Setting up a private network for Dedicated Servers or Bare Metal Servers (Ubuntu 24.04, Ubuntu 26.04, Debian 12, and Debian 13)
Please use the “Print” function at the bottom of the page to create a PDF.
Valid for Dedicated Servers and Bare Metal Servers managed in the Cloud Panel.
This article explains how to configure an Ethernet interface on a Dedicated Server or a Bare Metal Server running Ubuntu 24.04, Ubuntu 26.04, Debian 12, or Debian 13 as an IEEE 802.1Q VLAN interface in order to set up a private network. The configuration is carried out using the classic interface management system (ifupdown), with the /etc/network/interfaces file and the ifup command, rather than with Netplan.
With a private network, you can divide your existing network into several logical networks. The servers communicate using local IP addresses that are not routed on the internet.
Using private networks offers you the following advantages:
- You can structure your networks according to organizational criteria.
- You can add or remove your servers easily.
- You can reduce latency and network load.
- You can optimize traffic by prioritizing data packets.
- Each server can only communicate with servers on the same private network.
Using a private network can be useful in the following cases, for example:
- Setting up a private network for departments or project teams
- Setting up a private network that is connected to a load balancer
- Setting up a private network for a web server and a database server
You can create a private network consisting of Dedicated Servers or Bare Metal Servers by configuring tagged VLANs. VLANs are virtual local area networks, which are brought together as a single standard in IEEE 802.1Q. With VLANs, you can divide an existing physical network into several logical networks with different subnets. The data traffic is encapsulated so that data from one or more VLANs can be transmitted independently of one another.
With tagged VLANs, there is no fixed assignment between the virtual network and a port. Instead, the assignment is made by tagging the data packets. The data packets are given tags that hold the VLAN ID. Under IEEE 802.1Q, this is done by the respective end device. In this case, these are the servers assigned to the private network. Using the VLAN ID, a switch can identify which VLAN a data packet belongs to. This means that several VLANs can be used through a single switch port.
Please Note
- This article assumes a basic knowledge of Linux server administration.
- If you do not configure the server correctly, it may no longer be reachable.
- To use the private network for Dedicated Servers and Bare Metal Servers, you must configure every server assigned to the network.
Requirements
- You have created at least two servers.
- The servers have been assigned to the same private network.
- The servers are in the same Availability Zone.
- You have administrative access to the servers.
Determining the VLAN ID
How to determine the VLAN ID:
- Log in to your IONOS account.
Click on Menu > Servers & Cloud in the title bar.
Optional: If you have multiple server contracts, select the desired contract.
- Select the required server in the Infrastructure > Servers section.
- In the Features section, check which Availability Zone is entered and make a note of it.
- Check the Availability Zone for every server that is to be part of the private network.
- Select the required private network in the Network > Private Network section.
- Check which VLAN ID is specified for the servers assigned to the private network, and then make a note of it.
Installing the VLAN package
VLAN support is provided by the Linux kernel. On current distributions (Ubuntu 24.04/26.04, Debian 12/13), a separate kernel package is no longer required, because the 8021q module is included in the kernel. For VLAN configuration via /etc/network/interfaces, only the ifupdown and vlan packages are needed.
- Log in to the server as root, or as a user with sudo privileges.
Make sure that the VLAN package is installed. To install the VLAN package, enter the following commands:
root@server:~# apt update
root@server:~# apt upgrade
root@server:~# apt install ifupdown vlanLoad the 8021q kernel module and enable it permanently:
root@server:~# modprobe 8021q
root@server:~# echo "8021q" >> /etc/modules
Determining the network interface
Determine the name of the network interface. To do this, enter the following command:
root@server:~# ip addr
In your configuration, use the interface that your public network also runs on.
Configuring the network interface
In this step, you configure the network interface for the VLAN, and therefore for the private network. The example below assumes that a host needs access to a VLAN that is connected to the eth0 network interface. The IP address assigned to the host is 192.168.2.1/24 for VLAN 3509. The setup is the same for any further VLANs.
Note
The name of the network interface follows the naming convention ethX.Y, where ethX is the name of the physical interface and Y is the VLAN ID (for example, eth0.3509). From this name, ifupdown derives the VLAN ID automatically.
Open the /etc/network/interfaces file with vi.
root@server:~# vi /etc/network/interfaces
Note
The vi editor has an insert mode and a command mode. You can switch to insert mode by pressing the i key. In this mode, the characters you type are inserted into the text immediately. To switch to command mode, press the ESC key. When you use command mode, your keyboard input is interpreted as a command.
