Skip to content

IP address management

Explanation · Updated Jun 2026

Coming from another cloud?

▸AWS·VPC IP Addressing

This Quake AI feature maps to AWS’s VPC IP Addressing.

▸Azure·Vnet IP Addressing

This Quake AI feature maps to Azure’s Vnet IP Addressing.

▸Google Cloud·VPC IP Addressing

This Quake AI feature maps to Google Cloud’s VPC IP Addressing.

IP address management

Instances on Quake AI receive at least one private IP address from the subnet they connect to. How that address is allocated, how it reaches the guest OS, and what happens when you need multiple addresses or advanced forwarding are all governed by the Network service (OpenStack Neutron).

IP allocation methods#

When you create a port or launch an instance, Quake AI assigns a private IP from the subnet's allocation pool in one of two ways:

System-allocated (default): The platform picks an unused address from the pool automatically. The assigned IP is guaranteed not to conflict with other active addresses on the subnet.

Manually assigned: You specify the IP address at port or instance creation time. The address can be inside or outside the subnet's allocation pool. The Console may show a warning for out-of-pool addresses, but the assignment succeeds as long as the address is not already in use.

Both methods produce the same result: a port with a fixed IP recorded in Neutron's database. The allocation method has no effect on how the address reaches the guest OS.

DHCP vs. static configuration inside the instance#

The allocation method in Quake AI is independent of how the guest OS configures the interface. Any combination works:

Allocation methodDHCP in guestStatic in guest
System-allocatedDHCP delivers the assigned IP automaticallyYou can configure the same IP statically
Manually assignedIf DHCP is enabled on the subnet, the assigned IP is served via DHCPConfigure the IP manually or with automation

When DHCP is enabled on the subnet (the default), the Neutron DHCP agent serves the assigned fixed IP to the instance. DHCP is the default guest configuration path on most subnets.

When DHCP is disabled, or when you prefer static configuration, the guest must be configured to match the IP recorded in the port metadata. Mismatches between the guest IP and the port IP cause traffic to be dropped by port security.

Allowed address pairs#

By default, a port only permits traffic from its assigned fixed IP and MAC address. Any packet with a different source address is dropped by the virtual switch. This is port security, designed to prevent IP spoofing.

Allowed address pairs let you explicitly authorize additional IP/MAC combinations on a port. This is necessary for:

  • Virtual IPs for high availability (Keepalived, Pacemaker)
  • Software load balancers (HAProxy active-standby)
  • NAT gateways forwarding traffic for other instances
  • Multi-IP interfaces for applications that bind to multiple addresses

Adding allowed address pairs#

bash
openstack port set --allowed-address ip-address=192.168.1.100 YOUR_PORT_ID

To specify a different MAC address:

bash
openstack port set \
  --allowed-address ip-address=192.168.1.100,mac-address=fa:16:3e:12:34:56 \
  YOUR_PORT_ID

Verify the current allowed address pairs:

bash
openstack port show YOUR_PORT_ID -f json | jq '.allowed_address_pairs'

Security groups still apply to traffic from allowed addresses. The MAC address defaults to the port's MAC if not specified. Avoid wildcard entries (0.0.0.0/0); they can cause IP conflicts and bypass intended routing controls.

Disabling port security#

Port security enforces source IP/MAC validation and security group filtering on every port. Disabling it removes both protections, allowing the instance to:

  • Forward packets from arbitrary source IPs (NAT, routing)
  • Receive traffic without security group filtering
  • Act as a router, bridge, or Layer 2/Layer 3 appliance

When to disable port security#

  • Virtual routers using iptables or nftables
  • NAT gateways forwarding traffic for a private subnet
  • Software load balancers handling forwarded traffic
  • Custom network appliances (firewalls, VPNs)

Disabling on a new port#

bash
openstack port create \
  --network YOUR_NETWORK \
  --no-security-group \
  --disable-port-security \
  YOUR_PORT_NAME

Disabling on an existing port#

bash
openstack port set \
  --no-security-group \
  --disable-port-security \
  YOUR_PORT_ID

Key points#

  • Quake AI tracks IP-to-port mappings regardless of whether the guest uses DHCP or static configuration.
  • Manually assigned IPs still pass through network security and routing controls.
  • Allowed address pairs and disabled port security suit HA, NAT, and appliance workloads; keep port security enabled for standard instance NICs.
  • Address conflicts are your responsibility when using allowed address pairs or disabled port security.

Further reading#

Before this

Related content

Was this page helpful?