Private network and 802.1Q VLANs on Linux and Windows Server
Contents
For administrators with two or more dedicated servers who want database traffic, replication and backups on a separate isolated network. By the end, your Linux and Windows Server machines reach each other on private addresses — in a separate 802.1Q VLAN if needed.
The private network and where to get it#
The private network is an isolated network between your servers, including across countries. It runs over a separate network interface, usually the server’s second one, and its speed depends on the line: the private port speed is listed on the server card in the catalogue. Between countries, the response time is tens of milliseconds. More details are on the Private network page.
The Business, Power and Ultra lines have a private network, as do most Classic and Standard models (check the server card). The Lite and Turbo lines do not.
What you will need#
- A request to support. Support joins servers into one private network at your request; you can mention it as early as the comment on your server order. Support will also tell you the MAC address of each server’s private interface.
- A fallback way in. Ask support for the remote console beforehand: if a mistake cuts off SSH or RDP, the console is the only way to fix it.
- An address plan. Pick the addresses yourself from the private ranges
10.0.0.0/8,172.16.0.0/12,192.168.0.0/16so that the subnet does not overlap with office, VPN, container or virtual machine networks.
The values here are examples — substitute your own: subnet 10.10.0.0/24, Linux servers 10.10.0.11 and 10.10.0.12, Windows Server 10.10.0.21; for VLAN 100, subnet 10.10.100.0/24. The private interface in the examples is eno2 on Linux and Ethernet 2 on Windows; yours may be named differently: the name depends on the OS and the server model.
Before you change the network#
Warning. Work on the private interface only. Do not change the public interface, its address or the default route: you can lose access to the server and will need the remote console to get it back. A default gateway is never set on the private interface.
Find the private interface on Linux:
ip -br link
ip -br addr
ip route show defaultThe interface in the default via … dev … line is the public one. The private one is another physical interface with no public address; its MAC address matches the one support gave you.
Linux#
Step 1. A temporary test with ip commands#
These commands write nothing to disk: the settings are gone after a reboot. Run them on each server, substituting its own address:
sudo ip link set dev eno2 up
sudo ip addr add 10.10.0.11/24 dev eno2
ping -c 3 10.10.0.12Remove the temporary address before the permanent setup: sudo ip addr del 10.10.0.11/24 dev eno2.
Step 2. Permanent setup on Ubuntu: netplan#
For Ubuntu Server 24.04 LTS and 26.04 LTS. Do not edit the existing file with the public interface — create a separate /etc/netplan/60-private.yaml: netplan reads the files in alphabetical order and merges them.
network:
version: 2
ethernets:
eno2:
dhcp4: false
optional: true
addresses:
- 10.10.0.11/24No routes or gateway4 lines belong here. With optional: true, the system does not wait for this interface at boot. Restrict the file permissions and apply the changes:
sudo chmod 600 /etc/netplan/60-private.yaml
sudo netplan trynetplan try applies the configuration and waits 120 seconds for Enter. Before pressing it, check from a second SSH session that the server is reachable. Without confirmation, the previous settings are restored automatically.
Step 2. Permanent setup on Debian#
Depending on the image, the network on Debian 13 is managed by ifupdown (the /etc/network/interfaces file), netplan or systemd-networkd. First check which one you have:
ls /etc/netplan/
systemctl is-active networking systemd-networkdIf there are files in /etc/netplan/, proceed as on Ubuntu. If the public interface is described in /etc/network/interfaces, you have ifupdown. If only systemd-networkd is active, configure that.
ifupdown. Create the file /etc/network/interfaces.d/private (the main file must contain the line source /etc/network/interfaces.d/*):
auto eno2
iface eno2 inet static
address 10.10.0.11/24Do not add a gateway line. To apply: sudo ifup eno2. To undo: sudo ifdown eno2 and delete the file.
systemd-networkd. Create the file /etc/systemd/network/20-private.network with these contents — no Gateway= line:
[Match]
Name=eno2
[Link]
RequiredForOnline=no
[Network]
Address=10.10.0.11/24Run sudo networkctl reload. With RequiredForOnline=no, boot does not wait for this interface.
802.1Q VLANs on Linux#
A VLAN tag splits one private network into several segments — for the database and for backups, for example. Untagged traffic works as soon as the servers are joined, and you choose the 802.1Q VLAN numbers for the segments yourself; the number must be the same on every server in the segment.
On Linux, tags are handled by the 8021q kernel module. Load it and add it to the modules loaded at boot:
sudo modprobe 8021q
echo 8021q | sudo tee /etc/modules-load.d/8021q.confFor a temporary test, create a sub-interface with tag 100 (the parent interface eno2 must be up):
sudo ip link add link eno2 name vlan100 type vlan id 100
sudo ip link set dev vlan100 up
sudo ip addr add 10.10.100.11/24 dev vlan100Delete the sub-interface before the permanent setup: sudo ip link del vlan100.
netplan. Append a vlans section to the end of 60-private.yaml, at the same level as ethernets:
vlans:
vlan100:
id: 100
link: eno2
optional: true
addresses:
- 10.10.100.11/24Run sudo netplan try again. If the changes were reverted but vlan100 is still there, delete it: sudo ip link del vlan100.
