AS33083 network operational

877-829-2359 sales@axcelx.com

Boston, MA add-on for colocation, servers and VPS

Your server reaches the internet. Only your team reaches your server.

Rack it, cable it, boot it. Your server comes up on its own private VLAN behind our redundant firewalls, with a private address by DHCP and full outbound internet access. It holds no public address and accepts no connections from the internet, so the only machines that can reach it are the ones on your tailnet.

$25 per month per system Capped at $50 per account No public IP required

How it works

Outbound is all most tools ever needed.

Tailscale, WireGuard and Cloudflare Tunnel all dial out. None of them needs an inbound port, and none of them needs a public address on your server. Your server opens the tunnel, and once it is up you and your team work over it exactly as you would on any other machine. What changes is who else can try: your server holds a private RFC1918 address only, so nobody on the public internet can open a connection to it or find a service to probe.

Protected Internet network path Your server holds a private RFC1918 address only, never a public one. It connects to a dedicated private VLAN carrying its own RFC1918 slash 28 subnet, assigned by DHCP. That VLAN passes through a redundant pair of high availability firewalls, which allow outbound traffic to the internet over AS33083 and refuse connections opened from outside. Your Tailscale or WireGuard session is established outbound by the server and then carries traffic in both directions, so your own devices reach the server while nothing on the public internet can. Your server Colo, dedicated or VPS No public address Private VLAN RFC1918 /28 by DHCP Internal addresses only HA firewall pair Redundant, stateful No unsolicited inbound Internet AS33083 Sessions start outbound Your tunnel, opened outbound, carries traffic both ways

What you get

Included on every Protected Internet system.

Isolation

Dedicated private VLAN

Your account gets its own VLAN. Other customers cannot see it or route into it.

Addressing

Your own RFC1918 /28

A private subnet reserved for your servers, with larger subnets available on request at no extra charge.

Provisioning

DHCP, nothing to plan

No addressing scheme, no gateway to configure. Boot the server and it is on the network.

Resilience

Redundant HA firewalls

Traffic passes through a high availability pair, so losing one firewall does not take your server offline.

Exposure

Only your team gets in

Nothing on the public internet can open a connection to your server, so scanners and brute force attempts have no path to it. Your own devices reach it over your tunnel as normal.

Growth

Public IPs when you want them

Add a static public IPv4 address later with 1:1 NAT or specific port forwards, without renumbering anything.

Who it suits.

  • Tailscale and Headscale users who want an always on node, subnet router or exit node sitting in a real datacenter rather than a closet.
  • Homelabbers moving hardware out of the house and into a rack with conditioned power, cooling and real connectivity.
  • MSPs and IT teams running management servers, backup targets and jump hosts that have no business facing the internet.
  • Self hosters publishing through Cloudflare Tunnel instead of opening ports.
  • Small deployments where dropping a customer firewall frees up rack units, power and one more thing to maintain.

Works with

Anything that connects outbound works here. That covers effectively every modern mesh VPN and tunnel.

  • Tailscale and Headscale
  • WireGuard
  • ZeroTier
  • Netbird
  • Cloudflare Tunnel
  • Twingate

Pricing

$25 per month, per system.

Capped at $50 per month per account. Once you hit the cap, every additional server is on Protected Internet at no further cost.

  • Dedicated private VLAN and RFC1918 /28
  • DHCP and outbound internet
  • Redundant HA firewalls
  • Full isolation from other customers
  • Static public IPs added whenever you need them

Get started

Add it to any Boston service.

Ask for Protected Internet when you order, or tell us and we will move a server you already run with us onto it.

Need something public later?

We map a static public IPv4 address to your server with 1:1 NAT, or open only the ports you name. Your private subnet is untouched, so nothing gets renumbered and nothing goes down to do it.

Straight answers

Protected Internet questions.

What is Protected Internet?

Protected Internet is an add-on for Axcelx colocation, dedicated servers and virtual servers. Instead of a public IP on your server, you get a dedicated private VLAN and RFC1918 subnet behind our redundant HA firewalls. Your server gets a private address by DHCP and full outbound internet access, but holds no public address and accepts no connections from the internet. The only machines that can reach it are your own, over the tunnel your server opens.

Do I need a public IP to use Tailscale?

No. Tailscale, Headscale, WireGuard clients, ZeroTier, Netbird and Cloudflare Tunnel all connect outbound, so your server can join your tailnet or tunnel without a public IP or any open inbound ports.

Will Tailscale make direct connections or use DERP relays?

Tailscale tries a direct connection first and only falls back to its DERP relays when a direct path cannot be established, which usually depends on the network at the other end. If you see relayed connections to your server, open a ticket and our network team will review it with you.

Can I run a Tailscale subnet router or exit node?

Yes. A server on Protected Internet can act as a subnet router to expose your private subnet to your tailnet, or as an exit node for your devices. Exit node traffic leaves through our network and is subject to the Axcelx acceptable use policy.

Can I add a public IP later?

Yes. When you need something reachable from the internet, we map a static public IPv4 address to your server with 1:1 NAT, or open only the ports you choose. Your private subnet stays exactly as it is, so nothing has to be renumbered.

Is my traffic isolated from other customers?

Yes. Every account gets its own private VLAN and its own RFC1918 subnet. Customers cannot see or reach each other networks.

How much does Protected Internet cost?

Protected Internet is $25 per month per system, with a maximum of $50 per month per account. Once you reach the cap you can add as many servers as you like at no further cost.

Which services can use Protected Internet?

Protected Internet is available on Boston colocation, dedicated servers and virtual servers. Choose it when you order, or ask our team to add it to a service you already run with us.

What if I need more than a /28?

Each account starts with a dedicated /28. Larger private subnets are available on request at no extra charge.

Trademark notice

Tailscale, Headscale, WireGuard, ZeroTier, Netbird, Cloudflare and Twingate are trademarks of their respective owners. Axcelx Technologies LLC is not affiliated with or endorsed by any of them.

Reachable by your team, by nobody else.

Tell us what you are running and we will have it on Protected Internet in our Boston datacenter, on its own VLAN, behind our firewalls.