> For clean Markdown of any page, append .md to the page URL.
> For a complete documentation index, see https://docs.ibee.co.in/docs/llms.txt.
> For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/docs/_mcp/server.

# VPC

> Create isolated private networks, subnets, NAT gateways, port forwarding rules, and VM attachments on IBEE Solutions.

A VPC (Virtual Private Cloud) is an isolated Layer 3 network for resources in one
workspace. Resources in the same VPC communicate over private IPs without
traversing the public internet. A VPC belongs to one location, and only VMs in
that location can attach to it.

## Create a VPC

### Open VPCs

In the portal sidebar, click **VPC** under **Network & Security**, then click **Create VPC**.

### Enter the VPC details

Enter a **Name** (e.g. `production-vpc`), choose a **Location**, and optionally
add a **Description**.

### Choose connectivity

| Option                       | Behavior                                                                                                                                                                    |
| ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Private only** *(default)* | VMs receive private addresses only. To expose one specific VM, attach a [Reserved IP](/docs/network-security/vpc-and-ip-management/reserved-ips) to it later.               |
| **Managed NAT Gateway**      | Private VMs share one public IPv4 address for outbound internet. Unsolicited inbound traffic is not accepted unless you add a [port forwarding rule](#nat-port-forwarding). |

The VPC network and its default subnet are included at no extra charge. A
managed NAT gateway is billed while it exists; the summary panel shows its
price for the selected location before you create the VPC. Firewall rules
still control access to each VM.

### Choose the private IP range

* **Automatic** *(default)* picks a conflict-free RFC1918 range.
* **Custom CIDR** — enter a **Network address** (e.g. `10.10.0.0`) and pick a
  **Network size** from `/22` to `/28` (default `/24`). The range must be
  RFC1918 space (`10.0.0.0/8`, `172.16.0.0/12`, or `192.168.0.0/16`) and
  aligned to the chosen size. If the address is not aligned, the form suggests
  the nearest valid network address.

VPC ranges in the same account cannot overlap.

### Create

Click **Create VPC Network**. IBEE creates the VPC with a default subnet (and,
for **Managed NAT Gateway**, the NAT gateway). The VPC is usable when its
status is `available`.

## Connectivity modes

| Portal option           | API `connectivity_type` | Use it for                                                   |
| ----------------------- | ----------------------- | ------------------------------------------------------------ |
| **Private only**        | `private`               | Private networking; expose individual VMs with a Reserved IP |
| **Managed NAT Gateway** | `nat_gateway`           | Private VMs that share managed outbound internet access      |

If an API request omits `connectivity_type`, the VPC is created as `public`:
attached VMs keep their own public interface and also receive a private VPC
interface. The portal does not offer this mode.

NAT gateway controls (the gateway card and **Add Port Forwarding**) appear only
on VPCs created with **Managed NAT Gateway**.

## VPC detail page

Click a VPC in the list to open it. The page has four tabs — **Overview**,
**Subnets**, **Attached Nodes**, and **Reserved VIPs** — and an **Actions** menu
with **Attach Node**, **Add Subnet**, **Add Port Forwarding** (NAT VPCs only),
**Refresh**, and **Delete VPC**.

**Overview** shows the VPC details (name, location, private CIDR, connectivity,
creation time, VPC ID, and description). On a NAT VPC it also shows the NAT
gateway and its port forwarding rules.

## Subnets

### Add a subnet

1. Click **Actions → Add Subnet** (or **Add Subnet** on the **Subnets** tab).
2. Enter a **Name** and a **CIDR**. The CIDR must be a sub-range of the VPC
   range that does not overlap another subnet.
3. Click **Create Subnet**.

### Delete a subnet

On the **Subnets** tab, click the delete icon on the subnet row. Detach any
nodes that use the subnet first.

### Private IP ledger

The **Subnets** tab also lists every reserved and allocated address in the VPC
with its subnet, record type, owner, and status. Network and broadcast
addresses are reserved implicitly by each subnet.

## Attach a VM

### Open Attach Node

Click **Actions → Attach Node** (or **Attach Node** on the **Attached Nodes**
tab).

### Choose the node and subnet

Select a **Node** — only VMs in the VPC's location that are not already attached
are listed — and a **Subnet**.

### Choose the private IP

Under **Private IP assignment**, choose:

* **Automatic** — the next free address in the subnet is claimed for the VM.
* **Specific address** — enter an unused host address inside the subnet. The
  network, broadcast, and gateway addresses are rejected.

### Choose traffic routing (NAT VPCs)

On a NAT VPC, if the VM already has a network connection, choose:

* **Use VPC for internet** — internet and private traffic go through the VPC and
  its NAT gateway. The VM's current public IP stays connected until you remove
  it from the VM's networking settings.
* **Private traffic only** — the VM keeps its current internet connection and
  uses the VPC only for private traffic.

A VM with no other network connection uses the VPC as its primary network. If
the VM already has a network connection and the VPC is **Private only**, the VPC
carries private traffic only.

### Attach

Click **Attach Node**. The dialog follows the attachment status until it
completes.

The **Attached Nodes** tab lists each VM with its status, VPC address, subnet,
and access type (**Private**, **NAT**, or **Public IP**).