ifupdown. The tag is set by the interface name itself, in the form “name.number”. Append these lines to the private file after the eno2 stanza and run sudo ifup eno2.100:
auto eno2.100
iface eno2.100 inet static
address 10.10.100.11/24Windows Server#
Run the commands in PowerShell as an administrator (Windows Server 2022 and 2025). Find the adapters:
Get-NetAdapter | Format-Table Name, InterfaceDescription, MacAddress, LinkSpeed
Get-NetIPConfigurationThe adapter with IPv4DefaultGateway filled in is the public one — leave it alone. Identify the private one by its MAC address, rename it for convenience and assign an address without a gateway (do not pass -DefaultGateway):
Rename-NetAdapter -Name "Ethernet 2" -NewName "Private"
New-NetIPAddress -InterfaceAlias "Private" -IPAddress 10.10.0.21 -PrefixLength 24To undo: Remove-NetIPAddress -InterfaceAlias "Private" -IPAddress 10.10.0.21.
A VLAN tag on Windows Server#
Method 1 — an adapter property. According to the Microsoft documentation, not all adapters let you set a VLAN — it depends on the driver. The adapter restarts briefly and all its traffic becomes tagged, so replace its address with one from that VLAN’s subnet:
Set-NetAdapter -Name "Private" -VlanID 100
Get-NetAdapter -Name "Private" | Format-List Name, VlanIDIf the command fails or VlanID does not change, the driver does not support it. To return to untagged traffic: Set-NetAdapter -Name "Private" -VlanID 0.
Method 2 — a Hyper-V virtual switch. Use it when the driver cannot set a tag or you need several VLANs on one adapter.
Warning. The first command installs the Hyper-V role and reboots the server; run the rest after the reboot. Bind the switch to the private adapter only: binding it to the public one can cut off RDP. Once the switch is created, the address on the
Privateadapter itself stops working — addresses are set on the virtualvEthernetadapters. To undo:Remove-VMSwitch -Name "PrivateSwitch".
Install-WindowsFeature -Name Hyper-V -IncludeManagementTools -Restart
New-VMSwitch -Name "PrivateSwitch" -NetAdapterName "Private" -AllowManagementOS $false
Add-VMNetworkAdapter -ManagementOS -Name "Private100" -SwitchName "PrivateSwitch"
Set-VMNetworkAdapterVlan -ManagementOS -VMNetworkAdapterName "Private100" -Access -VlanId 100
New-NetIPAddress -InterfaceAlias "vEthernet (Private100)" -IPAddress 10.10.100.21 -PrefixLength 24The firewall on the private interface#
The private network is separated from the internet, but not from your own servers: if one is compromised, the attacker will try to reach the others through it. So do not turn the firewall off on the private interface: open only the ports you need, and only to the private subnet. Isolation is not encryption: keep TLS for sensitive data.
Linux, ufw, an example for PostgreSQL:
sudo ufw allow in on eno2 from 10.10.0.0/24 to any port 5432 proto tcpThe rule works only when ufw is enabled. Do not enable it until SSH is allowed: the steps are in “Basic Linux server hardening”.
Windows Server, an example for MS SQL Server and replies to ping:
New-NetFirewallRule -DisplayName "Private: SQL Server" -Direction Inbound -Protocol TCP -LocalPort 1433 -RemoteAddress 10.10.0.0/24 -Action Allow
New-NetFirewallRule -DisplayName "Private: ping" -Direction Inbound -Protocol ICMPv4 -IcmpType 8 -RemoteAddress 10.10.0.0/24 -Action AllowThe second rule is needed because Windows assigns a network without a gateway to the Public profile, where the firewall blocks ping by default. The service itself must listen on the private address: in PostgreSQL, that is the listen_addresses parameter.
How to check the result#
- Connectivity.
ping -c 4 10.10.0.12from the first server, and back from the second. - The neighbour.
ip neigh show dev eno2should show the neighbour’s address with its MAC and the stateREACHABLEorSTALE.FAILEDorINCOMPLETEmeans the servers do not see each other: they are not joined yet, the interface is wrong, or the VLAN tags differ. On Windows:Get-NetNeighbor -InterfaceAlias "Private".
Speed: iperf3#
Install iperf3 on both Linux servers: sudo apt install iperf3. During the test, open port 5201/tcp on the private interface. Run the first command on the receiving server, the second on the other:
iperf3 -s -1 -B 10.10.0.12
iperf3 -c 10.10.0.12 -t 10 -P 4The result is capped by the slower of the two private ports and, between countries, also depends on the response time. Close the port after the test.
Common mistakes#
- A gateway on the private interface. A second default route appears and the server stops answering on its public address. Remove the gateway.
- The subnet overlaps with the office network, a VPN or Docker (
172.17.0.0/16by default) — some addresses become unreachable.
What to do next#
- Standby site: three schemes and what to check and database backups.
- WireGuard between the office and the server: the office connects to the private network through a tunnel (WireGuard or IPsec) via one of the servers.
- The server catalogue and locations.
To join servers into a private network, contact support: phone +38 044 206 08 08, email info@united.net.ua.