Skip to main content
HostingSeller
Shop plans

Ops Brief

VPS for vpn — A fixed address your clients' servers can allowlist

Half your team works from home and every client firewall wants a single address to trust, which is the real reason a small agency ends up running its own tunnel.

Straight answer first

Run WireGuard on an Economy VPS. Twenty minutes of setup buys an always-on tunnel on a dedicated address that nobody else's behaviour has spoiled, and for an agency the point is not privacy but having one IP that client servers, databases and admin panels can be told to trust.

The rest of this page is the practical version: why an agency wants this, how to size and set it up honestly, what to do about keys when a member of staff leaves, and which box to order.

Written by the Hosting Seller staff · Checked 24 August 2026

NVMe

Disks under every box

Free

Domain on annual orders

99.9%

Uptime target we hold

Flat

Renewal, no year-two rise

Most writing on this subject is about anonymity. For a small hosting business or agency the motivation is usually duller and better: a stable exit address that can be allowlisted once and then relied on.

Running your own turns the usual trust arrangement around. Instead of believing a provider's no-logs advertising, you own the endpoint and you own whatever logs it keeps, which is a materially different position when a client asks who could see their traffic.

The real reason an agency wants one

Client servers, database ports, staging environments and admin panels are all safer behind an IP allowlist, and an allowlist is useless if your team's addresses change every time somebody works from a café.

One tunnel gives you one address to hand to a client's IT contact. It also means an ex-employee's home broadband is not still on somebody's trusted list two years later.

The second use is reaching things that should not be publicly exposed at all: a monitoring dashboard, a database on a private interface, a management port. A tunnel makes closing those to the world a practical decision rather than an aspiration.

Sizing and setup, honestly

VPN duty is the lightest work a VPS ever does. Memory needs are modest, CPU barely registers, and the only number worth checking is the bandwidth allowance against how much your team actually streams and transfers.

WireGuard installers such as wg-easy turn the setup into a twenty-minute job, complete with QR codes for phones. The Economy tier has resources to spare for this.

Take the dedicated IPv4 seriously, because its reputation is now yours to keep. That is an advantage over a commercial VPN whose shared exits are frequently blocked, and it becomes a liability if somebody on your team uses the tunnel carelessly.

Keys, leavers and the audit you will be asked for

Every device gets its own key. Not one shared configuration passed around, which is the arrangement that feels efficient for a fortnight and then cannot be unwound.

Put key revocation into your leavers process alongside the password manager and the email account. A tunnel with a stale key is a permanent hole in the allowlist you built it to protect.

Keep a short record of which key belongs to which person and device. The first time a client's security questionnaire asks how you control access to their environment, that list is the answer.

Which box, and what else it should carry

The plan for this is the Economy VPS. Root access, a flat price, a dedicated address, and enough headroom that the tunnel is unaware of itself.

It can double as the box for schedulers and small utilities, though keep anything a client depends on somewhere separate. A VPN endpoint should be boring, and boring means not rebooting it to restart something else.

Order an annual plan and the first year of the domain registration is on the house, which is a convenient way to give the endpoint a name of its own.

A shield icon standing in for site security and DDoS filtering

What a tunnel does not do

We are not going to tell you this makes anybody anonymous. Your own VPS gives you a consistent trusted exit point rather than a crowd to disappear into, and for agency work that is the more useful property anyway.

Order an annual plan and the first year of your domain registration is on the house.

  • A dedicated IPv4 with a reputation that stays yours
  • Root access, so the configuration is yours
  • One address for client allowlists
  • The renewal price is the price you quoted

Why Hosting Seller

On every plan, as standard

The plan behind this page

The Economy VPS gives root access and a dedicated address at a flat price, with resources to spare for tunnel duty.

An address you control

A dedicated IPv4 whose reputation is yours to keep, rather than a shared exit that streaming services and banks have already blocked.

Logs that belong to you

You own the endpoint, so what is recorded and what is not is your decision rather than a provider's marketing claim.

Upgrades applied in place

A box that takes on more work moves up on the same account rather than being rebuilt somewhere else.

A supplier you can name

IGI Security Services Ltd, registered in England and Wales, with terms published under English law.

Margin that survives renewal

The order price is the renewal price, so a long-lived piece of internal infrastructure stays a fixed cost.

First Steps

From choosing to live

  1. 1

    Decide what the tunnel is for

    An allowlisted address for client environments, or private access to things that should not face the internet. Both are good reasons; anonymity is not one of them.

  2. 2

    One key per device, from the start

    Shared configurations are convenient for a fortnight and impossible to revoke afterwards. Keep a short register of which key belongs to whom.

  3. 3

    Add revocation to your leavers checklist

    Alongside the password manager and the mailbox. A stale key is a permanent hole in the allowlist the tunnel exists to protect.

In the Box

Packed with every plan

  • Root access on the VPS range, with the configuration yours
  • A dedicated IPv4 address on every virtual server
  • KVM virtualisation with resources that are genuinely yours
  • DDoS filtering handled out at the network edge
  • Daily backups with restores you run yourself
  • Nothing added at setup, no joining fee ever
  • Upgrades apply to the account in place, with no move between plans
  • A domain free for year one when you order annually
  • Real people on the counter, every hour of every day
  • The renewal price on the tag matches the order price

Across the Counter

Things people ask us all the time

Why would an agency run its own tunnel rather than buy a VPN?

For a fixed address. Client servers, databases and admin panels are safer behind an allowlist, and an allowlist only works if your team's exit address is stable. A dedicated IP also avoids the blocking that shared commercial exits attract.

How long does it take to stand one of these up?

About twenty minutes with an installer such as wg-easy, which produces QR codes for phones and leaves you with a working tunnel. The Economy tier has resources to spare, because VPN work barely troubles a VPS at all. Budget rather more time for the register of keys than for the software.

How should keys be handled when somebody leaves?

One key per device from the start, a short register of which key belongs to whom, and revocation written into your leavers checklist beside the mailbox and the password manager. A shared configuration cannot be unwound cleanly and a stale key defeats the allowlist entirely.

Can this box also run my other automation?

It can, though keep anything a client depends on somewhere separate. A VPN endpoint should be dull, and dull means never rebooting it to restart something unrelated at an inconvenient moment.

Read next

  • Addon Domains vs Separate Accounts

    How far apart a client's several sites ought to be kept, and what each option costs you to administer.

  • Joomla Hosting Plans

    The Joomla client who wants a host that knows the platform exists, and what to check before quoting.

  • VPS Hosting

    KVM virtual servers with root access, DDoS filtering and one flat price.

  • Web Hosting

    cPanel accounts on NVMe disks, with SSL, the move-in and year-one domain included.

Moving your site to another host? Start with this checklist.

A step-by-step order of work for a move your visitors never spot: which files to copy first, how to carry email across without losing one message, the right moment to repoint DNS, and the two mistakes behind nearly every hour of downtime people ring us about.

One email brings the checklist, then now and again a note about running a site properly. Leave the list whenever you feel like it. Our privacy policy spells out the rest.

Give the team one address to be trusted by.

KVM virtual servers with root access, a dedicated IP, DDoS filtering and one flat price at renewal.

See VPS Hosting plans