> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/infrastructure/cloud-vms/networking-for-vms/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # Networking for VMs > How public IPs, VPCs, NAT, Reserved IPs, firewall groups, and bandwidth work for IBEE Solutions VMs. You choose how a Cloud VM connects to the network when you deploy it, and you can change most of it later from the VM's **Settings** tab. This page explains the options, the defaults, and the controls available to you. ## Network modes at deploy time On the Deploy page, **Network Configuration → VM network → Internet and VPC access** offers three modes: | Mode | Primary interface | Internet access | | ------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------- | | **Public IP** *(default)* | The platform network (**No VPC · public interface only**), or a VPC you select. With a VPC, the public IP maps to the VM's VPC private IP. | Direct inbound and outbound IPv4. | | **Private + NAT** | A NAT Gateway VPC. | Managed outbound internet; inbound internet is blocked. | | **Private only** | A VPC. | None. | When you select a VPC you must also select a **Subnet**. Only VPCs compatible with the chosen mode in the VM's location are listed. See [VPC](/docs/network-security/vpc-ip-management) to create VPCs and subnets. ### Reserved public IP With **Public IP** and a VPC selected, a **Reserved public IP** field appears: * **Allocate automatically** — the platform assigns an address. This is the default for public VPCs. * **A Reserved IP you own** — pick one from the same location. Required when the VPC is **private**; create one first under [Reserved IPs](/docs/network-security/vpc-ip-management/reserved-ips) if the list is empty. A specific Reserved IP can be attached to one VM at a time, so selecting one limits the deployment to a single VM. ## Default network setup | Property | Default | | ------------------ | -------------------------------------------------------------------------------------------------------------------------- | | Public IPv4 | One address assigned at deploy time with **Public IP** mode. **Private + NAT** and **Private only** VMs have no public IP. | | DHCP | Enabled on the primary interface (`eth0` / `ens3`) | | Firewall | The default firewall group, unless you select another group at deploy time | | Inbound bandwidth | Unmetered | | Outbound bandwidth | Per-plan allowance (see [Instance types](/docs/infrastructure/cloud-vms/instance-types)) | The **Cloud Virtual Machines** list shows the assigned address under the **IP Address** column once provisioning completes (for example `103.149.10.116`). ## Inside the guest The primary NIC uses `virtio-net`. Most cloud images bring the interface up automatically via DHCP at boot. To check: ```bash ip -4 addr show ip route ``` On a **Public IP** VM without a VPC, you should see the public IP on the primary interface and a default route via the IBEE gateway. On a VPC-attached VM, you see the VPC private IP. ## Firewalls Every VM is protected by a firewall group that controls inbound access: * At deploy time, pick a group under **Network Configuration → Firewall**, or click **Create Group** to create one and select it. * If you don't select a group, the **default firewall group is attached automatically**. * Add or edit rules on the [Firewalls](/docs/network-security/firewalls) page — see [Create firewall rules](/docs/network-security/firewalls/create-firewall-rules). Check the attached group's rules if a service isn't reachable. Inside the guest, you can also run `ufw`, `firewalld`, or Windows Defender Firewall — they stack with the platform firewall. ## Change networking after deploy Open the VM detail page → **Settings**: ### IPv4 & Reserved IP Shows the VM's public address and how it's managed: * **Main VM address** — the provider-assigned address is **Managed with VM**. If the VM also has a NAT VPC as its default route, **Keep as Reserved** opens **Remove direct public network**: the address is kept as a Reserved IP for later reuse, and the VM switches to its NAT VPC interface for outbound internet. Direct inbound traffic to the address stops, so add a NAT port-forwarding rule for services that must stay reachable. * **Attach IP** / **Attach or Move IP** — attach one of your same-location Reserved IPs, or move one from another VM. A Reserved IP can be attached to one VM at a time. * **Detach IP** — public traffic to that address stops; the address stays in **Reserved IPs**. When you delete a VM, the delete dialog also offers to keep its public IP as a Reserved IP — see [Power actions](/docs/infrastructure/cloud-vms/power-actions#delete). ### VPC Networks Lists the VPC interfaces attached to the VM, with each interface's private IP, subnet, and VPC ID: * **Attach VPC** — connect the VM to a VPC and subnet in the same site. * **Detach VPC** — remove a VPC interface. A VM must always keep at least one network interface, so the primary interface can't be detached until another route is in place. The guest may need network configuration after the change. ## Connecting to private VMs **Private + NAT** and **Private only** VMs can't accept direct connections from the internet. **Overview → Connection Details** shows the private SSH or RDP command to use from inside the VPC — for example through a VPN, a bastion host, or another VM in the VPC. NAT VMs can also use a NAT port-forward rule for inbound access. ## DNS Use any DNS provider to point a domain at your VM: 1. Add an `A` record for the VM's public IP. 2. Add a `CNAME` for `www` if needed. A [Reserved IP](/docs/network-security/vpc-ip-management/reserved-ips) keeps the address stable if you later replace the VM. ## Bandwidth and overage Each plan includes a monthly outbound bandwidth allowance (for example **2 TB** on `std.1.c2.m8`). The Monitoring tab's **Network Traffic** chart shows current inbound and outbound throughput and your monthly outbound usage. * Inbound traffic is unmetered. * Outbound usage above the included allowance is billed per GB; see your plan summary for the rate. ## Load balancing To put a load balancer in front of multiple VMs, use [Load Balancer](/docs/network-security/load-balancer): * Create the load balancer in the same region as your VMs. * Attach the VMs as backends and configure a health check. * Optionally terminate TLS at the load balancer. ## Troubleshooting **VM has no public IP after deploy** **Private + NAT** and **Private only** VMs don't get a public IP — this is expected. For **Public IP** VMs, refresh the list; the column updates after provisioning completes. If it stays blank for more than a few minutes, open the [Activity feed](/docs/infrastructure/cloud-vms/monitoring#activity-feed); a failed `VM create` will surface there. **Can't SSH but the VM is Running** * Check that the VM's firewall group allows port 22 from your address. * Confirm you're using the username and host from **Overview → Connection Details**. * If the key is wrong or lost, add another saved key, or reset the password and enable password login, on **Settings → Access**. Browser console access isn't available in the portal yet. **Deploy says a Reserved IP is required** You chose **Public IP** with a **private** VPC. Create a Reserved IP in the same location, or pick a public VPC or **No VPC**. **Bandwidth chart looks flat or empty** The chart smooths over its time range. Switch to **30m** for short-window detail. ## Related pages * [Create a VM](/docs/infrastructure/cloud-vms/create-a-vm) * [VPC](/docs/network-security/vpc-ip-management) * [Reserved IPs](/docs/network-security/vpc-ip-management/reserved-ips) * [Firewalls](/docs/network-security/firewalls) * [Load Balancer](/docs/network-security/load-balancer) > How public IPs, VPCs, NAT, Reserved IPs, firewall groups, and bandwidth work for IBEE Solutions VMs.