Before setup
A useful brief starts with the job.
Public IPs is available with assisted setup. Bring one real service or destination: a file server a partner must reach, an API that requires a fixed source address, or several workloads needing their own addresses. Fibmesh confirms the supported deployment and terms before delivery.
- Your infrastructure
- Device or gateway model, operating system, site country, access provider and who can change its configuration.
- Your connections
- Incoming services and ports, permitted callers, outgoing destinations and whether other traffic should stay on the ISP.
- Your allocation
- Dual-stack or IPv6-only for supported single targets; separate IPv4 and IPv6 blocks for routed infrastructure. Include the required address count.
For a gateway deployment, also record LAN target addresses and how selected outgoing traffic will reach the gateway. For Routed Subnets, bring a downstream addressing plan. Inventory, serving location, traffic allowance and price are agreed for the deployment.
From request to working connection
Keep each step visible.
- 01 / Confirm the allocation
Agree the device or gateway, address family, serving location and reservation terms. The assigned address is independent of the access ISP, but remains tied to its agreed Fibmesh delivery location.
- 02 / Connect the target
Use the supported Fibmesh client or gateway setup. It establishes a WireGuard tunnel over the existing internet connection. A plain WireGuard profile is Compatibility Mode; it does not supply every managed feature.
- 03 / Define the traffic
Choose inbound access, selected outbound or full tunnel. Set incoming rules independently. For a LAN gateway, configure the required forwarding or routing; simply plugging in an appliance does not redirect outgoing traffic.
- 04 / Prepare the application
Set its listening address, authentication and host firewall. For gateway forwarding, keep the private target address stable. Add domain records and application certificates if the service uses a name.
- 05 / Verify and hand over
Complete the tests below, record the assignment and responsible operator, and retain a way to administer the host if the tunnel is unavailable.
This guide describes the setup decisions. Exact installation steps, supported software and any platform-specific exceptions must come with the confirmed deployment.
Acceptance checks
A connected tunnel is not the same as a working service.
- Reach itTest from an external network using the real application and permitted source.
- Reject itConfirm a disallowed caller or port stays blocked. Keep application authentication in the test.
- Check the sourceFor outbound traffic, confirm the destination sees the assigned public IP. Check excluded traffic separately.
- Interrupt itDisconnect the tunnel in an agreed test window. Confirm blocking or explicit fallback, then recovery.
Test IPv4 and IPv6 separately. With full tunnel, an IPv6-only assignment still needs an explicit policy for IPv4. If using a gateway, confirm both forwarding directions and larger transfers; packet-size problems can appear even when a small request succeeds.
When something does not connect
Check the failing part of the path.
| What you see | What to check |
|---|---|
| Tunnel will not connect | Power, client or gateway service, internet access and whether the network permits WireGuard UDP traffic. |
| Tunnel connected, service unavailable | Assignment delivery health, app listening address, permitted sources, ports and host firewall. |
| LAN target unavailable | Target address, service port, gateway forwarding and the reply route. |
| Partner sees the ISP address | The selected destination route, source-address selection and whether LAN traffic actually passes through the gateway. |
| One address family works | IPv4 and IPv6 configuration and the destination’s support for each. |
| Small requests work, large transfers stall | Tunnel MTU—the maximum packet size—and path discovery. Use the supported platform’s diagnostics. |
| Address works, domain does not | A/AAAA records, DNS caching, app hostname settings and certificate validity. |
Share the assignment identifier, platform, approximate failure time, affected protocol and the failing step with support. Remove credentials, private keys and application payloads from diagnostics.
Support and troubleshooting →Before you commit
Practical questions, answered.
Does it work behind CGNAT?
It can where the customer’s device or gateway can establish and maintain its outbound WireGuard tunnel. CGNAT means the access provider shares public addressing between customers; Fibmesh’s assigned address travels inside the tunnel. Restrictive UDP filtering still needs assessment.
Do remote visitors need Fibmesh software?
Clients connect to the public IP using the application’s normal protocol. They do not need the Fibmesh tunnel, but must satisfy your firewall and application authentication requirements.
Do I have to move my application or join Networks?
No. The application can stay on supported infrastructure you operate. A Networks private network is optional; account identity and service entitlement still apply.
Which country will websites think I am in?
The public address is served from the agreed Fibmesh location. Third-party IP geolocation and reputation databases can differ; an allocation does not guarantee how every website classifies it.
What are the speed, price and usage limits?
Confirm the allocation charge, throughput, traffic allowance, overages and support terms before setup. Your access connection’s bandwidth and reliability remain part of the path. Public IP delivery is not a dedicated internet leased line.
Can I keep the address when I change ISP?
The reservation is separate from the access ISP. The supported tunnel can reconnect over another eligible connection, but sessions may need to restart. Moving the allocation to another serving region is a separate decision.
Does pausing give up the address?
Pause stops delivery while retaining the reservation. Release gives up the address. With full tunnel and a kill switch, pausing can also stop covered internet access until delivery resumes or an agreed alternative is selected.
