內部部署資料中心會透過外部虛擬私有雲端網路連線至 Google Cloud ,方法是使用與本機區域中 Cloud Router 相關聯的 Cloud Interconnect 或 Cloud VPN。混合式連線會新增至 Network Connectivity Center 中樞,hub 1做為混合式輪輻。
主機代管路由器設備執行個體的 VM 會新增至 Network Connectivity Center 中樞 hub 1,該中樞設定為使用網狀拓撲,並以 nic0 做為路由器設備輪輻。為了確保高可用性,主機路由器設備的 VM 會在多個區域中成對建立。每個區域都會新增為 Network Connectivity Center 中樞的單一路由器設備輪輻。
[[["容易理解","easyToUnderstand","thumb-up"],["確實解決了我的問題","solvedMyProblem","thumb-up"],["其他","otherUp","thumb-up"]],[["難以理解","hardToUnderstand","thumb-down"],["資訊或程式碼範例有誤","incorrectInformationOrSampleCode","thumb-down"],["缺少我需要的資訊/範例","missingTheInformationSamplesINeed","thumb-down"],["翻譯問題","translationIssue","thumb-down"],["其他","otherDown","thumb-down"]],["上次更新時間:2025-09-05 (世界標準時間)。"],[],[],null,["# Site-to-cloud topologies that use a third-party appliance\n\nNetwork Connectivity Center lets you use a third-party network virtual appliance to\nestablish connectivity between an external site and your\nVirtual Private Cloud (VPC) network resources. To establish this type of\nconnectivity, you use the Router appliance feature. Using\nRouter appliance in this way is supported in all Google Cloud regions.\n\n### Router appliance\n\nThe Router appliance feature lets you install a network virtual appliance\nwithin Google Cloud and use it as the backing resource for a spoke.\n\nTo create a router appliance instance, you install a virtual appliance image on\na Compute Engine virtual machine (VM) and complete additional setup steps.\nThis setup includes establishing Border Gateway Protocol (BGP) peering between\nthe VM and a Cloud Router. BGP enables the dynamic exchange of routes between\nthe Cloud Router and the Router appliance instance. Route exchange lets you\nestablish connectivity between your VPC network and other\nnetworks. We recommend using an image provided by a\n[supported Network Connectivity Center partner](/network-connectivity/docs/network-connectivity-center/partners).\nFor more information about Router appliance, see the\n[Router appliance overview](/network-connectivity/docs/network-connectivity-center/concepts/ra-overview).\n\nNetwork Connectivity Center lets you use a hub-and-spoke architecture for network\nconnectivity. For information about Network Connectivity Center, see the\n[Network Connectivity Center overview](/network-connectivity/docs/network-connectivity-center/concepts/overview). For more\ninformation about Router appliance, see the\n[Router appliance overview](/network-connectivity/docs/network-connectivity-center/concepts/ra-overview).\n\nConnect a site to a VPC network\n-------------------------------\n\nIn the following topology, a router appliance instance serves as the backing\nresource for a Network Connectivity Center spoke. The router appliance instance connects\nwith a peer router in an on-premises network. The router appliance instance also\npeers with a Cloud Router. Routes from the on-premises network are\ndynamically exchanged with the VPC network.\n[](/static/network-connectivity/docs/network-connectivity-center/images/site-to-cloud-one-network.svg) Use a Router appliance spoke to connect a site to a VPC network (click to enlarge)\n\nConnect a site to two VPC networks\n----------------------------------\n\nIn the following topology, a router appliance instance has interfaces in\ntwo VPC networks. Each interface has been used to create a\nRouter appliance spoke. In this case, routes from the on-premises network\nare propagated to each VPC network. Connectivity between the\ntwo VPC networks is determined by the features of the\nnetwork virtual appliance.\n[](/static/network-connectivity/docs/network-connectivity-center/images/site-to-cloud-sample-topology.svg) Use Router appliance spokes to connect a site to two VPC networks (click to enlarge)\n\nFor a detailed description of this topology and instructions about how to\nconfigure it, see\n[Establish connectivity by using a third-party appliance](/network-connectivity/docs/network-connectivity-center/how-to/connect-site-to-cloud).