Limits and quotas

Updated at:

Service quotas define the maximum number of cloud resources that an Alibaba Cloud account can use or the maximum number of operations that you can perform. This topic describes the limits and quotas for Virtual Private Cloud (VPC), including the quota names, default values, and whether they are adjustable. It also provides information about other VPC-related limits.

Alibaba Cloud service quotas are typically applied on a per-account or per-region basis. They are categorized as follows:

  • General quota: The maximum number of cloud resources that an Alibaba Cloud account can use.

  • API rate limit: The maximum frequency at which an Alibaba Cloud account can call a service API. This is also known as a queries per second (QPS) limit.

  • Privilege quota: A permission that is granted to an Alibaba Cloud account, such as the permission to use a specific feature.

VPC provides general quotas, API rate limits, and privilege quotas. You can log on to the Quota Center or the VPC console to view quotas or request quota increases. For detailed instructions on viewing quotas, requesting quota increases, creating quota alarms, and adding quota templates, see Manage VPC quotas.

Adjustments to general quotas apply to both new and existing resources.

General quotas

The following tables list the general quotas for VPC.

The default values listed in this topic are for reference only. For the actual default values, refer to the console.

VPC and vSwitch

Quota name

Description

Default limit

Adjustable

vpc_quota_instances_num

vpc_quota_instances_num_${RegionId} takes precedence over vpc_quota_instances_num.

The maximum number of VPCs that you can create in a region.

10

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_instances_num_${RegionId}

${RegionId} is a placeholder for the region ID.

The maximum number of VPCs that you can create in a specified region.

10

vpc_quota_vswitches_num

The maximum number of vSwitches that you can create in a VPC.

150

vpc_quota_secondary_cidr_num

The maximum number of secondary IPv4 CIDR blocks that you can add to a VPC.

5

None

The maximum number of secondary IPv6 CIDR blocks that you can add to a VPC.

5

No

The maximum number of reserved IPv4 CIDR blocks that you can create in a VPC.

100

The maximum number of reserved IPv6 CIDR blocks that you can create in a VPC.

100

The maximum number of user CIDR blocks that you can create in a VPC.

3

The maximum number of private network addresses that cloud resources in a VPC can use.

300,000

1. If an ECS instance has only one private IP address, it consumes only one network address.
2. If an ECS instance is attached to multiple elastic network interfaces (ENIs) or an ENI has multiple IP addresses, the number of network addresses it consumes is the sum of all IP addresses on its attached ENIs.

The maximum number of tags that you can add to a VPC.

20

The maximum number of tags that you can add to a vSwitch.

20

vRouter and route table

Quota name

Description

Default limit

Adjustable

vpc_quota_route_tables_num

The maximum number of custom route tables that you can create in a VPC.

9

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_route_entrys_num

The maximum number of custom route entries that you can create in a route table (excluding dynamically propagated route entries).

200

vpc_quota_dynamic_route_entrys_num

The maximum number of dynamically propagated route entries in a route table.

200

vpc_quota_havip_custom_route_entry

The maximum number of custom route entries that point to a HaVip.

5

vpc_quota_vpn_custom_route_entry

The maximum number of custom route entries that point to a VPN gateway in a VPC.

50

None

The maximum number of tags that you can add to a route table.

20

No

The maximum number of vRouters that you can create in a VPC.

1

The maximum number of route entries in a VPC that point to a Transit Router (TR) connection.

600

DHCP options set

Quota name

Description

Default limit

Adjustable

None

The maximum number of DHCP options sets that you can create per account.

10

No

The maximum number of VPCs that you can associate with a DHCP options set.

10

The maximum number of DHCP options sets that you can associate with a VPC.

1

The maximum number of domain names that you can configure in a DHCP options set.

1

The maximum number of DNS server IP addresses that you can configure in a DHCP options set.

4

Shared VPC

Quota name

Description

Default limit

Adjustable

vpc_quota_sharedvpc_share_user_num_per_vpc

The maximum number of vSwitch principals with which you can share a VPC.

50

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_sharedvpc_share_user_num_per_vswitch

The maximum number of vSwitch principals with which you can share a vSwitch.

50

vpc_quota_sharedvpc_accept_shared_vswitch_num

The maximum number of shared vSwitches that a vSwitch principal can accept.

30

Flow log

Quota name

Description

Default limit

Adjustable

vpc_quota_flowlog_inst_nums_per_user

The maximum number of flow log instances that a user can create.

10

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

Network ACL

Quota name

Description

Default limit

Adjustable

vpc_quota_nacl_ingress_entry

The maximum number of inbound rules that you can create in a network ACL.

