Cloud routers
With a cloud router, you can:
- route traffic between private subnets. All private subnets connected to the same router can exchange traffic and use the router's IP address as the default route;
- configure internet access for devices in a private subnet (outbound traffic) and from the internet (inbound traffic); for more information, see the Configure internet access and access from the internet instructions. The cloud router performs 1:1 NAT via an external IP address allocated when connecting the router to the internet: it organizes internet access from the private subnet and processes inbound traffic packets for public IP addresses.
You can configure static routes on a cloud router.
A cloud router can only be used within a single project and a single pool.
For cloud routers, there are traffic volume limitations: bandwidth. You can check it in the Bandwidth table.
You can work with cloud routers in the Control panel, using the OpenStack CLI, or with Terraform.
Cloud router types
Two router types are available:
-
Basic — consists of one instance. In case of failure, connectivity through the router will be disrupted;
-
High availability — consists of primary and backup instances located in different pool segments and joined via VRRP.
Redundancy works in Active-Passive mode: only one instance (primary) is active at a time, and traffic switches to the backup instance upon failure. The switchover takes up to 10 seconds; connections are interrupted and re-established on the backup instance. The instances swap roles — the backup becomes the primary. If the router has a firewall, its settings are preserved.
You can select the router type when creating a router. After creation, you can change its type only via the OpenStack CLI: enable redundancy or disable redundancy.
Create a cloud router
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- Click Create router.
- Select the location in which the cloud router will be created.
- Select the router type. You can change the router type after creation: enable redundancy or disable redundancy.
- Enter a router name.
- Optional: select the Connect router to the Internet checkbox — an external IP address will be allocated for the router.
- Click Create.
Connect a subnet to a cloud router
For devices in private subnets of the same pool to exchange traffic, the subnets must be connected to the same cloud router. The subnets must not overlap — they must not contain identical IP addresses.
To configure internet access and access from the internet for devices in private subnets, use the Configure internet access and access from the internet instructions.
Control panel
OpenStack CLI
-
In the Control panel, on the top menu, click Products and select Cloud Servers.
-
Go to the Network section → Cloud Routers tab.
-
Open the router page.
-
Click Connect subnet.
-
Select a private subnet.
-
Optional: enter the router IP address—any available IP address from the subnet. If you do not specify an IP address, one will be automatically selected from the available addresses in the subnet.
For devices in the subnet to access the internet without additional routes, the cloud router IP address must match the private subnet gateway. If the subnet gateway is already in use, you will need to configure a static route to the internet in the subnet via the cloud router.
You can view the subnet gateway in the control panel: in the top menu, click Products → Cloud Servers → Network → tab Private networks → network page → tab Subnets → subnet card → block Automatic network settings → field Subnet gateway.
-
Click Connect.
Disconnect a subnet from a cloud router
You cannot detach a subnet from a cloud router if:
- the router is processing traffic for public IP addresses of devices in this subnet;
- there are static routes on the router that specify IP addresses of this subnet as the next-hop.
Control panel
OpenStack CLI
- In the Control panel, on the top menu, click Products and select Cloud Servers.
- Go to the Network → tab Cloud Routers.
- Open the router page → Ports tab.
- In the port row of the required subnet, click .
- Click Delete.
Connect a cloud router to the internet
To configure internet access for devices in a private subnet, the subnet must be connected to a cloud router with internet access. For internet access, the router connects to an external network (external-network), and an external IP address is allocated to it, through which the router will perform 1:1 NAT. The router's external IP address does not change while the router is connected to the internet.
You cannot access devices behind the router from the internet using the router's external IP address. It is only used for devices to access the internet through the router.
To configure access from the internet to devices, use a public IP address or a public subnet; for more information, see the Configure internet access and access from the internet instructions.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- In the cloud router's menu, select Connect to internet.
Disconnect a cloud router from the internet
If you disconnect the cloud router from the internet, its external IP address will return to the address pool. After reconnecting, the IP address will change.
A cloud router cannot be disconnected from the internet if it processes traffic for public IP addresses.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- In the cloud router's menu, select Disconnect from internet.
- Click Disconnect.
Assign a firewall to a cloud router port
Inbound and outbound traffic that is not allowed by the cloud firewall rules will be blocked on the cloud router port. Active sessions on the router that are not allowed by the new rules will be terminated.
You cannot assign more than one firewall to a single router port.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- Open the cloud router page.
- In the line of the private subnet port for which you need to configure traffic filtering, in the Firewall field, click .
- Select a firewall.
- Click Save.
Detach a firewall from a cloud router port
The cloud firewall rules will no longer apply — all inbound and outbound traffic passing through the cloud router port will be allowed.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- Open the router page.
- In the line of the private subnet port for which traffic filtering was configured, in the Firewall field, click .
- Select No firewall.
- Click Save.
Enable cloud router redundancy
Active sessions on the router will be interrupted for the duration of the operation.
You can enable redundancy. The router type will change to High availability, and an additional instance will be added to the router.
OpenStack CLI
-
Shut down the cloud router:
openstack router set <router> --disableSpecify
<router>— the name of the cloud router; you can view it using theopenstack router listcommand. -
Enable redundancy. An additional instance will be added to the router:
openstack router set <router> --haSpecify:
<router>— the ID or name of the cloud router; you can view it using theopenstack router listcommand;- optional:
--availability-zone-hint <availability_zone>— pool segments where router instances will be located. The<availability_zone>parameter is a pool segment, for example,ru-6a. Specify at least two segments, each in a separate parameter, for example,--availability-zone-hint ru-6a --availability-zone-hint ru-6b.
-
Turn on the cloud router:
openstack router set --enable <router>Specify
<router>— the ID or name of the router; you can view it using theopenstack router listcommand.Connections that were interrupted when the router was shut down will be restored automatically on its original instance.
Disable cloud router redundancy
Active sessions on the router will be interrupted for the duration of the operation.
You can disable redundancy. The router type will change to Basic, and the backup router instance will be deleted.
OpenStack CLI
-
Shut down the cloud router:
openstack router set <router> --disableSpecify
<router>— the name of the cloud router; you can view it using theopenstack router listcommand. -
Disable redundancy. The backup router instance that was inactive before shutdown will be deleted:
openstack router set <router> --no-haSpecify:
<router>— the ID or name of the cloud router; you can view it using theopenstack router listcommand.
-
Turn on the cloud router:
openstack router set --enable <router>Specify
<router>— the ID or name of the router; you can view it using theopenstack router listcommand.Connections that were interrupted when the router was shut down will be restored automatically.
Turn on a cloud router
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- In the cloud router card, turn on the router.
Turn off a cloud router
A router cannot be disabled if it processes traffic for a public IP address.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → Cloud Routers tab.
- In the cloud router card, turn off the router.
Delete a cloud router
Control panel
OpenStack CLI
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Network → Cloud Routers tab.
-
Disconnect all connected subnets from the router by removing all subnet ports from the router:
3.1. Open the router page → Ports tab.
3.2. In the line of any port, click .
3.3. Click Delete.
3.4. Repeat steps 3.2–3.3 for all remaining ports.
-
In the router's menu, select Delete router.
-
Click Delete.