Setting up a private network for Dedicated Servers or Bare Metal Servers (AlmaLinux 9, AlmaLinux 10, Rocky Linux 9, and Rocky Linux 10)
Please use the “Print” function at the bottom of the page to create a PDF.
Valid for Dedicated Servers and Bare Metal Servers managed in the Cloud Panel.
This article explains how to configure an Ethernet interface on a Dedicated Server or Bare Metal Server running AlmaLinux 9, AlmaLinux 10, Rocky Linux 9, or Rocky Linux 10 as an IEEE 802.1Q VLAN trunk in order to set up a private network. Carry out the steps described below on every server that is assigned to the private network.
With a private network, you can divide your existing network into several logical networks. The servers communicate using local IP addresses that are not routed on the internet.
Using private networks offers you the following advantages:
- You can structure your networks according to organizational criteria.
- You can add or remove your servers easily.
- You can reduce latency and network load.
- You can optimize traffic by prioritizing data packets.
- The servers are isolated from one another. Communication is only possible within the same private network.
Using a private network can be useful in the following cases, for example:
- Setting up a private network for departments or project teams
- Setting up a private network that is connected to a load balancer
- Setting up a private network for a web server and a database server
You can create a private network consisting of Dedicated Servers or Bare Metal Servers by configuring tagged VLANs. VLANs are virtual local area networks, specified in the IEEE 802.1Q standard. With VLANs, you can divide an existing physical network into several logical networks with different subnets. The data traffic is encapsulated so that data from one or more VLANs can be transmitted independently of one another.
With tagged VLANs, there is no fixed assignment between the virtual network and a port. Instead, the assignment is made by tagging the data packets. The data packets are given tags that hold the VLAN ID. Under IEEE 802.1Q, this is done by the respective end device. In this case, these are the servers assigned to the private network. Using the VLAN ID, a switch can identify which VLAN a data packet belongs to. This means that several VLANs can be used through a single switch port.
Caution
- This article assumes a basic knowledge of Linux server administration.
- If you do not configure the server correctly, it may no longer be reachable.
- To use the private network for Dedicated Servers or Bare Metal Servers, you must configure every server assigned to the network.
Requirements
- You have created at least two Dedicated Servers or Bare Metal Servers.
- You have assigned the Dedicated Servers or Bare Metal Servers to a private network.
Determining the VLAN ID
The VLAN ID is required in order to configure the network card. How to determine the VLAN ID:
- Log in to your IONOS account.
Click on Menu > Servers & Cloud in the title bar.
Optional: If you have multiple server contracts, select the desired contract.
- Select the required server in the Infrastructure > Servers section.
- Scroll to the Private Networks entry.
- Make a note of the VLAN ID. Example: VLAN: 3509
Configuring the network interface
To configure the network interface, complete the following steps:
- Log in to the server as root.
Use vi to create the configuration file (keyfile) for the network interface in the /etc/NetworkManager/system-connections directory.
[root@localhost ~]# vi /etc/NetworkManager/system-connections/NAME_OF_THE_PHYSICAL_INTERFACE.VLAN-ID.nmconnection
Example:
[root@localhost ~]# vi /etc/NetworkManager/system-connections/eth0.3509.nmconnection
Note
- The vi editor has an insert mode and a command mode. You can switch to insert mode by pressing the i key. In this mode, the characters you type are inserted into the text immediately. To switch to command mode, press the ESC key. When you use command mode, your keyboard input is interpreted as a command.
- The name of the connection (id and interface-name) must follow the naming convention for VLAN interfaces (physical interface.VLAN ID, for example eth0.3509). The file name must end in .nmconnection.
