Direct Connect Overview

Last Updated At: 2025-11-11 17:51:13

What is Direct Connect?

Direct Connect provides a fast and secure way to connect the cloud platform and the local data center. Users can use a Connection to connect cloud platform computing resources located in multiple regions at one time, achieving flexible and reliable hybrid cloud deployment.

Hybrid Cloud Featuring DC Deployment
Use traditional DC tunnel to connect the user's IDC and the cloud VPC.
If a connection needs to connect multiple VPCs, you need to create DC tunnels with different VLAN IDs to connect multiple VPCs.

Components

DC consists of a Connection, a DC tunnel, and a DC gateway.

  • Connection
    The Connection supports dual-line hot standby connection, dual-line connection point power supply, and complete isolation of network pipelines.
  • DC Tunnel
    A DC tunnel is a network link division of a connection. Users can create DC tunnels connected to different DC gateways to interconnect local data centers with multiple Virtual Private Clouds.
  • DC Gateway
  • The dedicated traffic entrance of the VPC can be interconnected with multiple different IDCs by connecting with multiple DC tunnels. The DC gateway is implemented in the form of cluster, with no risk of single point failure across the entire route, meeting the requirements of financial-grade network interconnection.
  • A DC gateway is a bridge that connects a VPC and a Connection. You can create a DC tunnel in a Connection that is associated with a DC gateway.
  • The DC gateway can link DC tunnels from multiple Connections to interconnect with your multiple local data centers.
  • Users can create a DC gateway for each VPC in the DC gateway console. Each VPC only supports creating one DC gateway, which can connect with DC tunnel requests from different Connections.

Differences from and Strengths Over IPsec VPN

Strengths Direct Connect IPsec VPN
Stable Network Delay The network latency is reliable and limited to a low level. The connection network is based on a DC. You can use a fixed routing configuration to avoid the latency and instability caused by congestion or fault-triggered detours. The network connection is based on the Internet. When the network link is blocked during peak hours, it may cause routing detours and unstable latency.
Highly Reliable Disaster Recovery Connect Both connection devices and network forwarding devices are deployed in a distributed and clustered manner, with full-link high-reliability configuration, supporting dual-line connection with protection, meeting your stringent requirements for availability above 99.95%. It adopts a dual-machine hot backup configuration, which has high reliability at the gateway layer. However, due to the unreliable Internet network link, it cannot guarantee dedicated line-level network reliability.
Supporting Large Bandwidth A single line supports a maximum bandwidth connection of 10 Gbps, and can also allow connection with multiple 10 Gbps links for network CLB, with no theoretical upper limit. A single gateway supports a maximum bandwidth limit of 100 Mbps. VPC supports multiple VPN gateway configurations, which can support VPN connection in a bandwidth of greater than 100 Mbps.
High Security The network link is dedicated to users, with no risk of data leakage, ensuring high security and meeting the stringent network connection requirements of the finance, government, and enterprise sectors. Network transmission is based on the pre-shared key encryption of the IKE protocol, which can meet most network transmission security requirements.
Supporting Network Address Translation It supports configuring network address translation services on the gateway, enabling IP mapping at both ends of the DC and IP port mapping at the VPC end, thus resolving address conflicts when multiple networks are interconnected. Not support.