Networking on your own server comes down to three jobs: giving the server the right IP addresses, pointing your domain names at them, and checking that traffic flows the way you expect. This guide covers each job on a Linux VPS or dedicated server, using the modern tools that ship with current Ubuntu, Debian, AlmaLinux and Rocky Linux releases.
Everything below applies to a VPS or dedicated server where you have root access. On shared hosting (cPanel, DirectAdmin, Webuzo) the server's network, IP addresses and firewall are managed by Domain India and cannot be changed from your account; there you only manage DNS records for your domain.
Check addresses with ip addr, and make changes permanent in your distribution's own network configuration: netplan on Ubuntu, NetworkManager on AlmaLinux and Rocky Linux, and usually ifupdown on Debian. Point your domain at the server with A (IPv4) and AAAA (IPv6) records. Reverse DNS (PTR) belongs to whoever owns the IP address, so for a Domain India VPS it is set through us, not in your own DNS zone. Troubleshoot with ping, mtr, ss and dig, and keep the firewall closed to everything you do not serve.
1. The IP address basics you need
- Public IP address: reachable from the internet. Your VPS gets at least one public IPv4 address, and this is the address your DNS records point to.
- Private IP address: used only inside a private network, from ranges such as
10.0.0.0/8,172.16.0.0/12and192.168.0.0/16. The internet cannot reach these directly. - Static vs dynamic: a server needs a static address that does not change. Dynamic addresses, handed out by DHCP, suit laptops and home connections.
- IPv4 vs IPv6: IPv4 addresses look like
203.0.113.10; IPv6 addresses look like2001:db8::10. IPv6 has a vastly larger address space. Run both if your server has both, and test each one separately.
For the terms themselves (gateway, subnet, netmask and CIDR), see demystifying network terms.
2. See what your server has now
Start by reading the current state before you change anything:
ip -br addr # every interface and its addresses, one line each
ip route # the default gateway and routes
resolvectl status # DNS resolvers in use (on systemd-resolved systems)Note the interface name. Modern systems use names like ens3 or enp1s0 rather than eth0, so copy the real name from the output instead of assuming.
3. Add or change an IP address
A command such as ip addr add changes the running system only, and the change is lost at the next reboot. Use it to test, then write the change into the configuration your distribution actually uses.
# temporary, for testing only
sudo ip addr add 203.0.113.11/24 dev ens3| Distribution | Where permanent network settings live | Apply with |
|---|---|---|
| Ubuntu 22.04 / 24.04 | YAML files in /etc/netplan/ | sudo netplan try, then sudo netplan apply |
| AlmaLinux / Rocky Linux 9 | NetworkManager connection profiles | nmcli connection modify, then nmcli connection up |
| Debian 12 / 13 | /etc/network/interfaces on most installs | sudo systemctl restart networking, or a reboot |
On Ubuntu, a second address goes in the netplan file under your interface, for example:
network:
version: 2
ethernets:
ens3:
addresses:
- 203.0.113.10/24
- 203.0.113.11/24On AlmaLinux or Rocky Linux:
sudo nmcli connection modify ens3 +ipv4.addresses 203.0.113.11/24
sudo nmcli connection up ens3A wrong gateway or netmask cuts off your SSH session. Use netplan try, which rolls back automatically unless you confirm, and keep your provider's console open while you change networking. If the server was built with cloud-init, it may rewrite its own network file at boot; put your changes in a separate file or follow the comment at the top of the generated file. The old /etc/sysconfig/network-scripts files are deprecated on AlmaLinux and Rocky Linux 9, and CentOS Linux has reached end of life.
Only add addresses that are actually assigned to your server. An address your provider has not routed to you will not work, and using someone else's address causes an IP conflict.
4. Connect domain names to your IP addresses
DNS turns names into addresses. For a server you run yourself, these records do most of the work:
| Record | What it does | Example |
|---|---|---|
| A | Points a name at an IPv4 address | example.com to 203.0.113.10 |
| AAAA | Points a name at an IPv6 address | example.com to 2001:db8::10 |
| CNAME | Makes one name an alias of another | www.example.com to example.com |
| MX | Names the mail server for the domain | example.com to mail.example.com |
| TXT | Holds text such as SPF, DKIM and verification codes | v=spf1 ip4:203.0.113.10 -all |
| PTR | Reverse DNS: maps an IP address back to a name | 203.0.113.10 to mail.example.com |
Add A, AAAA, CNAME, MX and TXT records wherever your domain's DNS is managed. How to find and edit that zone is in how to change your domain DNS settings, and what nameservers do is explained in what is a nameserver. If you want your own branded nameservers, see registering and managing child name servers.
TTL (time to live) controls how long resolvers may cache a record. Before a planned move to a new IP address, lower the TTL to a few minutes, wait for the old TTL to pass, make the change, then raise the TTL again. Changes to nameservers themselves can take longer to spread, because the parent zone's caching also applies.
