IP Tunnel · France (GRA) or Germany (LIM)

Routed public IPv4 over WireGuard — anywhere

Get a real public IPv4 address, or a whole /29 or /28, delivered to any server or home lab over WireGuard. Inbound and outbound, even behind CGNAT, Starlink or 5G.

Single IP $2.50, /29 $10, /28 $18 per month, excl. VAT. 30-day paid pilot, best effort, no SLA.

  1. Your server or lab Behind CGNAT, Starlink, 5G or a home router
  2. WireGuard tunnel 198.51.100.8/29 France (GRA) or Germany (LIM)
  3. The internet Reaches you on your public IPs

Example block from a documentation range.

What people use it for

Behind CGNAT, Starlink or 5G

Carrier-grade NAT usually blocks inbound connections, so you cannot host anything reachable. A routed public IP over WireGuard gives your host an address the internet can connect to again.

Self-hosting

Run a web server, game server, VPN endpoint or mail server at home with a stable address that does not change when your ISP does. Port 25 opens after verification.

Small hosting providers

Add IPv4 space to your VMs or colocated servers without a new upstream contract. A /29 or /28 is routed to your gateway and you hand out addresses as you like.

Labs and test rigs work too: a public address for a CI lab, a router experiment or a demo box, up to 16 IPs per tunnel.

How it works

  1. Pick a size and a location

    A single IP (/32), a /29 with 8 IPs, or a /28 with 16 IPs, in France (GRA) or Germany (LIM). All are routed to your tunnel.

  2. Add the WireGuard config

    We send you the peer details. Put them on a Linux host, a router or a firewall that runs WireGuard, and bring the tunnel up.

  3. Use your public IPs

    Traffic to your addresses arrives through the tunnel, and traffic from your host leaves with your public IP as its source. You decide how to split the block between hosts, VMs and containers.

Choose France or Germany

Each tunnel terminates in Gravelines, France (GRA) or Limburg, Germany (LIM). Your addresses are announced from the country you pick, so your traffic enters and leaves the internet there. We publish the location of each block as geofeed data (RFC 8805); third-party geolocation databases update on their own schedule, so we cannot say how fast they follow.

Pick the location closer to you or to the people who connect to your hosts. The location is fixed once the address is assigned; changing it later means new addresses.

What a config looks like

An example for a host that sends all its traffic through the tunnel. Addresses come from documentation ranges; angle brackets mark values we or you fill in.

/etc/wireguard/penduses.conf
[Interface]
PrivateKey = <your-private-key>
# Your routed public IP. With a /29 or /28, use your block instead,
# for example 198.51.100.8/29
Address = 198.51.100.9/32

[Peer]
PublicKey = <penduses-public-key>
Endpoint = <endpoint-from-your-welcome-email>:51820
# Send all traffic through the tunnel
AllowedIPs = 0.0.0.0/0
# Keeps the tunnel open behind CGNAT
PersistentKeepalive = 25
shell
sudo wg-quick up penduses
curl https://api.ipify.org
# prints your routed public IP, for example 198.51.100.9

Routing everything through the tunnel changes how you reach the host, so keep console access handy for the first run. For a /29 or /28, the block is routed to your WireGuard peer and you decide how to distribute it: assign addresses to VMs or containers, or route it onward to other machines.

Pricing

Per month, excl. VAT. Every tunnel includes 1 TB of fair-use traffic, and you choose France (GRA) or Germany (LIM) when you order.

Single IP

$2.50 / month, excl. VAT

Works out at $2.50 per IP

  • 1 routed public IPv4 address (/32)
  • Inbound and outbound over WireGuard
  • Geolocation of your choice: France (GRA) or Germany (LIM)
  • 1 TB fair-use traffic per tunnel
  • rDNS on request; port 25 closed by default
Join the waitlist Single IP

/29 block

$10 / month, excl. VAT

Works out at $1.25 per IP

  • 8 routed public IPv4 addresses (/29)
  • Inbound and outbound over WireGuard
  • Geolocation of your choice: France (GRA) or Germany (LIM)
  • 1 TB fair-use traffic per tunnel
  • rDNS on request; port 25 closed by default
Join the waitlist /29 block

/28 block

$18 / month, excl. VAT

Works out at $1.13 per IP

  • 16 routed public IPv4 addresses (/28)
  • Inbound and outbound over WireGuard
  • Geolocation of your choice: France (GRA) or Germany (LIM)
  • 1 TB fair-use traffic per tunnel
  • rDNS on request; port 25 closed by default
Join the waitlist /28 block

What “pilot” means here

  • A paid 30-day pilot. We confirm every order by email and start the 30 days when your service is ready.
  • Best-effort service with no SLA and no service credits.
  • Support is asynchronous, by email, in business hours (Monday to Friday, 09:00 to 17:00 Central European Time).
  • Incidents and planned work are posted on the status page.
  • Prices are pilot prices and may change after the pilot.

Questions

Is port 25 open?

No, port 25 is closed by default to keep our address space in good standing. We can open it after verification: tell us what you plan to send and from which hostname, and we will check before opening it.

Can I get reverse DNS (rDNS)?

Yes, on request. Send us the hostname you want for each address; it should resolve back to the same IP.

What is your abuse policy?

Short version: you are responsible for everything that leaves your addresses. If we see abuse, or receive a credible report at abuse@penduses.com, we suspend first and talk afterwards, and we aim to review reports within 24 hours. A misbehaving address can be taken out of service and quarantined. Read the full acceptable use policy and the abuse process.

Do I have to be behind CGNAT?

No. Any server, router or lab that can run WireGuard and reach our endpoint can use a tunnel, whether or not it sits behind CGNAT.

What can I run it on?

Anything that runs WireGuard: Linux, BSD, and many routers and firewalls. You need a device that can bring the tunnel up and route the addresses.

What about latency?

Your traffic takes a round trip through the location you choose, Gravelines or Limburg. If that is far from you or from your users, expect the extra distance to show up in latency. Pick the closer one.

Can I take the addresses with me if I leave?

No. The addresses belong to our RIPE-registered space and are routed to you for as long as you are a customer.

I run a hosting business. Can I give the IPs to my customers?

You can assign addresses to your own customers’ servers. You stay responsible for their conduct under the acceptable use policy. Reselling tunnel access itself is not allowed.

Is there a service-level agreement?

No. The pilot is best effort with no SLA. Incidents are posted on the status page.