If IPv6 is enabled for the VPC associated with the network ACL, you can create up to 20 inbound rules for IPv4 and 20 for IPv6.

20

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_nacl_egress_entry

The maximum number of outbound rules that you can create in a network ACL.

If IPv6 is enabled for the VPC associated with the network ACL, you can create up to 20 outbound rules for IPv4 and 20 for IPv6.

20

nacl_quota_vpc_create_count

The maximum number of network ACLs that you can create in a VPC.

20

HaVip

Quota name

Description

Default limit

Adjustable

None

The network type that supports HaVips.

VPC

No

The maximum number of HaVips per ECS instance.

5

The maximum number of EIPs per HaVip.

1

The maximum number of ECS instances or elastic network interfaces (ENIs) that can be associated with a HaVip at the same time.

10

1. A HaVip can be associated with up to 10 ECS instances or 10 ENIs, but not with both simultaneously.
2. A HaVip can be associated only with ECS instances or ENIs that are in the same vSwitch as the HaVip.

Whether HaVips support broadcast and multicast communication.

Not supported

HaVip supports only unicast communication. If you use third-party software such as Keepalived to implement high availability, you must change the communication mode to unicast in the configuration file.

vpc_quota_havip_custom_route_entry

The maximum number of route entries in a route table where the destination is an HaVip.

5

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

Traffic mirror

Quota name

Description

Default limit

Adjustable

trafficmirror_quota_source_num_per_session

The maximum number of traffic mirror sources that you can add to a traffic mirror session.

10

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_traffic_mirror_source_num_per_large_ecs_target

The maximum number of traffic mirror sources for a traffic mirror destination that is an ENI attached to one of the following ECS instance types.

ECS instance types

ecs.ebmc7.32xlarge, ecs.ebmg7.32xlarge, ecs.ebmr7.32xlarge, ecs.ebmhfg7.48xlarge, ecs.ebmhfc7.48xlarge, ecs.ebmhfr7.48xlarge, ecs.ebmc7a.64xlarge, ecs.ebmg7a.64xlarge, ecs.ebmg7se.32xlarge, ecs.ebmg6a.64xlarge, ecs.ebmg6e.26xlarge, ecs.ebmc6a.64xlarge, ecs.ebmc6e.26xlarge, ecs.ebmr7a.64xlarge, ecs.ebmr6a.64xlarge, ecs.ebmr6e.26xlarge, ecs.c8i.48xlarge, ecs.g8i.48xlarge, ecs.c7nex.32xlarge, ecs.g7nex.32xlarge,

ecs.g7ne.24xlarge, ecs.c7.32xlarge, ecs.g7.32xlarge, ecs.r7.32xlarge, ecs.r6e.26xlarge,

ecs.g7t.32xlarge, ecs.g6t.26xlarge, ecs.g6e.26xlarge, ecs.c7t.32xlarge, ecs.c6t.26xlarge, ecs.c6e.26xlarge, ecs.g5ne.18xlarge, ecs.r7t.32xlarge

200

vpc_quota_traffic_mirror_source_num_per_small_ecs_target

The maximum number of traffic mirror sources for a traffic mirror destination that is an ENI attached to an ECS instance of a type other than the following.

ECS instance types

ecs.ebmc7.32xlarge, ecs.ebmg7.32xlarge, ecs.ebmr7.32xlarge, ecs.ebmhfg7.48xlarge, ecs.ebmhfc7.48xlarge, ecs.ebmhfr7.48xlarge, ecs.ebmc7a.64xlarge, ecs.ebmg7a.64xlarge, ecs.ebmg7se.32xlarge, ecs.ebmg6a.64xlarge, ecs.ebmg6e.26xlarge, ecs.ebmc6a.64xlarge, ecs.ebmc6e.26xlarge, ecs.ebmr7a.64xlarge, ecs.ebmr6a.64xlarge, ecs.ebmr6e.26xlarge, ecs.c8i.48xlarge, ecs.g8i.48xlarge, ecs.c7nex.32xlarge, ecs.g7nex.32xlarge,

ecs.g7ne.24xlarge, ecs.c7.32xlarge, ecs.g7.32xlarge, ecs.r7.32xlarge, ecs.r6e.26xlarge,

ecs.g7t.32xlarge, ecs.g6t.26xlarge, ecs.g6e.26xlarge, ecs.c7t.32xlarge, ecs.c6t.26xlarge, ecs.c6e.26xlarge, ecs.g5ne.18xlarge, ecs.r7t.32xlarge

20

vpc_quota_traffic_mirror_rules_num_per_filter

The maximum number of filter rules that you can create for a single filter.

