Limits and quotas
Service quotas define the maximum number of cloud resources that an Alibaba Cloud account can use or the maximum number of operations that you can perform. This topic describes the limits and quotas for Virtual Private Cloud (VPC), including the quota names, default values, and whether they are adjustable. It also provides information about other VPC-related limits.
Alibaba Cloud service quotas are typically applied on a per-account or per-region basis. They are categorized as follows:
General quota: The maximum number of cloud resources that an Alibaba Cloud account can use.
API rate limit: The maximum frequency at which an Alibaba Cloud account can call a service API. This is also known as a queries per second (QPS) limit.
Privilege quota: A permission that is granted to an Alibaba Cloud account, such as the permission to use a specific feature.
VPC provides general quotas, API rate limits, and privilege quotas. You can log on to the Quota Center or the VPC console to view quotas or request quota increases. For detailed instructions on viewing quotas, requesting quota increases, creating quota alarms, and adding quota templates, see Manage VPC quotas.
Adjustments to general quotas apply to both new and existing resources.
General quotas
The following tables list the general quotas for VPC.
The default values listed in this topic are for reference only. For the actual default values, refer to the console.
VPC and vSwitch
Quota name | Description | Default limit | Adjustable |
vpc_quota_instances_num
| The maximum number of VPCs that you can create in a region. | 10 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_instances_num_${RegionId} | The maximum number of VPCs that you can create in a specified region. | 10 | |
vpc_quota_vswitches_num | The maximum number of vSwitches that you can create in a VPC. | 150 | |
vpc_quota_secondary_cidr_num | The maximum number of secondary IPv4 CIDR blocks that you can add to a VPC. | 5 | |
None | The maximum number of secondary IPv6 CIDR blocks that you can add to a VPC. | 5 | No |
The maximum number of reserved IPv4 CIDR blocks that you can create in a VPC. | 100 | ||
The maximum number of reserved IPv6 CIDR blocks that you can create in a VPC. | 100 | ||
The maximum number of user CIDR blocks that you can create in a VPC. | 3 | ||
The maximum number of private network addresses that cloud resources in a VPC can use. | 300,000 1. If an ECS instance has only one private IP address, it consumes only one network address. 2. If an ECS instance is attached to multiple elastic network interfaces (ENIs) or an ENI has multiple IP addresses, the number of network addresses it consumes is the sum of all IP addresses on its attached ENIs. | ||
The maximum number of tags that you can add to a VPC. | 20 | ||
The maximum number of tags that you can add to a vSwitch. | 20 |
vRouter and route table
Quota name | Description | Default limit | Adjustable |
vpc_quota_route_tables_num | The maximum number of custom route tables that you can create in a VPC. | 9 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_route_entrys_num | The maximum number of custom route entries that you can create in a route table (excluding dynamically propagated route entries). | 200 | |
vpc_quota_dynamic_route_entrys_num | The maximum number of dynamically propagated route entries in a route table. | 200 | |
vpc_quota_havip_custom_route_entry | The maximum number of custom route entries that point to a HaVip. | 5 | |
vpc_quota_vpn_custom_route_entry | The maximum number of custom route entries that point to a VPN gateway in a VPC. | 50 | |
None | The maximum number of tags that you can add to a route table. | 20 | No |
The maximum number of vRouters that you can create in a VPC. | 1 | ||
The maximum number of route entries in a VPC that point to a Transit Router (TR) connection. | 600 |
DHCP options set
Quota name | Description | Default limit | Adjustable |
None | The maximum number of DHCP options sets that you can create per account. | 10 | No |
The maximum number of VPCs that you can associate with a DHCP options set. | 10 | ||
The maximum number of DHCP options sets that you can associate with a VPC. | 1 | ||
The maximum number of domain names that you can configure in a DHCP options set. | 1 | ||
The maximum number of DNS server IP addresses that you can configure in a DHCP options set. | 4 |
Shared VPC
Quota name | Description | Default limit | Adjustable |
