Skip to content

Subnets and IP addresses

A subnet is a block of IP addresses with a gateway, netmask, and networking mode. Every IP handed to an instance comes from a subnet, so subnets are one of the first things you add after connecting a hypervisor.

  • At least one hypervisor connected. See Add a hypervisor.
  • Host-side networking prepared for the mode you plan to use. See Networking modes.
  • Optional: an rDNS zone if you want automatic PTR records. See Reverse DNS.

In the admin panel go to Networking > Subnets. The list shows every subnet with its netmask, gateway, usage, mode, type, protocol, and status.

Subnets list

  1. Click Add subnet. The Add Subnet dialog opens.

    Add Subnet dialog

  2. Fill in the fields:

Fields

Field What to enter
Name A label you will recognise in lists, for example ipv4-pool-1.
Protocol IPv4 or IPv6. IPv6 is not available for private subnets.
Netmask IPv4: a dotted netmask such as 255.255.255.0. IPv6: the routed prefix length (the label changes to Netmask (Routed IPv6 Prefix)).
Gateway The gateway address from your network provider, for example 203.0.113.1.
DNS Resolver 1 / DNS Resolver 2 The resolvers handed to instances. The Google, OpenDNS, Cloudflare, and Quad9 buttons fill both fields for the selected protocol.
Networking Mode Bridged, NAT, or Routed. See Networking modes.
Type Public or Private.
Interface The host interface NAT traffic egresses through. Shown only for NAT mode.
Bridge The bridge on the hypervisor, for example br0. Shown only for Bridged and Routed modes.
Hypervisors One or more hypervisors that can deploy into this subnet.
  1. Click Add Subnet.

The panel opens the subnet’s detail page, where you edit the subnet and generate its IPs.

Private networking lets instances talk over internal addresses without touching the public internet. It uses ordinary subnets with Type set to Private and an RFC1918 range (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), plus a secondary interface on each instance.

  1. Create a subnet as above, with Type set to Private.
  2. In Hypervisors, select every hypervisor whose instances should share the network. If a VLAN connects your hypervisors on the private network, select all of them. Otherwise select only one.
  3. Generate the address range (next section).

Customers then add a secondary interface on their instance, and the panel assigns an IP from this pool. For a fully isolated network with its own subnets, NAT, and VPN, use VPCs instead. See VPCs.

IPs are generated from the subnet’s own page, not from the IP addresses list (which has its own smaller add shortcut, see below).

  1. Open the subnet (click its row on Networking > Subnets). The Generate IPs card sits in the right column, showing existing totals (free/used).

    Subnet detail page with Generate IPs card

  2. Pick an IP Type. The choices depend on the subnet’s protocol:

IP Types

Protocol IP Type Fields
IPv4 Individual Repeatable IP / MAC (optional) rows. Click Add another IP for more rows.
IPv4 Range Start IP and End IP. The panel fills in every address between them and shows the resulting count.
IPv6 IPv6 Count of single addresses to mint.
IPv6 IPv6 Subnets Generate Netmask (48, 64, 80, 96, or 112) and Count. Each subnet can be handed to one instance.
  1. Click Generate N IPs (the button’s label updates live with the count you are about to create).

Set a MAC on individual IPs when your upstream provider locks IPs to MAC addresses, as Hetzner does.

In the admin panel go to Networking > IP addresses. This page lists every IP across all subnets, and also lets you add individual IPs or a range directly, alongside the subnet page’s bulk generator.

Filter with the All / Assigned / Free pills, search by IP, instance, or rDNS, or add a Subnet, Instance, or Reserved filter.

IP addresses list

Column Meaning
Address The address. IPv6 subnets render as ip/mask.
Type IPv4 or IPv6.
Subnet The gateway of the subnet the IP belongs to.
Instance The instance currently using the IP.
Reverse DNS Click the edit icon to set a PTR hostname, for example vm-12.example.com.
State free, used, or reserved.
MAC Click the edit icon to set the MAC for provider-locked IPs.
Reserved Toggle to reserve the IP so instances do not claim it.
Comments A free-text note, click the edit icon to set it.

Click Add IP. Pick Single IP or Range, a Subnet, and either an Address or a Range start / Range end. This is a shortcut for adding to an existing subnet without opening its own page; the subnet’s Generate IPs card (above) is still the place for IPv6 subnets and MAC-tagged individual IPv4s.

To remove an unassigned IP, open its row’s actions menu and click Remove.

Open the subnet, change what you need, then click Update Subnet. Protocol and Mode cannot change after creation. The editable cards are:

  • General: name, netmask, gateway.
  • DNS: the two resolvers, with the same provider shortcut buttons.
  • Networking: Interface (NAT mode) or Bridge (bridged and routed modes).
  • Assignment: Hypervisors, RDNS Zone (the reverse zone that receives PTR records for this subnet), and Auto-rDNS (on deploy, set the primary public IP’s PTR to the instance hostname; needs an enabled rDNS zone and a base domain). See Reverse DNS.
  • Settings: the Enabled toggle.

Generated IPs show as free in Networking > IP addresses. The available counts shown for a subnet and a hypervisor use one rule: an address is available when it is free, not reserved, not held by a NAT gateway and not part of a running migration. When a customer deploys an instance, the panel claims free IPs from the subnets attached to the chosen hypervisor. With Auto-rDNS on, the PTR record is written at deploy time.

  • Instances on two hypervisors cannot talk over a private subnet. The subnet must be attached to both hypervisors, and a VLAN must connect them on the private network.
  • A new interface gets no IP. The generated pool is exhausted. Generate more IPs on the subnet page.
  • Instances with extra IPs have no connectivity on a MAC-locked provider. Set the MAC on each IP, either in the generator or on the IP Addresses page.
  • Ping works but real traffic fails. A security group with ingress rules drops anything not explicitly allowed. Check the attached groups. See Security groups.