Skip to main content

Connect a server in a C-DC to a dedicated server in a different pool

Last update:

You can connect a server in a C-DC and a dedicated server that are in different pools. Connectivity is provided over a private network via a Selectel Global Router.

How it works

A dedicated server in a C-DC connects to the Global Router through a firewall. For this, the firewall behind which the server is located must be connected to private network switches.

A dedicated server in another pool also connects to the Global Router. Dedicated servers, with the exception of some Chipcore Line servers, are connected to private network switches by default.

Connect a server in a C-DC to a dedicated server in a different pool over a private network

  1. Connect the firewall to the private network.
  2. Create a Global Router.
  3. Connect the network and subnet to the router for the dedicated server VLAN outside the C-DC.
  4. Connect the network and subnet to the router for the C-DC.
  5. Configure the firewall in the C-DC.
  6. Configure the dedicated server outside the C-DC.

1. Connect the firewall to the private network

  1. Create a ticket to connect the firewall in the C-DC to the private network. In the ticket, specify:

    • the firewall number in the C-DC; you can view it in the Control panel: in the top menu, click ProductsFirewalls → firewall page;
    • the port number on the firewall for connecting to the private network switch.
  2. Wait for a Selectel employee to confirm that the firewall in the C-DC has been connected to the private network.

2. Create a Global Router

  1. In the Control panel, in the top menu, click Products and select Global Router.
  2. Click Create router. A limit of five global routers is set for each account.
  3. Enter the router name.
  4. Click Create.
  5. If the router was created with the status ERROR or is stuck in one of the statuses, create a ticket.

3. Connect the network and subnet to the router for the dedicated server VLAN outside the C-DC

You can connect a new or existing network to the router if it is not already connected to any of the account's global routers.

  1. In the control panel, on the top menu, click Products and select Global Router.

  2. Go to the router page → Networks tab.

  3. Click Create network.

  4. Enter a network name. It will only be used in the control panel.

  5. Select the Servers and Equipment service.

  6. Select a location for the network.

  7. Select or enter a VLAN.

  8. If you want to create a network up to an internal segment (Q-in-Q), specify its tag—a number from 2 to 4094. If a network already exists for the VLAN, you must specify the Q-in-Q segment of this VLAN.

  9. Enter a subnet name. It will only be used in the control panel.

  10. Enter the CIDR—the IP address and mask of the private subnet. You can enter a new subnet or an existing private server subnet if it has not yet been added to any of the global routers in the account. The subnet must meet the following conditions:

    • belong to the RFC 1918 private address range: 10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16;
    • have a size of at least /29, as three addresses will be occupied by Selectel network equipment;
    • do not overlap with other subnets added to this router—IP addresses must not repeat across subnets on the same router;
    • if a Managed Kubernetes cluster on cloud servers is included in the global router network, the subnet must not overlap with the ranges 10.10.0.0/16, 10.96.0.0/12, 10.250.0.0/16 and 10.251.0.0/24. If a cluster on dedicated servers is included in the network — with ranges 10.10.0.0/16, 10.222.0.0/16, 10.250.0.0/16, 10.251.0.0/24 and 172.250.0.0/14. These subnets are used for Managed Kubernetes internal addressing, and their use may lead to conflicts in the global router network.
  11. Enter the gateway IP or leave the first address from the subnet that is assigned by default. Do not assign this address to your devices to avoid network disruption.

  12. Enter the service IPs or leave the last addresses from the subnet that are assigned by default. Do not assign these addresses to your devices to avoid network disruption.

  13. Click Create network.

  14. Optional: check the network topology on the global router. In the Control panel, in the top menu, click ProductsGlobal Router → router page → Network map.

  15. If you specified a Q-in-Q tag in step 8, you need to enable Q-in-Q technology on the switch port and configure the private network interface that you specified in step 10. Learn more in the Configure Q-in-Q subsection of the Q-in-Q guide.