5. Reverse DNS (PTR) for mail servers
A PTR record answers the question "which name belongs to this IP address?". Receiving mail servers check it, and mail from an IP address with no PTR, or a generic one, is often rejected or sent to spam.
The PTR record lives with the owner of the IP address, not in your domain's zone. For a good setup:
- Choose the mail hostname, for example
mail.example.com, and give it an A record pointing at the server's IP address. - Set the PTRfor that IP address to the same name, so forward and reverse lookups match.
- Set the server's own hostnameto that name as well.
On a Domain India VPS, you set PTR records for your IP addresses from the client area. If you cannot find the option for your server, open a support ticket with the IP address and the hostname you want. Check the result with dig -x 203.0.113.10 +short.
6. Test and troubleshoot connectivity
| Tool | Use it to | Example |
|---|---|---|
| ping | Check that a host answers at all | ping -c 4 example.com |
| mtr | See where along the path packets are lost | mtr -rw example.com |
| ss | List listening ports and connections (replaces netstat) | sudo ss -tulpn |
| dig | Query DNS records directly | dig +short A example.com |
| ip neigh | Show neighbours on the local network (replaces arp -a) | ip neigh |
| curl -v | Test a web service end to end | curl -v https://example.com |
Common problems and where to look:
- The server does not answer: check the firewall first, then that the service is actually listening with
ss -tulpn, then the path withmtr. - The domain opens the wrong server: query the record with
dig, compare it with your server's IP address, and check the TTL you are waiting on. - A service works on IPv4 but not IPv6: check the AAAA record, the IPv6 address on the interface, and the IPv6 rules in your firewall. Many firewalls keep separate rule sets for each.
- Mail is rejected as spam: check the PTR, SPF, DKIM and DMARC records together.
- IP conflict: two machines using one address. On a VPS this usually means an address was typed wrongly; use only the addresses assigned to your server.
7. Keep the network secure
- Firewall: allow only what you serve, typically SSH plus 80 and 443 for a web server. On Ubuntu,
ufwis the simple front end; AlmaLinux and Rocky Linux usefirewalld. Both drive nftables underneath, which has replaced raw iptables rules on current releases. - SSH: use key logins, disable password login, and restrict SSH to your own IP addresses where you can.
- Databases and caches: bind MySQL, PostgreSQL and Redis to
127.0.0.1or a private network. Never leave them open to the internet; reach them through an SSH tunnel. - VPN for admin access: for private dashboards, a VPN such as WireGuard is safer than exposing more ports.
- DNSSEC protects DNS answers from forgery. It is set up where your DNS is hosted and at the registrar. To add DNSSEC to a domain registered with Domain India, ask support.
8. Where Domain India fits
Domain India VPS plans are KVM virtual servers with full root access. They are self-managed: you look after the operating system, networking, firewall and software yourself, using guides like this one. Every plan includes at least one IPv4 address; VPS Pro includes 2 and VPS Enterprise 4. The cards show live prices, excluding 18% GST.
- 1 vCPU
- 2 GB DDR4 RAM
- 64 GB NVMe SSD Storage
- 2 TB Monthly Bandwidth
- 2 vCPU
- 4 GB DDR4 RAM
- 128 GB NVMe SSD Storage
- 3 TB Monthly Bandwidth
If you only need a website and email, shared hosting is simpler, because we run the server and its network for you. If you are deploying an application, the App Platform runs it for you without a server to manage.
Frequently asked questions
Why does my new IP address disappear after a reboot?
Commands such as ip addr add change only the running system. Write the address into your distribution's network configuration: netplan on Ubuntu, NetworkManager on AlmaLinux and Rocky Linux, or /etc/network/interfaces on most Debian installs.
Where do I set reverse DNS for my VPS?
Reverse DNS (PTR) is set by the owner of the IP address, not in your domain's DNS zone. On a Domain India VPS, use the option in the client area if it is shown for your server, or open a support ticket with the IP address and hostname.
How long do DNS changes take?
A changed record is seen everywhere once cached copies expire, which depends on the record's TTL. Lower the TTL before a planned change. Nameserver changes can take longer because the parent zone is cached too.
Can I change IP addresses or firewall rules on shared hosting?
No. On shared hosting the server's network and firewall are managed by Domain India. You manage DNS records for your domain; for anything else, open a support ticket.
Is netstat still the right tool?
It still exists on some systems, but ss, from the iproute2 package, has replaced it on current Linux distributions. Use ss -tulpn to see which services are listening.
Are Domain India VPS plans managed?
VPS plans are self-managed by default. You have full root access and look after the operating system, networking, security and software yourself.
Ready to run your own server? Compare VPS plans, read demystifying network terms for the vocabulary, or open a support ticket for reverse DNS on your VPS.
KVM virtual servers with NVMe storage, at least one IPv4 address and full root access.
See VPS plans