vpc_quota_sharedvpc_share_user_num_per_vpc | The maximum number of vSwitch principals with which you can share a VPC. | 50 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_sharedvpc_share_user_num_per_vswitch | The maximum number of vSwitch principals with which you can share a vSwitch. | 50 | |
vpc_quota_sharedvpc_accept_shared_vswitch_num | The maximum number of shared vSwitches that a vSwitch principal can accept. | 30 |
Flow log
Quota name | Description | Default limit | Adjustable |
vpc_quota_flowlog_inst_nums_per_user | The maximum number of flow log instances that a user can create. | 10 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
Network ACL
Quota name | Description | Default limit | Adjustable |
vpc_quota_nacl_ingress_entry | The maximum number of inbound rules that you can create in a network ACL. If IPv6 is enabled for the VPC associated with the network ACL, you can create up to 20 inbound rules for IPv4 and 20 for IPv6. | 20 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_nacl_egress_entry | The maximum number of outbound rules that you can create in a network ACL. If IPv6 is enabled for the VPC associated with the network ACL, you can create up to 20 outbound rules for IPv4 and 20 for IPv6. | 20 | |
nacl_quota_vpc_create_count | The maximum number of network ACLs that you can create in a VPC. | 20 |
HaVip
Quota name | Description | Default limit | Adjustable |
None | The network type that supports HaVips. | VPC | No |
The maximum number of HaVips per ECS instance. | 5 | ||
The maximum number of EIPs per HaVip. | 1 | ||
The maximum number of ECS instances or elastic network interfaces (ENIs) that can be associated with a HaVip at the same time. | 10 1. A HaVip can be associated with up to 10 ECS instances or 10 ENIs, but not with both simultaneously. 2. A HaVip can be associated only with ECS instances or ENIs that are in the same vSwitch as the HaVip. | ||
Whether HaVips support broadcast and multicast communication. | Not supported HaVip supports only unicast communication. If you use third-party software such as Keepalived to implement high availability, you must change the communication mode to unicast in the configuration file. | ||
vpc_quota_havip_custom_route_entry | The maximum number of route entries in a route table where the destination is an HaVip. | 5 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
Traffic mirror
Quota name | Description | Default limit | Adjustable |
trafficmirror_quota_source_num_per_session | The maximum number of traffic mirror sources that you can add to a traffic mirror session. | 10 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_traffic_mirror_source_num_per_large_ecs_target | The maximum number of traffic mirror sources for a traffic mirror destination that is an ENI attached to one of the following ECS instance types. | 200 | |
vpc_quota_traffic_mirror_source_num_per_small_ecs_target | The maximum number of traffic mirror sources for a traffic mirror destination that is an ENI attached to an ECS instance of a type other than the following. | 20 | |
vpc_quota_traffic_mirror_rules_num_per_filter | The maximum number of filter rules that you can create for a single filter. | 20 | |
None | The maximum number of traffic mirror sessions that you can create with a single account in a single region. | 20,000 | No |
The maximum number of traffic mirror sessions per traffic mirror source. | 3 | ||
The maximum number of traffic mirror sources supported by a single traffic mirror destination when the destination is a private Classic Load Balancer (CLB). | 500 | ||
The maximum number of traffic mirror sources for a traffic mirror destination that is a Gateway Load Balancer endpoint (GWLBe). | 500 | ||
The maximum number of filters that you can create with a single account in a single region. | 100 | ||
The maximum number of traffic mirror sessions per filter. | 2,000 |
VPC peering connection
Quota name | Description | Default limit | Adjustable |
vpc_quota_cross_region_peer_num_per_vpc | The maximum number of inter-region VPC peering connections per VPC. | 20 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_intra_region_peer_num_per_vpc | The maximum number of intra-region VPC peering connections per VPC. | 10 | |
vpc_quota_peer_num | The maximum number of VPC peering connections supported per Alibaba Cloud account per region. | 20 | |
vpc_quota_peer_cross_border_bandwidth | The maximum cross-border bandwidth. | 1,024 Mbps | |
vpc_quota_peer_cross_region_bandwidth | The maximum inter-region bandwidth. | 1,024 Mbps |
IPv4 gateway
Quota name | Description | Default limit | Adjustable |
