--- title: "How to set up Static Routes for direct IP use in VDC" slug: "how-to-set-up-static-routes-for-direct-ip-use-in-vdc" description: "Learn how to set up static routes in NSX Edge for direct public IP assignment to VMs, bypassing SNAT for seamless network communication." updated: 2026-09-02T00:28:55Z published: 2026-09-02T00:28:55Z canonical: "docs.serversaustralia.com.au/how-to-set-up-static-routes-for-direct-ip-use-in-vdc" --- > ## Documentation Index > Fetch the complete documentation index at: https://docs.serversaustralia.com.au/llms.txt > Use this file to discover all available pages before exploring further. # How to set up Static Routes for direct IP use in VDC ## Set up the static route in the NSX edge The following is a guide on how to use static routes in the NSX to use public IPs directly on VMs in your VDC. This will bypass the need for SNAT and allow public IPs to be assigned directly to VMs. ### Create routed network in NSX First, you will need to create a routed local network for the VMs to use. The VMs will get a local IP in this network, and the public IP will route to this local IP. The public IP will also be assigned to the interface of the VM in a later step. In VDC go to “Networks” → “New” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-H5ZUK217.png) In Scope, select “Current Organization Virtual Data Center” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-RIUVQ0EA.png) Create the network as a Routed network ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-3ATGGDVQ.png) Select the Primary Edge. This is the metered edge, and it has the public IPs assigned to it. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-LBKW1EUN.png) In the next window you must name the network, and assign a gateway/cidr for the network. I am using the 10.1.1.0/24 network in this example. Due to this the gateway will be 10.1.1.1, so the Gateway CIDR will be 10.1.1.1/24. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-S9EGPR8B.png) In the next window, optionally set the usable IPs in this range. In our example this will be 10.1.1.2-10.1.1.254. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-MDT9VR2A.png) Optionally set the DNS for the network. Our resolvers are 221.121.130.3 and 221.121.134.9. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-CAKOZ536.png) Click next on the “Segment Profile Template” section without selecting a template. This will not be needed. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-LPN7ESMP.png) Click “Finish” on the final window. This will create the network. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-0YXRSIW4.png) ### Set the network on VM NICs Edit a VM that will need to use the routed network. Go to NICs, and select EDIT. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-0DQ7Z9SY.png) Click “ADD NETWORK TO VAPP” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-4UI2TLVK.png) Select “Direct”, and select the routed network you created. Click “ADD”. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-DBRNCDM5.png) Under the “Network” dropdown box, select the network you have added. Under “IP Mode” select “Static - Manual”. Under “IP” enter the IP address that you will use. Click “SAVE”. On the Windows VM in this example I am setting this to 10.1.1.4. There will be two other Linux VMs, one Ubuntu, and one AlmaLinux that will use other IPs in this range. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-MIZSFITI.png) This has added the network to the VM. We will configure the network in the VM’s OS in a later step. ### Create static route in NSX In VDC go to “Edges”, then your primary metered edge. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-UOEBDEYQ.png) Go to IP Allocations, and take note of the available public IPs. You will use these in your static routes in the NSX edge. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-BE9614UW.png) In this example I will be making 3 static routes. One for a Windows VM, one for a Ubuntu VM, and one for an AlmaLinux VM. The following are the IPs that I will use in this example for the static routes. | VM | Public IP | Local IP | | --- | --- | --- | | Ubuntu | 118.127.48.220 | 10.1.1.2 | | AlmaLinux | 118.127.48.221 | 10.1.1.3 | | Windows | 118.127.40.138 | 10.1.1.4 | In the Edge go to “Routing” → “Static Routes”, and click “NEW”. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-C09LCTUD.png) Add a name and a description for the route you are creating. The network is a /32 of the public IP. See the image below as an example. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-IL384440.png) Click on “Next Hops” at the top. Under “IP Address” add the local IP from the routed network that the public IP will route to. Under “Scope” select the routed network that we created earlier. Click Save. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-1QKUAZHV.png) Perform this for each static route that needs to be created for your VMs. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-HSX7QJZA.png) ### Create firewall rule in NSX In order for your VMs to communicate outbound via the public IP, create an IP Set with the public IPs in it, then use this to create an allow rule for outbound communication. First, create the IP set by going to “Security” → “IP Sets” and click “NEW” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-13GN86PX.png) Name the IP Set and add all the public IPs that you will be using. