Behind CGNAT, Starlink or 5G
Carrier-grade NAT usually blocks inbound connections, so you cannot host anything reachable. A routed public IP over WireGuard gives your host an address the internet can connect to again.
IP Tunnel · France (GRA) or Germany (LIM)
Get a real public IPv4 address, or a whole /29 or /28, delivered to any server or home lab over WireGuard. Inbound and outbound, even behind CGNAT, Starlink or 5G.
Single IP $2.50, /29 $10, /28 $18 per month, excl. VAT. 30-day paid pilot, best effort, no SLA.
198.51.100.8/29
France (GRA) or Germany (LIM)
Example block from a documentation range.
Carrier-grade NAT usually blocks inbound connections, so you cannot host anything reachable. A routed public IP over WireGuard gives your host an address the internet can connect to again.
Run a web server, game server, VPN endpoint or mail server at home with a stable address that does not change when your ISP does. Port 25 opens after verification.
Add IPv4 space to your VMs or colocated servers without a new upstream contract. A /29 or /28 is routed to your gateway and you hand out addresses as you like.
Labs and test rigs work too: a public address for a CI lab, a router experiment or a demo box, up to 16 IPs per tunnel.
A single IP (/32), a /29 with 8 IPs, or a /28 with 16 IPs, in France (GRA) or Germany (LIM). All are routed to your tunnel.
We send you the peer details. Put them on a Linux host, a router or a firewall that runs WireGuard, and bring the tunnel up.
Traffic to your addresses arrives through the tunnel, and traffic from your host leaves with your public IP as its source. You decide how to split the block between hosts, VMs and containers.
Each tunnel terminates in Gravelines, France (GRA) or Limburg, Germany (LIM). Your addresses are announced from the country you pick, so your traffic enters and leaves the internet there. We publish the location of each block as geofeed data (RFC 8805); third-party geolocation databases update on their own schedule, so we cannot say how fast they follow.
Pick the location closer to you or to the people who connect to your hosts. The location is fixed once the address is assigned; changing it later means new addresses.
An example for a host that sends all its traffic through the tunnel. Addresses come from documentation ranges; angle brackets mark values we or you fill in.
[Interface]
PrivateKey = <your-private-key>
# Your routed public IP. With a /29 or /28, use your block instead,
# for example 198.51.100.8/29
Address = 198.51.100.9/32
[Peer]
PublicKey = <penduses-public-key>
Endpoint = <endpoint-from-your-welcome-email>:51820
# Send all traffic through the tunnel
AllowedIPs = 0.0.0.0/0
# Keeps the tunnel open behind CGNAT
PersistentKeepalive = 25
sudo wg-quick up penduses
curl https://api.ipify.org
# prints your routed public IP, for example 198.51.100.9
Routing everything through the tunnel changes how you reach the host, so keep console access handy for the first run. For a /29 or /28, the block is routed to your WireGuard peer and you decide how to distribute it: assign addresses to VMs or containers, or route it onward to other machines.
Per month, excl. VAT. Every tunnel includes 1 TB of fair-use traffic, and you choose France (GRA) or Germany (LIM) when you order.
$2.50 / month, excl. VAT
Works out at $2.50 per IP
$10 / month, excl. VAT
Works out at $1.25 per IP
$18 / month, excl. VAT
Works out at $1.13 per IP
No, port 25 is closed by default to keep our address space in good standing. We can open it after verification: tell us what you plan to send and from which hostname, and we will check before opening it.
Yes, on request. Send us the hostname you want for each address; it should resolve back to the same IP.
Short version: you are responsible for everything that leaves your addresses. If we see abuse, or receive a credible report at abuse@penduses.com, we suspend first and talk afterwards, and we aim to review reports within 24 hours. A misbehaving address can be taken out of service and quarantined. Read the full acceptable use policy and the abuse process.
No. Any server, router or lab that can run WireGuard and reach our endpoint can use a tunnel, whether or not it sits behind CGNAT.
Anything that runs WireGuard: Linux, BSD, and many routers and firewalls. You need a device that can bring the tunnel up and route the addresses.
Your traffic takes a round trip through the location you choose, Gravelines or Limburg. If that is far from you or from your users, expect the extra distance to show up in latency. Pick the closer one.
No. The addresses belong to our RIPE-registered space and are routed to you for as long as you are a customer.
You can assign addresses to your own customers’ servers. You stay responsible for their conduct under the acceptable use policy. Reselling tunnel access itself is not allowed.
No. The pilot is best effort with no SLA. Incidents are posted on the status page.