Fibmesh Outbound

Choose your internet exit.

Route internet traffic through a Fibmesh exit over your existing connection. Request an agreed stable or dedicated source when external services require one.

For people & workloads using external services

Available

The route is the product

Your connection gets you online. Fibmesh provides the exit.

Where does the request go?Interactive explanation · no settings change

Without the Fibmesh exit

  1. Your deviceStarts the request
  2. Existing ISPOrdinary public source
  3. Internet serviceSees the ISP-side source

Traffic takes the ordinary internet route. The service sees the public source provided by the existing connection, which can change when you change networks.

An internet connection remains necessary in every scenario.

A new exit over the connection you already have

  1. Your devicePrivate tunnel identity
  2. WireGuard over your ISPEncrypted tunnel to Fibmesh
  3. Fibmesh exitPublic outgoing source
  4. Internet serviceSees the exit source

The supported full-tunnel profile directs eligible internet traffic to the Fibmesh exit. A stable or dedicated source requires an agreed allocation; ordinary exit routing does not promise either.

The tunnel ends at Fibmesh. HTTPS continues to protect an HTTPS session between the application and its destination.

The current profile model uses full-tunnel routing. It does not offer an application picker or destination-by-destination rules. Local, private and operating-system exceptions need to be checked for the supported platform.

Follow the route, including the return path →

Choose the source you need

An exit address is not always a reserved address.

01 / Regular exit

A chosen internet path

Route through the supported Fibmesh exit. A regular exit does not promise a fixed address or exclusive use of its public IP.

02 / Stable source

An address others recognise

For an API or service with a source-IP allowlist. Confirm the assigned address and continuity terms before the provider adds it to a rule.

03 / Dedicated source

An address for your use

For deployments that need exclusive use of the outgoing address. Allocation, region and retention terms need an explicit agreement.

Stable describes continuity. Dedicated describes exclusivity. Neither term means that the public address is installed directly on your device, or that incoming connections to it reach your device.

Put the exit to work

A common way out for work that moves.

Colleagues working from laptops in a bright shared workspace

Illustrative scenario / external service access

A changing workplace. An agreed source identity.

When an external provider requires an IP allowlist, an agreed stable exit can give supported working devices a recognised source. Confirm the full-tunnel scope before setup.

  1. Working laptop
  2. Agreed Fibmesh exit
  3. Allowlisted service
Illustrative image and scenario.

Reconnecting as your underlying connection changes may interrupt sessions. The provider’s application login still applies.

Servers calling external APIs

A worker running at an office, in a cloud or on your own server can call a provider through a known exit. Check the impact on its other internet traffic before changing the default route.

A whole site needs a supported routing gateway and a deliberate LAN configuration. Connecting a Fibmesh device to a spare router port does not automatically redirect everyone’s traffic.

Work through a provider allowlisting example →

Choose once, for the right reason

Public IPs gives you an address. Outbound gives you an exit.

Both can provide an outgoing source that an external service recognises. Choose by how you want to deliver and operate the connection.

Swipe the table sideways to see all columns.

Your requirement Start here Why
Send a device’s internet traffic through a Fibmesh exit Outbound Manage the exit through its routing profile.
Give a server, router or gateway its own public address Public IPs The address is assigned to your infrastructure.
Use a recognised source for an external allowlist Either, depending on delivery Outbound can use an agreed stable exit; Public IPs can use the assigned address for outgoing traffic.
Accept incoming connections, or route a public subnet Public IPs Outbound does not publish a device or deliver a subnet.
Use an assigned public source for selected destinations Public IPs, with the supported routing mode Outbound’s current profile model is full tunnel.

A stable-source requirement does not require both products. If an existing Public IP assignment already covers your incoming and outgoing needs, a second exit service may add nothing.

Compare address delivery and traffic modes →

Before the first connection

Agree the exit. Check the whole path.

Prerequisites: an eligible workspace, a supported client or gateway, a working internet connection and a provisioned exit. Confirm the region, IPv4 and IPv6 handling, DNS, address terms and recovery procedure. Release availability is verified by platform and deployment.

Do I need Networks or a Public IP first?

No. Outbound is a separate product journey. Private access, public address delivery and application publishing are optional capabilities with their own policies.

Does this add a firewall, filtering or anonymous browsing?

The tunnel changes the route. It does not establish web filtering, malware inspection, a secure web gateway or anonymity. Continue to use HTTPS, application authentication and host firewall controls.

What happens if the tunnel disconnects?

Do not assume traffic will be blocked. A kill switch is not a verified current capability. Agree and test interruption behaviour before using an exit for traffic that must never take the ordinary ISP path.

Prepare your first Outbound connection →

Compare all four products and choose the right fit →