Skip to content
+1 (813) 212-3723 [email protected]
WireGuard

A VPN endpoint you actually control.

Host your own WireGuard endpoint for remote access, site-to-site tunnels, or private browsing. Every plan includes a dedicated IPv4 address.

Why self-host

An endpoint with an address you control.

Personal VPNs, site-to-site tunnels, and road-warrior access all fit a small VPS. Peers connect to a dedicated IPv4, not a shared CGNAT pool.

Dedicated IPv4

One address per VPS, included. DNS and peer configs stay stable for as long as the server does.

IncludedNo CGNAT

Minutes to install

Debian or Ubuntu, then WireGuard from the distro repos. Manage peers with wg-quick or the tooling you already use.

wg-quickDebianUbuntu

Tampa routes

Southeast US, Caribbean, and Latin America from the live Tampa region. Run MTR from the looking glass before you buy.

Looking glass

Hourly, from prepaid credit

gc.nano is enough for a personal endpoint. Destroy the VPS and billing stops. Nothing renews behind your back.

From $2.50/moHourly
How it works

A VPN you can rebuild from a unit file.

Personal use fits gc.nano. Small teams with several peers usually want gc.micro for memory headroom.

1

Order Debian or Ubuntu

gc.nano for a personal endpoint. gc.micro if several people will stay connected at once.

2

Install WireGuard

apt install wireguard, generate keys, and write the interface config. The upstream docs apply as written.

3

Add peers

Each laptop or phone gets a unique IP on the tunnel subnet. Keep the private keys off the VPS if you can.

4

Firewall the host

Allow UDP 51820, or whichever port you chose, and nothing else you do not need.

The server config from step 2

# /etc/wireguard/wg0.conf
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = SERVER_PRIVATE_KEY
PostUp = iptables -t nat -A POSTROUTING -o ens18 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -o ens18 -j MASQUERADE

[Peer]
# laptop
PublicKey = LAPTOP_PUBLIC_KEY
AllowedIPs = 10.8.0.2/32
sudo ufw allow 51820/udp
sudo ufw route allow in on wg0 out on ens18
sudo systemctl enable --now wg-quick@wg0

Replace ens18 with the interface that ip route show default names, and turn on IPv4 forwarding first. Keys, forwarding, and the client profile: How to set up a WireGuard VPN on a VPS.

Plan fit

Peer count decides the size.

A road-warrior endpoint is a gc.nano workload. Teams should start on gc.micro. Transfer is a 2 TB account pool plus up to 500 GB per server each month, prorated by time provisioned.

gc.nano

Personal endpoint

One or two devices, light browsing, and remote SSH into home or cloud boxes.

  • 1 vCPU
  • 1 GB RAM
  • 20 GB SAS SSD
gc.micro

Small teams

Several peers and twice the memory. Transfer is shared from the account pool.

  • 1 vCPU
  • 2 GB RAM
  • 40 GB SAS SSD
gc.medium

Site-to-site and heavier use

Office tunnels, more throughput, and room to run DNS filtering beside WireGuard.

  • 4 vCPU
  • 8 GB RAM
  • 160 GB SAS SSD
Sized example: gc.nano

A personal endpoint for a laptop and a phone

WireGuard runs in the Linux kernel and sits near zero CPU when idle, so a personal endpoint needs memory for updates and logs more than it needs cores. When sustained throughput keeps the single vCPU busy, step up to gc.small (2 vCPU, 4 GB RAM) or larger.

Deploy gc.nano
  • 1 vCPU
  • 1 GB RAM
  • 20 GB SAS SSD
  • $3.00/mo ($0.0041/hr)

Need exact specs and order links?

Get a VPN VPS
FAQ

Frequently asked questions

Straight answers on billing, the platform, and what is included on every plan.

Full FAQ

Can I run WireGuard on any plan?

Yes. WireGuard works on all Linux plans with a dedicated IPv4 address.

How many peers can I support?

Peer count depends on plan CPU. gc.nano works for personal use; gc.medium fits small teams. Transfer is 2 TB included per account, plus up to 500 GB for each server per UTC calendar month, earned in proportion to time provisioned and shared across the pool.

Is outbound bandwidth metered?

General Compute includes a 2.5 Gbps port. Network Optimized includes a 10 Gbps port. Transfer is a separate account pool: 2 TB included per account, plus up to 500 GB for each server per UTC calendar month, earned in proportion to time provisioned and shared across the pool. Stopped and suspended servers keep earning instance credits; destroying a server stops new credits, with earned transfer retained until the monthly reset. Extra transfer is $3.00/TB per calendar month, whether you add Extra Bandwidth blocks in advance or usage goes beyond the pool. Bought mid-month, blocks are charged for the days remaining.

Can I put a WireGuard endpoint on a private network?

Yes. Attach the VPN server to a private network so peers on that LAN reach it without a public address, or keep a dedicated IPv4 on the WAN and use the private network for east-west traffic. The platform does not route between private networks. See Using pfSense with LayerOne if the VPN lives on a firewall appliance.

Ready to deploy a VPS?

Tampa is live. Pick a plan, pick an OS, and the server is online in under a minute.