Insert the required information in the following form:
[connection]
id=NAME_OF_THE_PHYSICAL_INTERFACE.VLAN-ID
type=vlan
interface-name=NAME_OF_THE_PHYSICAL_INTERFACE.VLAN-ID
autoconnect=true
[vlan]
parent=NAME_OF_THE_PHYSICAL_INTERFACE
id=VLAN-ID
flags=1
[ipv4]
method=manual
address1=IP_ADDRESS/PREFIX
[ipv6]
method=disabledExample:
[connection]
id=eth0.3509
type=vlan
interface-name=eth0.3509
autoconnect=true
[vlan]
parent=eth0
id=3509
flags=1
[ipv4]
method=manual
address1=192.168.4.3/24
[ipv6]
method=disabledTo exit vi and save the file, enter the command below and then press Enter:
:wq
Set the file permissions to 600, reload the connection profiles, and activate the network interface for the private network using the following commands:
[root@localhost ~]# chmod 600 /etc/NetworkManager/system-connections/NAME_OF_THE_PHYSICAL_INTERFACE.VLAN-ID.nmconnection
[root@localhost ~]# nmcli connection reload
[root@localhost ~]# nmcli connection up NAME_OF_THE_PHYSICAL_INTERFACE.VLAN-IDExample:
[root@localhost ~]# chmod 600 /etc/NetworkManager/system-connections/eth0.3509.nmconnection
[root@localhost ~]# nmcli connection reload
[root@localhost ~]# nmcli connection up eth0.3509
Note
Alternatively, you can create the connection with a single command. nmcli creates the keyfile automatically in the /etc/NetworkManager/system-connections directory, with the correct permissions:
[root@localhost ~]# nmcli connection add type vlan con-name eth0.3509 dev eth0 id 3509 ip4 192.168.4.3/24 gw4 192.168.4.1
Testing the network configuration
To check whether the network interface for the private network has been configured correctly, send a ping to the IP address of another server assigned to the private network. This requires the target server to have already been configured in the same way (192.168.4.2/24 in this example).
Example:
[root@localhost ~]# ping -c 1 192.168.4.2
PING 192.168.4.2 (192.168.4.2) 56(84) bytes of data.
64 bytes from 192.168.4.2: icmp_seq=1 ttl=64 time=0.478 ms
--- 192.168.4.2 ping statistics ---
1 packets transmitted, 1 received, 0% packet loss, time 0ms
rtt min/avg/max/mdev = 0.478/0.478/0.478/0.000 ms
If the data packets are delivered to the server, the network interface for the private network has been configured. You can also check the connection with the following commands:
[root@localhost ~]# nmcli -f GENERAL,IP4 connection show eth0.3509
[root@localhost ~]# ip -d link show eth0.3509
Troubleshooting
The connection cannot be found
After you enter the command nmcli connection up eth0.3509, an error message is displayed. Example:
Error: unknown connection 'eth0.3509'.
This message usually indicates that the permissions on the keyfile are incorrect. NetworkManager ignores keyfiles whose permissions are not set to 600. Also check that the file name ends in .nmconnection and that the values for parent and interface-name are correct. Set the permissions with chmod 600, reload the connection profiles with nmcli connection reload, and then activate the interface with nmcli connection up eth0.3509.
No 802.1Q VLAN support available in the kernel
If the VLAN interface cannot be activated and the journal (journalctl -u NetworkManager) contains a reference to missing 802.1Q support, the kernel module required to provide VLAN support has not been loaded.
802.1Q VLAN support is not available in the kernel.
To check whether the 802.1Q kernel module is loaded, enter the following command:
lsmod | grep 8021q
If the 802.1Q kernel module is not listed, try to load it manually:
modprobe 8021q
If an error message such as the following is then displayed, you are probably using a different kernel from the one originally installed and have not loaded a matching set of kernel modules (the kernel version in the path depends on the operating system concerned):
FATAL: Could not open '/lib/modules/5.14.0-503.el9_5.x86_64/kernel/net/8021q/8021q.ko.xz': No such file or directory
If this is the case, there is no directory in /lib/modules that matches the running kernel version. In this case, install or boot the appropriate kernel, including its associated kernel-modules package, and then activate the connection again with nmcli connection up eth0.3509.
Other causes of this error are:
- The file concerned has been deleted.
- You are using a kernel that does not include the 802.1Q kernel module.