Skip to content

Software-defined networking

By default a machine attaches to a bridge on the node it runs on, and its network is whatever that bridge is connected to. Datacenter → SDN lets you define networks centrally instead, and have machines attach to those.

This is worth doing when you want networks that follow machines across nodes, isolated networks per team or customer, or address management handled for you.

If you only need machines on the same network as the node, you do not need any of this — see Node network configuration.

Object What it is
Zone A networking technology, and the nodes it applies to
VNet A virtual network inside a zone. Machines attach to this.
Subnet The address range and gateway on a VNet
IPAM Hands out addresses from those subnets

A cluster that has never used SDN still shows one zone per node, named localnetwork — that is the node’s existing bridge presented as a zone. The Zones panel itself starts empty, because that default zone is not something you configured:

The Zones panel before any zone has been created

Zones, VNets and the routing objects have a State column. Changes are held until applied, which lets you build a complete design and commit it once.

Check State before assuming a change is live.

Type What it does Use it when
Simple An isolated network on each node, with optional routing and NAT You want a private network for a group of machines, with no switch configuration
VLAN Each VNet is a VLAN on an existing bridge Your switches already carry VLANs. The most common choice.
QinQ VLANs stacked inside a VLAN You give each tenant their own VLAN space inside one provider VLAN
VXLAN A layer-2 network stretched across nodes over a routed network Nodes are on different networks and machines must share one
EVPN VXLAN with a routing control plane and an exit point to the outside Multi-tenant routing at scale
  1. Open Datacenter → SDN → Zones.
  2. Click Add and choose the type.
  3. Give it an ID.
  4. Set Nodes to the nodes it applies to, or leave empty for all.
  5. Fill in the type-specific fields — a VLAN zone needs the bridge its VLANs live on.
  6. Click Add.
  1. Open Datacenter → SDN → VNets.
  2. Click Create.
  3. Give it an ID and select the Zone.
  4. For a VLAN or VXLAN zone, set Tag to the VLAN or network identifier.
  5. Tick VLAN Aware if machines on it will carry their own tags.
  6. Click Create.

Select the VNet, then click Create in the Subnets panel. Enter the address range in Subnet and set its Gateway. Turn on SNAT if machines on this network need outbound access through the node.

Open Datacenter → SDN, click Apply and confirm the question that appears. Apply also applies any node network changes that are waiting, and the confirmation says so. Then return to Zones or VNets and confirm State shows the change as live.

Edit the machine’s network adapter under guest → Hardware. The VNet appears in the bridge list; select it instead of a plain bridge.

Datacenter → SDN → IPAM shows which address each machine holds on each network, with its MAC address and gateway. Addresses are allocated from the subnets you defined.

This is mostly a view rather than a place you configure things — it answers “what address does this machine have” without opening its console.

SDN → Options is where additional address-management or DNS backends are registered, if you integrate with an external system. The built-in one needs no configuration.

Datacenter → SDN → VNet Firewall attaches rules to the network itself, so the policy applies to everything on it regardless of which machine. Rules work exactly as described in Firewall.

This is the cleanest way to express “machines on this network may not talk to that network”.

Fabrics, Route Maps and Prefix Lists support VXLAN and EVPN designs: the fabric defines the routed network between nodes, and route maps and prefix lists control which routes are accepted and advertised.

What you see What to do
A VNet is not offered on a machine’s network adapter The zone excludes that node, or the change was never applied. Check Nodes and State.
Machines on a VNet cannot reach each other For a VLAN zone, confirm the switch carries that VLAN to every node involved.
No outbound access from a Simple zone The subnet needs a gateway, and SNAT turned on.
Machines have no address No subnet is defined, or the machine is set to a static address outside it.
A change did nothing It is still pending. Apply it and check State.

Still stuck? Contact VM2Cloud support.