# ONE 5.0.1 - Networking best practice

**URL:** https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578
**Category:** Product Support
**Created:** [July 15, 2016, 9:25am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578 "2016-07-15T09:25:31Z")
**Posts on this page:** 6
**Page:** 1

<div class="post-metadata">

### Author: ![heathen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/heathen/32/4720_2.png) [@heathen](https://forum.opennebula.io/u/heathen)
#### Post date: [July 15, 2016, 9:25am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/1 "2016-07-15T09:25:31Z")

</div>

Hi!

I would be very gratefull if somebody will be able to point me to any articles or even google search terms to find any info about OpenNebula multi-tenant network best practices.

For example, is it possible to give rights to a user group to create their own private networks with their own (private) IP space (and without oneadmin intervention) in a secure way - I mean, in a way where users will not be able to join other user group or system networks? Something like it’s possible with openstack.

Thank you in advance!

Best regards,  
Vladimir

---

<div class="post-metadata">

### Author: ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)
#### Post date: [July 15, 2016, 9:30am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/2 "2016-07-15T09:30:01Z")

</div>

[http://docs.opennebula.org/5.0/operation/network\_management/manage\_vnets.html#virtual-network-self-provisioning-reservations](http://docs.opennebula.org/5.0/operation/network_management/manage_vnets.html#virtual-network-self-provisioning-reservations)

---

<div class="post-metadata">

### Author: ![heathen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/heathen/32/4720_2.png) [@heathen](https://forum.opennebula.io/u/heathen)
#### Post date: [July 15, 2016, 9:52am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/3 "2016-07-15T09:52:55Z")

</div>

Thanks, ruben!

To be honest, I’ve read this chapter before. Do I understand it correctly that different users (group of users) will have an access to the reserved network parts of each other (cause they use the same bridge/VLAN configuration)?

Best regards,  
Vladimir

---

<div class="post-metadata">

### Author: ![ruben](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/ruben/32/19_2.png) [@ruben](https://forum.opennebula.io/u/ruben)
#### Post date: [July 18, 2016, 8:07am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/4 "2016-07-18T08:07:53Z")

</div>

Hi Vladimir,

You are right, In this case you setup a network and let users of the same  
group to get subnetworks from there.

If the users needs to access different isolated networks, the safer way is  
to pre-set the available network in your infrastructure and assigned them  
to the users. You could also let the users create the networks by updating  
the ACLs, but in this case they will need to define some low-level  
parameters…

Cheers

---

<div class="post-metadata">

### Author: ![DaD](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/dad/32/8466_2.png) [@DaD](https://forum.opennebula.io/u/DaD)
#### Post date: [July 19, 2016, 9:37am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/5 "2016-07-19T09:37:11Z")

</div>

heathen [opennebula@discoursemail.com](mailto:opennebula@discoursemail.com) writes:

> Hi!

Hello,

> I would be very gratefull if somebody will be able to point me to any articles or even google search terms to find any info about OpenNebula multi-tenant network best practices.
> 
> For example, is it possible to give rights to a user group to create their own private networks with their own (private) IP space (and without oneadmin intervention) in a secure way - I mean, in a way where users will not be able to join other user group or system networks? Something like it’s possible with openstack.

We openned a request[1] for this.

Regards.

Footnotes:  
[1] [Feature #3224: Authorize user/group to create restricted networks - OpenNebula - OpenNebula Development pages](https://dev.opennebula.org/issues/3224)

Daniel Dehennin  
Récupérer ma clef GPG: gpg --recv-keys 0xCC1E9E5B7A6FE2DF  
Fingerprint: 3E69 014E 5C23 50E8 9ED6 2AAD CC1E 9E5B 7A6F E2DF

---

<div class="post-metadata">

### Author: ![heathen](https://yyz1.discourse-cdn.com/flex031/user_avatar/forum.opennebula.io/heathen/32/4720_2.png) [@heathen](https://forum.opennebula.io/u/heathen)
#### Post date: [July 19, 2016, 10:28am UTC](https://forum.opennebula.io/t/one-5-0-1-networking-best-practice/2578/6 "2016-07-19T10:28:59Z")

</div>

Daniel,

thanks for the pointing, this feature is exactly what I was looking for. Will try to watch this request.

Best regards,  
Vladimir
