Skip to content

VPC peering

VPC peering connects two VPCs owned by the same customer. Once peered, instances in either VPC reach instances in the other over an encrypted WireGuard tunnel that runs between the two VPN gateways.

  • Fully automatic. One action provisions keys, tunnel IPs, endpoints, routes, and firewall rules on both sides.
  • Bidirectional. Creating the peering configures both gateways. Deleting either side removes the peering on both.
  • Encrypted. WireGuard with a unique preshared key per peering.
  • NAT-free inside the tunnel. Source IPs are preserved end to end.
  • Two VPCs in locations with VPN Gateway enabled.
  • One active VPN gateway in each VPC. See VPN gateways.
  • Non-overlapping VPC CIDRs, for example 172.16.0.0/16 and 10.0.0.0/16.
  • Non-overlapping tunnel subnets. Each gateway’s tunnel subnet must not overlap the other gateway’s tunnel subnet or either VPC CIDR.

There is no dedicated peering page. Peerings are created from a VPN gateway’s Peers tab.

  1. Go to Networking > VPN gateways and open one of the two gateways.
  2. On the Peers tab, click VPC Peering.
  3. Pick the remote gateway in the Create VPC Peering dialog. The list shows the customer’s other active gateways in different VPCs.
  4. Click Create Peering.

Behind the scenes the panel exchanges WireGuard public keys, allocates tunnel IPs from each gateway’s tunnel subnet, generates the preshared key, sets each side’s allowed IPs to the remote VPC CIDR and the remote tunnel subnet, sets the endpoints, and reloads WireGuard on both gateways.

The new connection appears in the VPC Peering Connections table on the gateway’s own VPC Peering tab.

The panel rejects the peering when any of these is true, checked in this order:

Check Error
Both gateways are in the same VPC “Cannot create peering between gateways in the same VPC.”
VPC CIDRs overlap “Cannot create peering: VPC CIDRs overlap. Peered VPCs must have non-overlapping address ranges.”
Tunnel subnets overlap “Cannot create peering: VPN tunnel subnets overlap. Each gateway must use a unique tunnel subnet.”
A tunnel subnet overlaps the remote VPC CIDR “Cannot create peering: a VPN tunnel subnet overlaps with the remote VPC CIDR.”
Peering already exists “A peering connection already exists between these two gateways.”

On either gateway’s Peers or VPC Peering tab, find the peering (names carry a vpc-peering- prefix) and delete it. The remote side is cleaned up automatically, and both gateways reload WireGuard. Deleting a VPN gateway also removes every peering it took part in.

When a remote-access peer downloads its WireGuard config, the allowed IPs include every peered VPC’s CIDR. A customer dialled into one gateway reaches all peered VPCs with no extra setup.