Review build Not the live site — unlaunched products, unfinished copy, no prices. comsky.ai →
Comsky Cloud
Sign in Try Cloud free
NETWORKING · SHARED IRON, SEPARATE NETWORKS

Your network is yours alone.

Accounts share hypervisors. Accounts never share a network. Your first instance brings up an isolated network with a virtual router in front of it, and every instance you deploy after that joins the same one — nothing to design, nothing to request, and nothing another customer can route into.

ZONE01 · FOUR HOSTS, TWO ACCOUNTSTWO NETWORKS THAT NEVER MEET
hv-01
web-01 A
app-02 B
db-01 A
hv-02
queue-01 B
cache-01 A
hv-03
web-02 B
batch-01 B
staging A
hv-04
db-02 B
edge-01 A
Network A · router 203.0.113.44 · 10.1.1.0/244 INSTANCES
Network B · its own router, its own range5 INSTANCES
Routes between Network A and Network BNONE

The boundary is drawn around the instances, not around the hosts — which is exactly the point. The console keeps the other account on screen on purpose: hiding it would prove nothing.

The network model

One account, one isolated network, one router in front of it.

Three moving parts, and you are given all three with the account rather than buying them as a networking bundle on top of the machine.

01

A dedicated virtual router

Not a shared gateway with your rules filed alongside everyone else’s. Your account gets its own virtual router, and the firewall, NAT and egress rules you write live on it. Nothing you change there can be affected by, or affect, another account.

02

Source-NAT public IPv4, included

Every account gets a public IPv4 with source NAT as part of the account, not as a line item. Your instances reach the internet through it from day one, and it is the address your port-forwarding rules point at.

03

Self-service NAT and firewall

Open a port, forward a port, add a static NAT, change an egress policy — from the console, applied without a ticket and without waiting for a working day to begin. Port forwarding itself is free.

Addresses and forwarding

What the network screen actually holds.

The included source-NAT address, any dedicated IPs you have bound to an instance, and the forwarding rules in front of them — each with its charge printed beside it, including the ones that are free.

NETWORK · PUBLIC IP ADDRESSESONE ISOLATED NETWORK PER ACCOUNT
IP ADDRESS TYPE BOUND TO ASSIGNED RATE
203.0.113.44 Source NAT All instances 27 Aug 2026 Included
203.0.113.57 Dedicated comsky-web-01 31 Aug 2026 Chargeable
Port forwarding — free on ComskyNEW RULE
203.0.113.44:8080 → 10.1.1.14:80 TCP · comsky-web-01 Free
203.0.113.44:443 → 10.1.1.14:443 TCP · comsky-web-01 Free
Egress policy · applied at the virtual routerSELF-SERVICE
What you can add

Three paid pieces, and nothing hidden behind them.

Everything above comes with the account. These three are the only networking lines that cost money, and each is a flat monthly figure with GST already inside it.

Dedicated IPv4

A public address of your own with static NAT and port forwarding, bound to one instance rather than shared across the account. Assign it and release it yourself from the network screen; billing follows the assignment.

Load balancer

Spread traffic across two or more instances on the same isolated network, with health-checked targets so a machine that stops answering stops receiving. It lives inside your network, not in front of everyone’s.

Remote-access VPN

Reach private addresses on your network without exposing a public port at all, with VPN users you create and remove yourself. The alternative — opening SSH to the internet and hoping — is not a plan.

VPC with tiers and ACLs API TODAY

A private address range of your own, split into tiers, each tier with its own network ACL. It is reachable over the API and has no console screen yet, creation is asynchronous, and it consumes a routable public address. We would rather say that than let you find it after designing around it.

One warning about the routed VPC type

The VPC type decides what the network can do, and a routed type has no port forwarding, no static NAT, no load balancer and no VPN. If those are how you were planning to reach your machines, the routed type is the wrong choice — and it is much easier to know now.

Everything networking carries

The rest of it, without the paragraphs.

Included with the account

  • An isolated network per account
  • A dedicated virtual router
  • Source-NAT public IPv4
  • Private addresses on your own range
  • Port forwarding — free, any number of rules
  • Self-service firewall and egress policy

Paid additions

  • Dedicated IPv4 with static NAT
  • Load balancer, health-checked
  • Remote-access VPN
  • Flat monthly rates, GST inside
  • Removable, with the unused part credited back

Isolation

  • Accounts share hypervisors
  • Accounts never share a network
  • No route between two accounts’ networks
  • The console draws both, side by side
  • Rules live on your own router
  • Everything inside ZONE01

Reaching your machines

  • Forward a public port to a private one
  • Bind a dedicated address to one instance
  • VPN in without opening a port
  • A one-time browser console session
  • SSH keys injected at create time

Over the API

  • VPC with tiers and per-tier ACLs
  • Asynchronous VPC creation
  • A routed type loses forwarding, NAT, LB and VPN
  • Firewall and forwarding rules as resources
  • Signed webhooks on network changes

Data movement

  • No egress metering
  • No bandwidth allowance to exceed
  • Private traffic stays on your network
  • Public traffic leaves through your router
  • One Indian zone, and no cross-region hop
Questions

About the network specifically.

Can another customer on the same host reach my instances?

No. Accounts share hypervisors and never share a network. Your instances sit on an isolated network behind your own virtual router, and there is no route from another account’s network into it. The console draws both accounts on one diagram specifically so you can see that rather than take our word for it.

Do I have to design the network before I deploy?

No. The first instance you create brings up the isolated network and its router, and every instance after that joins the same one. There is no VPC to plan, no subnet to request and no ticket in the way of your first machine.

Is a public IP included or extra?

A source-NAT public IPv4 comes with the account and costs nothing. A dedicated address bound to one instance, with static NAT, is a paid addition. Port forwarding onto the included address is free and unlimited.

Can I open and close ports myself?

Yes — firewall rules, port forwarding, static NAT and egress policy are all changed from the console and applied without raising a ticket. That is the difference between an outage at 2am you can fix and one you can only report.

How do I reach a machine with no public address?

Either forward a port from the included source-NAT address, or add the remote-access VPN and reach private addresses directly with VPN users you manage yourself. There is also a one-time browser console session for the case where the network itself is what broke.

Do you offer a VPC?

Over the API, yes — a private range split into tiers, each with its own ACL. It has no console screen yet, its creation is asynchronous, and it consumes a routable public address. Note that a routed VPC type has no port forwarding, static NAT, load balancer or VPN.

What do I pay for bandwidth?

Nothing. Traffic out is not metered and there is no allowance to exceed, so the networking part of your invoice is the included router, any dedicated IPs, and whichever of the load balancer and the VPN you asked for.

Start with Comsky Cloud.
Grow into the ecosystem.

One account opens every Comsky product — and one invoice covers them, however many you run.