4. Connect the network and subnet to the router for the C-DC

  1. In the Control panel, in the top menu, click Products and select Global Router.

  2. In the Selectel Global Router section, open the router page → Networks.

  3. Click Create network.

  4. Enter a network name. It will only be used in the Control panel.

  5. Select the Servers and Hardware service.

  6. Select a pool.

  7. Select a VLAN.

  8. If you want to create a network for the internal VLAN segment (Q-in-Q), specify its tag — a number from 2 to 4094.

  9. Enter a subnet name. It will only be used in the Control panel.

  10. Enter a CIDR — the IP address and mask of the private subnet. The subnet must meet the following conditions:

    • belong to the RFC 1918 private address range: 10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16;
    • have a size of at least /29, as three addresses will be occupied by Selectel network equipment;
    • not overlap with other subnets added to this router — there must be no identical IP addresses in the subnets of one router;
    • if a Managed Kubernetes cluster on cloud servers is to be included in the Global Router network, the subnet must not overlap with the ranges 10.10.0.0/16, 10.96.0.0/12, 10.250.0.0/16 and 10.251.0.0/24. If a cluster on dedicated servers is included in the network — with the ranges 10.10.0.0/16, 10.222.0.0/16, 10.250.0.0/16, 10.251.0.0/24 and 172.250.0.0/14. These subnets are used for internal Managed Kubernetes addressing, and using them may lead to conflicts in the Global Router network.
  11. Enter the gateway IP or leave the first address of the subnet, which is assigned by default. Do not assign this address to your devices, so as not to disrupt network operation.

  12. Enter service IPs or leave the last addresses of the subnet, which are assigned by default. Do not assign these addresses to your devices, so as not to disrupt network operation.

  13. Click Create network.

  14. Optional: check the network topology on the Global Router. In the Control panel, in the top menu, click ProductsGlobal Router → router page → Network map.

  15. If you specified a Q-in-Q tag in step 8, ensure that you have configured Q-in-Q. When configuring, use the subnet you specified in step 10.

5. Configure the firewall in the C-DC

  1. Connect to FortiGate via the GUI.

  2. Create and configure a private interface with a dedicated subnet:

    2.1. Go to the NetworkInterfaces section.

    2.2. Click Create NewInterface.

    2.3. In the Address field, enter an IP address from the private subnet that you connected to the Global Router for the C-DC, for example 192.168.100.2/28.

  3. Add a static route to the subnet that you connected to the Global Router for the dedicated server VLAN outside the C-DC:

    3.1. Go to the NetworkStatic Routes section.

    3.2. Click Create NewIPv4 Static Route.

    3.3. In the Destination field, enter the destination subnet—the subnet that you connected to the Global Router for the dedicated server VLAN outside the C-DC.

    3.4. In the Gateway Address field, enter the gateway—the IP address that you assigned to the Global Router when connecting the network for the C-DC in step 11.

    3.5. In the Interface field, specify the local interface that you created in step 2.

  4. Configure a security policy that will allow traffic from the dedicated server outside the C-DC to the dedicated server in the C-DC:

    4.1. Go to Policy & ObjectsFirewall Policy.

    4.2. Click Create New.

    4.3. Enter a policy name.

    4.4. In the Incoming Interface field, select the interface for which you configured the IP address in step 2.

    4.5. In the Outgoing Interface field, select the interface to which the dedicated server in the C-DC is connected.

    4.6. In the Source field, enter another IP address from the same private subnet that you configured on the firewall in step 2. This address will be used on the dedicated server outside the C-DC.

    4.7. In the Destination field, enter the IP address of the dedicated server in the C-DC.

    4.8. Click Save.

  5. Configure a security policy that will allow traffic from the dedicated server outside the C-DC to the dedicated server in the C-DC:

    5.1. Go to Policy & ObjectsFirewall Policy.

    5.2. Click Create New.

    5.3. Enter a policy name.

    5.4. In the Incoming Interface field, select the interface to which the dedicated server in the C-DC is connected.

    5.5. In the Outgoing Interface field, select the interface for which you configured the IP address in step 2.

    5.6. In the Source field, enter the IP address of the dedicated server in the C-DC.

    5.7. In the Destination field, enter the IP address that will be used on the dedicated server outside the C-DC.

    5.8. Click Save.

6. Configure the dedicated server outside the C-DC

  1. Assign an IP address from the subnet that you connected to the Global Router for the dedicated server VLAN outside the C-DC to the private network interface. Use the Configure a private network interface section of the Configure a network interface on a server article.

  2. Add a static route on the network interface you configured in step 1. In the route, specify: