---
title: VPC
---
import { Box, Sliders, Plus, Globe, Hash, Trash2, HelpCircle } from 'react-feather';
# Virtual Private Cloud (VPC)
A **VPC** is a private network inside a TIR project. You choose its IPv4 address range, and the
resources you place on it reach each other over private addresses instead of over the public
internet.
Use a VPC when you want your workloads to talk to each other privately — without giving them
public IPs, and without their traffic leaving your own network.
},
{ href: '#open-the-vpc-page', label: 'Open the page', icon: },
{ href: '#create-a-vpc', label: 'Create a VPC', icon: },
{ href: '#choosing-an-address-range', label: 'Address range', icon: },
{ href: '#ip-addresses-in-a-vpc', label: 'IP addresses', icon: },
{ href: '#delete-a-vpc', label: 'Delete', icon: },
{ href: '#troubleshooting', label: 'Troubleshooting', icon: },
]} />
---
## What You Get
You supply one thing — an address range — and TIR sets up the network around it.
| | |
|---|---|
| **Your own custom CIDR Range** | You can choose your own custom Private IP Address Range. |
| **Private communication** | Resources on the same VPC reach each other directly, with no public IP and no internet hop. |
| **Isolation** | VPCs cannot see each other's traffic, even when two of them use the same address range. |
| **Nothing else to configure** | There is no routing, gateway or address assignment to set up. It is ready as soon as it reports **Active**. |
---
## Open the VPC Page
1. Log in to the **TIR** portal.
2. Select the project you want to work in.
3. Go to **Network → VPC** in the sidebar.
A VPC belongs to one project in one region. You will only see the VPCs that belong to the
project and region you currently have selected, and a VPC cannot be shared across projects.
---
## Create a VPC
Creating a VPC takes two values: a name and an address range. The address range is **fixed once
the VPC is created**, so choose it with room to grow — see
[Choosing an Address Range](#choosing-an-address-range) before you start.
1. Go to **Network → VPC** and click **Create VPC**.
2. Fill in the dialog:
| Field | Required | Description |
|-------|----------|-------------|
| **VPC Name** | Yes | A name for the VPC, unique within the project. A suggested name is filled in for you — replace it if you like. |
| **IPv4 CIDR Block** | Yes | A valid private address range for the VPC, for example `172.16.231.0/24`. |
3. Click **Create VPC**.
The new VPC appears at the top of the list as **Creating**, and turns **Active** on its own once
it is ready.
### VPC Name
The name is just a label and can be changed later.
Use up to 50 characters: start with a letter, end with a letter or digit, and use letters,
digits, hyphens and underscores in between. It must be unique within your project.
---
## Choosing an Address Range
The range must be:
- inside `172.16.0.0/16` or `192.168.0.0/16`;
- between **/16** and **/28** in size;
- written as a network address, with the host portion bits set to zero.
| Value | Accepted |
|-------|----------|
| `172.16.231.0/24` | Yes |
| `192.168.0.0/16` | Yes |
| `172.16.231.5/24` | No — the host portion bits are not zero |
| `192.168.1.0/16` | No — the host portion bits are not zero |
### Ranges You Cannot Use
Some private ranges are already in use for platform networking and are not available to VPCs,
even though they are valid private ranges elsewhere:
| Range | Notes |
|-------|-------|
| `10.0.0.0/8` | **The entire block is currently unavailable for use.** No range inside `10.x.x.x` can be used for a VPC. |
| `172.30.0.0/16` | Unavailable. Reserved for internal use |
| `172.31.0.0/16` | Unavailable. Reserved for internal use |
Everything else inside `172.16.0.0/16` and `192.168.0.0/16` is available, so `172.16.231.0/24`
or `192.168.50.0/24` are safe starting points.
### Picking a Size
The range cannot be widened after the VPC is created, so size it for where you expect to be, not
where you are starting.
| If you expect | Consider |
|---------------|----------|
| A handful of resources, for a test or a demo | `/27` or `/26` |
| A normal project workload | `/24` — 247 usable addresses, and the most common choice |
| A large or growing deployment | `/22` or `/20` |
| To consolidate many workloads in one network | `/16` |
:::tip
A `/28` leaves you only seven usable addresses, which is easy to outgrow. When in doubt, take
the larger range. A range that is too small means
rebuilding the VPC and moving your workloads.