Define the network interface. To do this, enter the required information in the following form:
auto [PHYSICAL_INTERFACE].[VLAN-ID]
iface [PHYSICAL_INTERFACE].[VLAN-ID] inet static
address [IP_ADDRESS_OF_THE_SERVER_IN_THE_PRIVATE_NETWORK]
netmask [NETMASK]Example:
auto eth0.3509
iface eth0.3509 inet static
address 192.168.2.1
netmask 255.255.255.0To exit vi and save the file, enter the command below and then press Enter:
:wq
To restart the network interface for the private network, enter the following command:
root@server:~# ifup [PHYSICAL_INTERFACE].[VLAN-ID]
Example:
root@server:~# ifup eth0.3509
Testing the network configuration
Check the configuration of the VLAN interface with the following command:
root@server:~# ip addr show [PHYSICAL_INTERFACE].[VLAN-ID]
Example:
ip addr show eth0.3509
If the network interface has been configured successfully, a message such as the following is displayed:
4: eth0.3509@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 qdisc noqueue state UP group default qlen 1000
link/ether 3c:ec:ef:aa:bb:cc brd ff:ff:ff:ff:ff:ff
inet 192.168.2.1/24 brd 192.168.2.255 scope global eth0.3509
valid_lft forever preferred_lft forever
To check that the interface has been set up correctly as an 802.1Q VLAN with the expected VLAN ID, also enter the following command:
root@server:~# ip -d link show eth0.3509
4: eth0.3509@eth0: <BROADCAST,MULTICAST,UP,LOWER_UP> mtu 1500 ...
link/ether 3c:ec:ef:aa:bb:cc brd ff:ff:ff:ff:ff:ff
vlan protocol 802.1Q id 3509 <REORDER_HDR>
Testing connectivity within the private network
If both servers are on the same private network, you can test connectivity with the ping command. To do this, send a ping to the IP address of the other server assigned to the private network. Example:
root@server:~# ping -c 3 192.168.2.3
PING 192.168.2.3 (192.168.2.3) 56(84) bytes of data.
64 bytes from 192.168.2.3: icmp_seq=1 ttl=64 time=0.176 ms
64 bytes from 192.168.2.3: icmp_seq=2 ttl=64 time=0.151 ms
64 bytes from 192.168.2.3: icmp_seq=3 ttl=64 time=0.170 ms
--- 192.168.2.3 ping statistics ---
3 packets transmitted, 3 received, 0% packet loss, time 2050ms
rtt min/avg/max/mdev = 0.151/0.165/0.176/0.018 ms
If the data packets are delivered to the server, the network interface for the private network has been configured successfully.
Note
If the server is no longer reachable because of a configuration error, you can log in to it using the VNC Console and correct the configuration. You can find instructions for this in the following article:
Troubleshooting
The physical network interface was not found
If the physical interface does not exist or has been named incorrectly, activating the VLAN interface fails with a message such as the following:
root@server:~# ifup eth0.3509
Cannot find device "eth0"
Failed to bring up eth0.3509.
Use the ip addr command to check whether the physical network interface exists. Then open the /etc/network/interfaces file and check whether the name of the interface has been entered correctly.
The 8021q kernel module is not loaded
If the 8021q module is not loaded, the VLAN interface cannot be set up. In this case, activating the interface with ifup produces an error message such as the following:
root@server:~# ifup eth0.1
WARNING: Could not open /proc/net/vlan/config. Maybe you need to load the 8021q module, or maybe you are not using PROCFS??
ERROR: trying to set name type for VLAN subsystem, error: Package not installed
WARNING: Could not open /proc/net/vlan/config. Maybe you need to load the 8021q module, or maybe you are not using PROCFS??
ERROR: trying to add VLAN #1 to IF -:eth0:- error: Package not installed
SIOCSIFADDR: No such device
eth0.1: ERROR while getting interface flags: No such device
SIOCSIFNETMASK: No such device
eth0.1: ERROR while getting interface flags: No such device
Failed to bring up eth0.1.
If an error message like this is displayed when you test the network configuration, it may have the following causes:
- The 8021q kernel module was not found.
- The /proc directory was not mounted.
First, check whether the 8021q module is currently loaded:
root@server:~# lsmod | grep 8021q
If the 8021q module is not listed, it is not loaded. In this case, load it with the following command:
root@server:~# modprobe 8021q
Then use lsmod | grep 8021q again to check whether the module is now loaded, and activate the VLAN interface again with ifup.
Updating the kernel
To update the kernel, complete the following steps:
Update all packages. To do this, enter the following command:
apt update && apt upgrade
To install the latest kernel version, enter the following command:
apt dist-upgrade
When you enter this command, the operating system handles the dependencies of the kernel update intelligently.
Restart the server. To do this, enter the following command:
reboot
To check whether the installation was successful, enter the following command:
uname -r