Boston, MA add-on for colocation, servers and VPS
Your server reaches the internet. Only your team reaches your server.
Rack it, cable it, boot it. Your server comes up on its own private VLAN behind our redundant firewalls, with a private address by DHCP and full outbound internet access. It holds no public address and accepts no connections from the internet, so the only machines that can reach it are the ones on your tailnet.
$25 per month per system Capped at $50 per account No public IP required
How it works
Outbound is all most tools ever needed.
Tailscale, WireGuard and Cloudflare Tunnel all dial out. None of them needs an inbound port, and none of them needs a public address on your server. Your server opens the tunnel, and once it is up you and your team work over it exactly as you would on any other machine. What changes is who else can try: your server holds a private RFC1918 address only, so nobody on the public internet can open a connection to it or find a service to probe.
What you get
Included on every Protected Internet system.
Dedicated private VLAN
Your account gets its own VLAN. Other customers cannot see it or route into it.
Your own RFC1918 /28
A private subnet reserved for your servers, with larger subnets available on request at no extra charge.
DHCP, nothing to plan
No addressing scheme, no gateway to configure. Boot the server and it is on the network.
Redundant HA firewalls
Traffic passes through a high availability pair, so losing one firewall does not take your server offline.
Only your team gets in
Nothing on the public internet can open a connection to your server, so scanners and brute force attempts have no path to it. Your own devices reach it over your tunnel as normal.
Public IPs when you want them
Add a static public IPv4 address later with 1:1 NAT or specific port forwards, without renumbering anything.
Who it suits.
- Tailscale and Headscale users who want an always on node, subnet router or exit node sitting in a real datacenter rather than a closet.
- Homelabbers moving hardware out of the house and into a rack with conditioned power, cooling and real connectivity.
- MSPs and IT teams running management servers, backup targets and jump hosts that have no business facing the internet.
- Self hosters publishing through Cloudflare Tunnel instead of opening ports.
- Small deployments where dropping a customer firewall frees up rack units, power and one more thing to maintain.
Works with
Anything that connects outbound works here. That covers effectively every modern mesh VPN and tunnel.
- Tailscale and Headscale
- WireGuard
- ZeroTier
- Netbird
- Cloudflare Tunnel
- Twingate
Pricing
$25 per month, per system.
Capped at $50 per month per account. Once you hit the cap, every additional server is on Protected Internet at no further cost.
- Dedicated private VLAN and RFC1918 /28
- DHCP and outbound internet
- Redundant HA firewalls
- Full isolation from other customers
- Static public IPs added whenever you need them
Add it to any Boston service.
Ask for Protected Internet when you order, or tell us and we will move a server you already run with us onto it.
- Boston colocation, per U from 1U to 48U.
- Boston dedicated servers, bare metal from $145 per month.
- Boston virtual servers, KVM from $20 per month.
Need something public later?
We map a static public IPv4 address to your server with 1:1 NAT, or open only the ports you name. Your private subnet is untouched, so nothing gets renumbered and nothing goes down to do it.
Straight answers
Protected Internet questions.
What is Protected Internet?
Protected Internet is an add-on for Axcelx colocation, dedicated servers and virtual servers. Instead of a public IP on your server, you get a dedicated private VLAN and RFC1918 subnet behind our redundant HA firewalls. Your server gets a private address by DHCP and full outbound internet access, but holds no public address and accepts no connections from the internet. The only machines that can reach it are your own, over the tunnel your server opens.
Do I need a public IP to use Tailscale?
No. Tailscale, Headscale, WireGuard clients, ZeroTier, Netbird and Cloudflare Tunnel all connect outbound, so your server can join your tailnet or tunnel without a public IP or any open inbound ports.
Will Tailscale make direct connections or use DERP relays?
Tailscale tries a direct connection first and only falls back to its DERP relays when a direct path cannot be established, which usually depends on the network at the other end. If you see relayed connections to your server, open a ticket and our network team will review it with you.
Can I run a Tailscale subnet router or exit node?
Yes. A server on Protected Internet can act as a subnet router to expose your private subnet to your tailnet, or as an exit node for your devices. Exit node traffic leaves through our network and is subject to the Axcelx acceptable use policy.
Can I add a public IP later?
Yes. When you need something reachable from the internet, we map a static public IPv4 address to your server with 1:1 NAT, or open only the ports you choose. Your private subnet stays exactly as it is, so nothing has to be renumbered.
Is my traffic isolated from other customers?
Yes. Every account gets its own private VLAN and its own RFC1918 subnet. Customers cannot see or reach each other networks.
How much does Protected Internet cost?
Protected Internet is $25 per month per system, with a maximum of $50 per month per account. Once you reach the cap you can add as many servers as you like at no further cost.
Which services can use Protected Internet?
Protected Internet is available on Boston colocation, dedicated servers and virtual servers. Choose it when you order, or ask our team to add it to a service you already run with us.
What if I need more than a /28?
Each account starts with a dedicated /28. Larger private subnets are available on request at no extra charge.
Trademark notice
Tailscale, Headscale, WireGuard, ZeroTier, Netbird, Cloudflare and Twingate are trademarks of their respective owners. Axcelx Technologies LLC is not affiliated with or endorsed by any of them.
Reachable by your team, by nobody else.
Tell us what you are running and we will have it on Protected Internet in our Boston datacenter, on its own VLAN, behind our firewalls.