Use Limits

Last Updated At: 2025-10-29 17:57:02

Note the following when you use a NAT Gateway:

  • When a user deletes a NAT Gateway, its EIP is disassociated, but the EIP is not released from the user account.
  • Users cannot associate a security group with a NAT Gateway but can bind a security group to instances in a private subnet to control traffic in and out of these instances.
  • Users cannot use network ACLs directly to control traffic in and out of a NAT Gateway but can use network ACLs to control traffic in and out of the subnet associated with the NAT Gateway.
  • Users cannot route traffic to a NAT Gateway through a VPC peering connection, VPN connection, or Direct Connect because the resources on the other end of such connections cannot use a NAT Gateway.
    For example, all traffic from VPC 1 to the internet can be sent through the NAT Gateway. VPC 1 and VPC 2 have established a peering connection. All resources in VPC 2 can access all resources in VPC 1, but all resources in VPC 2 cannot access the internet through the NAT Gateway.
  • NAT Gateway supports TCP, UDP, and ICMP protocols, but ESP and AH used by GRE tunnel and IPSec cannot use NAT Gateway and ALG-related technologies are not supported yet. This is determined by the features of the NAT Gateway itself and has nothing to do with the service provider. However, most internet applications are TCP applications, and TCP and UDP applications together account for 99% of internet application types.
  • The resource limits supported by the NAT Gateway are shown in the following table.
Note:

Users can request higher quotas for certain resources as indicated in the table below.

Resources Limit Can request for high quota
Number of NAT Gateways Supported by Each VPC 3 No
Number of Elastic IPs Supported by Each NAT Gateway 10 Yes
Maximum Forwarding Capacity Supported by Each NAT Gateway 5Gbps No
Maximum Port Forwarding Entries Per NAT Gateway 200 Yes