This topic describes the default quotas and usage limits for IPsec-VPN resources and explains how to request a quota increase.
VPN gateway attachments
Resource | Default limit | Adjustable |
Number of vpn gateway instances per Alibaba Cloud account | 30 (total across all regions) This quota is shared with ipsec-vpn connections attached to Transit Routers. | Yes, quota name: vpn_quota_instances_num |
Number of ipsec-vpn connections per vpn gateway instance | 10 | Yes, quota name: vpn_quota_ipsec_connections_num |
Maximum bandwidth specification per vpn gateway instance | Enhanced VPN gateway: No bandwidth specification attribute. Standard VPN gateway: 1,000 Mbps (500 Mbps in some regions). | No |
Bandwidth per ipsec-vpn connection attached to a vpn gateway | Enhanced VPN gateway: 1 Gbps Standard VPN gateway: All connections share the gateway's bandwidth (1,000 Mbps, or 500 Mbps in some regions). | No |
Total bidirectional packets per second (pps) per vpn gateway instance | The total bidirectional pps for all ipsec-vpn connections on a vpn gateway instance cannot exceed 120,000 (at 256 bytes per packet). | No |
Maximum number of concurrent connections per vpn gateway instance | 200,000 A network 5-tuple (source IP, destination IP, source port, destination port, and protocol) uniquely identifies a connection. This count includes connections over TCP, UDP, and ICMP. | No |
Number of policy-based route entries per vpn gateway instance | Enhanced VPN gateway: Not supported. Standard VPN gateway: 20 | For Standard VPN gateway only: Yes, quota name: vpn_pbr_route_entry_quota |
Number of destination-based route entries per vpn gateway instance | 30 | Yes, quota name: vpn_route_entry_quota |
Number of BGP routes learned from peers per vpn gateway instance | Enhanced VPN gateway: 200 Standard VPN gateway: 50 | For Standard VPN gateway only. Contact your account manager to request an increase up to a maximum of 200. |
Number of local/remote network CIDR blocks per ipsec-vpn connection | Enhanced VPN gateway: 10 Standard VPN gateway: 5 | No |
Unsupported ports for ipsec-vpn connections | Enhanced VPN gateway: None Standard VPN gateway: 2222 Port 2222 is reserved for internal use by the vpn gateway service. Traffic to port 2222 of an ipsec-vpn connection is dropped. | No |
Transit Router attachments
Resource | Default limit | Adjustable |
Number of ipsec-vpn connections attached to a Transit Router per Alibaba Cloud account | 30 (total across all regions) This quota is shared with vpn gateway instances. | Yes, quota name: vpn_quota_instances_num |
Bandwidth per ipsec-vpn connection attached to a Transit Router |
The 3 Gbps tunnel bandwidth is available in an invitation-only preview. To use this feature, contact your account manager. | No |
Total bidirectional packets per second (pps) per ipsec-vpn connection attached to a Transit Router | 120,000 pps per tunnel (at 256 bytes per packet) | No |
Number of tunnels that support ECMP per Transit Router | 32 tunnels (16 ipsec-vpn connections) | No |
Number of BGP routes that can be learned from a peer through an ipsec-vpn connection | 1,000 per tunnel, for a total of 2,000 The limit for legacy single-tunnel connections is 50. | For single-tunnel connections only. Contact your account manager to request an increase up to a maximum of 200. |
Number of local/remote network CIDR blocks per ipsec-vpn connection | 5 You can add up to 10 CIDR blocks in an invitation-only preview. To use this feature, contact your account manager. | No |
Maximum number of concurrent connections per ipsec-vpn connection | 200,000 A network 5-tuple (source IP, destination IP, source port, destination port, and protocol) uniquely identifies a connection. This count includes connections over TCP, UDP, and ICMP. | No |
Unsupported ports for ipsec-vpn connections | 2222 Port 2222 is reserved for internal use by the vpn gateway service. Traffic to port 2222 of an ipsec-vpn connection is dropped. | No |
Number of Transit Routers to which an ipsec-vpn connection can be attached | 1 | No |
Customer gateway limits
Resource | Default limit | Adjustable |
Number of customer gateways per region | 150 | No |
API rate quotas
For the rate quota of each API, see Throttling.
To request a quota increase, see Request a quota increase.
You can receive alerts when your usage nears a quota's limit, allowing you to request an increase in advance. For more information, see quota alarms.
Request a quota increase
You can request self-service increases for some quotas. In Quota Center, find the desired quota and click Apply in the Actions column. To increase the likelihood of approval, specify a reasonable new quota value and provide a detailed justification for your request. The technical support team for each cloud service reviews these requests, with approvals typically taking less than one minute.
If you use Resource Directory to manage multiple accounts, you can use a Quota Template to submit bulk requests for quota increases.
To use a RAM user for this operation, first grant the RAM user permissions to manage quotas. The required permission is AliyunQuotasFullAccess.