Quotas for your transit gateways - Amazon Virtual Private Cloud

Quotas for your transit gateways

Your AWS account has the following service quotas (previously referred to as limits) related to transit gateways. Unless indicated otherwise, you can request an increase for a quota. For more information about service quotas, see AWS Service Quotas in the Amazon Web Services General Reference.

General

  • Number of transit gateways per Region per account: 5

Routing

  • Number of transit gateway route tables per transit gateway: 20

  • Number of routes per transit gateway: 10,000

    For VPC route table quotas, see Amazon VPC quotas in the Amazon VPC User Guide.

Transit gateway attachments

  • Total number of transit gateway attachments per transit gateway: 5,000

  • Number of transit gateway attachments per VPC: 5

    This value cannot be increased.

  • Number of transit gateway peering attachments per transit gateway: 50

  • Number of pending transit gateway peering attachments transit gateway:10

Bandwidth

  • Maximum bandwidth (burst) per VPC, Direct Connect gateway, or peered transit gateway connection: 50 Gbps

  • Maximum bandwidth per VPN tunnel: 1.25 Gbps

    This is a hard value. You can use ECMP to get higher VPN bandwidth by aggregating multiple VPN tunnels.

AWS Direct Connect gateways

  • Number of AWS Direct Connect gateways per transit gateway: 20

    This value cannot be increased.

  • Transit gateways per AWS Direct Connect gateway: 3

    This value cannot be increased.

MTU

  • The maximum transmission unit (MTU) of a network connection is the size, in bytes, of the largest permissible packet that can be passed over the connection. The larger the MTU of a connection, the more data can be passed in a single packet. A transit gateway supports an MTU of 8500 bytes for traffic between VPCs, Direct Connect and peering attachments. Traffic over VPN connections can have an MTU of 1500 bytes.

  • Packets with a size larger than 8500 bytes which arrive at the transit gateway are dropped.

  • The transit gateway does not generate the FRAG_NEEDEDICMP packet, so Path MTU Discovery (PMTUD) is not supported.

  • The transit gateway enforces Maximum Segment Size (MSS) clamping for all packets. For more information, see RFC879.

Multicast

  • Number of multicast domains per transit gateway: 20

  • Number of multicast group members and sources per transit gateway: 1000

  • Number of members per transit gateway multicast group: 100

  • Number of multicast domain associations per VPC: 20

  • Number of sources per transit gateway multicast group: 1

Additional quota resources

For information about quotas that apply to Site-to-Site VPN connections, see Site-to-Site VPN Quotas in the AWS Site-to-Site VPN User Guide.

For information about quotas that apply to VPC attachments see Amazon VPC Quotas in the Amazon VPC User Guide.

For information about quotas that apply to Direct Connect gateway attachments see AWS Direct Connect Quotas in the AWS Direct Connect User Guide.

For more information about service quotas for Transit Gateway Network Manager, see Network Manager quotas.