Skip to content

Routers CLI Reference

Reference · Updated Sep 2026

Coming from another cloud?

▸AWS·Amazon Virtual Private Cloud

Amazon Virtual Private Cloudhigh

  • AWS VPC is regional with CIDR /16-/28.
  • OpenStack Networks project-scoped L2 with flexible CIDR.
  • AWS requires IGW for public.
  • OpenStack provider nets or floating IPs.
AWS docs ↗
▸Azure·Virtual Network (VNet)

Virtual Network (VNet)high

  • Azure VNets are strictly regional Layer 3 overlays scoped to one subscription with no L2 VLAN support ().
  • VNets and subnets creation free, but subnets min /29 with Azure reserving 5 IPs per subnet ().
  • Managed via ARM REST APIs/PowerShell/CLI vs Neutron REST API.
  • Isolated per subscription; peering for cross-VNet connectivity vs OpenStack project networks connected via routers.
Azure docs ↗
▸DigitalOcean·VPC (VPC Network)

VPC (VPC Network)high

  • Region-scoped: a VPC network is created in a specific datacenter region and resources must be in that same region to be attached, whereas OpenStack Neutron networks/subnets are generally available across all AZs in a region and attachments are controlled by network reachability rather than an explicit region slug ().
  • Resource migration is limited: Droplets require snapshot/recreate to move between VPCs and some resources (Kubernetes clusters, load balancers, NAT gateways) cannot be migrated between VPCs, whereas in OpenStack you typically can attach/detach ports or move router interfaces without recreating servers (behavior depends on deployment, but Neutron’s object model supports it) ().
  • NAT is a managed NAT Gateway with tiered capacity (1–16 increments; each increment gives 25 Mbps symmetrical bandwidth and 100 GiB outbound transfer/month) and can be set as the default gateway for the VPC, whereas OpenStack commonly expresses egress via Neutron routers with SNAT and does not use this specific ‘size tier’ model ().
  • Security-policy coupling differs: DigitalOcean notes Cloud Firewall rules affect both public and VPC traffic and rules must specify whether they apply to the public or private IP range, whereas in OpenStack security groups are generally applied to ports and are not framed as “public vs private IP range” rule modes ().
DigitalOcean docs ↗
▸Google Cloud·VPC Network

VPC Networkhigh

  • GCP VPC is global (spans all regions) whereas OpenStack Neutron networks are project-scoped and region-local.
  • GCP uses shared VPC for cross-project networking (requires org-level config); OpenStack uses shared networks via admin.
  • Subnets in GCP are regional, auto-mode creates one per region automatically; OpenStack requires explicit subnet creation.
  • GCP VPC Flow Logs per-subnet; OpenStack has no native equivalent without external tools.
Google Cloud docs ↗
▸Hetzner·Networks

Networkshigh

  • Private networks (vSwitch-like but called Networks) created via API, up to 10.0.0.0/8 subnets, attach to servers/LBs.
  • CCM supports route controller for pod networking when enabled; no native provider networks like OpenStack.
  • Limited to Hetzner regions, IPv4 only for private (IPv6 public).
  • Networks are free with no usage charges, unlike potential metering in OpenStack clouds ().
Hetzner docs ↗

Routers CLI reference

See the OpenStack CLI router reference for the full list of openstack router subcommands.

Use these commands to create, list, show, update, and delete routers, add or remove interfaces, and set or clear a router external gateway. Replace ROUTER_ID_OR_NAME, EXTERNAL_NETWORK_ID_OR_NAME, SUBNET_ID_OR_NAME, and PORT_ID with the IDs or names of your routers, external networks, subnets, and ports.

List routers#

bash
openstack router list

Show router details#

bash
openstack router show ROUTER_ID_OR_NAME

Create a router#

bash
openstack router create ROUTER_NAME

Specify an external network for the gateway at create time:

bash
openstack router create --external-gateway EXTERNAL_NETWORK_ID_OR_NAME ROUTER_NAME

Update a router#

bash
openstack router set --name NEW_ROUTER_NAME ROUTER_ID_OR_NAME

Set the external gateway:

bash
openstack router set --external-gateway EXTERNAL_NETWORK_ID_OR_NAME ROUTER_ID_OR_NAME

Delete a router#

bash
openstack router delete ROUTER_ID_OR_NAME

Add an interface to a router#

Using a subnet ID:

bash
openstack router add subnet ROUTER_ID_OR_NAME SUBNET_ID_OR_NAME

Using a port ID:

bash
openstack router add port ROUTER_ID_OR_NAME PORT_ID

Remove an interface from a router#

Using a subnet ID:

bash
openstack router remove subnet ROUTER_ID_OR_NAME SUBNET_ID_OR_NAME

Using a port ID:

bash
openstack router remove port ROUTER_ID_OR_NAME PORT_ID

Clear the external gateway from a router#

bash
openstack router unset --external-gateway ROUTER_ID_OR_NAME

Output columns#

Select specific columns with --column COL1 --column COL2 or change the output format with -f json, -f csv, or -f table (default).

openstack router list#

ColumnDescription
IDRouter UUID
NameRouter name
StatusCurrent state (ACTIVE, ERROR)
StateAdministrative state (UP, DOWN)
ProjectOwning project ID
Was this page helpful?