Private networks and subnets
Private networks are L2 network segments. To add a device to a private network, at least one private subnet must be added to it. Private subnets are L3 private IP address ranges defined by the CIDR size. Devices in the same private subnet can communicate directly.
Different private networks can contain subnets with the same prefixes (the same IP address range), but within the same network, subnet prefixes must be unique. By default, private networks and subnets do not have access to or from the internet, and public addressing cannot be used in them.
To enable devices in different private subnets of the same pool to exchange traffic, the subnets must be connected to the same cloud router. To connect devices in different pools, including across different projects and accounts, you need to connect the private subnets of these devices to a global router. The addresses of subnets connected to the same router (cloud or global) must not overlap. Connectivity through a cloud and global router is established at L3.
You can configure DNS in a private network so that devices in it can address each other using domain names instead of IP addresses, as well as resolve public domain names.
By default, private networks and their subnets can only be used within the same project and the same pool. You can configure shared access to a private network across different projects within a single account.
Within private subnets, there are traffic limits: bandwidth. You can check it in the Bandwidth table. The default MTU is 1,500 B; you can change the MTU in the private network.
You can work with private subnets and networks in the Control panel, using the OpenStack CLI, or with Terraform.
Automatic private subnet settings
Default settings are specified in private subnets: default gateway and public DNS servers. If you add a device to an existing subnet, the settings are applied to it automatically. If you change the settings of a subnet that already contains devices, to apply the settings, you must update the network settings on all devices in the subnet.
Default gateway
When creating a private subnet, the first available IP address is reserved for the default gateway. For example, for a subnet with CIDR 192.168.0.0/24, 192.168.0.1 will be reserved for the gateway. The default gateway can be changed when creating a subnet or changed after creation.
DNS servers
When creating a private subnet, Servercore public DNS servers are automatically configured on devices in the subnet. DNS servers can be changed when creating a subnet or changed after creation.
Static routes
By default, static routes are not specified in subnets. For private subnets, you can configure static routes.
Create a private network
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Click Create network.
- Select the location where the private network will be created.
- Enter the network name.
- Optional: enter a comment for the network.
- Enter the subnet CIDR — the range of IP addresses available in the subnet.
- Optional: to change the IP address of the default gateway, click . Enter a value. Click .
- Optional: to change the DNS servers, click . Enter from one to three values. Click .
- Optional: to enable DHCP, select the Enable DHCP checkbox.
- Optional: to add another subnet, click Add subnet and repeat steps 7-10.
- Click Create.
Add a subnet to the private network
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the network page → the Subnets tab.
- Click Create subnet.
- Enter the subnet CIDR — the range of IP addresses available in the subnet.
- Optional: change the IP address of the default gateway.
- Optional: change the DNS servers. Enter from one to three values.
- Optional: to enable DHCP, select the Enable DHCP checkbox.
- Click .
Configure access to the private network in different projects
By default, a private network can only be used within the same project and the same pool. You can configure shared access to a private network across different projects within a single account. The network will also remain accessible only within the same pool.
The private network will receive the Cross-project tag. Managing the network will only be possible in the project where the subnet is located.
If you need to connect private networks from different pools (including across different projects and accounts), connect the private network to a global router.
Control panel
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Copy the ID of the recipient project to share the network with. To do this, open the project menu (name of the current project) and click in the project line.
- Make sure you are in the project where the network is located.
- Open the network page → the Projects tab.
- Click Add project.
- Paste the ID of the recipient project that you copied in step 3.
- Click .
Enable DHCP in a private subnet
The DHCP protocol can be used for automatic network configuration on devices. It allows devices in a private subnet to automatically receive IP addresses, a subnet mask, a default gateway, DNS server addresses, and static routes. Devices in a subnet with DHCP enabled will automatically request settings from the DHCP server: upon enabling a network interface or when the address lease expires (default is 24 hours).
When enabling DHCP, two ports for DHCP servers will be created in the subnet: for the primary and backup servers. The first two available IP addresses in the subnet will be reserved for these ports. For example, for a subnet with CIDR 192.168.0.0/24, 192.168.0.2 and 192.168.0.3 will be reserved
DHCP in a private subnet can be enabled when creating a private network, adding a subnet to a network, or for an existing private subnet.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the private network page → the Subnets tab.
