<p>点击“+添加路由”按钮，源网段选择自定义配置，输入0.0.0.0/0，目的网段输入VPC-A的网段，路由类型选择实例路由，下一跳实例选择用户第三方防火墙实例。用同样的方法也添加目的地址为VPC-B网段、其他配置相同的路由。</p>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/17_f411b3f.png\" alt=\"17.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/18_d3da975.png\" alt=\"18.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/19_8d74beb.png\" alt=\"19.png\"></p>\n<p>步骤四：绑定TGW与安全VPC自定义路由表</p>\n<ul>\n<li>在路由表A详情页面中，点击左侧边栏的“绑定TGW”按钮，再点击“+绑定TGW”按钮，与已创建的TGW实例进行绑定，使得TGW进入安全VPC方向的流量匹配自定义路由表。</li>\n</ul>\n<p><img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/20_ef059b5.png\" alt=\"20.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/21_a0bd56d.png\" alt=\"21.png\">\n<img src=\"https://bce.bdstatic.com/doc/bce-doc/VPC/22_3c14d7b.png\" alt=\"22.png\"></p>\n<ul>\n<li>配置完成后，各VPC路由表信息如下表所示：</li>\n</ul>\n<table>\n    <thead>\n        <tr>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>VPC名称</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>路由表名称</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"2\" style=\"text-align:center\">\n                <p>绑定资源</p>\n            </th>\n            <th colspan=\"3\" rowspan=\"1\" style=\"text-align:center\">\n                <p>路由</p>\n            </th>\n        </tr>\n        <tr>\n            <th colspan=\"1\" rowspan=\"1\" style=\"border-radius:0;border-left:none;border-top:none\">\n                <p>源网段</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"1\" style=\"border-radius:0;border-left:none;border-top:none\">\n                <p>目标网段</p>\n            </th>\n            <th colspan=\"1\" rowspan=\"1\" style=\"border-radius:0;border-left:none;border-top:none\">\n                <p>下一跳</p>\n            </th>\n        </tr>\n    </thead>\n    <tbody>\n        <tr>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>VPC-A</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>default</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>VPC内全部资源</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>系统</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/12</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>10.0.0.0/8</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>VPC-B</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>default</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>VPC内全部资源</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>系统</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/12</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>10.0.0.0/8</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"7\">\n                <p>安全VPC</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>default</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"4\">\n                <p>VPC内除TGW外全部资源</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>10.0.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>系统</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/12</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>10.0.0.0/8</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>TGW实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"3\">\n                <p>路由表A</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"3\">\n                <p>TGW实例（TGW进入VPC方向的流量匹配该路由表）</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>10.0.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>系统</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>192.168.