Limits on Express Connect circuits, network configurations, hosted connections, and data center installations.
Resource limits
Express Connect resource limits are managed through Quotas.
Network requirements
When connecting a data center to Alibaba Cloud with Express Connect, ensure that your cloud and on-premises CIDR blocks do not conflict. Your data center network must also meet these requirements:
-
For optical fiber connections, use a single-mode optical module with one of the following specifications. Ensure identical optical module parameters at both ends.
-
1000BASE-LX Ethernet single-mode optical module
-
10GBASE-LR Ethernet single-mode optical module
-
40GBASE-LR Ethernet single-mode optical module
-
100GBASE-LR Ethernet single-mode optical module
-
-
You must disable port auto-negotiation and manually configure the port speed and full-duplex mode.
-
All devices in the connection path, including intermediate devices, must support 802.1Q VLAN encapsulation.
-
Your on-premises network equipment must support Border Gateway Protocol (BGP) with BGP MD5 authentication, or static routing.
-
In redundant connection scenarios, your devices must support route weight configuration.
-
The physical connection layer must support a maximum transmission unit (MTU) of 1,500 bytes.
-
We recommend using non-conflicting private IP addresses for your cloud and on-premises networks.
-
Do not use 100.64.0.0/10 for your on-premises network. This range is reserved for Alibaba Cloud internal services and causes address conflicts.
-
VBR-to-data-center interconnect addresses cannot use the 100.64.0.0/10 CIDR block.
-
Configure your data center gateway to allow more than 500 ICMP ECHO REQUEST packets per second. Rate-limiting health check probes disrupts connectivity and causes network jitter.
Alibaba Cloud-side rate limits
Beyond the express connect circuit bandwidth limit, VPC-to-data-center traffic is subject to these rate limits:
-
The maximum read/write throughput for OSS is 10 Gbps.
-
For reliability, Express Connect enforces these bandwidth limits on a single hashed traffic flow from a VPC to a VBR:
-
If the configured bandwidth of the VBR or VBR-to-VPC connection is less than or equal to 1 Gbps, the rate limit equals the configured bandwidth.
-
If the configured bandwidth of the VBR or VBR-to-VPC connection is greater than 1 Gbps, the rate limit is 1/4 of the configured bandwidth. For example, if the bandwidth from the VPC to the VBR is 2 Gbps, the maximum bandwidth for a single hashed traffic flow is 500 Mbps.
Note-
The rate limit is based on the VBR bandwidth for CEN or ECR connections, and on the VBR-to-VPC connection bandwidth for VBR-to-VPC connections.
-
The VBR-to-VPC connection feature is not enabled by default. To use this feature, contact your account manager.
-
A hashed traffic flow is defined by a five-tuple: source IP, source port, protocol, destination IP, and destination port. For example,
192.168.1.1 10000 TCP 121.XX.XX.76 80is one hashed traffic flow — a TCP connection from 192.168.1.1:10000 to 121.XX.XX.76:80. -
Express connect circuit limits
-
Plan non-overlapping CIDR blocks for your VPC and on-premises data center before using Express Connect.
-
The 100.64.0.0/10 CIDR block is reserved for internal cloud services. Your data center CIDR block must not overlap with this range.
-
By default, Alibaba Cloud provides single-mode optical modules (1/10/40/100 Gbps) with a 10 km transmission distance.
-
An express connect circuit does not support VXLAN traffic (UDP destination port 4789).
Redundant connection limits
-
Alibaba Cloud guarantees service availability only when multiple express connect circuits connect to different access points. Single circuits or multiple circuits at the same access point do not qualify.
-
Configure a health check when using two express connect circuits for redundancy. Without it, a physical connection failure disrupts your services.
Hosted connection limits
-
Custom port configurations are not supported.
-
Total allocated bandwidth for hosted connections must not exceed the underlying express connect circuit bandwidth.
-
Users with reseller accounts cannot apply to become a Network Service Provider (NSP).
Installation requirements
-
When entering an Alibaba Cloud data center, installation providers must comply with construction regulations from the data center operator and Alibaba Cloud engineers. Non-compliance prevents installation completion.
-
If you purchase optical ports, instruct your carrier to connect to the Alibaba Cloud express connect circuit port using fiber optic cables.
-
Alibaba Cloud prohibits the installation and colocation of optical-to-electrical conversion devices in its data centers.
-
Network lockdowns mandated by policy or Alibaba Group may delay installation. Contact your account manager if affected.
-
Access-point data centers are operated by telecom carriers or third-party providers, not Alibaba Cloud. You are responsible for their building access and in-building cabling fees.
Installation timelines
Timelines for Express Connect installation services:
|
Work item |
Duration |
|
Application for a site survey in an Alibaba Cloud data center |
2 business days. |
|
Application for an LOA |
2 business days. |
|
Fiber pigtail installation |
Fiber pigtail installation timelines:
|
|
Application to enter an Alibaba Cloud data center for express connect circuit maintenance |
3 business days. |