All Products
Search
Document Center

VPN Gateway:IPsec-VPN quotas and limits

Last Updated:Aug 20, 2026

This topic describes the default quotas and usage limits for IPsec-VPN resources and explains how to request a quota increase.

VPN gateway attachments

Resource

Default limit

Adjustable

Number of vpn gateway instances per Alibaba Cloud account

30 (total across all regions)

This quota is shared with ipsec-vpn connections attached to Transit Routers.

Yes, quota name:

vpn_quota_instances_num

Number of ipsec-vpn connections per vpn gateway instance

10

Yes, quota name:

vpn_quota_ipsec_connections_num

Maximum bandwidth specification per vpn gateway instance

  • Enhanced VPN gateway: No bandwidth specification attribute.

  • Standard edition: 1,000 Mbps in total for the inbound and outbound directions. 500 Mbps in some regions

No

Bandwidth supported by an IPsec-VPN connection (associated with a VPN gateway)

  • Enhanced edition: 1 Gbps.

    Each tunnel supports 1 Gbps in the inbound direction and 1 Gbps in the outbound direction. The two tunnels of a VPN gateway work in active/standby mode. Under normal circumstances, only one tunnel carries traffic. Therefore, the actual available bandwidth of a single IPsec-VPN connection is 1 Gbps.
  • Standard edition: All IPsec-VPN connections share the bandwidth of the VPN gateway instance (up to 1,000 Mbps, 500 Mbps in some regions)

No

The number of packets that a VPN gateway instance can transmit per second

  • Enhanced edition: 140,000 pps in each of the inbound and outbound directions per tunnel

  • Standard edition: The sum of the pps in both directions of all IPsec-VPN connections under a VPN gateway instance does not exceed 120,000 pps

256 bytes per packet.

No

Maximum number of concurrent connections per vpn gateway instance

  • Enhanced edition: 200,000 per tunnel

  • Standard edition: 200,000 per VPN gateway instance

A network 5-tuple (source IP, destination IP, source port, destination port, and protocol) uniquely identifies a connection. This count includes connections over TCP, UDP, and ICMP.

No

Number of policy-based route entries per vpn gateway instance

  • Enhanced VPN gateway: Not supported.

  • Standard VPN gateway: 20

For Standard VPN gateway only: Yes, quota name:

vpn_pbr_route_entry_quota

Number of destination-based route entries per vpn gateway instance

30

Yes, quota name:

vpn_route_entry_quota

Number of BGP routes learned from peers per vpn gateway instance

  • Enhanced VPN gateway: 200

  • Standard VPN gateway: 50

For Standard VPN gateway only. Contact your account manager to request an increase up to a maximum of 200.

The number of local/remote CIDR blocks that can be added to each IPsec-VPN connection (associated with a VPN gateway)

  • Enhanced VPN gateway: 10

  • Standard VPN gateway: 5

No

Ports that cannot be used by IPsec-VPN connections (associated with a VPN gateway)

  • Enhanced VPN gateway: None

  • Standard VPN gateway: 2222

    Port 2222 is reserved for internal use by the VPN gateway service. All traffic that accesses port 2222 of an IPsec-VPN connection is dropped.

No

Transit Router attachments

Resource

Default limit

Adjustable

Number of ipsec-vpn connections attached to a Transit Router per Alibaba Cloud account

30 (total across all regions)

This quota is shared with vpn gateway instances.

Yes, quota name:

vpn_quota_instances_num

Bandwidth supported by an IPsec-VPN connection (associated with a transit router)

  • Standard edition: 1 Gbps in total for the inbound and outbound directions per tunnel

  • Large edition: 3 Gbps in each of the inbound and outbound directions per tunnel

    The large edition is in invitational preview. To use it, contact your account manager.

No

The number of packets that an IPsec-VPN connection can transmit per second (associated with a transit router)

  • Standard edition: 120,000 pps in total for both directions per tunnel (256 bytes per packet)

  • Large edition: 400,000 pps in each of the inbound and outbound directions per tunnel (256 bytes per packet)

    The large edition is in invitational preview. To use it, contact your account manager.

No

Number of tunnels that support ECMP per Transit Router

32 tunnels (16 ipsec-vpn connections)

No

The number of route entries that the BGP route table of an IPsec-VPN connection can learn from the peer (associated with a transit router)

1,000 per tunnel, for a total of 2,000

The limit for legacy single-tunnel connections is 50.

For single-tunnel connections only. Contact your account manager to request an increase up to a maximum of 200.

Number of local/remote network CIDR blocks per ipsec-vpn connection

  • Standard edition: 5

  • Large edition: 10

    The large edition is in invitational preview. To use it, contact your account manager.

No

The maximum number of connections supported by an IPsec-VPN connection (associated with a transit router)

  • Standard edition: 200,000 per tunnel

  • Large edition: 400,000 per tunnel

    The large edition is in invitational preview. To use it, contact your account manager.
A network 5-tuple (source IP, destination IP, source port, destination port, and protocol) uniquely identifies a connection. This count includes connections over TCP, UDP, and ICMP.

No

Ports that cannot be used by IPsec-VPN connections (associated with a transit router)

2222

Port 2222 is reserved for internal use by the VPN gateway service. All traffic that accesses port 2222 of an IPsec-VPN connection is dropped.

No

Number of Transit Routers to which an ipsec-vpn connection can be attached

1

No

Customer gateway limits

Resource

Default limit

Adjustable

Number of customer gateways per region

150

No

API rate quotas

Request a quota increase

  • You can request self-service increases for some quotas. In Quota Center, find the desired quota and click Apply in the Actions column. To increase the likelihood of approval, specify a reasonable new quota value and provide a detailed justification for your request. The technical support team for each cloud service reviews these requests, with approvals typically taking less than one minute.

  • If you use Resource Directory to manage multiple accounts, you can use a Quota Templates to submit bulk requests for quota increases.

  • To use a RAM user for this operation, first grant the RAM user permissions to manage quotas. The required permission is AliyunQuotasFullAccess.