VPC peering
VPC peering connects two VPCs owned by the same customer. Once peered, instances in either VPC reach instances in the other over an encrypted WireGuard tunnel that runs between the two VPN gateways.
How it works
Section titled “How it works”- Fully automatic. One action provisions keys, tunnel IPs, endpoints, routes, and firewall rules on both sides.
- Bidirectional. Creating the peering configures both gateways. Deleting either side removes the peering on both.
- Encrypted. WireGuard with a unique preshared key per peering.
- NAT-free inside the tunnel. Source IPs are preserved end to end.
Before you begin
Section titled “Before you begin”- Two VPCs in locations with VPN Gateway enabled.
- One active VPN gateway in each VPC. See VPN gateways.
- Non-overlapping VPC CIDRs, for example
172.16.0.0/16and10.0.0.0/16. - Non-overlapping tunnel subnets. Each gateway’s tunnel subnet must not overlap the other gateway’s tunnel subnet or either VPC CIDR.
Create a peering
Section titled “Create a peering”There is no dedicated peering page. Peerings are created from a VPN gateway’s Peers tab.
- Go to Networking > VPN gateways and open one of the two gateways.
- On the Peers tab, click VPC Peering.
- Pick the remote gateway in the Create VPC Peering dialog. The list shows the customer’s other active gateways in different VPCs.
- Click Create Peering.
Behind the scenes the panel exchanges WireGuard public keys, allocates tunnel IPs from each gateway’s tunnel subnet, generates the preshared key, sets each side’s allowed IPs to the remote VPC CIDR and the remote tunnel subnet, sets the endpoints, and reloads WireGuard on both gateways.
The new connection appears in the VPC Peering Connections table on the gateway’s own VPC Peering tab.
Validation
Section titled “Validation”The panel rejects the peering when any of these is true, checked in this order:
| Check | Error |
|---|---|
| Both gateways are in the same VPC | “Cannot create peering between gateways in the same VPC.” |
| VPC CIDRs overlap | “Cannot create peering: VPC CIDRs overlap. Peered VPCs must have non-overlapping address ranges.” |
| Tunnel subnets overlap | “Cannot create peering: VPN tunnel subnets overlap. Each gateway must use a unique tunnel subnet.” |
| A tunnel subnet overlaps the remote VPC CIDR | “Cannot create peering: a VPN tunnel subnet overlaps with the remote VPC CIDR.” |
| Peering already exists | “A peering connection already exists between these two gateways.” |
Remove a peering
Section titled “Remove a peering”On either gateway’s Peers or VPC Peering tab, find the peering (names carry a vpc-peering- prefix) and delete it. The remote side is cleaned up automatically, and both gateways reload WireGuard. Deleting a VPN gateway also removes every peering it took part in.
Road-warrior access across peerings
Section titled “Road-warrior access across peerings”When a remote-access peer downloads its WireGuard config, the allowed IPs include every peered VPC’s CIDR. A customer dialled into one gateway reaches all peered VPCs with no extra setup.

