CEN quotas and limits
Cloud Enterprise Network (CEN) has the following feature and performance limitations. You can request quota increases for select resources.
CEN instances
Resource | Default quota | Quota increase |
Number of CEN instances per Alibaba Cloud account | 5 | You can request a quota increase by using one of the following methods:
|
Enterprise Edition transit routers
Enterprise Edition transit router instances
Resource | Default quota | Quota increase |
Number of CIDR blocks per transit router | 5 | Not adjustable |
Network instance connections
Resource | Default quota | Quota increase |
Maximum bandwidth per network instance connection (VPC, ECR, VPN, or VBR connection) per availability zone |
| Not adjustable |
VPC Connection | ||
Number of VPC instances a transit router can connect to | 1,000 | Not adjustable |
Number of transit routers a VPC can connect to. This is a physical connection limit that restricts the number of connections between a VPC and transit routers. | 5 | You can request a quota increase by using one of the following methods:
|
Number of route tables that each network instance connection can be associated with. This is a routing configuration rule: each connection can be associated with only one route table. Note A VPC can create multiple network instance connections so that each connection is associated with the route table of a different transit router. | 1 | Not adjustable |
VBR Connection | ||
Number of virtual border router (VBR) instances a transit router can connect to | 32 | Not adjustable |
VPN Connection | ||
Number of VPN connections per transit router | 50 | You can request a quota increase by using one of the following methods:
|
Number of transit routers an IPsec-VPN connection can connect to | 1 | Not adjustable |
Number of VPN connections that support equal-cost multi-path (ECMP) routing per transit router | 32 | Not adjustable |
Inter-region Connection | ||
Number of inter-region connections between a pair of transit routers | 1 | Not adjustable |
Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between two regions in the Chinese mainland | 1,000 Mbps | You can request a quota increase by using one of the following methods:
|
Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between two regions outside the Chinese mainland | 100 Mbps | You can request a quota increase by using one of the following methods:
|
Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between a region in the Chinese mainland and a region outside the Chinese mainland | 100 Mbps | You can request a quota increase by using one of the following methods:
|
ECR connection | For quotas on Express Connect Router (ECR) resources, see Express Connect quotas. | |
Routing
Resource | Default quota | Quota increase |
Route Table | ||
Number of route tables per transit router | 50 | Not adjustable |
Transit router route entry | ||
Number of route entries per route table of a transit router Important The total number of route entries across all route tables of a transit router instance cannot exceed 40,000. | 10,000 | Not adjustable |
Number of route entries per transit router instance | 40,000 | Not adjustable |
Route Synchronization | ||
Number of VPC instances per transit router on which you can enable route synchronization | 50 | Not adjustable |
Aggregate Route | ||
Number of aggregate routes per route table of a transit router | 20 | Not adjustable |
Route Maps | ||
Number of routing policies for the inbound direction per transit router | 100 | Not adjustable |
Number of routing policies for the outbound direction per transit router | 100 | Not adjustable |
Policy-Based Routing Table | ||
Number of policy tables per Transit Router instance ( | 20 | Contact your account manager to request a quota increase. |
Total number of policy-based routes per transit router instance ( | 100 | Contact your account manager to request a quota increase. |
Number of policy tables per attachment ( | 1 | Not adjustable |
Multicast
Resource | Default quota | Quota increase |
Number of multicast domains per transit router | 20 | Not adjustable |
Number of multicast domains that a VPC can be associated with Note
The total number of multicast domains associated with all vSwitch instances in a VPC cannot exceed the quota. | 20 | |
Number of static or dynamic (IGMP) multicast sources and members per transit router | 2,000 | You can request a quota increase by using one of the following methods:
You can request an increase up to 3,000. To request a quota above 3,000 (up to 10,000), contact your account manager. |
Number of static and dynamic (IGMP) multicast members per multicast group on a transit router | 100 | Not adjustable |
Number of vSwitches per multicast domain on a transit router | 10 | |
Number of static and dynamic (IGMP) multicast sources per multicast group on a transit router | 100 | |
Number of inter-region multicast members per multicast group on a transit router | 15 | |
Number of multicast groups per multicast domain | 20 (Deprecated) | |
Maximum bandwidth per multicast group Note This is the total bandwidth consumed by traffic from all multicast sources to the multicast group and from the multicast group to all multicast members. | 10 Gbps |
Traffic scheduling
Resource | Default quota | Quota increase |
Number of traffic classification rules per transit router | 500 | Not adjustable |
Number of queues per traffic scheduling policy | 64 | Not adjustable |
Basic Edition transit routers
Network instance connections
Resource | Default quota | Quota increase |
Total number of VPC and VBR instances that can be connected to a transit router | 10 | Not adjustable |
Number of Cloud Connect Network (CCN) instances that can be connected to a transit router | 1 | Not adjustable |
Number of inter-region connections between a pair of transit routers | 1 | Not adjustable |
Number of transit routers a VPC can connect to | 1 | Not adjustable |
Routing
Resource | Default quota | Quota increase |
Number of route tables per transit router | 1 | Not adjustable |
Number of route entries per transit router | 100 | Not adjustable |
Route Maps | ||
Number of routing policies for the inbound direction per transit router | 100 | Not adjustable |
Number of routing policies for the outbound direction per transit router | 100 | Not adjustable |
Inter-region bandwidth limits
Transit routers use a distributed, highly reliable cluster architecture. To guarantee the performance and stability of inter-region bandwidth, the transit router automatically enables distributed rate limiting when the peak bandwidth of the inter-region bandwidth plan that you purchase exceeds 1 Gbps. All inter-region traffic is evenly distributed across multiple system servers in the cluster. The peak bandwidth that you configure for the inter-region bandwidth plan is also evenly distributed across these servers. As a result, the transit router reaches the configured peak bandwidth only when multiple connections are used. The required number of connections varies with your actual workload.
Maximum bandwidth per connection = Peak bandwidth of the inter-region bandwidth plan of the transit router ÷ Number of servers in the transit router clusterFor example, if you configure a peak bandwidth of 2,000 Mbps and the transit router cluster uses four system servers to forward traffic, the maximum bandwidth per connection is 2,000 Mbps ÷ 4 = 500 Mbps. In this case, the maximum bandwidth of a single inter-region connection on the transit router is 500 Mbps, and the transit router instance reaches the peak bandwidth configured for the inter-region bandwidth plan when it has four or more inter-region connections.
The inter-region bandwidth of a transit router may occasionally exceed the configured bandwidth limit. As the technology continues to evolve, bandwidth enforcement will become increasingly accurate. To be safe, configure a peak bandwidth slightly larger than your workload requirements.
The bandwidth cap is not a guaranteed service commitment; it serves only as a reference value and an upper limit. When resource contention occurs, the actual available bandwidth may be subject to throttling.
Bandwidth limiting rules for the inbound and outbound directions:
Alibaba Cloud allocates both inbound bandwidth and outbound bandwidth equal to the purchased peak bandwidth.
For example, if the bandwidth limit that you purchase is 5 Gbps, the maximum inbound bandwidth and the maximum outbound bandwidth are both 5 Gbps.