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>第三方防火墙实例</p>\n            </td>\n        </tr>\n        <tr>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>0.0.0.0/0</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>172.16.0.0/16</p>\n            </td>\n            <td colspan=\"1\" rowspan=\"1\">\n                <p>第三方防火墙实例</p>\n            </td>\n        </tr>\n    </tbody>\n</table>\n<h3 id=\"连通性测试\"><a href=\"#%E8%BF%9E%E9%80%9A%E6%80%A7%E6%B5%8B%E8%AF%95\" aria-label=\"连通性测试 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>连通性测试</h3>\n<ol>\n<li>登录安全VPC中的第三方防火墙实例，执行以下命令启动允许转发。</li>\n</ol>\n\n    <div class=\"code-block-wrapper\">\n        <div class=\"code-block\">\n            <div class=\"code-block-header\">\n                <span class=\"code-block-name\">Plain Text</span>\n                <button class=\"code-copy-btn\" data-tooltip-text=\"\">\n                    <svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" fill=\"none\"> <path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M5.57894 3.45614C5.57894 3.38832 5.63392 3.33333 5.70175 3.33333H12.5439C12.6117 3.33333 12.6667 3.38832 12.6667 3.45614V10.2982C12.6667 10.3661 12.6117 10.4211 12.5439 10.4211H11.7544V5.70175C11.7544 4.89754 11.1025 4.24561 10.2982 4.24561H5.57894V3.45614ZM4.24561 4.24561V3.45614C4.24561 2.65194 4.89754 2 5.70175 2H12.5439C13.3481 2 14 2.65194 14 3.45614V10.2982C14 11.1025 13.3481 11.7544 12.5439 11.7544H11.7544V12.5439C11.7544 13.3481 11.1025 14 10.2982 14H3.45614C2.65194 14 2 13.3481 2 12.5439V5.70175C2 4.89754 2.65194 4.24561 3.45614 4.24561H4.24561ZM3.33333 5.70175C3.33333 5.63392 3.38832 5.57894 3.45614 5.57894H10.2982C10.3661 5.57894 10.4211 5.63392 10.4211 5.70175V12.5439C10.4211 12.6117 10.3661 12.6667 10.2982 12.6667H3.45614C3.38832 12.6667 3.33333 12.6117 3.33333 12.5439V5.70175Z\" fill=\"currentColor\"></path> </svg>\n                    复制\n                </button>\n            </div>\n            <div class=\"code-block-content\">\n                <pre class=\"language-text\"><code><span class=\"line-number\">1</span># 临时启用允许转发，重启后会失效\n<span class=\"line-number\">2</span>echo 1 &gt; /proc/sys/net/ipv4/ip_forward\n<span class=\"line-number\">3</span>\n<span class=\"line-number\">4</span># 永久启动允许转发\n<span class=\"line-number\">5</span>echo &#039;net.ipv4.ip_forward=1&#039; &gt;&gt; /etc/sysctl.conf\n<span class=\"line-number\">6</span>sudo sysctl -p</code></pre>\n            </div>\n        </div>\n    </div>\n  \n<ol start=\"2\">\n<li>登录VPC-A中的虚机，对VPC-B中虚机的ip执行ping操作，测试VPC-A与VPC-B的连通性，同时在安全VPC中的第三方防火墙实例上，执行tcpdump命令，检查VPC-A与VPC-B的互访流量是否经过第三方防火墙。</li>\n</ol>\n\n    <div class=\"code-block-wrapper\">\n        <div class=\"code-block\">\n            <div class=\"code-block-header\">\n                <span class=\"code-block-name\">Plain Text</span>\n                <button class=\"code-copy-btn\" data-tooltip-text=\"\">\n                    <svg xmlns=\"http://www.w3.org/2000/svg\" width=\"16\" height=\"16\" viewBox=\"0 0 16 16\" fill=\"none\"> <path fill-rule=\"evenodd\" clip-rule=\"evenodd\" d=\"M5.57894 3.45614C5.57894 3.38832 5.63392 3.33333 5.70175 3.33333H12.5439C12.6117 3.33333 12.6667 3.38832 12.6667 3.45614V10.2982C12.6667 10.3661 12.6117 10.4211 12.5439 10.4211H11.7544V5.70175C11.7544 4.89754 11.1025 4.24561 10.2982 4.24561H5.57894V3.45614ZM4.24561 4.24561V3.45614C4.24561 2.65194 4.89754 2 5.70175 2H12.5439C13.3481 2 14 2.65194 14 3.45614V10.2982C14 11.1025 13.3481 11.7544 