How to change CIDR range of account created by Control Tower


I created two accounts using Control Tower that have the same CIDR range. I'm wanting to change one of the CIR ranges so I can have enable VPC peering across accounts via the transit gateway.

How can I do this?

1 Answer

According to

If you change the CIDR range in the settings of Account Factory, all new accounts that are subsequently created by AWS Control Tower (using Account Factory) are assigned the new CIDR range. The old accounts are not updated. For example, you can create an account, then change the CIDR range and create a new account, and the VPCs allocated to those two accounts can be peered.

So it doesn't look like you can change the CIDR range of a VPC on-the-fly, you would have to delete one of the accounts with the overlapping CIDR range, then change the CIDR range in Account Factory, then re-create the account.

profile picture
answered a year ago
profile pictureAWS
reviewed a year ago

You are not logged in. Log in to post an answer.

A good answer clearly answers the question and provides constructive feedback and encourages professional growth in the question asker.

Guidelines for Answering Questions