> For clean Markdown of any page, append .md to the page URL. > For a complete documentation index, see https://docs.ibee.co.in/docs/network-security/vpc-ip-management/llms.txt. > For AI client integration (Claude Code, Cursor, etc.), connect to the MCP server at https://docs.ibee.co.in/_mcp/server. # VPC > Create isolated private networks, subnets, NAT gateways, port forwarding rules, and VM attachments on IBEE Solutions. A VPC (Virtual Private Cloud) is an isolated Layer 3 network for resources in one workspace. Resources in the same VPC communicate over private IPs without traversing the public internet. A VPC belongs to one location, and only VMs in that location can attach to it. ## Create a VPC ### Open VPCs In the portal sidebar, click **VPC** under **Network & Security**, then click **Create VPC**. ### Enter the VPC details Enter a **Name** (e.g. `production-vpc`), choose a **Location**, and optionally add a **Description**. ### Choose connectivity | Option | Behavior | | ---------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Private only** *(default)* | VMs receive private addresses only. To expose one specific VM, attach a [Reserved IP](/docs/network-security/vpc-and-ip-management/reserved-ips) to it later. | | **Managed NAT Gateway** | Private VMs share one public IPv4 address for outbound internet. Unsolicited inbound traffic is not accepted unless you add a [port forwarding rule](#nat-port-forwarding). | The VPC network and its default subnet are included at no extra charge. A managed NAT gateway is billed while it exists; the summary panel shows its price for the selected location before you create the VPC. Firewall rules still control access to each VM. ### Choose the private IP range * **Automatic** *(default)* picks a conflict-free RFC1918 range. * **Custom CIDR** — enter a **Network address** (e.g. `10.10.0.0`) and pick a **Network size** from `/22` to `/28` (default `/24`). The range must be RFC1918 space (`10.0.0.0/8`, `172.16.0.0/12`, or `192.168.0.0/16`) and aligned to the chosen size. If the address is not aligned, the form suggests the nearest valid network address. VPC ranges in the same account cannot overlap. ### Create Click **Create VPC Network**. IBEE creates the VPC with a default subnet (and, for **Managed NAT Gateway**, the NAT gateway). The VPC is usable when its status is `available`. ## Connectivity modes | Portal option | API `connectivity_type` | Use it for | | ----------------------- | ----------------------- | ------------------------------------------------------------ | | **Private only** | `private` | Private networking; expose individual VMs with a Reserved IP | | **Managed NAT Gateway** | `nat_gateway` | Private VMs that share managed outbound internet access | If an API request omits `connectivity_type`, the VPC is created as `public`: attached VMs keep their own public interface and also receive a private VPC interface. The portal does not offer this mode. NAT gateway controls (the gateway card and **Add Port Forwarding**) appear only on VPCs created with **Managed NAT Gateway**. ## VPC detail page Click a VPC in the list to open it. The page has four tabs — **Overview**, **Subnets**, **Attached Nodes**, and **Reserved VIPs** — and an **Actions** menu with **Attach Node**, **Add Subnet**, **Add Port Forwarding** (NAT VPCs only), **Refresh**, and **Delete VPC**. **Overview** shows the VPC details (name, location, private CIDR, connectivity, creation time, VPC ID, and description). On a NAT VPC it also shows the NAT gateway and its port forwarding rules. ## Subnets ### Add a subnet 1. Click **Actions → Add Subnet** (or **Add Subnet** on the **Subnets** tab). 2. Enter a **Name** and a **CIDR**. The CIDR must be a sub-range of the VPC range that does not overlap another subnet. 3. Click **Create Subnet**. ### Delete a subnet On the **Subnets** tab, click the delete icon on the subnet row. Detach any nodes that use the subnet first. ### Private IP ledger The **Subnets** tab also lists every reserved and allocated address in the VPC with its subnet, record type, owner, and status. Network and broadcast addresses are reserved implicitly by each subnet. ## Attach a VM ### Open Attach Node Click **Actions → Attach Node** (or **Attach Node** on the **Attached Nodes** tab). ### Choose the node and subnet Select a **Node** — only VMs in the VPC's location that are not already attached are listed — and a **Subnet**. ### Choose the private IP Under **Private IP assignment**, choose: * **Automatic** — the next free address in the subnet is claimed for the VM. * **Specific address** — enter an unused host address inside the subnet. The network, broadcast, and gateway addresses are rejected. ### Choose traffic routing (NAT VPCs) On a NAT VPC, if the VM already has a network connection, choose: * **Use VPC for internet** — internet and private traffic go through the VPC and its NAT gateway. The VM's current public IP stays connected until you remove it from the VM's networking settings. * **Private traffic only** — the VM keeps its current internet connection and uses the VPC only for private traffic. A VM with no other network connection uses the VPC as its primary network. If the VM already has a network connection and the VPC is **Private only**, the VPC carries private traffic only. ### Attach Click **Attach Node**. The dialog follows the attachment status until it completes. The **Attached Nodes** tab lists each VM with its status, VPC address, subnet, and access type (**Private**, **NAT**, or **Public IP**). ### Detach a VM On the **Attached