A BGP gateway for your VPC. Over Zenlayer's network fabric it reaches public clouds, your on-prem data centers, internet exchanges, and other fabrics — privately, under an ASN you assign.

Border Gateway is your VPC's BGP edge. Over Zenlayer's network fabric it connects out to the networks your architecture depends on — public clouds, your on-prem data centers, internet exchanges, and other fabrics — without touching the public internet.
One border gateway per VPC per region — the VPC's single door to the outside.
The Border Gateway advertises your VPC's routes over BGP and links directly to a Cloud Router — both inside Zenlayer's network. The Cloud Router reaches the public cloud across the network fabric: a routed, private path that never touches the public internet.
The gateway speaks BGP under the ASN you set. Advertise every subnet or just the ones you choose, and control whether routes stay Regional or go Global.
A /27 or /28 BGP interconnect CIDR — standard BGP, your control.
Architectures whose value is in the connections between networks, not just the compute inside one.
Connect your on-prem data center to your cloud VPC privately, over the network fabric — not the public internet.
Reach AWS, Azure, Google Cloud, and Oracle from one VPC over Layer-3 private connect for consistent, private paths.
Private reach to clouds, IXs, and fabrics from the regions hyperscalers underserve (APAC, MEA, LATAM).
Stand up a Border Gateway in one call — set your ASN, VPC, and routing scope — then attach a Cloud Router to reach your clouds. Drive it over the REST API, the Go and Node SDKs, or the CLI.
What you can connect to, BGP/ASN, and routing scope.
Public clouds (AWS, Azure, Google Cloud, Oracle, Tencent, and Alibaba), your on-prem data centers via a datacenter port, internet exchanges, and 3rd-party network fabrics — all privately, over Zenlayer's network fabric.
Yes — the gateway runs BGP under a private ASN you assign (65000–65534). That's the gateway's local BGP ASN, not a public ASN you hold at a RIR — to announce your own public prefixes, see BYOIP. You then advertise all of your subnets or just selected ones, with Regional or Global routing scope.
Yes — interconnect rides Layer-3, BGP-routed private connect over the network fabric, off the public internet.
One per region within the VPC — it's the VPC's single BGP edge in that region.