CloudrawSetup guides
Download PDF
Apps & networks · For IT admins

Give access to a whole network (private networks)

Give trusted devices access to whole IP ranges and their DNS names through one Cloudraw connector, including when home and office ranges overlap.

Last updated 7 October 2026 · Download this guide as PDF

Overview

Most of the time you publish one app at a time: one website, one remote desktop, one file server. Some older systems need more than that. A Windows domain, a printer subnet or a set of servers that talk on many ports is easier to give as a whole network.

A private network in Cloudraw is:

  • one or more IP ranges, for example 10.20.0.0/16,
  • optionally the DNS names of that environment, for example corp.local,
  • reached through one Cloudraw connector (or up to five, for failover).

Because a whole network is broad access, Cloudraw is stricter with it than with a single app:

  • Nobody can reach a new private network until you add an access rule.
  • Each access rule gives one network. There is no rule for "all networks".
  • By default only trusted devices can reach it.
Tip

If people need only one or two systems, publish those as apps instead. Apps give narrower access and show up by name in Cloudraw Connect.

You need

  • A Cloudraw connector inside that network, or one that can route to it.
  • The Owner, Security admin or Connector operator role in the Cloudraw admin console.
  • A workspace can have up to 5 private networks by default.

Step 1. Add a private network

  1. Open private networksIn the Cloudraw admin console go to Private networks→Add private network.
  2. Fill in the fieldsUse the table below.
  3. SaveCloudraw sets up the network in a few seconds. Its page then says that no one can reach it yet. Go on to step 2.
FieldWhat to enterRequired
NameFor example Head office. Up to 64 characters.Yes
ConnectorThe connector that reaches this network. You cannot change it later. To move the network, create a new one on the other connector. You can add up to four more connectors for failover.Yes
IP ranges1 to 32 ranges in CIDR form, for example 10.20.0.0/16. See Writing IP ranges.Yes
DNS zonesUp to 10 domain names of that environment, for example corp.local. Subdomains are included automatically, so do not type *.corp.local.No
DNS serversUp to 4 IP addresses of that environment's DNS servers, usually your domain controllers. Each must be inside one of the IP ranges.No
Protocols and portsTCP and UDP on all ports by default. You can limit them, with up to 20 port ranges.No
Require a trusted deviceOn by default. See step 2.No
Translate addressesOff by default. See overlapping ranges.No

DNS zones and DNS servers

How names are found depends on whether you add DNS servers:

You addWhat happensGood for
DNS zones onlyThe connector looks up names in those zones with its own DNS. Only normal address records are returned.Reaching servers by name, for example remote desktop to fs01.corp.local.
DNS zones and DNS serversQuestions for those zones go through Cloudraw to your own DNS servers, so all record types come back.Active Directory tasks that need full DNS, such as a domain join.

The network's page shows a note that explains which of these applies. Read it after you save.

Writing IP ranges

Write each range as address/size, where the address is the first address of the range.

RangeCovers
192.168.51.0/24192.168.51.0 to 192.168.51.255 (256 addresses)
10.20.0.0/16All of 10.20.x.x
10.0.0.0/8All of 10.x.x.x. This is the widest range allowed.
192.168.51.20/32One address

Typos Cloudraw catches

If the address is not the first address of the range, Cloudraw does not guess. It tells you and suggests the two most likely ranges:

You typeCloudraw says
192.168.51.0/16"192.168.51.0/16" is not a network address. Did you mean 192.168.51.0/24 (192.168.51.x) or 192.168.0.0/16 (all of 192.168.x.x)?
10.20.1.0/16Did you mean 10.20.1.0/24 (10.20.1.x) or 10.20.0.0/16 (all of 10.20.x.x)?

The first suggestion is usually what you meant: the range that starts at the address you typed. Pick one and save again.

Ranges Cloudraw refuses

  • 0.0.0.0/0 and anything wider than /8. Split it into the ranges you really need.
  • Loopback (127.0.0.0/8), link-local (169.254.0.0/16), multicast and other reserved ranges.
  • Anything inside 100.64.0.0/10. Cloudraw Connect uses that range itself.
  • Two ranges in the same network that overlap each other.
  • A range that overlaps a range of another private network in your workspace.

