On this page
In this scenario:
- Devices are connected to the Internet
- The Internet connections are direct
- Devices communicate with each other via standard Equinix Metal networking
- Devices use both public and private IPs allocated by Equinix Metal
- Devices may be all in one metro or in multiple metros
This is the normal, default Equinix Metal scenario.
Each and every device receives a public IPv4 address and a private IPv4 address. Each device is on its own private subnet, to which just the device and its upstream router are connected.
The device can communicate with the Internet using its public address, and can communicate with other devices in the same project using its private address or the public address.
All packets bound for the Internet, upon reaching the upstream router, will be recognized as coming from the given device and passed onwards, while packets inbound from the Internet for the public address will be recognized and routed to the specific device.
Both the public and the private addresses are provided and managed by Equinix Metal.
This scenario requires no additional work on your behalf, as it is the standard Equinix Metal model. Simply deploy your devices.
If you wish to deploy devices in multiple metros while enabling communications between them, you have several options.
First, you can deploy the devices as-is, and use the public IP addresses to communicate between them. This may be sufficient if the communications use publicly available services anyways, such that they already are secure. It may also be sufficient if the communications need not be secure.
Second, you have the option of installing your own VPN.
- On one of the devices in each metro, install VPN services, such as openvpn or StrongSWAN.
- Create a VPN tunnel between the two devices over the Internet.
- Configure routing on each device, such that the addresses for the private range in the other metro is via the local VPN device.
Finally, and most simply for a secure channel, you can enable Backend Transfer. Backend Transfer is the Equinix Metal service that enables your devices in a single project to communicate with each other across metros using the Equinix-assigned private IP addresses.
Last updatedJanuary 30, 2024
Ready to kick the tires?
Sign up and get going today, or request a demo to get a tour from an expert.