代管路由器設備執行個體的 VM 在兩個 VPC 網路中都有介面。每個介面都已用於建立 Router 應用程式輻條。
路由器設備執行個體會參與總共四個邊界閘道通訊協定 (BGP) 對等互連工作階段:在 VPC 網路 A 中,Cloud Router A 會與路由器設備執行個體建立兩個工作階段。在 VPC 網路 B 中,Cloud Router B 會與路由器設備執行個體建立兩個工作階段。
在這個情況下,Cloud Router A 會透過防火牆路由器設備學習 192.168.10.0/24 子網路。這個路徑會安裝在 VPC 網路 A 的路由表中。同樣地,Cloud Router B 會透過防火牆路由器裝置取得 10.1.3.0/24 子網路,並在 VPC 網路 B 的轉送表格中安裝路徑。這時,VM A 和 VM B 就能通訊,但仍須遵守您為機器定義的防火牆規則。
所有 Google Cloud地區都支援以這種方式使用 Router 應用程式。
使用防火牆設備 (按一下即可放大)
如要透過這種方式設定 Router 應用程式輻條,請按照「使用第三方應用程式建立連線」一文中的程序操作。雖然「連線至 Google Cloud」說明的是網站到雲端的連線情境,但 Network Connectivity Center 的步驟與上圖相同。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-05 (世界標準時間)。"],[],[],null,["# VPC-to-VPC topology that uses a third-party appliance\n\nNetwork Connectivity Center lets you use a third-party network virtual appliance to\nestablish connectivity between your\nVirtual Private Cloud (VPC) networks. To establish this type of\nconnectivity, you use the Router appliance feature. Using\nRouter appliance in this way is supported in all Google Cloud regions.\n\nWhen you use Router appliance, you install the image of a virtual appliance\non a Compute Engine virtual machine (VM) that uses Border Gateway Protocol\n(BGP). We recommend using an image provided by a\n[supported Network Connectivity Center partner](/network-connectivity/docs/network-connectivity-center/partners).\nFor more information about Router appliance, see the\n[Router appliance overview](/network-connectivity/docs/network-connectivity-center/concepts/ra-overview).\n\nThis page uses a firewall appliance as an example. However, you could use the\ntopology described on this page when setting up an SD-WAN router, a\nload-balancing appliance, or another type of device.\n\nNetwork Connectivity Center lets you use a hub-and-spoke architecture for network\nconnectivity. For information about Network Connectivity Center, see the\n[Network Connectivity Center overview](/network-connectivity/docs/network-connectivity-center/concepts/overview). For more\ninformation about Router appliance, see the\n[Router appliance overview](/network-connectivity/docs/network-connectivity-center/concepts/ra-overview).\n\nSample topology\n---------------\n\nIn the following topology, the router appliance instance hosts a firewall\nappliance image. The firewall appliance mediates connectivity between\ntwo Virtual Private Cloud (VPC) networks.\n\nThe VM that hosts the router appliance instance has interfaces in both\nVPC networks. Each interface has been used to create a\nRouter appliance spoke.\n\nThe router appliance instance engages in a total of four Border\nGateway Protocol (BGP) peering sessions: In VPC network A,\nCloud Router A establishes two sessions with the router appliance instance.\nIn VPC network B, Cloud Router B establishes two sessions\nwith the router appliance instance.\n\nIn this scenario, Cloud Router A learns the 192.168.10.0/24 subnet through\nthe firewall Router appliance. This route is installed on the routing table\nin VPC network A. Similarly, Cloud Router B learns the\n10.1.3.0/24 subnet through the firewall Router appliance, and the route is\ninstalled on the routing table in VPC network B. Now, VM A\nand VM B can communicate---subject to the firewall rules that you've\ndefined for your appliance.\n\nUsing Router appliance in this way is supported in all Google Cloud\nregions.\n[](/static/network-connectivity/docs/network-connectivity-center/images/firewall-topology.svg) Use a firewall appliance (click to enlarge) **Note:** This topology would also work for a scenario where you want to use an SD-WAN router, a load balancer, or some other type of appliance in two VPC networks.\n\nTo set up Router appliance spokes in this way, follow the procedure in\n[Establish connectivity by using a third-party appliance](/network-connectivity/docs/network-connectivity-center/how-to/connect-site-to-cloud).\nAlthough \"Connect to Google Cloud\" describes a site-to-cloud connectivity\nscenario, the Network Connectivity Center steps are the same as in the preceding diagram.\n\nWhat's next\n-----------\n\n- To create hubs and spokes, see [Working with hubs and spokes](/network-connectivity/docs/network-connectivity-center/how-to/working-with-hubs-spokes).\n- To view a list of partners whose solutions are integrated with Network Connectivity Center, see [Network Connectivity Center partners](/network-connectivity/docs/network-connectivity-center/partners).\n- To find solutions for Router appliance issues, see [Troubleshooting](/network-connectivity/docs/network-connectivity-center/support/troubleshooting#troubleshooting-ra).\n- To get details about API and `gcloud` commands, see [APIs and reference](/network-connectivity/docs/network-connectivity-center/apis)."]]