Skip to main content

General information about cloud platform networks

Cloud platform networks run on OpenStack Neutron. For details, see the Neutron section of OpenStack documentation.

You can manage cloud platform networks in the Control panel, using the OpenStack CLI, or with Terraform.

Cloud platform networks support user types and roles.

You can track cloud platform network metrics using the Metrics service.

Records of operations on cloud platform networks are saved in audit logs.

Tasks

In the cloud platform, you can use network resources to:

  • configure connectivity between devices in the same pool and connect devices into private subnets using ports: cloud servers, load balancers, file storages, Managed Kubernetes clusters, and Cloud Databases clusters;
  • route traffic between private subnets and configure internet access for devices in a private subnet using cloud routers;
  • attach public floating IP addresses to devices in private subnets to set up access to them from the internet;
  • attach direct public IP addresses to cloud servers for access to and from the internet;
  • connect devices to public subnets for access to and from the internet. You can connect cloud servers, load balancers, and Cloud Databases clusters to public subnets using ports;
  • distribute incoming network traffic across cloud servers using load balancers;
  • to set up network connectivity between devices in different pools (including different projects and accounts) or between different services, private subnets can be connected to a global router;
  • configure static routes for subnets.

To restrict traffic, you can use:

  • cloud firewalls — assigned to a cloud router port, allow filtering traffic for private subnets and public IP addresses;
  • security groups — assigned to a cloud server port, allow filtering all port traffic;
  • allowed address pairs — configured on a cloud server port, except ports with a direct public IP address, and allow outgoing port traffic only from specific IP/MAC address pairs.

To use security groups and allowed address pairs, the network must have traffic filtering (port security) enabled.

Network examples

Internet access

Cloud servers can be connected to a private network without internet access, and various internet access options can be configured using routers and public IP addresses.

Private network and bastion host

A bastion host is a host in a network that acts as a gateway or proxy for all other servers. This host is available via a public IP address and communicates with other servers over a private network.

Public subnet

All servers in a public subnet have internet access. Servers communicate with each other via public interfaces.

Load balancer and bastion host

You can add a load balancer to a schema with a bastion host. The bastion host is used to access the private network and manage infrastructure, and the load balancer proxies requests.

Bandwidth

Cloud platform network objects have limits on outgoing and incoming traffic bandwidth.

Outgoing trafficPrivate network and bastion host
Private network traffic
Public subnet3 Gbps — in all pools except ru-1

1 Gbps — in the ru-1 pool

10 Gbps — for the 10G Net line
Unlimited *
Internet traffic
St. Petersburg3 Gbps — in all pools except ru-1

1 Gbps — in the ru-1 pool

10 Gbps — for the 10G Net line
Unlimited *
Cloud server port with a direct public IP address3 Gbps — in all pools except ru-1

1 Gbps — in the ru-1 pool

10 Gbps — for the 10G Net line
Unlimited *
Cloud server port in a public subnet3 Gbps — in all pools except ru-1

1 Gbps — in the ru-1 pool
5 Gbps
Cloud server port in a private subnet without a public floating IP address (traffic via the cloud router external IP address)3 Gbps—
Cloud router, total bandwidth for all devices without a public floating IP address behind one router5 Gbps5 Gbps

* Actual bandwidth depends on the device configuration and network conditions.

The list of regions, availability zones, and pools can be viewed in the Selectel infrastructure table.

You can increase the bandwidth for devices in private networks up to 10 Gbps — submit a ticket or create a flavor in the 10G Net line.

Port speed may decrease significantly, for example down to 0.1 Gbps, if the associated IP address is blocked by the Selectel security system. To increase the speed, submit a ticket.

Traffic filtering (port security)

Traffic filtering (port security) is a network feature for protection against unauthorized access and attacks. Filtering allows you to:

You can check the network filtering status in the Control panel: in the top menu, click Products → Cloud Servers → Network → Private networks or Public networks tab. A network with filtering enabled is marked with .

Traffic filtering is enabled by default in all new private networks and public subnets and cannot be disabled. If filtering is enabled in a network, then for each new port in this network:

Filtering is disabled in private networks and public subnets that were created:

  • in the ru-1 pool before June 2, 2025;
  • in the ru-2 pool before June 3, 2025;
  • in the ru-3 pool before June 4, 2025;
  • in the ru-7 pool before June 5, 2025;
  • in the ru-8 pool before May 15, 2025;
  • in the ru-9 pool before May 26, 2025;
  • in the gis-1 pool before May 29, 2025;
  • in the kz-1 pool before May 28, 2025;
  • in the uz-1 pool before May 27, 2025;
  • in the uz-2 pool before May 22, 2025;
  • in the ke-1 pool before May 26, 2025.

Filtering cannot be enabled in these networks. If you need to use security groups, add allowed IP/MAC addresses, or restrict access to the load balancer, create a new private network or public subnet and configure addresses from it on your devices.

Blocked ports

In Selectel, some TCP/UDP ports are blocked by default, and traffic through them is blocked.

Cost

Public IP addresses and public subnets are billed according to the cloud platform payment model.

You can check the pricing on selectel.ru.

Other network resources are provided free of charge.