20

None

The maximum number of traffic mirror sessions that you can create with a single account in a single region.

20,000

No

The maximum number of traffic mirror sessions per traffic mirror source.

3

The maximum number of traffic mirror sources supported by a single traffic mirror destination when the destination is a private Classic Load Balancer (CLB).

500

The maximum number of traffic mirror sources for a traffic mirror destination that is a Gateway Load Balancer endpoint (GWLBe).

500

The maximum number of filters that you can create with a single account in a single region.

100

The maximum number of traffic mirror sessions per filter.

2,000

VPC peering connection

Quota name

Description

Default limit

Adjustable

vpc_quota_cross_region_peer_num_per_vpc

The maximum number of inter-region VPC peering connections per VPC.

20

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_intra_region_peer_num_per_vpc

The maximum number of intra-region VPC peering connections per VPC.

10

vpc_quota_peer_num

The maximum number of VPC peering connections supported per Alibaba Cloud account per region.

20

vpc_quota_peer_cross_border_bandwidth

The maximum cross-border bandwidth.

1,024 Mbps

vpc_quota_peer_cross_region_bandwidth

The maximum inter-region bandwidth.

1,024 Mbps

IPv4 gateway

Quota name

Description

Default limit

Adjustable

None

The maximum number of IPv4 gateways per VPC.

1

No

The maximum number of gateway route tables per IPv4 gateway.

1

Prefix list

Quota name

Description

Default limit

Adjustable

vpc_quota_prefixlist_num

The maximum number of prefix lists that you can create with an Alibaba Cloud account.

10

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

vpc_quota_prefixlist_cidr_num_per_prefixlist

The maximum number of CIDR entries per prefix list.

50

vpc_quota_prefixlist_accept_shared_prefixlist_num

The maximum number of shared prefix lists that a resource principal can accept.

100

vpc_quota_prefixlist_share_user_num_per_prefixlist

The maximum number of resource principals with which you can share a prefix list.

10

IPAM

Quota name

Description

Default limit

Adjustable

ipam_quota_per_region

The maximum number of IPAMs that you can create per region.

1

No

ipam_scope_quota_per_ipam

The maximum number of IPAM scopes per IPAM.

5

ipam_pool_quota_depth

The maximum depth per pool.

10

ipam_cidr_quota_per_ipam_pool

The maximum number of CIDR blocks that can be provisioned per pool.

50

ipam_sub_pool_quota_per_ipam_pool

The maximum number of sub-pools per pool.

50

ipam_pool_quota_per_scope

The maximum number of pools per private IPAM scope.

500

custom_ipam_resource_discovery_quota_per_region

The maximum number of custom resource discoveries per account per region.

1

resource_share_quota_per_ipam_resource_discovery

The maximum number of shared resources per resource discovery.

100

shared_ipam_resource_discovery_quota_per_user

The maximum number of shared resource discoveries per user.

100

resource_share_quota_per_ipam_pool

The maximum number of shared resources per IPAM pool.

100

shared_ipam_pool_quota_per_user

The maximum number of shared pools per user.

100

ipam_public_ipv6_top_pool_quota_per_region_isp

The maximum number of public IPv6 top-level IPAM pools that a user can create per ISP type per region.

1

ipam_cidr_quota_per_public_ipv6_top_pool

The maximum number of CIDR blocks that a user can provision for a public IPv6 top-level IPAM pool in a region.

1

API rate limits

Item

Limit

Adjustable

API rate limit

You can view API rate limits in one of the following ways:

  • In the Quota Center, go to the API Rate Limits page to view the rate limits for VPC API operations.

  • On the Quota Management page, click the API Rate Limit tab in the Quota Type section to view the rate limits for VPC API operations.

Yes. To request a quota increase, go to the Quota Management page or Quota Center.

Privilege quotas

The default value for a privilege quota for VPC is 0. This means that the feature is unavailable by default. You can use the feature only after Alibaba Cloud grants you the required permissions. The following table describes the privilege quotas for VPC.

Quota name

Description

Adjustable

HaVip privilege whitelist

Controls access to a new feature (HaVip) during its invitation-only private beta phase.

Go to the Quota Management page or Quota Center to request a quota increase.

Manage VPC quotas

Managing VPC quotas includes querying quotas and quota usage, requesting quota increases, and setting up quota alarms. This section describes how to view quotas, request quota increases, create quota alarms, and add quota templates for VPC.

Permissions

By default, only Alibaba Cloud accounts can manage quotas in Quota Center. To allow a RAM user to perform quota management operations, grant the RAM user the AliyunQuotasFullAccess permission, which is AliyunQuotasFullAccess.

