Usage restrictions
Updated at:2025-10-16
The product specifications supported by VPC are detailed below. If you need to apply for more quotas, please submit an application via Quota Management.
VPC quota
- Each user can create up to 10 VPC instances per region, including one default VPC.
- A maximum of 10 subnets can be created per VPC.
- Each VPC allows adding up to 5 auxiliary network segments.
- Every VPC includes a default security group. Default VPCs support the creation of up to 100 security groups (including the default one), while custom VPCs allow up to 20.
- Once a VPC is created, its address space and the number of IP addresses it supports cannot be adjusted.
- BCC instances can join only one subnet within a VPC. Specifying an IP or disassociating from the VPC is not possible.
- BCC instances in a VPC are allowed to modify their DHCP-assigned IP addresses.
Route table quota
Each VPC can have up to 50 route table entries by default.
Security group quota
- In each default VPC, up to 100 security groups can be created.
- In each custom VPC, up to 20 security groups can be created.
- Each regular security group allows a maximum of 100 rules per direction by default. To create additional rules, apply via the Quota Center.
- Each enterprise security group allows a maximum of 150 ingress rules and 150 egress rules by default. To create additional rules, apply at the Quota Center.
ACL restrictions
For rules in the same ACL, each direction supports a maximum of 150 rules.
Elastic network interface quota
- Each VPC allows up to 500 unmounted elastic network interfaces. Mounted elastic network interfaces do not consume quota.
- The number of IPs per network interface card must be between 1 and 40.
- The number of elastic network interfaces that can be mounted by a cloud host is determined by the smaller value between the host's core count and 8.
- The number of configurable IPs for network interface cards attached to the cloud host.
| Memory | Count of IPs |
|---|---|
| 1G | 2 |
| (1-8]G | 8 |
| (8-32]G | 16 |
| (32-64]G | 30 |
| Greater than 64G | 40 |
Service network interface card restrictions
- A maximum of 20 service network interface cards are allowed per VPC.
- Each subnet supports only one SNIC for a specific service.
- The highest internal bandwidth available for a single service network interface card is 5,000 Mbps.
- The combined internal bandwidth of all service network interface cards in a single region must not exceed 50,000 Mbps.
NAT gateway quota
- Each VPC supports up to 3 NAT gateways.
- Standard NAT gateway: Small NAT gateways support up to 5 public IPs; medium NAT gateways support up to 10 public IPs; large NAT gateways support up to 15 public IPs.
- Enhanced NAT gateway: Each CU can bind up to 5 EIPs, with a maximum limit of 50 EIPs in total.
- The total number of EIPs used for SNAT+DNAT must not exceed the maximum number of EIPs bindable to a NAT.
- SNAT or DNAT can bind either a regular EIP or multiple IPs from an EIPGROUP but cannot bind both simultaneously.
- SNAT and DNAT can share an EIPGROUP as long as the public IPs do not overlap. A single public IP cannot be used for both SNAT and DNAT at the same time.
- A single SNAT table can have up to 40 entries.
- A single SNAT entry can associate with a maximum of 50 public IPs.
- A single DNAT table can support up to 100 port forwarding entries.
IPv6 gateway quota
- Each VPC supports up to one IPv6 gateway.
- The IPv6 gateway's IP rate-limiting policy supports a maximum of 50 records.
VPN gateway quota
- Each VPC supports a maximum of three VPN gateways.
- Each VPN gateway supports up to 10 VPN tunnels.
Peering connection quota
- Each VPC can establish up to 10 peering connection instances.
- Each user can create up to 10 peering connection instances.
Flow log quota
- A maximum of 10 flow log instances can be created per VPC.
Traffic mirror quota
- Each filter criterion can support up to 9 filtering rules.
- A maximum of 50 filter criteria can be set for a single region.
- Each account can support up to 1,000 mirror sessions per region.
- A single mirror source can support the creation of only 1 mirror session.
- A single mirror session allows the addition of only 1 mirror source.
- A single mirror destination can be utilized by a maximum of 200 mirror sessions.
Network probe quota
- A maximum of 50 network probe instances can be created within a VPC.
Other Restrictions
- CDS disks, images, snapshots, and EIPs are independent of VPCs and are not subordinate to them. Only security groups are directly affiliated with VPCs.
