Skip to main content

Private networks

Your devices and labs meet on a private network. Most people only ever use the shared one and never need this page. It matters when you want to keep an address, or when an organization wants its own network that only its members' devices and labs join.

Go to Connectivity → My Network. It has two tabs.

IP Addresses

Every address you have reserved, with the network it belongs to and the device it is linked to — or Unallocated if no device holds it right now.

ActionEffect
Reserve an addressFrom the device's menu on My DevicesReserve IP, or tick Reserve IP when Allocated when adding a device
Reuse a reserved addressChoose it under Reallocate IP when adding a device, or on a lab's Preferences
DeleteReleases the reservation. The address goes back to the pool and you may not get it again.
Reserve before you depend on it

If anything points at a fixed address — an SSH config, a firewall rule, a script — reserve that address first. Unreserved addresses can change.

WG Interfaces

The private networks you can use.

The WG Interfaces tab showing the public network card and one owned network card with its Share and Delete buttons.
Card badgeMeaning
Public network — everyoneThe shared network every account uses by default
OwnedA network you, or the organization you are acting as, created
Shared with youSomeone shared their network with you

Each card shows the network's range, its name inside machines, its status and how many peers (devices and labs) are on it.

Create a network

Creating a network is an organization feature. On a personal account the Create interface button explains this: create or join an organization, or ask an administrator to enable it for your account.

In an organization or department:

  1. On WG Interfaces, click Create interface.

  2. Fill in the dialog:

    FieldWhat to enter
    Display nameHow the network appears in lists, e.g. Engineering VPN
    CIDRThe private range it hands out, e.g. <private-range>/24. It must not overlap networks your labs also join.
    Listen portOptional — picked automatically if left empty
    Name inside machinesOptional, up to 15 characters — what the network is called inside your labs
  3. Click Create.

Each organization or department can create a small number of networks. When you reach it, you see Interface limit reached.

Share a network

On a network you own, click Share and choose a person, workgroup, organization or department. They can then attach their devices and labs to it. Revoke removes that access.

Delete is disabled while any device or lab is still on the network — remove them first.

Put a device on a network

When you add a device, the Network field appears once you have more than the public network. Pick the network the device should join.

Put a lab on networks

A lab's Preferences has WG Networks tiles: the Default network plus every network you can use. Select one to four. The lab joins every selected network on its next redeploy.

Selected networks must not overlap in address range.

Default networks for an organization

Organization and department admins can choose default networks — shown at the top of WG Interfaces, and also in Account Settings while acting as the organization. Labs owned by the organization that do not pick networks themselves join all of the selected defaults (up to 4). Clearing every box falls back to the public network.

Do it with an AI assistant

You can also do this by asking an AI assistant connected to your account — see Connect an AI assistant to set one up.

AskWhat the assistant does
“Can I create a private network?”list_networks, which says whether you can make one
“Create a private network called Engineering VPN”list_networks, then create_network
“Share it with priya@example.comshare_network
“Put my lab on that network”configure_lab_runtime, then deploy_lab
Do not retry a network that did not come up

If the assistant reports a network was created but not provisioned, stop and tell an administrator — trying again spends another of your networks. When sharing, give an email address rather than a username; a mistyped name is stored as a grant rather than refused.

Next

  • Devices — reserving and managing device addresses
  • Organizations — the feature that unlocks private networks