\n\nEnable cross-region failover for multicloud deployments\n-------------------------------------------------------\n\nThe following topology shows automatic failover through router appliances\nacross two regions by using [dynamic routing](/vpc/docs/vpc#routing_for_hybrid_networks).\nThe router instance hosts a router\nappliance image. The Router appliance mediates connectivity between\non-premises and multiple VPC networks for hybrid or multicloud scenarios.\n[](/static/network-connectivity/docs/network-connectivity-center/images/cross-region-failover-site-to-cloud-topology.svg) Cross-region failover site-to-cloud topology (click to enlarge)\n\nIn this topology, Router appliances are added to two Network Connectivity Center\nhubs, `hub 1` for route exchange with on-premises, and `hub 2` for route\nexchange with [VPC spokes](/network-connectivity/docs/network-connectivity-center/concepts/vpc-spokes-overview).\nThe numerical values in the diagram depict the following connections:\n\n1. On-premises data centers are connected to Google Cloud through the external VPC network by using an Cloud Interconnect or Cloud VPN associated with the Cloud Router in the local region. The hybrid connections are added to the Network Connectivity Center hub, `hub 1` as hybrid spokes.\n2. The VMs that host the router appliance instances are added to the Network Connectivity Center hub, `hub 1`, which is configured to use mesh topology using `nic0` as a [Router appliance spoke](/network-connectivity/docs/network-connectivity-center/concepts/ra-overview). The VMs that host the router appliances are created in pairs across multiple regions for high-availability purposes. Each region is added as a single router appliance spoke to the Network Connectivity Center hub.\n3. In each region, the router appliance instance establishes Border Gateway Protocol (BGP) peering with the local `Cloud Router 1` or `Cloud Router 2`. Each Cloud Router receives and advertises route prefixes from the peered appliance. Because the Router appliance has to exchange data with the on-premises connections, site-to-site data transfer field must be enabled for all spokes in Network Connectivity Center `hub 1`. The dynamic routing mode for the external VPC network must be set to global.\n4. To allow communication with spoke VPC networks, the VMs that host the router appliance instances are connected to Network Connectivity Center `hub 2` through `nic1` as a Router appliance spoke in the center group.\n5. In each region, the router appliance instance establishes BGP peering with the local `Cloud Router 3` or `Cloud Router 4`. Each Cloud Router receives and advertises route prefixes from the peered appliance. To enable cross-region failover for appliances in case of region failures, the dynamic routing mode for the internal VPC network must be set to global.\n6. VPC spokes A, B, and C are all connected to the\n Network Connectivity Center `hub 2` in star topology through VPC spokes\n in an edge group to prevent direct communication between VPCs.\n\n For supported locations, see [Locations supported for data transfer](/network-connectivity/docs/network-connectivity-center/concepts/locations).\n For detailed information about connectivity topologies, see\n [Preset connectivity topologies](/network-connectivity/docs/network-connectivity-center/concepts/connectivity-topologies).\n\nWhat's next\n-----------\n\n- To create hubs and spokes, see [Work with hubs and spokes](/network-connectivity/docs/network-connectivity-center/how-to/working-with-hubs-spokes).\n- To view a list of partners whose solutions are integrated with Network Connectivity Center, see [Network Connectivity Center partners](/network-connectivity/docs/network-connectivity-center/partners).\n- To find solutions for Router appliance issues, see [Troubleshooting](/network-connectivity/docs/network-connectivity-center/support/troubleshooting#troubleshooting-ra).\n- To get details about API and `gcloud` commands, see [APIs and reference](/network-connectivity/docs/network-connectivity-center/apis)."]]