Updated: 28 September 2026 · Applies to: Self-managed dedicated servers on Ubuntu 24.04 and 26.04 LTS
Ubuntu configures its network with netplan. This guide shows two things: how to use extra addresses that use your main gateway (for example on a plan that includes 5 usable addresses), and how to configure an additional subnet that has its own gateway, so that traffic from the new addresses leaves through that gateway. It also shows how to test the change safely.
How it works
- Addresses that come with your plan and use the gateway of your main address (for example the 5 usable addresses of a /29 plan) are simply added to the interface.
- An additional subnet (/28 to /24) is delivered with its own gateway. You add its addresses to the same interface and create a second routing table with the block's gateway. A routing rule sends every packet that comes from the block's addresses through that table. This is called source-based routing. Your main address keeps using the main gateway.
- If you have IP addresses from several different subnets, each subnet gets its own table.
Before you start
- Log in over SSH as a user with
sudo. Keep the IPMI console at hand (How to get started with Console Redirection of an out-of-band-management?) in case you make a mistake in the network settings. - Have the network details from the delivery message ready: the addresses, the block (for example
198.51.100.0/26) and the gateway of the block (How to order an additional IPv4 subnet for your dedicated server?).
1. Look at the current configuration
ip -br address ls /etc/netplan/ sudo cat /etc/netplan/*.yaml
Note the interface name (for example eno1, enp3s0 or eth0) and the address and gateway that are already configured.
2. Make a copy
sudo cp /etc/netplan/50-cloud-init.yaml /root/netplan-backup.yaml
Use the name of your file if it is different.
3. Extra addresses that use your main gateway
Add them to the addresses: list of the interface, each as address/prefix (edit with sudo nano /etc/netplan/50-cloud-init.yaml):
network:
version: 2
ethernets:
eno1:
addresses:
- 203.0.113.10/29
- 203.0.113.11/29
- 203.0.113.12/29
routes:
- to: default
via: 203.0.113.9
nameservers:
addresses: [1.1.1.1, 8.8.8.8]
Use spaces, never tabs. Keep other lines of your file (such as match or set-name) as they are. The routes: block with to: default replaces the older gateway4 setting.
4. An additional subnet with its own gateway
Add the addresses of the block to the same addresses: list, add a second default route to a separate table, and add a routing policy for the block. Example for a /26 block 198.51.100.0/26 whose gateway is 198.51.100.1 (replace all values with your own):
network:
version: 2
ethernets:
eno1:
addresses:
- 203.0.113.10/29 # main block
- 198.51.100.10/26 # addresses of the additional block,
- 198.51.100.11/26 # each with the prefix of the block
- 198.51.100.12/26
routes:
- to: default
via: 203.0.113.9 # gateway of the main block
- to: default
via: 198.51.100.1 # gateway of the additional block
table: 100
on-link: true
routing-policy:
- from: 198.51.100.0/26
table: 100
priority: 100
nameservers:
addresses: [1.1.1.1, 8.8.8.8]
table: 100puts the block's default route into its own routing table (any number from 1 upward that you do not use elsewhere).on-link: truetells the system that the gateway is directly reachable on this interface.routing-policywithfromsends traffic that has a source address in the block to table 100.
Several subnets: repeat the pattern with a new table for each: a second block gets table: 101, its own via, and a routing-policy entry with its own from. For addresses taken from several different subnets, use one entry per subnet, and one from: per subnet (or per single address, for example from: 192.0.2.25/32).
5. Test with automatic rollback
sudo netplan try
netplan applies the settings and asks you to confirm within 120 seconds; if you lose your connection and cannot confirm, it rolls back by itself. Press Enter to keep them. Then make them permanent and check:
sudo netplan apply ip -br address ip rule show ip route show table 100
ip rule show must list your rule (from 198.51.100.0/26 lookup 100), and ip route show table 100 must show default via 198.51.100.1.
6. Test each address
Continue with How to test that every additional IP address works on your server?. In particular, curl --interface 198.51.100.10 https://ifconfig.me must print 198.51.100.10.
If something goes wrong
- YAML errors: netplan names the line. Check the indentation (2 spaces per level) and that every list item starts with
-. - You lost SSH access: wait for the rollback of
netplan try, or use the IPMI console and restore your copy:sudo cp /root/netplan-backup.yaml /etc/netplan/50-cloud-init.yaml && sudo netplan apply. - The block's addresses answer, but outgoing traffic uses the main address: the routing policy is missing or the
fromdoes not match the block. Checkip rule show. - The file is rewritten after a reboot: on some images a service called cloud-init regenerates the network configuration. To stop it, create
/etc/cloud/cloud.cfg.d/99-disable-network-config.cfgwith the contentnetwork: {config: disabled}. - Warning about file permissions: run
sudo chmod 600 /etc/netplan/*.yaml.
Frequently asked questions
Do I have to restart the server?
No. netplan apply is enough.
Can Ucartz configure it for me?
Yes. Free Basic Managed Support helps with quick checks (best effort), and our engineers can do the full configuration by the task, which is useful for orders with several different subnets.
Source: Netplan documentation (routes, on-link, table and routing-policy).
Need a dedicated server, more IP addresses, or a hand with the setup?
- Unmanaged dedicated servers: full root access and IPv4 subnets from /29 up to /24, ordered with the server or added later.
- Managed dedicated servers: our team looks after the operating system, updates, security and monitoring.
- Dedicated server locations: choose the country and data centre when you order.
Prefer a hand with the setup? Our engineers can do it for you: Hire an Expert, or use our on-demand server management.
