Yandex Cloud
Search
Contact UsGet started
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
  • All Services
  • System Status
    • Featured
    • Infrastructure & Network
    • Data Platform
    • Containers
    • Developer tools
    • Serverless
    • Security
    • Monitoring & Resources
    • AI for business
    • Business tools
  • All Solutions
    • By industry
    • By use case
    • Economics and Pricing
    • Security
    • Technical Support
    • Start testing with double trial credits
    • Cloud credits to scale your IT product
    • Gateway to Russia
    • Cloud for Startups
    • Center for Technologies and Society
    • Yandex Cloud Partner program
  • Pricing
  • Customer Stories
  • Documentation
  • Blog
© 2025 Direct Cursus Technology L.L.C.
Yandex BareMetal
  • Getting started
    • All guides
    • Overview
      • Overview
      • Server configurations
      • Disk status analysis
      • Additional server settings
      • Overview
      • DHCP
      • MC-LAG
      • Restrictions in BareMetal networks
    • Images
    • Quotas and limits
    • All tutorials
    • Connecting an existing BareMetal server to Cloud Backup
    • Configuring VRRP for a cluster of BareMetal servers
    • Establishing network connectivity in a BareMetal private subnet
    • Establishing network connectivity between BareMetal and Virtual Private Cloud private subnets
    • Establishing network connectivity between a BareMetal private subnet and on-premise resources
    • Delivering USB devices to a BareMetal server or virtual machine
    • Configuring an OPNsense firewall in high availability cluster mode
    • Deploying a web app on BareMetal servers with an L7 load balancer and Smart Web Security protection
    • Connecting a BareMetal server as an external node to a Managed Service for Kubernetes cluster
  • Monitoring metrics
  • Audit Trails events
  • Access management
  • Pricing policy
  • FAQ

In this article:

  • MAC addresses
  • MTU and MSS
  • Bandwidth
  • Bandwidth model in a public network
  • Bandwidth between Baremetal and VPC
  • Storm Control
  • Blocked network ports
  1. Concepts
  2. Network
  3. Restrictions in BareMetal networks

Restrictions in BareMetal networks

Written by
Yandex Cloud
Updated at December 3, 2025
  • MAC addresses
  • MTU and MSS
  • Bandwidth
    • Bandwidth model in a public network
    • Bandwidth between Baremetal and VPC
  • Storm Control
  • Blocked network ports

There is a number of restrictions in BareMetal networks.

MAC addressesMAC addresses

Type of limit Quantity
MAC addresses per port 5

The limit on the number of MAC addresses is set separately for each server’s network interface. If you need more MAC addresses, create a request to support specifying the servers for which you need to increase the limit.

Request template
Subject: [BareMetal]: Changing limits on the number of MAC addresses

Request text:
Please change the limits on the number of MAC addresses for the following servers.

servers:
  - id: "ly5ckajdi38d********"
    mac_addresses: ["aa:bb:cc:dd:ee:ff"]
  - id: "ly5fy37fir9s********"
    mac_addresses: ["aa:bb:cc:dd:ee:fd", "aa:bb:cc:dd:ee:fc"]
mac_limit: 10

Note

Network ports with the connection speed of 1 Gbps do not support increasing the number of MAC addresses beyond the set limit.

MTU and MSSMTU and MSS

The following MTU and MSS limits apply to the service:

Type of limit Value, bytes
MTU in public network 1500
MSS in public network 1460
MTU in private network 8910
MSS in private network 8870

BandwidthBandwidth

Bandwidth model in a public networkBandwidth model in a public network

By default, in a public network, the following the bandwidth package is enabled for all BareMetal servers, including servers with over 1 Gbps NICs and servers with MC-LAG aggregation groups:

Data amount, TB per day Connection capacity, Gbps
10 1

Note

To request a bandwidth package of 100 TB, contact support.

To increase this amount, you can use a package with daily billing:

Data amount, TB per day Connection capacity, Gbps Note
100 10 You can use this package only for servers with 10 and 25 Gbps NICs.

Billing for increased bandwidth.

Bandwidth between Baremetal and VPCBandwidth between Baremetal and VPC

You can set up a connection between BareMetal and Virtual Private Cloud within the same region.

This connection has a default bandwidth limit of 10 Gbps for each user, regardless of the number of servers and their network card types. To request for a higher bandwidth, contact support.

Storm ControlStorm Control

The service is subject to the following broadcast traffic limits:

Type of limit Value,
packets per second (pps)
Broadcast 100
UnknownUnicast 100
Multicast 100

Blocked network portsBlocked network ports

The routers connecting BareMetal servers to the internet limit the incoming internet traffic to public server addresses on some TCP and UDP ports as well as the outgoing SMTP traffic. By blocking these ports you can protect the Yandex BareMetal infrastructure against malicious networking traffic.

Incoming traffic
Outgoing traffic
Port Application layer protocol Transport protocol
17 QOTD TCP, UDP
23 Telnet TCP
67–68 DHCP UDP
111 SUNRPC UDP
135–139 NetBIOS TCP, UDP
389 LDAP TCP, UDP
427 SLP TCP, UDP
445 SMB TCP, UDP
513 rlogin TCP
520 RIP UDP
631 IPP TCP, UDP
646 LDP TCP, UDP
750 Kerberos-IV UDP
1900 SSDP UDP
3702 WSD UDP
11211 memcached UDP

If the port you need is not in the table, use the Nmap utility to check if it is available on the BareMetal server OS side.

Port Application layer protocol Transport protocol
25 SMTP1 TCP

1 SMTP traffic is blocked to avoid unauthorized newsletters. We recommend using Yandex Cloud Postbox as an alternative for newsletters.

Was the article helpful?

Previous
MC-LAG
Next
Images
© 2025 Direct Cursus Technology L.L.C.