Nodes** tab, click the detach icon on the VM's row, then confirm **Detach VM** in the **Detach VPC Interface** dialog. You can attach the VM again later. > **Warning** > > A VPC interface that is the VM's only network path cannot be detached. Give the > VM another network path first (for example, attach it to another VPC and use > that VPC for internet), then detach this one. ## NAT gateway A **Managed NAT Gateway** VPC starts with one NAT gateway. The **Overview** tab shows the gateway's status and public IP, and whether that IP is a platform-assigned NAT IP or one of your Reserved IPs. ### Use a Reserved IP To give the gateway a stable address you control, click **Use Reserved IP** (or **Replace Reserved IP**) on the gateway card, select an unattached Reserved IP in the same workspace and location, and click **Attach Reserved IP**. Existing port forwarding rules move to the new address. A previous Reserved IP returns to your Reserved IP pool; a platform-assigned address is released. ### Delete the NAT gateway Click **Delete NAT Gateway** on the gateway card. The dialog shows the impact: * VMs routed through the gateway lose outbound internet access. Private VPC connectivity remains. * All port forwarding rules on the gateway are permanently deleted. * NAT gateway billing stops after deletion. Choose what happens to the gateway's public IP: | Choice | Result | | ------------------------ | --------------------------------------------------------------------------------------------------------- | | **Reserve this NAT IP** | Keep the platform-assigned address as a Reserved IP (billed as a Reserved IP; the dialog shows the price) | | **Keep in Reserved IPs** | Shown when the gateway uses one of your Reserved IPs — it is detached and stays reserved | | **Release this IP** | Return the address to the platform pool. You may not get it back. | If VMs or rules are affected, tick the confirmation checkbox, then confirm. ### Create a NAT gateway again After a NAT gateway is deleted, the **Overview** tab shows **Create NAT Gateway** (when VMs are attached, the **Attached Nodes** tab also offers **Add Managed NAT**). Choose a **Public IP** — **Automatic NAT IP** (assigned and released with the gateway) or one of your unattached Reserved IPs — and click **Create NAT Gateway**. Attached VMs use the new gateway without changing their VPC interfaces or private IPs. Deleted port forwarding rules are not restored. ## NAT port forwarding Port forwarding routes a public port on the NAT gateway to a private service. ### Open the rule form Click **Actions → Add Port Forwarding**, or **Add Rule** in the **NAT Port Forwarding** section of the **Overview** tab. ### Fill in the rule | Field | Description | | --------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | **Rule name** | e.g. `SSH access` | | **Protocol** | **TCP** or **UDP** | | **External port** | Public port on the NAT gateway, `1`–`65535`. Each protocol and external port can be used by only one rule. | | **Destination type** | **Private VM** — one NAT-connected VM address, or **MetalLB VIP** — a [Virtual IP](/docs/network-security/vpc-and-ip-management/virtual-ips) announced by cluster nodes | | **Internal IP** / **MetalLB VIP** | The attached VM or reserved VIP to forward to | | **Internal port** | Port on the destination, `1`–`65535` | | **Note** | Optional reason for the inbound access | | **Enable this rule** | The public endpoint accepts traffic once the rule is active | The form previews the traffic path, for example `203.0.113.10:2222 → 10.10.0.5:22`. ### Save Click **Add Rule**. Each rule row has **Edit**, **Enable**/**Disable**, and **Delete** actions. When editing, click **Save Changes** to apply. ## Use the API First call `GET /networking/sites?workspace_id=607005` and copy the exact `site_id` from an entry where `available` is `true`. A site ID is an opaque identifier, not a region name. ```bash curl -X POST \ "https://api.ibee.ai/v1/networking/vpcs?workspace_id=607005" \ -H "Authorization: Bearer $IBEE_TOKEN" \ -H "Content-Type: application/json" \ -d '{ "name": "production", "site_id": "68b99bd78a8eda32ff3f16ea", "auto_cidr": true, "create_default_subnet": true, "connectivity_type": "nat_gateway" }' ``` ## Delete a VPC Before you delete a VPC: 1. Detach every VM on the **Attached Nodes** tab. 2. Delete the NAT gateway, if the VPC has one. 3. Delete every Virtual IP reservation on the **Reserved VIPs** tab. Subnets are removed automatically with the VPC. Then click **Actions → Delete VPC** and confirm. You can also delete a VPC from the VPC list; its dialog checks dependencies and offers to delete the NAT gateway first. The API returns `409 Conflict` while dependencies remain. ## Related pages * [Networking for VMs](/docs/infrastructure/cloud-vms/networking-for-vms) * [Reserved IPs](/docs/network-security/vpc-and-ip-management/reserved-ips) * [Virtual IPs](/docs/network-security/vpc-and-ip-management/virtual-ips) * [Firewalls](/docs/network-security/firewalls) * [API reference](/docs/api-reference) > Create isolated private networks, subnets, NAT gateways, port forwarding rules, and VM attachments on IBEE Solutions. ## Docs - [Reserved IPs](https://docs.ibee.co.in/docs/network-security/vpc-ip-management/reserved-ips.md): Reserve portable public IPv4 addresses and attach them to VMs, NAT gateways, and Virtual IPs. - [Virtual IPs](https://docs.ibee.co.in/docs/network-security/vpc-ip-management/virtual-ips.md): Reserve a specific private IP inside a VPC subnet for MetalLB and Kubernetes LoadBalancer services, announced by nodes you authorize.