12.5439 11.7544H11.7544V12.5439C11.7544 13.3481 11.1025 14 10.2982 14H3.45614C2.65194 14 2 13.3481 2 12.5439V5.70175C2 4.89754 2.65194 4.24561 3.45614 4.24561H4.24561ZM3.33333 5.70175C3.33333 5.63392 3.38832 5.57894 3.45614 5.57894H10.2982C10.3661 5.57894 10.4211 5.63392 10.4211 5.70175V12.5439C10.4211 12.6117 10.3661 12.6667 10.2982 12.6667H3.45614C3.38832 12.6667 3.33333 12.6117 3.33333 12.5439V5.70175Z\" fill=\"currentColor\"></path> </svg>\n                    复制\n                </button>\n            </div>\n            <div class=\"code-block-content\">\n                <pre class=\"language-text\"><code><span class=\"line-number\">1</span># 测试VPC-A与VPC-B连通性\n<span class=\"line-number\">2</span>ping &lt;虚机ip地址&gt;\n<span class=\"line-number\">3</span>\n<span class=\"line-number\">4</span># 测试流量是否通过第三方防火墙\n<span class=\"line-number\">5</span>tcpdump host &lt;源虚机ip地址&gt; and &lt;目的虚机ip地址&gt;</code></pre>\n            </div>\n        </div>\n    </div>\n  \n<h3 id=\"相关产品\"><a href=\"#%E7%9B%B8%E5%85%B3%E4%BA%A7%E5%93%81\" aria-label=\"相关产品 permalink\" class=\"anchor\"><svg aria-hidden=\"true\" focusable=\"false\" height=\"16\" version=\"1.1\" viewBox=\"0 0 16 16\" width=\"16\"><path fill-rule=\"evenodd\" d=\"M4 9h1v1H4c-1.5 0-3-1.69-3-3.5S2.55 3 4 3h4c1.45 0 3 1.69 3 3.5 0 1.41-.91 2.72-2 3.25V8.59c.58-.45 1-1.27 1-2.09C10 5.22 8.98 4 8 4H4c-.98 0-2 1.22-2 2.5S3 9 4 9zm9-3h-1v1h1c1 0 2 1.22 2 2.5S13.98 12 13 12H9c-.98 0-2-1.22-2-2.5 0-.83.42-1.64 1-2.09V6.25c-1.09.53-2 1.84-2 3.25C6 11.31 7.55 13 9 13h4c1.45 0 3-1.69 3-3.5S14.5 6 13 6z\"></path></svg></a>相关产品</h3>\n<p><a href=\"https://cloud.baidu.com/product/bcc.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">云服务器BCC</a>、<a href=\"https://cloud.baidu.com/product/vpc.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">私有网络VPC</a>、<a href=\"https://cloud.baidu.com/product/csn.html\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">云智能网CSN</a></p>","fields":{"slug":"fm5aqhghr-intl","title":"CSN支持VPC自定义路由表实现流量安全互访","date":"2025-08-21","extractedHeadings":[]},"headings":[{"value":"概览","depth":2},{"value":"需求场景","depth":2},{"value":"方案概述","depth":2},{"value":"两个VPC之间的互访流量经过安全VPC","depth":3},{"value":"配置步骤","depth":2},{"value":"环境准备","depth":3},{"value":"配置流程","depth":3},{"value":"连通性测试","depth":3},{"value":"相关产品","depth":3}]}},"pageContext":{"isCreatedByStatefulCreatePages":false,"slug":"fm5aqhghr-intl","prev":{"id":"ekk7z0ver-intl","name":"产品描述","path":"ekk7z0ver-intl","filePath":"产品描述/应用场景.md","seo":null,"parentIds":["Rkk7yxf0g-intl"],"parents":[{"id":"Rkk7yxf0g-intl","documentId":"b8449bcd-116c-442e-a836-31a53cd03ef8","name":"产品描述","repoName":"CSN","filePath":"产品描述","disabled":false,"path":"Rkk7yxf0g-intl","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null}]},"next":{"id":"Fm9b18t79-intl","name":"多IDC间通过云智能网实现灾备","path":"Fm9b18t79-intl","filePath":"典型实践/多IDC间通过云智能网实现灾备.md","seo":null,"parentIds":["Ell3fz1kn-intl"],"parents":[{"id":"Ell3fz1kn-intl","documentId":"bfdc531c-9e8e-49cd-90a8-3d3739bf5b77","name":"典型实践","repoName":"CSN","filePath":"典型实践","disabled":false,"path":"Ell3fz1kn-intl","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null}]},"parents":[{"id":"Ell3fz1kn-intl","documentId":"bfdc531c-9e8e-49cd-90a8-3d3739bf5b77","name":"典型实践","repoName":"CSN","filePath":"典型实践","disabled":false,"path":"Ell3fz1kn-intl","lastMergeTime":null,"isApiDoc":null,"httpMethod":null,"seo":null}],"specificSeo":null}}}