CEN quotas and limits

Updated at:

Cloud Enterprise Network (CEN) has the following feature and performance limitations. You can request quota increases for select resources.

CEN instances

Resource

Default quota

Quota increase

Number of CEN instances per Alibaba Cloud account

5

You can request a quota increase by using one of the following methods:

Enterprise Edition transit routers

Enterprise Edition transit router instances

Resource

Default quota

Quota increase

Number of CIDR blocks per transit router

5

Not adjustable

Network instance connections

Resource

Default quota

Quota increase

Maximum bandwidth per network instance connection (VPC, ECR, VPN, or VBR connection) per availability zone

  • 100 Gbps in China (Hangzhou), China (Shanghai), China (Beijing), China (Shenzhen), China (Hong Kong), and Singapore

  • 50 Gbps in China (Guangzhou), China (Heyuan), China (Wuhan - Local Region), Indonesia (Jakarta), and Mexico

  • 15 Gbps in other regions

Not adjustable

VPC Connection

Number of VPC instances a transit router can connect to

1,000

Not adjustable

Number of transit routers a VPC can connect to. This is a physical connection limit that restricts the number of connections between a VPC and transit routers.

5

You can request a quota increase by using one of the following methods:

Number of route tables that each network instance connection can be associated with. This is a routing configuration rule: each connection can be associated with only one route table.

Note

A VPC can create multiple network instance connections so that each connection is associated with the route table of a different transit router.

1

Not adjustable

VBR Connection

Number of virtual border router (VBR) instances a transit router can connect to

32

Not adjustable

VPN Connection

Number of VPN connections per transit router

50

You can request a quota increase by using one of the following methods:

Number of transit routers an IPsec-VPN connection can connect to

1

Not adjustable

Number of VPN connections that support equal-cost multi-path (ECMP) routing per transit router

32

Not adjustable

Inter-region Connection

Number of inter-region connections between a pair of transit routers

1

Not adjustable

Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between two regions in the Chinese mainland

1,000 Mbps

You can request a quota increase by using one of the following methods:

Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between two regions outside the Chinese mainland

100 Mbps

You can request a quota increase by using one of the following methods:

Maximum bandwidth of a Pay-By-Data-Transfer inter-region connection between a region in the Chinese mainland and a region outside the Chinese mainland

100 Mbps

You can request a quota increase by using one of the following methods:

ECR connection

For quotas on Express Connect Router (ECR) resources, see Express Connect quotas.

Routing

Resource

Default quota

Quota increase

Route Table

Number of route tables per transit router

50

Not adjustable

Transit router route entry

Number of route entries per route table of a transit router

Important

The total number of route entries across all route tables of a transit router instance cannot exceed 40,000.

10,000

Not adjustable

Number of route entries per transit router instance

40,000

Not adjustable

Route Synchronization

Number of VPC instances per transit router on which you can enable route synchronization

50

Not adjustable

Aggregate Route

Number of aggregate routes per route table of a transit router

20

Not adjustable

Route Maps

Number of routing policies for the inbound direction per transit router

100

Not adjustable

Number of routing policies for the outbound direction per transit router

100

Not adjustable

Policy-Based Routing Table

Number of policy tables per Transit Router instance (PolicyTableNumberPerTransitRouter)

20

Contact your account manager to request a quota increase.

Total number of policy-based routes per transit router instance (PolicyBasedRoutePerTransitRouter)

100

Contact your account manager to request a quota increase.

Number of policy tables per attachment (AttachmentAssociatedPbrPolicy)

1

Not adjustable

Multicast

Resource

Default quota

Quota increase

Number of multicast domains per transit router

20

Not adjustable

Number of multicast domains that a VPC can be associated with

Note

The total number of multicast domains associated with all vSwitch instances in a VPC cannot exceed the quota.

20

Number of static or dynamic (IGMP) multicast sources and members per transit router

2,000

You can request a quota increase by using one of the following methods:

You can request an increase up to 3,000. To request a quota above 3,000 (up to 10,000), contact your account manager.

Number of static and dynamic (IGMP) multicast members per multicast group on a transit router

100

Not adjustable

Number of vSwitches per multicast domain on a transit router

10

Number of static and dynamic (IGMP) multicast sources per multicast group on a transit router

100

Number of inter-region multicast members per multicast group on a transit router

15

Number of multicast groups per multicast domain

20 (Deprecated)

Maximum bandwidth per multicast group

Note

This is the total bandwidth consumed by traffic from all multicast sources to the multicast group and from the multicast group to all multicast members.

10 Gbps

Traffic scheduling

Resource

Default quota

Quota increase

Number of traffic classification rules per transit router

500

Not adjustable

Number of queues per traffic scheduling policy

64

Not adjustable

Basic Edition transit routers

Network instance connections

Resource

Default quota

Quota increase

Total number of VPC and VBR instances that can be connected to a transit router

10

Not adjustable

Number of Cloud Connect Network (CCN) instances that can be connected to a transit router

1

Not adjustable

Number of inter-region connections between a pair of transit routers

1

Not adjustable

Number of transit routers a VPC can connect to

1

Not adjustable

Routing

Resource

Default quota

Quota increase

Number of route tables per transit router

1

Not adjustable

Number of route entries per transit router

100

Not adjustable

Route Maps

Number of routing policies for the inbound direction per transit router

100

Not adjustable

Number of routing policies for the outbound direction per transit router

100

Not adjustable

Inter-region bandwidth limits

Transit routers use a distributed, highly reliable cluster architecture. To guarantee the performance and stability of inter-region bandwidth, the transit router automatically enables distributed rate limiting when the peak bandwidth of the inter-region bandwidth plan that you purchase exceeds 1 Gbps. All inter-region traffic is evenly distributed across multiple system servers in the cluster. The peak bandwidth that you configure for the inter-region bandwidth plan is also evenly distributed across these servers. As a result, the transit router reaches the configured peak bandwidth only when multiple connections are used. The required number of connections varies with your actual workload.

Maximum bandwidth per connection = Peak bandwidth of the inter-region bandwidth plan of the transit router ÷ Number of servers in the transit router cluster

For example, if you configure a peak bandwidth of 2,000 Mbps and the transit router cluster uses four system servers to forward traffic, the maximum bandwidth per connection is 2,000 Mbps ÷ 4 = 500 Mbps. In this case, the maximum bandwidth of a single inter-region connection on the transit router is 500 Mbps, and the transit router instance reaches the peak bandwidth configured for the inter-region bandwidth plan when it has four or more inter-region connections.

Important
  • The inter-region bandwidth of a transit router may occasionally exceed the configured bandwidth limit. As the technology continues to evolve, bandwidth enforcement will become increasingly accurate. To be safe, configure a peak bandwidth slightly larger than your workload requirements.

  • The bandwidth cap is not a guaranteed service commitment; it serves only as a reference value and an upper limit. When resource contention occurs, the actual available bandwidth may be subject to throttling.

Bandwidth limiting rules for the inbound and outbound directions:

  • Alibaba Cloud allocates both inbound bandwidth and outbound bandwidth equal to the purchased peak bandwidth.

    For example, if the bandwidth limit that you purchase is 5 Gbps, the maximum inbound bandwidth and the maximum outbound bandwidth are both 5 Gbps.