None | The maximum number of IPv4 gateways per VPC. | 1 | No |
The maximum number of gateway route tables per IPv4 gateway. | 1 |
Prefix list
Quota name | Description | Default limit | Adjustable |
vpc_quota_prefixlist_num | The maximum number of prefix lists that you can create with an Alibaba Cloud account. | 10 | Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
vpc_quota_prefixlist_cidr_num_per_prefixlist | The maximum number of CIDR entries per prefix list. | 50 | |
vpc_quota_prefixlist_accept_shared_prefixlist_num | The maximum number of shared prefix lists that a resource principal can accept. | 100 | |
vpc_quota_prefixlist_share_user_num_per_prefixlist | The maximum number of resource principals with which you can share a prefix list. | 10 |
IPAM
Quota name | Description | Default limit | Adjustable |
ipam_quota_per_region | The maximum number of IPAMs that you can create per region. | 1 | No |
ipam_scope_quota_per_ipam | The maximum number of IPAM scopes per IPAM. | 5 | |
ipam_pool_quota_depth | The maximum depth per pool. | 10 | |
ipam_cidr_quota_per_ipam_pool | The maximum number of CIDR blocks that can be provisioned per pool. | 50 | |
ipam_sub_pool_quota_per_ipam_pool | The maximum number of sub-pools per pool. | 50 | |
ipam_pool_quota_per_scope | The maximum number of pools per private IPAM scope. | 500 | |
custom_ipam_resource_discovery_quota_per_region | The maximum number of custom resource discoveries per account per region. | 1 | |
resource_share_quota_per_ipam_resource_discovery | The maximum number of shared resources per resource discovery. | 100 | |
shared_ipam_resource_discovery_quota_per_user | The maximum number of shared resource discoveries per user. | 100 | |
resource_share_quota_per_ipam_pool | The maximum number of shared resources per IPAM pool. | 100 | |
shared_ipam_pool_quota_per_user | The maximum number of shared pools per user. | 100 | |
ipam_public_ipv6_top_pool_quota_per_region_isp | The maximum number of public IPv6 top-level IPAM pools that a user can create per ISP type per region. | 1 | |
ipam_cidr_quota_per_public_ipv6_top_pool | The maximum number of CIDR blocks that a user can provision for a public IPv6 top-level IPAM pool in a region. | 1 |
API rate limits
Item | Limit | Adjustable |
API rate limit | You can view API rate limits in one of the following ways:
| Yes. To request a quota increase, go to the Quota Management page or Quota Center. |
Privilege quotas
The default value for a privilege quota for VPC is 0. This means that the feature is unavailable by default. You can use the feature only after Alibaba Cloud grants you the required permissions. The following table describes the privilege quotas for VPC.
Quota name | Description | Adjustable |
HaVip privilege whitelist | Controls access to a new feature (HaVip) during its invitation-only private beta phase. | Go to the Quota Management page or Quota Center to request a quota increase. |
Manage VPC quotas
Managing VPC quotas includes querying quotas and quota usage, requesting quota increases, and setting up quota alarms. This section describes how to view quotas, request quota increases, create quota alarms, and add quota templates for VPC.
Permissions
By default, only Alibaba Cloud accounts can manage quotas in Quota Center. To allow a RAM user to perform quota management operations, grant the RAM user the AliyunQuotasFullAccess permission, which is AliyunQuotasFullAccess.
View quotas
You can view VPC quotas using one of the following methods:
Open the Limits and quotas page in the product documentation to view all quota names and their default values.
View quotas in the VPC console.
View quotas in the VPC console
Go to the VPC console - Quota Management page.
In the Product section, select the VPC tab.
View general quotas: In the Quota Type section, select the General Quota tab. You can filter by keywords to view the quota name, description, and usage of the target general quota.
View API rate limits: In the Quota Type section, click the API Rate Limit tab. You can filter by keywords and regions to view the version and quota information of the target API rate limit.
View privilege quotas: In the Quota Type section, click the Privilege tab. You can filter by quota ID to view the quota name, description, and default value of the target privilege quota.
Increase quotas
If your business requires a quota higher than the default value and the quota supports adjustments, you can request a quota increase using one of the following methods.
