This topic describes the quotas and performance limits of Elastic IP Address (EIP), and the limits on associating an EIP with a resource.
Quota
Item | Default value | Adjustable |
Maximum number of EIPs that each Alibaba Cloud account can apply for | 20 | Go to the Quota Management page or the Quota Center and request a quota increase. |
Performance limits
You can associate an EIP only with one cloud resource. The EIP that you want to associate must be in the Available state. After you associate an EIP with a cloud resource, the EIP immediately takes effect.
If an EIP is locked for security reasons, you cannot release the EIP, associate the EIP with a cloud resource, or disassociate the EIP from a cloud resource.
The following table describes the bandwidth limits on EIPs.
Pay-by-data-transfer EIP
Pay-by-bandwidth EIP
The maximum bandwidth of a pay-by-data-transfer EIP cannot exceed 200 Mbit/s. The maximum bandwidth is for reference only and is not guaranteed. In scenarios of resource contention, the maximum bandwidth may not be reached.
The maximum bandwidth of a pay-by-bandwidth EIP is 500 Mbit/s. In scenarios of resource contention, the maximum bandwidth is guaranteed. In scenarios of resource contention, the maximum bandwidth is guaranteed.
For each Alibaba Cloud account, the sum of the peak bandwidth of all pay-by-data-transfer EIPs in a region cannot exceed 5 Gbit/s. If your business requires guaranteed bandwidth or larger bandwidth, you can purchase pay-by-bandwidth EIPs.
For each Alibaba Cloud account, the sum of the peak bandwidth of all pay-by-bandwidth EIPs in a region cannot exceed 50 Gbit/s. You can contact your account manager to request a quota increase.
NoteAfter a pay-by-data-transfer EIP is associated with an Internet Shared Bandwidth instance, the billing method and maximum bandwidth of the EIP become invalid. You are charged a data transfer fee for the Internet Shared Bandwidth instance and the maximum bandwidth of the Internet Shared Bandwidth is the same as that of the Internet Shared Bandwidth instance. Therefore, the preceding rules do not apply to the EIP.
The following limits apply to the inbound and outbound bandwidth for EIPs that are purchased after 00:00:00 (UTC+8) on February 15, 2020:
Inbound bandwidth (data is transferred to EIPs)
If the maximum bandwidth of the EIP that you purchased is 10 Mbit/s or more, the inbound bandwidth allocated to the EIP equals the maximum bandwidth of the EIP.
If the maximum bandwidth of the EIP that you purchased is lower than 10 Mbit/s, the inbound bandwidth allocated to the EIP is 10 Mbit/s.
Outbound bandwidth (data is transferred from EIPs)
The outbound bandwidth allocated to an EIP equals the maximum bandwidth of the EIP.
The following limits are imposed when you configure Anti-DDoS protection for EIPs:
Anti-DDoS (Enhanced) is applicable only to pay-as-you-go EIPs of the BGP (Multi-ISP) line type.
Select an IP address pool protected by Anti-DDoS (Enhanced) to assign an EIP of the Anti-DDoS (Enhanced) type from the IP address pool.
The security protection type can only be specified when creating an EIP or IP address pool. After the creation is complete, the security protection type cannot be changed.
Regions where Anti-DDoS (Enhanced) is available:
EIP
China: China (Beijing), China (Hangzhou), China (Shanghai), and China (Hong Kong)
Asia Pacific: Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta), South Korea (Seoul), and Thailand (Bangkok)
Others: US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London), and Mexico
IP address pool
China: China (Hong Kong)
Asia Pacific: Philippines (Manila), Japan (Tokyo), Singapore, Malaysia (Kuala Lumpur), Indonesia (Jakarta), South Korea (Seoul), and Thailand (Bangkok)
Others: US (Virginia), US (Silicon Valley), Germany (Frankfurt), UK (London), and Mexico
When Elastic Compute Service (Elastic Compute Service) instances associated with EIPs in China (including Hong Kong and Macao, but excluding Taiwan in this example) access ECS instances in other regions and countries, the network latency is high and packet loss may occur. We recommend that you deploy services in the same region or use Cloud Enterprise Network (CEN) for cross-region connections.
Limits on associating an EIP with an ECS instance
The ECS instance must be deployed in a virtual private cloud (VPC).
The ECS instance and the EIP must belong to the same region.
The ECS instance must be in the Running or Stopped state.
The ECS instance is not assigned a static public IP address or associated with an EIP.
Each ECS instance can be associated only with one EIP. However, you can associate secondary elastic network interfaces (ENIs) with an ECS instance to associate multiple EIPs with an ECS instance.
Associate an EIP with each secondary ENI. Then, associate the secondary ENIs with the ECS instance. The number of ENIs that can be associated varies with the ECS instance family.
Associate multiple EIPs with a secondary ENI in NAT mode. In this mode, each EIP is associated with a secondary private IP address of the secondary ENI. Then, associate the secondary ENI with the ECS instance.
Limits on associating an EIP with an Internet NAT gateway
The EIP and Internet NAT gateway must belong to the same region.
Each Internet NAT gateway can be associated with at most 20 EIPs.
Effective September 19, 2022, when you associate an EIP with a newly created Internet NAT gateway, it will consume one private IP address from the vSwitch where the NAT gateway is located. (Existing NAT gateways are not affected by this change.) Please ensure that the NAT gateway's vSwitch has a sufficient number of available private IP addresses. If there are no available private IPs in the vSwitch, you will be unable to associate new EIPs.
Limits on associating an EIP with a Classic Load Balancer (CLB) instance
The CLB instance must be deployed in a VPC.
The CLB instance and the EIP must belong to the same region.
You can associate only one EIP with each CLB instance.
Limits on associating an EIP with a high-availability virtual IP address (HAVIP)
The HAVIP and the EIP must belong to the same region.
The HAVIP must be in the Available or Allocated state.
You can associate only one EIP with each HAVIP.
Limits on associating an EIP with a secondary ENI
The secondary ENI must be deployed in a VPC.
The secondary ENI and the EIP must belong to the same region.
You can associate an EIP with a secondary ENI in NAT mode or cut-through mode.
The number of EIPs that you can associate with a secondary ENI in NAT mode depends on the number of private IP addresses of the secondary ENI.
You can associate only one EIP with a secondary ENI in cut-through mode.