### Detach a VM

On the **Attached Nodes** tab, click the detach icon on the VM's row, then
confirm **Detach VM** in the **Detach VPC Interface** dialog. You can attach the
VM again later.

> **Warning**
>
> A VPC interface that is the VM's only network path cannot be detached. Give the
> VM another network path first (for example, attach it to another VPC and use
> that VPC for internet), then detach this one.

## NAT gateway

A **Managed NAT Gateway** VPC starts with one NAT gateway. The **Overview** tab
shows the gateway's status and public IP, and whether that IP is a
platform-assigned NAT IP or one of your Reserved IPs.

### Use a Reserved IP

To give the gateway a stable address you control, click **Use Reserved IP** (or
**Replace Reserved IP**) on the gateway card, select an unattached Reserved IP in
the same workspace and location, and click **Attach Reserved IP**. Existing port
forwarding rules move to the new address. A previous Reserved IP returns to your
Reserved IP pool; a platform-assigned address is released.

### Delete the NAT gateway

Click **Delete NAT Gateway** on the gateway card. The dialog shows the impact:

* VMs routed through the gateway lose outbound internet access. Private VPC
  connectivity remains.
* All port forwarding rules on the gateway are permanently deleted.
* NAT gateway billing stops after deletion.

Choose what happens to the gateway's public IP:

| Choice                   | Result                                                                                                    |
| ------------------------ | --------------------------------------------------------------------------------------------------------- |
| **Reserve this NAT IP**  | Keep the platform-assigned address as a Reserved IP (billed as a Reserved IP; the dialog shows the price) |
| **Keep in Reserved IPs** | Shown when the gateway uses one of your Reserved IPs — it is detached and stays reserved                  |
| **Release this IP**      | Return the address to the platform pool. You may not get it back.                                         |

If VMs or rules are affected, tick the confirmation checkbox, then confirm.

### Create a NAT gateway again

After a NAT gateway is deleted, the **Overview** tab shows **Create NAT Gateway**
(when VMs are attached, the **Attached Nodes** tab also offers **Add Managed
NAT**). Choose a
**Public IP** — **Automatic NAT IP** (assigned and released with the gateway) or
one of your unattached Reserved IPs — and click **Create NAT Gateway**. Attached
VMs use the new gateway without changing their VPC interfaces or private IPs.
Deleted port forwarding rules are not restored.

## NAT port forwarding

Port forwarding routes a public port on the NAT gateway to a private service.

### Open the rule form

Click **Actions → Add Port Forwarding**, or **Add Rule** in the **NAT Port
Forwarding** section of the **Overview** tab.

### Fill in the rule

| Field                             | Description                                                                                                                                                             |
| --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
| **Rule name**                     | e.g. `SSH access`                                                                                                                                                       |
| **Protocol**                      | **TCP** or **UDP**                                                                                                                                                      |
| **External port**                 | Public port on the NAT gateway, `1`–`65535`. Each protocol and external port can be used by only one rule.                                                              |
| **Destination type**              | **Private VM** — one NAT-connected VM address, or **MetalLB VIP** — a [Virtual IP](/docs/network-security/vpc-and-ip-management/virtual-ips) announced by cluster nodes |
| **Internal IP** / **MetalLB VIP** | The attached VM or reserved VIP to forward to                                                                                                                           |
| **Internal port**                 | Port on the destination, `1`–`65535`                                                                                                                                    |
| **Note**                          | Optional reason for the inbound access                                                                                                                                  |
| **Enable this rule**              | The public endpoint accepts traffic once the rule is active                                                                                                             |

The form previews the traffic path, for example
`203.0.113.10:2222 → 10.10.0.5:22`.

### Save

Click **Add Rule**.

Each rule row has **Edit**, **Enable**/**Disable**, and **Delete** actions. When
editing, click **Save Changes** to apply.

## Use the API

First call `GET /networking/sites?workspace_id=607005` and copy the exact
`site_id` from an entry where `available` is `true`. A site ID is an opaque
identifier, not a region name.

```bash
curl -X POST \
  "https://api.ibee.ai/v1/networking/vpcs?workspace_id=607005" \
  -H "Authorization: Bearer $IBEE_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{
    "name": "production",
    "site_id": "68b99bd78a8eda32ff3f16ea",
    "auto_cidr": true,
    "create_default_subnet": true,
    "connectivity_type": "nat_gateway"
  }'
```

## Delete a VPC

Before you delete a VPC:

1. Detach every VM on the **Attached Nodes** tab.
2. Delete the NAT gateway, if the VPC has one.
3. Delete every Virtual IP reservation on the **Reserved VIPs** tab.

Subnets are removed automatically with the VPC. Then click **Actions → Delete
VPC** and confirm. You can also delete a VPC from the VPC list; its dialog
checks dependencies and offers to delete the NAT gateway first. The API returns
`409 Conflict` while dependencies remain.

## Related pages

* [Networking for VMs](/docs/infrastructure/cloud-vms/networking-for-vms)
* [Reserved IPs](/docs/network-security/vpc-and-ip-management/reserved-ips)
* [Virtual IPs](/docs/network-security/vpc-and-ip-management/virtual-ips)
* [Firewalls](/docs/network-security/firewalls)
* [API reference](/docs/api-reference)