Step 2. Give access, trusted devices only

  1. Add an access ruleIn Access rules, add a rule that allows a group, for example IT staff, to reach this private network. One rule gives one network.
  2. Make sure their computers are trustedWith Require a trusted device on, a device must be in the group and trusted. A device that is not trusted stays blocked, even if the person is in the group. Set up trust rules under Device trust, or trust computers one by one in Devices. See What "trusted device" means.
  3. TestOn a trusted computer in that group, connect with Cloudraw Connect and reach an address in the range, for example with remote desktop or ping.
Important

Leave Require a trusted device on unless you have a clear reason. A whole network is much more than one app. A personal or unknown computer should not get it.

To see why a device can or cannot reach the network, use the access explanation for that device in the console. It names the step that blocks it. When you delete a private network, its access rules are removed too.

When home and office ranges overlap

Many home routers use 192.168.0.0/24 or 192.168.1.0/24. If your office uses the same range, a computer at home cannot tell which 192.168.1.20 is meant: the printer at home or the server at the office.

Translate addresses solves this. Cloudraw gives the office network a second, unique range from 100.65.0.0/16. People reach the office through that range, and their home network keeps working as before.

How it works

  • The translated range has the same size as the office range. The last part of each address stays the same.
  • For example, the office range 192.168.1.0/24 might get 100.65.0.0/24. Then 100.65.0.20 reaches the office server 192.168.1.20.
  • The connector sends the traffic to the real office address. Nothing changes on the office side.
  • The network keeps its translated range. Each range is given out once in your workspace and is never reused.

Turn it on

  1. Check the rangeTranslation works when the network has exactly one IP range, between /16 and /30.
  2. Update Cloudraw ConnectEveryone who uses this network needs Cloudraw Connect 0.4.1 or newer. Older versions cannot reach a translated network.
  3. Turn on Translate addressesOn the network's page, turn on Translate addresses and save. The page then shows the range people use, for example reached as 100.65.0.0/24.
  4. Tell your peopleGive them the new addresses, or better, the names.

How people reach it

  • By name: names in the network's DNS zones, such as fs01.corp.local, keep working. This is the easiest way.
  • By address: use the translated address, for example 100.65.0.20 instead of 192.168.1.20.
Limits
  • With translation on, names are always looked up by the connector. Questions are not sent to the network's own DNS servers, so a domain join through this network is not possible.
  • Programs that put IP addresses inside their own data can fail, for example active FTP, SIP phones and LDAP referrals by IP address.
  • If you turn translation off and on again, or change the range to a different size, the network gets a new translated range. Tell your people the new addresses.

Turn translation on for common home ranges such as 192.168.0.0/24, 192.168.1.0/24 and 10.0.0.0/24.

Troubleshooting

Message or symptomCause and fix
Console: "… is not a network address. Did you mean …?"The address is not the first address of the range. Pick one of the suggestions. See Writing IP ranges.
Console: "… is not an IPv4 CIDR (expected a.b.c.d/nn)"Write the range as an address, a slash and a size, for example 10.20.0.0/16.
Console: "… is broader than /8; split it into the ranges you actually need" or "0.0.0.0/0 is not allowed"A private network cannot cover the whole internet or more than a /8. Add the smaller ranges you need.
Console: "… overlaps the client tunnel's own address range (100.64.0.0/10)"Cloudraw Connect uses that range. If your office really uses it, contact support.
Console: "… overlaps … of private network "X""Another private network already covers part of this range. Change one of them so they do not overlap.
Console: "… is not inside any of the private network's cidrs"A DNS server must be inside one of the network's IP ranges. Add its range, or remove the server.
Console: "give the zone itself (e.g. corp.local), not a wildcard"Type corp.local. Subdomains are included.
Console: "address translation needs exactly one range" or "works for ranges from /16 to /30"Translation needs one range of a supported size. Split the network into several private networks, one range each.
Console: "This workspace has used all translated address ranges."All of 100.65.0.0/16 has been given out. Contact support.
Console: "this workspace allows 5 private network(s)"You reached your plan's limit. Remove a network you no longer need, or contact support.
A person in the group cannot reach the networkTheir device is probably not trusted. Check the device in Devices, or use the access explanation for that device.
The network page says no one can reach itThere is no access rule for it yet. Add one in Access rules.
At home, the office address reaches the home router or nothing at allThe home network uses the same range as the office. Turn on Translate addresses, and use the translated address or the name.
Translation is on, but nothing works for one personTheir Cloudraw Connect is older than 0.4.1. Update it.
Names work, but a domain join or other Active Directory task failsAdd the domain controllers as DNS servers, and make sure translation is off for this network.