> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# Networking for VMs

> How public IPs, VPCs, NAT, Reserved IPs, firewall groups, and bandwidth work for IBEE Solutions VMs.

You choose how a Cloud VM connects to the network when you deploy it, and you can change most of it later from the VM's **Settings** tab. This page explains the options, the defaults, and the controls available to you.

## Network modes at deploy time

On the Deploy page, **Network Configuration → VM network → Internet and VPC access** offers three modes:

| Mode                      | Primary interface                                                                                                                          | Internet access                                         |
| ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------- |
| **Public IP** *(default)* | The platform network (**No VPC · public interface only**), or a VPC you select. With a VPC, the public IP maps to the VM's VPC private IP. | Direct inbound and outbound IPv4.                       |
| **Private + NAT**         | A NAT Gateway VPC.                                                                                                                         | Managed outbound internet; inbound internet is blocked. |
| **Private only**          | A VPC.                                                                                                                                     | None.                                                   |

When you select a VPC you must also select a **Subnet**. Only VPCs compatible with the chosen mode in the VM's location are listed. See [VPC](/docs/network-security/vpc-ip-management) to create VPCs and subnets.

### Reserved public IP

With **Public IP** and a VPC selected, a **Reserved public IP** field appears:

* **Allocate automatically** — the platform assigns an address. This is the default for public VPCs.
* **A Reserved IP you own** — pick one from the same location. Required when the VPC is **private**; create one first under [Reserved IPs](/docs/network-security/vpc-ip-management/reserved-ips) if the list is empty.

A specific Reserved IP can be attached to one VM at a time, so selecting one limits the deployment to a single VM.

## Default network setup

| Property           | Default                                                                                                                    |
| ------------------ | -------------------------------------------------------------------------------------------------------------------------- |
| Public IPv4        | One address assigned at deploy time with **Public IP** mode. **Private + NAT** and **Private only** VMs have no public IP. |
| DHCP               | Enabled on the primary interface (`eth0` / `ens3`)                                                                         |
| Firewall           | The default firewall group, unless you select another group at deploy time                                                 |
| Inbound bandwidth  | Unmetered                                                                                                                  |
| Outbound bandwidth | Per-plan allowance (see [Instance types](/docs/infrastructure/cloud-vms/instance-types))                                   |

The **Cloud Virtual Machines** list shows the assigned address under the **IP Address** column once provisioning completes (for example `103.149.10.116`).

## Inside the guest

The primary NIC uses `virtio-net`. Most cloud images bring the interface up automatically via DHCP at boot. To check:

```bash
ip -4 addr show
ip route
```

On a **Public IP** VM without a VPC, you should see the public IP on the primary interface and a default route via the IBEE gateway. On a VPC-attached VM, you see the VPC private IP.

## Firewalls

Every VM is protected by a firewall group that controls inbound access:

* At deploy time, pick a group under **Network Configuration → Firewall**, or click **Create Group** to create one and select it.
* If you don't select a group, the **default firewall group is attached automatically**.
* Add or edit rules on the [Firewalls](/docs/network-security/firewalls) page — see [Create firewall rules](/docs/network-security/firewalls/create-firewall-rules).

Check the attached group's rules if a service isn't reachable. Inside the guest, you can also run `ufw`, `firewalld`, or Windows Defender Firewall — they stack with the platform firewall.

## Change networking after deploy

Open the VM detail page → **Settings**:

### IPv4 & Reserved IP

Shows the VM's public address and how it's managed:

* **Main VM address** — the provider-assigned address is **Managed with VM**. If the VM also has a NAT VPC as its default route, **Keep as Reserved** opens **Remove direct public network**: the address is kept as a Reserved IP for later reuse, and the VM switches to its NAT VPC interface for outbound internet. Direct inbound traffic to the address stops, so add a NAT port-forwarding rule for services that must stay reachable.
* **Attach IP** / **Attach or Move IP** — attach one of your same-location Reserved IPs, or move one from another VM. A Reserved IP can be attached to one VM at a time.
* **Detach IP** — public traffic to that address stops; the address stays in **Reserved IPs**.

When you delete a VM, the delete dialog also offers to keep its public IP as a Reserved IP — see [Power actions](/docs/infrastructure/cloud-vms/power-actions#delete).

### VPC Networks

Lists the VPC interfaces attached to the VM, with each interface's private IP, subnet, and VPC ID:

* **Attach VPC** — connect the VM to a VPC and subnet in the same site.
* **Detach VPC** — remove a VPC interface. A VM must always keep at least one network interface, so the primary interface can't be detached until another route is in place. The guest may need network configuration after the change.

## Connecting to private VMs

**Private + NAT** and **Private only** VMs can't accept direct connections from the internet. **Overview → Connection Details** shows the private SSH or RDP command to use from inside the VPC — for example through a VPN, a bastion host, or another VM in the VPC. NAT VMs can also use a NAT port-forward rule for inbound access.

## DNS

Use any DNS provider to point a domain at your VM:

1. Add an `A` record for the VM's public IP.
2. Add a `CNAME` for `www` if needed.

A [Reserved IP](/docs/network-security/vpc-ip-management/reserved-ips) keeps the address stable if you later replace the VM.

## Bandwidth and overage

Each plan includes a monthly outbound bandwidth allowance (for example **2 TB** on `std.1.c2.m8`). The Monitoring tab's **Network Traffic** chart shows current inbound and outbound throughput and your monthly outbound usage.

* Inbound traffic is unmetered.
* Outbound usage above the included allowance is billed per GB; see your plan summary for the rate.

## Load balancing

To put a load balancer in front of multiple VMs, use [Load Balancer](/docs/network-security/load-balancer):

* Create the load balancer in the same region as your VMs.
* Attach the VMs as backends and configure a health check.
* Optionally terminate TLS at the load balancer.

## Troubleshooting

**VM has no public IP after deploy**
**Private + NAT** and **Private only** VMs don't get a public IP — this is expected. For **Public IP** VMs, refresh the list; the column updates after provisioning completes. If it stays blank for more than a few minutes, open the [Activity feed](/docs/infrastructure/cloud-vms/monitoring#activity-feed); a failed `VM create` will surface there.

**Can't SSH but the VM is Running**

* Check that the VM's firewall group allows port 22 from your address.
* Confirm you're using the username and host from **Overview → Connection Details**.
* If the key is wrong or lost, add another saved key, or reset the password and enable password login, on **Settings → Access**. Browser console access isn't available in the portal yet.

**Deploy says a Reserved IP is required**
You chose **Public IP** with a **private** VPC. Create a Reserved IP in the same location, or pick a public VPC or **No VPC**.

**Bandwidth chart looks flat or empty**
The chart smooths over its time range. Switch to **30m** for short-window detail.

## Related pages

* [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm)
* [VPC](/docs/network-security/vpc-ip-management)
* [Reserved IPs](/docs/network-security/vpc-ip-management/reserved-ips)
* [Firewalls](/docs/network-security/firewalls)
* [Load Balancer](/docs/network-security/load-balancer)