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-OCCY7P59.png) Now that the IP Set is created you can use this in a firewall rule to allow outbound communication. Go to “Services” → “Firewall” and click “NEW” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-XVD1CEE7.png) Name the Firewall rule. Click the pencil near ‘Source”, select the public IP Set you created. Click the pencil near Destination and select ANY. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-U5ZVBQ0X.png) ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-QS449950.png) ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-QV5V4W8F.png) Click “Save” near the bottom to create the allow rule. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-MQP6ACEX.png) > [!NOTE] > Ensure that there are NO SNAT or DNAT rules using the public IP > > If there are any NAT rules currently using the public IP the routing will not work. Go into the NAT rules on the edge and remove any NAT rules that reference the public IP ## Set up the IP address in Linux ### Setting up the network in Ubuntu based distros In Ubuntu the network is setup using netplan. There will be a YAML file for the netplan config in `/etc/netplan`. Edit the config file in `/etc/netplan` and ensure that the public IP and local IP are both in `addresses`, as well as a `routes` section that not only has the default route, but also a `from` section that specifies the public IP. Here is an example of the netplan config I have for the VM in this guide. ```yaml network:  version: 2  renderer: networkd  ethernets:    ens160:      dhcp4: no      dhcp6: no      addresses:        - 118.127.48.220/32        - 10.1.1.2/24      routes:        - to: default          via: 10.1.1.1          from: 118.127.48.220      nameservers:        addresses:          - 221.121.130.3          - 221.121.134.9 ``` Note that the important changes to the default YAML file are in `addresses` and `routes` . Be sure to run `netplan apply` to apply the new configuration. ### Setting up the network in RHEL based distros Modern RHEL based distros, like AlmaLinux, use Network Manager for the IP configuration. You will first need to use `nmtui` to add the public IP and the local IP to the interfaces IP addresses. Type `nmtui` to bring up the configuration wizard. Select “Edit a connection”. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-K1J68AW1.png) Select your interface an select edit. In this example the interface is `ens192` . ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-WAA5HYER.png) Edit the IPs in “Addresses” so that the Public IP and the local IP are both present. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-7RTAML45.png) Select “OK” at the bottom, then “Back” in the interface select window. Finally select “Quit” to save and apply the changes. `ip a` should now show both the IPs on the interface. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-XNS2JL16.png) Next you need to create a new route that has a lower metric value and the public IP as the source. Here is the command for this example. You may need to adjust this to use the IPs that you are assigning to the interface, and the interface name that you are using. ```bash nmcli connection modify "ens192" ipv4.routes "0.0.0.0/0 10.1.1.1 10 src=118.127.48.221" ``` Next run the following to apply the change ```bash nmcli device reapply ens192 ``` This will create a default route for 0.0.0.0/0 to use the gateway 10.1.1.1 with a metric of 10 and the source IP of 118.127.48.221. If you run `ip r` you should see the following route. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-0EDQJX1P.png) ## Set up the IP address in Windows ### Add IPs to interface In the OS for Windows, search for “Control Panel” and open up the control panel. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-WTAQ2QG4.png) Go to “Network and Internet” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-NFO4Z7EN.png) Go to “Network and Sharing Center” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-93MKO2Z8.png) Click “Change adapter settings” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-EJ1YMZIP.png) Right click on the interface and go to “Properties” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-QF2TN62J.png) Go to “Internet Protocol Version 4 (TCP/IPv4)” and click “Properties” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-V2L25NFZ.png) Ensure that the local IP address from the routed network is set, and also the routed networks gateway. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-9EEA5UFV.png) Click “Advanced…” near the bottom. ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-AM4DBRVH.png) Click “Add…” under “IP addresses” ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-E1TK688X.png) Add in the public IP as a /32 ![](https://cdn.document360.io/d809f158-d4f4-47ff-83d4-18d9c9f7a04d/Images/Documentation/image-6XWEMM82.png) ### Set primary IP to public IP Run the following command in PowerShell, using the local IP for routing in the command. In this example the local IP for routing is 10.1.1.4, but this will vary based on how the VM was set up in previous steps. ```powershell Get-NetIPAddress | Where-Object { $_.IPAddress -eq "10.1.1.4" } | Set-NetIPAddress -SkipAsSource $true ``` This will tell the OS to skip the local routing IP as the source IP, and use the assigned public IP for network operations. ## Related - [Unmetered Bandwidth to Servers Australia Network](/unmetered-bandwidth-to-servers-australia-network.md) - [Create and Manage Networks in VDC](/create-and-manage-networks-in-vdc.md)