An address, or room to grow
Start with what needs an IP.
A public IP is an internet address other systems can connect to, or recognise as the source of your connections. Fibmesh supplies that address over an encrypted tunnel while your existing ISP continues to carry the connection.
- Address
- The public identity assigned to your device, gateway or group of workloads.
- Delivery
- The WireGuard tunnel that carries traffic between Fibmesh and your infrastructure.
- Traffic policy
- Which connections use the tunnel, which stay on the ISP, and which incoming connections are allowed.
Customer proof of concept
Their router stayed. Their equipment became reachable.
We supplied a preconfigured Fibmesh Edge device. The customer connected it to the existing network; we configured the targets remotely so their NVRs and servers could be reached. No software installation on the equipment. No replacement router.
Read the Quick Connect story →See how billing and ERP servers used Device IPs →
Proof-of-concept deployment · Fibmesh Edge hardware remains in development or pilot.
Address delivery and traffic policy
Choose the address path and the traffic it carries.
Direct to the device
A fully routed public address is assigned to the supported endpoint through an encrypted tunnel. No address translation is needed between that assigned address and the endpoint.
Through a gateway
A gateway can forward incoming connections to LAN services or carry outgoing traffic from devices behind it. Routing and NAT let supported setups keep private LAN addresses.
Both work over supported existing connections. Choose dual-stack for IPv4 and IPv6 reachability, or IPv6-only where your clients and destinations support it. Fully routed describes address delivery; it does not mean all your traffic must use the tunnel.
Explore a traffic preset Illustration · no settings are changed
Incoming firewall rules and outgoing routing are separate decisions. A server can receive permitted connections and use its assigned public address when calling a partner API. Replies to incoming connections follow the Fibmesh return path; unrelated outgoing traffic follows the selected routing policy.
If you need an internet exit rather than an address assigned to your infrastructure, explore Outbound. An agreed source identity is an option there; receiving incoming connections is not required.
Need an HTTPS URL for a selected web app instead of an address assigned to the machine? Publish provides that web publishing workflow with assisted setup. Visitors use a browser or API client; a Fibmesh connector reaches the application.
Put the address to work
Keep the workload where it makes sense.

Illustrative scenario / your infrastructure
A public address, without relocating your server.
Use an assigned address for a permitted service on a supported device or gateway. Plan the host firewall, service authentication and return route together.
- Internet client
- Assigned address
- Tunnel → your server
For an office server, local GPU or colocated machine, keep private administration separate from public application traffic. Explore self-hosting and uncloud →
Be recognised by the systems you use
Use an assigned source address for partner APIs, business systems and supported SaaS allowlists. A public IP does not replace the destination’s sign-in or access rules.
Plan outbound allowlisting →Connect equipment without an agent
Reach selected services on NVRs, NAS appliances and other equipment through a gateway. Give private maintenance and public service access different policies.
Explore equipment and IoT →Make it work for your setup
Know the path before you request the address.
Prepare a deployment
Choose the target, address family, service ports and outgoing destinations. Check platform support and verify both directions before relying on the address.
Getting started and troubleshooting →Understand automation
The API contract covers assignment requests and lifecycle. Dedicated Public IP CLI commands remain to be implemented.
CLI and API scope →Before you start
A few things worth knowing.
Can I keep the address when my ISP connection changes?
The reserved Fibmesh address is separate from the access ISP’s address. A supported tunnel reconnects over the new connection. Existing sessions may restart; keeping an address does not promise uninterrupted roaming or portability between serving regions.
Which ports can I use?
Choose the application ports and permitted sources through the supported firewall configuration. Confirm protocol support and any service or platform reservations. Managed inbound access starts closed; a routed IP is not an instruction to open every port.
Is this an internet leased line?
No. Fibmesh delivers the public address over your existing access connection. Its bandwidth, reliability and local network conditions still matter. Throughput, traffic allowance and support are agreed separately.
How do I inspect an assignment?
The developer contract includes GET /v1/public-ip/assignments. Delivery health and observed policy state help an operator verify the assignment alongside an actual service test.
