VorticPanel

Administration

IP pools

An IP pool is a range of addresses handed to servers on its nodes. Manage them under Network → IP pools (needs the “Manage IP pools” permission).

IPv4 and IPv6 pools are added the same way, with New pool: type an IPv4 range or an IPv6 prefix and the panel works out which it is. The page lists them in an IPv4 and an IPv6 section; an empty section has an Add an IPv6 pool (or IPv4) button. A server gets IPv6 when its package has IPv6 on and its node has an IPv6 pool attached.

Fields

Field Rules
Name Lowercase, 2–32 characters
Network IPv4 from /20 to /29, or IPv6 from /32 to /56 so each server can get a /64. Aligned to its boundary. Servers get its netmask and gateway, even when the pool only hands out some of its addresses.
Addresses to hand out IPv4 only. The whole network, or Only some addresses: one per line or separated by commas, as single addresses or ranges, e.g. 69.162.79.196-198 (short for 69.162.79.196-69.162.79.198) and 69.162.79.205. Use it when your provider routed a few addresses out of a bigger network to you.
Gateway Inside the range. For IPv4, not the network or broadcast address.
Region Its nodes must be in this region
Nodes The nodes that assign from it, and where the subnet is routed: servers with its addresses only move to these nodes
Assignment Automatic, or Manual only for addresses you hand out by hand

After creating a pool, its name, nodes, assignment and addresses can change. On the pool’s page, Addresses → Edit adds addresses as you get more (or goes back to the whole network); an address a server uses, or that’s reserved, has to stay in.

Pools can share a network as long as each lists its own addresses, e.g. one pool per node from the same /24. Two pools can never hand out the same address.

How addresses are handed out

  • IPv4: each new server gets the first free address in an automatic IPv4 pool attached to its node, skipping the gateway and reserved addresses.
  • IPv6: when the package includes IPv6, the server gets the next unused /64 from an IPv6 pool attached to its node.
  • Staff with the IP pools permission are notified when a pool passes 90% used.

An IPv4 pool’s size is the addresses it hands out: its listed addresses, or the whole network without the network, broadcast and gateway addresses.

Addresses on a node itself

Server addresses must not also be on the node. Providers often put every IP they give you on the host when they set it up (in /etc/netplan/*.yaml). The node then answers for those addresses on the network, so a server given one gets no traffic, and Windows refuses it as a duplicate: ipconfig shows a 169.254 address and the gateway, and nothing else.

Each node’s agent reports the addresses on its own interfaces. If any is in an IP pool, the panel:

  • shows a red warning on the node’s page, on the pool’s page, on the IP pools list and under Needs attention on the Overview, naming any server already given one
  • doesn’t hand that address out to new servers, moves or floating IPs while the node has it

To fix it, keep only the node’s own address in its netplan file and run netplan apply. To take one off straight away, run ip addr del 203.0.113.42/24 dev br-public with your address and bridge. The warning clears within a minute. A Windows server that was refused its address takes it after a reboot, or after its network adapter is turned off and on again.

Reservations

On a pool’s page, reserve any address that mustn’t be handed out: the nodes themselves, the controller, routers, anything else on that network. A reservation needs a note (up to 120 characters). Only free IPv4 addresses can be reserved.

Deleting a pool

Delete pool, at the bottom of a pool’s settings, works once nothing has an address from it: no server, GPU instance or customer floating IP, and no unfinished import that puts servers in it. Until then the button is greyed out, or the panel names what’s still using it. Change those servers’ addresses, delete them or move them to another pool first.

Its reservations and the reverse DNS staff set on its spare addresses go with it. Servers using other pools aren’t affected, and you can add the same range again later as a new pool. Over the API it’s DELETE /admin/ip-pools/{id} (see Endpoints), with the network:write permission.

Floating IPs

Customers reserve floating IPv4 addresses on their Networks page and point each at any of their servers in that location. Moving one takes about a second, and reverse DNS follows it.

  • They come from an automatic IPv4 pool attached to a node in a public group in that location, taken from the top of the range.
  • Each is held as a reservation in its pool, noted “Floating IP · customer email”, so normal allocation never hands it out.
  • How many an account can keep is a customer limit (3 by default), and the feature can be switched off.
  • floating_ip.created and floating_ip.released webhooks let billing charge for them.

Adding addresses to a server

A server’s Network tab lists its addresses with their pool, gateway and reverse DNS, then reverse DNS for each, its network card (MAC address, setting the addresses again, and whether it may send from other addresses) and its private networks. The Overview shows a short list with a link here. Add addresses opens the choices above the list:

  • IPv4, next free: 1 to 8 addresses from a pool you pick, or from any automatic pool of the server’s node.
  • IPv4, a specific address: type the address, or pick one of a pool’s free ones (the list narrows as you type). This also works for manual pools, and for a reserved address, whose reservation goes.
  • IPv6: another /64 from the node’s IPv6 pool, up to 4 per server.

A server has up to 16 IPv4 addresses. Only pools attached to the server’s node are offered: other pools’ addresses wouldn’t reach it. Make primary on an IPv4 address makes it the one shown everywhere, the one the server sends from, and its pool’s gateway the server’s default route. Any address but the primary IPv4 can be removed.

Every change is a job (it shows on the server and under Jobs, with its log). The node lets new addresses through and stops removed ones straight away, and the server’s guest agent sets the full list inside it:

  • Linux: the addresses are saved where the system keeps its network settings: netplan (/etc/netplan/50-panel-public.yaml), NetworkManager, ifupdown (/etc/network/interfaces.d/50-panel-public) or systemd-networkd (/etc/systemd/network/50-panel-public.network). Settings for the card that cloud-init wrote on the first boot are moved to a panel-disabled folder next to them, not deleted. If netplan refuses the new settings, the old ones are put back.
  • Windows: the network card is set up from scratch with the full list.

A server that’s off, or whose guest agent doesn’t answer, picks the change up once it’s running and the agent answers. Customers can only add the next free IPv4 address, when their package or reseller allows it.

Firewall policies

Firewall in the admin sidebar holds your own rules for customers’ servers: blocking outbound mail, closing ports nobody should expose, cutting off a bad network. The node enforces them in front of each server’s own firewall, whether or not the customer has turned theirs on.

  • Rules go incoming (matched by who sends it) or outgoing (matched by where it goes), with a protocol, ports and addresses, checked top to bottom. Add common has outbound mail (SMTP 25), Windows file sharing, outbound IRC and open DNS resolvers.
  • Apply to new servers by default gives the policy to every new server as it’s created, or only to those on some packages or in some locations. It applies to servers created after you turn it on.
  • Apply to… and Take off… give or take the policy at will: chosen servers, every server on a node, in a location or on a package, or all of them. A server’s Firewall tab can also apply or take off a single policy.
  • Customers can turn it off: customers always see your policies on their Firewall tab, read-only. Locked ones only staff can take off; optional ones the customer can turn off for their server. Lock rules like outbound mail and take them off for the servers that ask, such as a real mail server.
  • Changing a policy re-applies it on every server that has it; deleting one takes it off them all. It needs the Manage IP pools permission (network:write).

The demo comes with outbound mail blocked on every server except its mail servers.

Every word has to appear. ↑ ↓ to move, Enter to open.