General information about cloud platform networks
Cloud platform networks run on OpenStack Neutron. For details, see the Neutron section of OpenStack documentation.
You can manage cloud platform networks in the Control panel, using the OpenStack CLI, or with Terraform.
Cloud platform networks support user types and roles.
You can track cloud platform network metrics using the Metrics service.
Records of operations on cloud platform networks are saved in audit logs.
Tasks
In the cloud platform, you can use network resources to:
- configure connectivity between devices in the same pool and connect devices into private subnets using ports: cloud servers, load balancers, file storages, Managed Kubernetes clusters, and Cloud Databases clusters;
- route traffic between private subnets and configure internet access for devices in a private subnet using cloud routers;
- attach public floating IP addresses to devices in private subnets to set up access to them from the internet;
- attach direct public IP addresses to cloud servers for access to and from the internet;
- connect devices to public subnets for access to and from the internet. You can connect cloud servers, load balancers, and Cloud Databases clusters to public subnets using ports;
- distribute incoming network traffic across cloud servers using load balancers;
- to set up network connectivity between devices in different pools (including different projects and accounts) or between different services, private subnets can be connected to a global router;
- configure static routes for subnets.
To restrict traffic, you can use:
- cloud firewalls — assigned to a cloud router port, allow filtering traffic for private subnets and public IP addresses;
- security groups — assigned to a cloud server port, allow filtering all port traffic;
- allowed address pairs — configured on a cloud server port, except ports with a direct public IP address, and allow outgoing port traffic only from specific IP/MAC address pairs.
To use security groups and allowed address pairs, the network must have traffic filtering (port security) enabled.
Network examples
Internet access
Cloud servers can be connected to a private network without internet access, and various internet access options can be configured using routers and public IP addresses.

Private network and bastion host
A bastion host is a host in a network that acts as a gateway or proxy for all other servers. This host is available via a public IP address and communicates with other servers over a private network.

Public subnet
All servers in a public subnet have internet access. Servers communicate with each other via public interfaces.

Load balancer and bastion host
You can add a load balancer to a schema with a bastion host. The bastion host is used to access the private network and manage infrastructure, and the load balancer proxies requests.

Bandwidth
Cloud platform network objects have limits on outgoing and incoming traffic bandwidth.
Internet access
Moscow
Novosibirsk
Tashkent
Almaty
Nairobi
* Actual bandwidth depends on the device configuration and network conditions.
The list of regions, availability zones, and pools can be viewed in the Selectel infrastructure table.
You can increase the bandwidth for devices in private networks up to 10 Gbps — submit a ticket or create a flavor in the 10G Net line.
Port speed may decrease significantly, for example down to 0.1 Gbps, if the associated IP address is blocked by the Selectel security system. To increase the speed, submit a ticket.
Traffic filtering (port security)
Traffic filtering (port security) is a network feature for protection against unauthorized access and attacks. Filtering allows you to:
- use security groups on cloud server ports;
- add allowed IP/MAC addresses for outbound traffic from cloud server ports;
- restrict access to the load balancer.
You can check the network filtering status in the Control panel: in the top menu, click Products → Cloud Servers → Network → Private networks or Public networks tab. A network with filtering enabled is marked with .
Traffic filtering is enabled by default in all new private networks and public subnets and cannot be disabled. If filtering is enabled in a network, then for each new port in this network:
- the default security group is assigned, which allows all traffic through the port. You can assign another security group;
- one allowed IP/MAC address pair is assigned for outbound port traffic. This blocks MAC/IP spoofing, overlay networks, VPN, and VRRP. If you use solutions based on them, you need to add allowed IP/MAC addresses to the port that can be used to send traffic.
Filtering is disabled in private networks and public subnets that were created:
- in the ru-1 pool before June 2, 2025;
- in the ru-2 pool before June 3, 2025;
- in the ru-3 pool before June 4, 2025;
- in the ru-7 pool before June 5, 2025;
- in the ru-8 pool before May 15, 2025;
- in the ru-9 pool before May 26, 2025;
- in the gis-1 pool before May 29, 2025;
- in the kz-1 pool before May 28, 2025;
- in the uz-1 pool before May 27, 2025;
- in the uz-2 pool before May 22, 2025;
- in the ke-1 pool before May 26, 2025.
Filtering cannot be enabled in these networks. If you need to use security groups, add allowed IP/MAC addresses, or restrict access to the load balancer, create a new private network or public subnet and configure addresses from it on your devices.
Blocked ports
In Selectel, some TCP/UDP ports are blocked by default, and traffic through them is blocked.
Cost
Public IP addresses and public subnets are billed according to the cloud platform payment model.
You can check the pricing on selectel.ru.
Other network resources are provided free of charge.