All Products
Search
Document Center

NAT Gateway:Limits and quotas

Last Updated:Aug 26, 2026

Service quotas specify the maximum number of cloud resources or operations that an Alibaba Cloud account (primary account) can use. This topic describes the quota items, default values, whether adjustments are supported, and how to manage quotas for NAT Gateway.

Alibaba Cloud service quotas are typically based on accounts or regions. Quotas can be classified into the following types by dimension:

  • General quotas: the maximum number of cloud resources that an Alibaba Cloud account can use.

  • API rate limits: the frequency at which an Alibaba Cloud account can call cloud service APIs, also known as QPS limits.

  • Privilege quotas: permissions granted to an Alibaba Cloud account by Alibaba Cloud, such as the entitlement to use specific features.

You can log on to Alibaba Cloud Quota Center or the Quota Management page to view quotas or request quota increases.

After a general quota is adjusted, the change takes effect on both new and existing resources.

NAT gateway quotas

General quotas

The following table lists the general quotas of NAT Gateway.

Quota name

Description

Default value

Adjustable

natgw_quota_nat_num_per_vpc

Number of NAT gateways that can be created in a VPC

5

Go to the Quota Center or the Quota Management page to request a quota increase.

natgw_quota_nat_ip_num_per_vpc_nat

Number of NAT IPs that can be created for a NAT gateway in a VPC

15

natgw_quota_eip_num_per_nat

Number of EIPs that can be associated with a public NAT gateway

20

natgw_quota_dnat_entry_num

Number of DNAT entries that can be created for a NAT gateway

100

natgw_quota_snat_entry_num

Number of SNAT entries that can be created for a NAT gateway

40

API rate limits

Item

Limit

Request increase

API rate limits

Choose either of the following methods to view API rate limits:

  • On the Quota Center API Rate Limits page, view the rate limits for NAT Gateway API operations.

  • On the Quota Management page, click NAT Gateway and select the API Rate Limits tab to view the rate limits for NAT Gateway API operations.

Go to the Quota Center or the Quota Management page to request a quota increase.

Manage quotas

By default, only Alibaba Cloud accounts (primary accounts) can perform operations in Quota Center. If you need to use a RAM user (sub-account) to manage quotas, you must first grant the RAM user the permissions to manage quotas, which is AliyunQuotasFullAccess.

View quotas

You can view NAT Gateway quotas by using either of the following methods:

  1. View quotas in Quota Center

    Log on to the Quota Center console and view quotas in Quota Center.

  2. View quotas in the VPC console

    Go to the VPC console - Quota Management page. In the Product section, click the NAT Gateway tab.

    • General quotas: In the Quota type section, select the General Quotas tab. Filter by keywords to view the name, description, usage, and other information of the target general quota.

    • API rate limits: In the Quota type section, select the API Rate Limits tab. Filter by keywords, region, and other conditions to view the version, quota, and other information of the target API rate limit.

Request quota increases

If your business requires more NAT Gateway quota than the default value and the quota supports adjustments, you can request a quota increase through the Quota Center console or the VPC console. The quota items and results are the same regardless of which console you use.

  1. Request a quota increase in Quota Center

    Log on to the Quota Center console and Request a quota increase.

  2. Request a quota increase in the VPC console

    Go to the VPC console - Quota Management page.

    • In the Product section, click the NAT Gateway tab. Select the Quota type. In the Actions column of the target quota, click Apply.

    • In the Apply for Quotas dialog box, set the Applied Quotas and Reason, and then click OK.

      Quota increase requests are reviewed by the technical support team of each cloud product. Provide a reasonable requested value and a detailed reason to increase the approval rate.
      You will be notified of the review result by text message and email. Alibaba Cloud evaluates your request based on the information you provide and approves or rejects your request.
    • After you submit the request, you can click in the Actions column or select Application Records to view the review status. If the status is Approved, the quota increase is successful.

Create quota alerts

Some NAT Gateway quotas support alert creation, which allows you to set thresholds for quota usage or remaining available quota. When the quota usage or remaining available quota reaches the preset threshold, the system sends an alert message to the callback URL specified in the alert. You can request a quota increase in advance based on the alert to prevent business impact. You can create quota alerts by using the following methods.

  1. Create quota alerts in Quota Center

    Log on to the Quota Center console and Create quota alerts.

  2. Create quota alerts in the VPC console

    Go to the VPC console - Quota Management page.

    • In the Product section, click the NAT Gateway tab. Select the Quota type. In the Actions column of the target quota, click Create Alert.

    • In the Create Alert Rule panel, set the quota alert parameters and click Confirm.

      • Basic Information: Specify a custom Alarm Rule Name.

      • Alarm Object: Information about the corresponding quota item.

      • Alarm Rule:

        • Alarm Metric: Select a metric such as quota, quota usage, utilization rate, availability rate, or remaining availability rate for alerts.

        • Set Threshold and Alarm Level by specifying thresholds for Critical, Warning, and Normal severity. Different statuses use different notification methods.

      • Notification Type:

        • Select Mute For: If an alert is triggered and has not returned to normal, specifies how long to wait before repeating the alert notification.

        • Set the Effective Time and Alarm Contact Group.

        • Callback: When the alert rule is triggered, Cloud Monitor sends the alert message to the URL you specify.

Add to quota template

When the quota template status is Enabled and you have added it to the quota template, the system automatically applies the quota template to new members when the management account of the resource directory adds new members. Existing members are not affected. With quota templates, you can request increases for multiple quota items at once, improving the efficiency and automation of quota management across your organization.

Before adding to a quota template, ensure that:

You can add quotas to a quota template by using the following methods.

  1. Add to a quota template in Quota Center

    Log on to the Quota Center console and Add a quota item to a quota template.

  2. Add to a quota template in the VPC console

    Go to the VPC console - Quota Management page.

    • In the Product section, click the NAT Gateway tab. Select the Quota type. Find the target general quota, and in the Actions column, click Add to quota template.

    • Set the Applied Quotas and Notify Result for the target quota.