- In the subnet card, open the Automatic network settings block.
- Enable the DHCP server toggle.
Disable DHCP in a private subnet
When you disable DHCP in a private subnet, two IP addresses that were reserved for DHCP servers are released.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the private network page → the Subnets tab.
- In the subnet card, open the Automatic network settings block.
- Turn off the DHCP server toggle.
Change the default gateway in a private subnet
When creating a private subnet, the first available IP address is reserved for the default gateway. For example, for a subnet with CIDR 192.168.0.0/24, 192.168.0.1 will be reserved.
The default gateway can be changed when creating a private network, adding a subnet to a network, or for an existing private subnet.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the private network page → the Subnets tab.
- In the subnet card, open the Automatic network settings block.
- In the Subnet gateway field, click .
- Enter a new value for the default gateway IP address.
- Click .
- Apply the changes. To do this, update the network settings on the devices in the subnet.
Change DNS servers in a private subnet
When creating a private subnet, public Servercore recursive DNS servers are automatically configured on devices in the subnet. DNS servers can be changed when creating a private network, when adding a subnet to a network, or for an existing private subnet.
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the private network page → the Subnets tab.
- In the subnet card, open the Automatic network settings block.
- In the DNS server addresses field, click .
- Enter one to three values.
- Click .
- Apply the changes. To do this, update the network settings on the devices in the subnet.
Connect a subnet to a cloud router
For private subnets from different networks to communicate with each other, they must be connected to the same cloud router. Subnets must not overlap — they must not contain identical IP addresses.
To configure internet access to and from devices in private subnets using a cloud router, refer to the Configure internet access instructions.
Control panel
OpenStack CLI
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
Open the network page → the Subnets tab.
-
In the subnet card, in the Cloud router field, click Connect. If the subnet is already connected to a cloud router, you can connect it to another cloud router from the router card.
-
Select a cloud router — existing or new.
-
Optional: if the router will be used for internet access, select the Connect to internet checkbox. If the router is already connected to the internet, the checkbox is not displayed.
-
If you chose to create a new router, configure it:
7.1. Enter the router name
7.2. Optional: enter the router IP address. If you do not specify an IP address, it will be automatically selected from the available subnet addresses. The cloud router IP address must match the default gateway of the private subnet. You can check the gateway in the Control panel: in the top menu, click Products → Cloud Servers → Network → the Private networks tab → the network page → the Subnets tab → the subnet card → the Automatic network settings block → the Subnet gateway field.
-
Click Connect.
Disconnect a subnet from a cloud router
Control panel
OpenStack CLI
- In the Control panel, in the top menu, click Products and select Cloud Servers.
- Go to Network → the Private networks tab.
- Open the private network page → the Ports tab. Ports used by cloud routers are marked with the Router tag.
- In the port row of the cloud router to which the subnet is connected, click .
- Click Delete.
Connect a private network to a global router
When you connect a private network to a global router, all subnets belonging to that network will be connected to it. All subnets will communicate at the L3 level.
The private network will receive the Global router tag. Managing the network and subnets connected to the global router will only be possible in the global router section in the Control panel: in the top menu, click Products → Global Router.
Three service ports for network equipment will be automatically created in the private network.
Control panel
-
Verify that subnets in the private network meet the following conditions:
- belong to the RFC 1918 private address range:
10.0.0.0/8,172.16.0.0/12, or192.168.0.0/16; - have a size of at least
/29, as three addresses will be occupied by Servercore network equipment; - they do not overlap with other networks and subnets connected to this global router (IP addresses in subnets must not coincide);
- if a Managed Kubernetes cluster on cloud servers is to be included in the global router network, the subnet must not overlap with the ranges
10.10.0.0/16,10.96.0.0/12,10.250.0.0/16, and10.251.0.0/24. If a cluster on dedicated servers is included in the network — with the ranges10.10.0.0/16,10.222.0.0/16,10.250.0.0/16,10.251.0.0/24, and172.250.0.0/14. These subnets are part of the internal Managed Kubernetes addressing, and their use may lead to conflicts in the global router network.
- belong to the RFC 1918 private address range:
-
In the Control panel, in the top menu, click Products → Cloud Servers.
