Fibmesh Public IPs

Public IPs. Your infrastructure.

Give supported devices and gateways a public address over your existing connection—for incoming access, outgoing identity, or both.

For servers, sites & infrastructure owners

Available

An address, or room to grow

Start with what needs an IP.

A public IP is an internet address other systems can connect to, or recognise as the source of your connections. Fibmesh supplies that address over an encrypted tunnel while your existing ISP continues to carry the connection.

Address
The public identity assigned to your device, gateway or group of workloads.
Delivery
The WireGuard tunnel that carries traffic between Fibmesh and your infrastructure.
Traffic policy
Which connections use the tunnel, which stay on the ISP, and which incoming connections are allowed.
Device IPs

One device. Its own address.

A server that accepts connections. A laptop that needs a fixed source for an allowlist. A supported endpoint with an address independent of its access ISP.

Explore Device IPs →
Gateway IPs

Bring existing equipment along.

Reach LAN services and give devices a stable outgoing public identity. Choose inbound access, selected outbound or full tunnel on a supported gateway.

Explore Gateway IPs →
Routed Subnets · Invitation-led service

A block for your workloads.

A separate managed service for an IPv4 block or an IPv6 prefix from /48 through /64. Give servers, VMs and downstream networks separate public addresses. This service is outside the app MVP.

Explore Routed Subnets →

Customer proof of concept

Their router stayed. Their equipment became reachable.

We supplied a preconfigured Fibmesh Edge device. The customer connected it to the existing network; we configured the targets remotely so their NVRs and servers could be reached. No software installation on the equipment. No replacement router.

Read the Quick Connect story →

See how billing and ERP servers used Device IPs →

Proof-of-concept deployment · Fibmesh Edge hardware remains in development or pilot.

Address delivery and traffic policy

Choose the address path and the traffic it carries.

Direct to the device

A fully routed public address is assigned to the supported endpoint through an encrypted tunnel. No address translation is needed between that assigned address and the endpoint.

Through a gateway

A gateway can forward incoming connections to LAN services or carry outgoing traffic from devices behind it. Routing and NAT let supported setups keep private LAN addresses.

Both work over supported existing connections. Choose dual-stack for IPv4 and IPv6 reachability, or IPv6-only where your clients and destinations support it. Fully routed describes address delivery; it does not mean all your traffic must use the tunnel.

Explore a traffic preset Illustration · no settings are changed

Traffic preset
Internet clientFibmesh + inbound rulesYour service

Let the intended connections in.

Permitted incoming connections use Fibmesh, with a matching return path for their replies. New, unrelated outgoing connections keep their existing ISP route.

Incoming: allowed by rulesOrdinary outgoing: existing ISP
Your deviceAssigned Fibmesh sourceSelected destinations

Use your public address where it matters.

Chosen destinations see the assigned Fibmesh source address. Other destinations use the existing ISP. Replies to your connections are allowed.

Add incoming access too

Enable separate inbound rules to host a service while making selected outgoing calls from the same address. Incoming access is blocked by default in the selected-outbound preset.

Incoming: blocked by defaultOther outgoing: existing ISP
Your deviceFibmesh tunnelEligible internet traffic

Make Fibmesh the internet path.

Eligible internet connections use Fibmesh. Incoming access remains a separate firewall choice. Confirm both address families, disconnect behaviour and local or platform exceptions.

Incoming: independent rulesIPv4 + IPv6: explicit policy
Explore address delivery, firewall and routing options →

Incoming firewall rules and outgoing routing are separate decisions. A server can receive permitted connections and use its assigned public address when calling a partner API. Replies to incoming connections follow the Fibmesh return path; unrelated outgoing traffic follows the selected routing policy.

If you need an internet exit rather than an address assigned to your infrastructure, explore Outbound. An agreed source identity is an option there; receiving incoming connections is not required.

Need an HTTPS URL for a selected web app instead of an address assigned to the machine? Publish provides that web publishing workflow with assisted setup. Visitors use a browser or API client; a Fibmesh connector reaches the application.

Put the address to work

Keep the workload where it makes sense.

An office workstation and server infrastructure

Illustrative scenario / your infrastructure

A public address, without relocating your server.

Use an assigned address for a permitted service on a supported device or gateway. Plan the host firewall, service authentication and return route together.

  1. Internet client
  2. Assigned address
  3. Tunnel → your server
Illustrative image and scenario.

For an office server, local GPU or colocated machine, keep private administration separate from public application traffic. Explore self-hosting and uncloud →

Be recognised by the systems you use

Use an assigned source address for partner APIs, business systems and supported SaaS allowlists. A public IP does not replace the destination’s sign-in or access rules.

Plan outbound allowlisting →

Connect equipment without an agent

Reach selected services on NVRs, NAS appliances and other equipment through a gateway. Give private maintenance and public service access different policies.

Explore equipment and IoT →

Make it work for your setup

Know the path before you request the address.

Prepare a deployment

Choose the target, address family, service ports and outgoing destinations. Check platform support and verify both directions before relying on the address.

Getting started and troubleshooting →

Understand automation

The API contract covers assignment requests and lifecycle. Dedicated Public IP CLI commands remain to be implemented.

CLI and API scope →

Before you start

A few things worth knowing.

Can I keep the address when my ISP connection changes?

The reserved Fibmesh address is separate from the access ISP’s address. A supported tunnel reconnects over the new connection. Existing sessions may restart; keeping an address does not promise uninterrupted roaming or portability between serving regions.

Which ports can I use?

Choose the application ports and permitted sources through the supported firewall configuration. Confirm protocol support and any service or platform reservations. Managed inbound access starts closed; a routed IP is not an instruction to open every port.

Is this an internet leased line?

No. Fibmesh delivers the public address over your existing access connection. Its bandwidth, reliability and local network conditions still matter. Throughput, traffic allowance and support are agreed separately.

How do I inspect an assignment?

The developer contract includes GET /v1/public-ip/assignments. Delivery health and observed policy state help an operator verify the assignment alongside an actual service test.

Developer reference →

Compare all four products and choose the right fit →