Yandex Cloud
Search
Contact UsGet started
  • Blog
  • Pricing
  • Documentation
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • ML & AI
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Customer Stories
    • Gateway to Russia
    • Cloud for Startups
    • Education and Science
  • Blog
  • Pricing
  • Documentation
Yandex project
© 2025 Yandex.Cloud LLC
Yandex BareMetal
  • Getting started
    • All guides
    • Service overview
      • Overview
      • Server configurations
      • Overview
      • DHCP
      • Restrictions in BareMetal networks
    • Quotas and limits
    • All tutorials
    • Connecting a BareMetal server to Cloud Backup
    • Configuring VRRP for a cluster of BareMetal servers
    • Setting up network connectivity in a BareMetal subnet
    • Setting up network connectivity between BareMetal and Virtual Private Cloud subnets
  • Monitoring metrics
  • Audit Trails events
  • Access management
  • Pricing policy
  • FAQ

In this article:

  • MAC addresses
  • MTU and MSS
  • Bandwidth
  • Storm Control
  • Blocked network ports
  1. Concepts
  2. Network
  3. Restrictions in BareMetal networks

Restrictions in BareMetal networks

Written by
Yandex Cloud
Updated at April 17, 2025
  • MAC addresses
  • MTU and MSS
  • Bandwidth
  • Storm Control
  • Blocked network ports

There is a number of restrictions in BareMetal networks.

MAC addressesMAC addresses

If you need more MAC addresses per port, contact support and describe the tasks that require the change.

Limit type Amount
MAC addresses per port 5

MTU and MSSMTU and MSS

The following MTU and MSS limits apply to the service:

Limit type Value, bytes
MTU in public network 1500
MSS in public network 1460
MTU in private network 8910
MSS in private network 8870

BandwidthBandwidth

Public networks have a 1 Gbps bandwidth limit for all servers, including those with 10 Gbps NICs.

Limit type Value, Gbps
Bandwidth in public network 1

Storm ControlStorm Control

The service is subject to the following broadcast traffic limits:

Limit type Value,
packets per second (pps)
Broadcast 100
UnknownUnicast 100
Multicast 100

Blocked network portsBlocked network ports

The routers connecting BareMetal servers to the internet limit the incoming internet traffic to public server addresses on some TCP and UDP ports as well as the outgoing SMTP traffic. By blocking these ports you can protect the Yandex BareMetal infrastructure against malicious networking traffic.

Incoming traffic
Egress
Port Application layer protocol Transport protocol
17 QOTD TCP, UDP
23 Telnet TCP
67–68 DHCP UDP
111 SUNRPC UDP
135–139 NetBIOS TCP, UDP
389 LDAP TCP, UDP
427 SLP TCP, UDP
445 SMB TCP, UDP
513 rlogin TCP
520 RIP UDP
631 IPP TCP, UDP
646 LDP TCP, UDP
750 Kerberos-IV UDP
1900 SSDP UDP
3702 WSD UDP
11211 memcached UDP

If the port you need is not in the table, use the Nmap utility to check if it is available on the BareMetal server OS side.

Port Application layer protocol Transport protocol
25 SMTP1 TCP

1 SMTP traffic is blocked to avoid unauthorized newsletters. We recommend using Yandex Cloud Postbox as an alternative for newsletters.

Was the article helpful?

Previous
DHCP
Next
Quotas and limits
Yandex project
© 2025 Yandex.Cloud LLC