Skip to content

Network CLI

Neutron · OpenStack CLI · python-openstackclient

Manage networks, subnets, routers, floating IPs, security groups, and ports from the command line.

Networks & Subnets

openstack network listList networks
openstack network show <name|id>Show network details
openstack network create <name>Create a network
openstack subnet listList subnets
openstack subnet create --network <net> --subnet-range <cidr> <name>Create a subnet

Routers

openstack router listList routers
openstack router create <name>Create a router
openstack router set --external-gateway <net> <router>Set external gateway
openstack router add subnet <router> <subnet>Attach a subnet
openstack router remove subnet <router> <subnet>Detach a subnet

Floating IPs

openstack floating ip listList floating IPs
openstack floating ip create <ext-net>Allocate a floating IP
openstack server add floating ip <server> <ip>Associate with an instance
openstack server remove floating ip <server> <ip>Disassociate from an instance
openstack floating ip delete <ip>Release a floating IP

Security Groups

openstack security group listList security groups
openstack security group create <name>Create a security group
openstack security group rule create ...Add an ingress or egress rule
openstack security group rule list <group>List rules in a group
openstack security group rule delete <rule-id>Delete a rule

Ports

openstack port listList ports
openstack port show <id>Show port details
openstack port create --network <net> <name>Create a port
openstack port set --security-group <group> <port>Attach security group to port

Common flags: security group rule create

--protocol tcp|udp|icmpIP protocol
--dst-port <port|range>Destination port or range (e.g., 80, 8000:9000)
--remote-ip <cidr>Source CIDR (default: 0.0.0.0/0)
--remote-group <group>Allow traffic from another security group
--ingress | --egressRule direction (default: ingress)
--ethertype IPv4|IPv6IP version (default: IPv4)

Examples

Create a private network with internet access

# Create a private network with a subnet
openstack network create my-private-net
openstack subnet create \
  --network my-private-net \
  --subnet-range 10.0.0.0/24 \
  --dns-nameserver 8.8.8.8 \
  my-private-subnet

# Create a router and connect to the internet
openstack router create my-router
openstack router set --external-gateway public-network my-router
openstack router add subnet my-router my-private-subnet

# Verify connectivity
openstack router show my-router -c external_gateway_info
# external_gateway_info: {"network_id": "pub-net-id", "enable_snat": true}

Set up a web server security group

# Create a security group for a web server
openstack security group create web-server \
  --description "HTTP, HTTPS, and SSH access"

# Allow SSH from anywhere
openstack security group rule create \
  --protocol tcp --dst-port 22 \
  --remote-ip 0.0.0.0/0 \
  web-server

# Allow HTTP and HTTPS
openstack security group rule create \
  --protocol tcp --dst-port 80 \
  web-server
openstack security group rule create \
  --protocol tcp --dst-port 443 \
  web-server

# Allow ICMP (ping)
openstack security group rule create \
  --protocol icmp \
  web-server

# Verify
openstack security group rule list web-server -f table
# +------+------+-----------+----------+-----------+-----------+
# | ID   | Proto| IP Range  | Port Min | Port Max  | Direction |
# +------+------+-----------+----------+-----------+-----------+
# | ...  | tcp  | 0.0.0.0/0 | 22       | 22        | ingress   |
# | ...  | tcp  | 0.0.0.0/0 | 80       | 80        | ingress   |
# | ...  | tcp  | 0.0.0.0/0 | 443      | 443       | ingress   |
# | ...  | icmp | 0.0.0.0/0 |          |           | ingress   |
# +------+------+-----------+----------+-----------+-----------+

Floating IP lifecycle

# Allocate a floating IP from the public pool
openstack floating ip create public-network
# +---------------------+--------------------------------------+
# | Field               | Value                                |
# +---------------------+--------------------------------------+
# | floating_ip_address | 203.0.113.42                         |
# | status              | DOWN                                 |
# +---------------------+--------------------------------------+

# Attach to an instance
openstack server add floating ip my-server 203.0.113.42

# Verify
openstack server show my-server -c addresses
# +-----------+-------------------------------------------+
# | Field     | Value                                     |
# +-----------+-------------------------------------------+
# | addresses | my-private-net=10.0.0.5, 203.0.113.42     |
# +-----------+-------------------------------------------+

# When done, release it
openstack server remove floating ip my-server 203.0.113.42
openstack floating ip delete 203.0.113.42

Quake AI tips

Public network name

The external network is named 'public-network' in all regions. Use this name when creating routers or floating IPs.

Default security group blocks ingress

New projects get a default security group that allows all egress but no ingress. You must explicitly add rules for SSH (22), HTTP (80), HTTPS (443), or any other port you need.

Floating IP quota

Floating IPs count against your project quota, including allocated IPs that aren't associated with an instance. Check your current limit and usage with 'openstack quota show --usage' and release IPs you no longer need. See the Quake AI pricing page for what each plan includes, and contact support to request an increase.

DNS nameservers

When creating subnets, specify --dns-nameserver (e.g., 8.8.8.8 or 1.1.1.1). Without it, instances on the subnet won't resolve DNS.

Related