-
Go to Network → the Private networks tab.
-
In the network menu, select Connect to global router.
-
Select an existing global router or create a new one.
-
For each subnet, enter the gateway IP address that will be assigned to the global router. Do not assign this address to devices to avoid disrupting network operation.
-
Optional: change the service IP addresses that are assigned automatically for global router reservation.
-
Click Connect. Do not close the window until the network is connected.
Disconnect a private network from a global router
Control panel
- In the Control panel, in the top menu, click Products → Cloud Servers.
- Go to Network → the Private networks tab.
- In the network menu, select Disconnect from global router.
- Enter the network name to confirm disconnection.
- Click Disconnect. Do not close the window until the network is disconnected.
Change MTU in a private network
When creating a private network, a standard MTU of 1 500 B is set; you can change the MTU.
A cloud router accepts packets up to 1,500 B; larger packets are dropped. If you set the network MTU to more than 1,500 B, when sending traffic from this network to a cloud router, you must reduce the packet size to 1,500 B. For example, PMTUD can be used for this. The limitation does not apply to TCP transmissions.
A global router accepts packets up to 8,500 B.
OpenStack CLI
-
Specify a new MTU value in the network:
openstack network set \--mtu <mtu> \<network>Specify:
<mtu>— the new MTU value in B, maximum value is8500;<network>— ID or name of the private network; you can view it using theopenstack network listcommand.
-
Apply the changes. To do this, update the network settings on the devices in the network. You can view the list of devices in the network in the Control panel: in the top menu, click Products → Cloud Servers → Network → the Private networks tab → the private network page → the Ports tab.
View private network metrics
You can view private network metrics for a cloud server as charts in the Control panel.
If no cloud server is added to the private network, metrics are not collected. To collect network metrics, add a cloud server to the subnet via a port.
Values for all metrics are collected every minute. If you have just connected a private network to a cloud server, the first metric values will appear in a few minutes.
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
Open the private network page → the Metrics tab.
-
Optional: filter the metrics:
3.1. Select a preset range or specify the period for which you need metrics
3.2. Select UTC time or Local time for the displayed metric time.
-
View charts for available network metrics:
- incoming traffic rate in bits per second;
- outgoing traffic rate in bits per second;
- incoming traffic rate in packets per second;
- outgoing traffic rate in packets per second.
Delete a private subnet
When deleting a private subnet, you must delete all ports in it.
Control panel
OpenStack CLI
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
If the card of the private network containing the subnet has the Global router tag, disconnect the network from the global router:
3.1. In the network menu, select Disconnect from global router.
3.2. Enter the network name to confirm disconnection
3.3. Click Disconnect. Do not close the window until the network is disconnected.
-
Delete all subnet ports:
4.1. Open the page of the network where the subnet is created → the Ports tab.
4.2. In the subnet port menu, select Delete port.
4.3. Depending on whether additional actions are required to delete the port, a dialog box will appear:
- if additional actions are required, a window with a description of the actions will appear. Perform them and return to step 4.1;
- if no additional actions are required, a confirmation window will appear. Click Delete.
4.4. Repeat steps 4.1–4.3 for each subnet port
-
In the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
Open the network page → the Subnets tab.
-
In the subnet card, click .
-
Click Delete.
Delete a private network
Together with the network, the subnets created within it will be deleted.
When deleting a private network, you must delete all ports in it.
Control panel
OpenStack CLI
-
In the Control panel, in the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
If the network card has the Global router tag, disconnect it from the global router:
3.1. In the network menu, select Disconnect from global router.
3.2. Enter the network name to confirm disconnection
3.3. Click Disconnect. Do not close the window until the network is disconnected.
-
Delete all network ports:
4.1. Open the network page → the Ports tab.
4.2. In the port menu, select Delete port.
4.3. Depending on whether additional actions are required to delete the port, a dialog box will appear:
- if additional actions are required, a window with a description of the actions will appear. Perform them and return to step 4.1;
- if no additional actions are required, a confirmation window will appear. Click Delete.
4.4. Repeat steps 4.1–4.3 for each network port
-
In the top menu, click Products and select Cloud Servers.
-
Go to Network → the Private networks tab.
-
In the network menu, select Delete network.