Log on to the Alibaba Cloud Quota Center and Request a quota increase.
Request a quota increase in the VPC console.
The quota items and results are consistent between the Quota Center and the VPC console.
Increase quotas in the VPC console
Go to the VPC console - Quota Management page.
In the Product section, select the VPC tab, then select the quota type you want to increase and perform the following operations.
Increase general quotas
In the Quota Type section, select the General Quota tab. In the Actions column for the target general quota, click Apply.
In the Apply for Quotas dialog box, set Applied Quotas and Reason, then click OK.
Quota increase requests are reviewed and approved by the technical support team of each cloud product. To improve the chances of approval, provide a reasonable target quota value and a detailed business justification.
Quota application results will be sent to you via text message and email. Alibaba Cloud will evaluate your application based on the information you provide, and then approve or reject your request.
After submitting the request, you can check the review status in the Actions column by clicking Application Records or selecting .
If the quota increase request status is Approved, the quota increase is successful.
Request privilege quotas
In the Quota Type section, click the Privilege tab. In the Actions column for the target privilege quota, click Apply.
In the Apply for Privilege Quota dialog box, set Quota Application Value, Time, Reason, and Notify Result, then click OK.
If you do not specify an effective time, the effective time defaults to the submission time of the request. Quota application results will be sent to you via text message and email.
After submitting the request, you can check the application status in the Actions column by clicking Application Records or selecting . When the application status is Approved, the privilege quota request is successful.
Create quota alarms
Some VPC quota items support alarms. You can set a threshold for quota usage or remaining available amount. When the quota usage or remaining available amount reaches the threshold, the system sends an alert to the alarm callback URL. You can use the alert to request a quota increase before your business is affected.
You can create quota alarms using one of the following methods.
Log on to the Alibaba Cloud Quota Center and Create quota alerts.
Log on to the VPC console to create a quota alarm.
The following VPC quota items support alarms:
Quota name:
vpc_quota_secondary_cidr_num. Description: The number of secondary IPv4 CIDR blocks supported by a single VPC.Quota name:
vpc_privilege_allow_buy_havip_instance. Description: The privilege to purchase HaVip instances.
Create quota alarms in the VPC console
Go to the VPC console - Quota Management page.
In the Quota Type section, select the General Quota tab. In the Actions column for the target general quota, click Create Alert.
In the Create Alarm Rule panel, configure the alarm parameters and click Confirm.
Basic Information: Enter a custom rule name.
Alarm Object: Displays information about the selected quota item.
Alarm Rule:
Alarm Metric: Select a metric to monitor, such as quota, quota usage, usage rate, availability rate, or remaining availability rate.
Set Threshold and Alarm Level, with thresholds for critical, warning, and normal levels. Different levels use different notification methods.
Notification Type:
Select Mute For: Specify how long to wait before sending the next alert if the alarm does not recover after triggering.
Set Effective Time and Alarm Contact Group.
Alarm Callback: When the alarm rule is triggered, CloudMonitor sends an alert message to the URL you specify.
Add quota templates
When the quota template status is Enabled and you have added a quota template, the system automatically applies the quota template to new members added to the resource directory. Existing members are not affected. With quota templates, you can request increases for multiple quota items at once, improving the efficiency and automation of quota management across your organization.
Before adding a quota template, ensure that:
You are logged on with the management account of your enterprise.
You have Enable Resource Directory and Enable a quota template.
You can add quota templates using one of the following methods.
Log on to the Alibaba Cloud Quota Center and Add a quota item to a quota template.
Log on to the VPC console to add quota templates.
Add quota templates in the VPC console
Go to the VPC console - Quota Management page.
In the Product section, select the VPC tab, then select the quota type you want to add to a quota template and perform the following operations.
Add general quota items to a quota template
In the Quota Type section, select the General Quota tab. Find the target general quota, and in the Actions column, click Add to quota template.
Set Applied Quotas and Notify Result for the target quota.
Add privilege quota items to a quota template
In the Quota Type section, click the Privilege tab. Find the target privilege quota, and in the Actions column, click Add to quota template.
Set Quota Application Value, Time, and Notify Result for the target privilege quota.