View quotas

You can view VPC quotas using one of the following methods:

View quotas in the VPC console

  1. Go to the VPC console - Quota Management page.

  2. In the Product section, select the VPC tab.

    • View general quotas: In the Quota Type section, select the General Quota tab. You can filter by keywords to view the quota name, description, and usage of the target general quota.

    • View API rate limits: In the Quota Type section, click the API Rate Limit tab. You can filter by keywords and regions to view the version and quota information of the target API rate limit.

    • View privilege quotas: In the Quota Type section, click the Privilege tab. You can filter by quota ID to view the quota name, description, and default value of the target privilege quota.

Increase quotas

If your business requires a quota higher than the default value and the quota supports adjustments, you can request a quota increase using one of the following methods.

The quota items and results are consistent between the Quota Center and the VPC console.

Increase quotas in the VPC console

  1. Go to the VPC console - Quota Management page.

  2. In the Product section, select the VPC tab, then select the quota type you want to increase and perform the following operations.

    • Increase general quotas

      1. In the Quota Type section, select the General Quota tab. In the Actions column for the target general quota, click Apply.

      2. In the Apply for Quotas dialog box, set Applied Quotas and Reason, then click OK.

        Quota increase requests are reviewed and approved by the technical support team of each cloud product. To improve the chances of approval, provide a reasonable target quota value and a detailed business justification.

        Quota application results will be sent to you via text message and email. Alibaba Cloud will evaluate your application based on the information you provide, and then approve or reject your request.

      3. After submitting the request, you can check the review status in the Actions column by clicking Application Records or selecting Application Records.

        If the quota increase request status is Approved, the quota increase is successful.

    • Request privilege quotas

      1. In the Quota Type section, click the Privilege tab. In the Actions column for the target privilege quota, click Apply.

      2. In the Apply for Privilege Quota dialog box, set Quota Application Value, Time, Reason, and Notify Result, then click OK.

        If you do not specify an effective time, the effective time defaults to the submission time of the request. Quota application results will be sent to you via text message and email.

      3. After submitting the request, you can check the application status in the Actions column by clicking Application Records or selecting Application Records. When the application status is Approved, the privilege quota request is successful.

Create quota alarms

Some VPC quota items support alarms. You can set a threshold for quota usage or remaining available amount. When the quota usage or remaining available amount reaches the threshold, the system sends an alert to the alarm callback URL. You can use the alert to request a quota increase before your business is affected.

You can create quota alarms using one of the following methods.

The following VPC quota items support alarms:

  • Quota name: vpc_quota_secondary_cidr_num. Description: The number of secondary IPv4 CIDR blocks supported by a single VPC.

  • Quota name: vpc_privilege_allow_buy_havip_instance. Description: The privilege to purchase HaVip instances.

Create quota alarms in the VPC console

  1. Go to the VPC console - Quota Management page.

  2. In the Quota Type section, select the General Quota tab. In the Actions column for the target general quota, click Create Alert.

  3. In the Create Alarm Rule panel, configure the alarm parameters and click Confirm.

    1. Basic Information: Enter a custom rule name.

    2. Alarm Object: Displays information about the selected quota item.

    3. Alarm Rule:

      1. Alarm Metric: Select a metric to monitor, such as quota, quota usage, usage rate, availability rate, or remaining availability rate.

      2. Set Threshold and Alarm Level, with thresholds for critical, warning, and normal levels. Different levels use different notification methods.

    4. Notification Type:

      1. Select Mute For: Specify how long to wait before sending the next alert if the alarm does not recover after triggering.

      2. Set Effective Time and Alarm Contact Group.

      3. Alarm Callback: When the alarm rule is triggered, CloudMonitor sends an alert message to the URL you specify.

Add quota templates

When the quota template status is Enabled and you have added a quota template, the system automatically applies the quota template to new members added to the resource directory. Existing members are not affected. With quota templates, you can request increases for multiple quota items at once, improving the efficiency and automation of quota management across your organization.

Before adding a quota template, ensure that:

You can add quota templates using one of the following methods.

Add quota templates in the VPC console

  1. Go to the VPC console - Quota Management page.

  2. In the Product section, select the VPC tab, then select the quota type you want to add to a quota template and perform the following operations.

    • Add general quota items to a quota template

      1. In the Quota Type section, select the General Quota tab. Find the target general quota, and in the Actions column, click Add to quota template.

      2. Set Applied Quotas and Notify Result for the target quota.

    • Add privilege quota items to a quota template

      1. In the Quota Type section, click the Privilege tab. Find the target privilege quota, and in the Actions column, click Add to quota template.

      2. Set Quota Application Value, Time, and Notify Result for the target privilege quota.