:::
---
## IP Addresses in a VPC
### Reserved Addresses
Every VPC sets aside nine addresses from its range for network services:
| Addresses | Reserved for |
|-----------|--------------|
| The **first eight** in the range (in a `/24` starting at `.0`, that is `.0` – `.7`) | Networking purposes & internal use (e.g., network ID) |
| The **last** in the range (in a `/24`, that is `.255`) | Networking purposes (e.g., broadcast address) |
These are not available to your resources. Everything else in the range is.
For a VPC on `172.16.231.0/24`, that means `172.16.231.0` through `172.16.231.7` and
`172.16.231.255` are reserved, leaving `172.16.231.8` – `172.16.231.254` for your workloads.
:::note
The nine addresses are taken once from the **whole** VPC range — not nine from every block
within it. A `/16` gives up the same nine addresses that a `/28` does.
:::
### How Many You Get
The **Available IPs** column in the VPC list reads as `available / assignable`.
| Term | Meaning |
|------|---------|
| **Assignable** | Every address the VPC can ever hand out — the size of the range, less the nine reserved addresses. |
| **Available** | How many of those are still free right now. |
| Size | Addresses in the range | Assignable |
|------|------------------------|------------|
| `/16` | 65,536 | 65,527 |
| `/20` | 4,096 | 4,087 |
| `/22` | 1,024 | 1,015 |
| `/24` | 256 | 247 |
| `/26` | 64 | 55 |
| `/27` | 32 | 23 |
| `/28` | 16 | 7 |
---
## Delete a VPC
Deleting a VPC removes the network and releases its address range. **This cannot be undone.**
Detach all resources from the VPC first — you cannot **Delete** the VPC unless any IP is still
attached to any resource.
---
## Status Values
| Status | What it means |
|--------|---------------|
| **Creating** | The VPC is being set up. It is not usable yet. |
| **Active** | The VPC is ready. |
| **Failed** | The VPC could not be set up and cannot be used. Delete it and try again. |
---
## Limits
| Limit | Default |
|-------|---------|
| VPCs per account, per region | **5** |
| Address range size | **/16** (largest) to **/28** (smallest) |
The VPC limit is counted across every project in your account for that region, not per project.
Contact support if you need it raised.
---
## Troubleshooting
| What you see | Why | What to do |
|--------------|-----|------------|
| *Enter a valid IPv4 CIDR, for example 172.31.0.0/24.* | The range is not valid CIDR notation, or its host portion bits is not zero. | Write it as a network address — `172.16.231.0/24`, not `172.16.231.5/24`. |
| *CIDR prefix must be between /16 and /28.* | The range is too large or too small. | Pick a size within those bounds. See [Picking a Size](#picking-a-size). |
| *A VPC must use a private IPv4 range.* | The range is outside the private blocks a VPC may use. | Choose a range inside `172.16.0.0/16` or `192.168.0.0/16`. See [Ranges You Cannot Use](#ranges-you-cannot-use). |
| A VPC stays on **Creating** | It is still being set up. | Give it a moment — it updates on its own. If it does not, raise a support ticket with the VPC name and region. |
| A VPC shows **Failed** | It could not be set up and cannot be used. | Delete it and create it again. Contact support if it happens repeatedly. |
| **Delete** is greyed out | Something is still using the VPC. | Remove or disconnect everything on it, then try again. |
| **Available IPs** is lower than you expected | Nine addresses in every VPC are reserved for networking. | See [Reserved Addresses](#reserved-addresses). |
| You need a bigger address range | A VPC's range is fixed when it is created. | Create a new VPC with a larger range and move your workloads to it. |
---
## Related Resources
- [VPC API reference](/api/tir/network/vpc/) — create, list, rename and delete VPCs programmatically.
- [VPC Connect](../VPC/VPC.mdx) — a separate feature for reserving a private IP from a **MyAccount** VPC and attaching it to a TIR resource.
- [Security Groups](../Security_Group/security_group.mdx) — traffic rules for TIR resources.
- [Reserve IP](../Reserve_IP/reserve_ip.mdx) — static public IP management.
---