To give a remote team one fixed IP for allowlists, run a WireGuard VPN or SSH/RDP jump host on a JUSTG cloud VPS in Tokyo, Japan, Seoul, South Korea or Moscow, Russia — each plan includes a dedicated native IPv4 (plus free IPv6) from $19.99/mo, so every teammate's traffic to allowlisted services leaves from the same static, locally registered address. This hands-on guide covers when you need a fixed egress IP, a working WireGuard config, the jump-host alternative, security hardening, logging, and how to choose between Tokyo, Seoul and Moscow.
- Locations: Tokyo, Japan; Seoul, South Korea (KT network); Moscow, Russia; Johannesburg, South Africa (cloud coming soon, dedicated available from $199/mo).
- IP: one static native IPv4 registered and geolocated in that country, plus free IPv6; extra IPs can be added anytime via Upgrade options.
- Price: JUSTG cloud VPS from $19.99/mo (1 core / 512 MB) to $169.99/mo (7 cores / 24 GB RAM).
- Network: typically 500 Mbps port; Moscow has China Telecom CN2 GIA, Tokyo and Seoul use Asia-optimized routes.
- Setup: auto-deployed after payment; KVM, Linux or Windows; 24/7 ticket support.
This guide is for legitimate business access only — your own admin panels, services you are authorized to use, and partners who asked you for a static source IP.
When a team needs one fixed IP
You need a fixed egress IP whenever a system you depend on only accepts connections from addresses it has explicitly allowlisted.
- Company admin panels — WordPress/WHMCS admin, Grafana, internal dashboards locked to an office IP.
- Bank, payment and merchant dashboards — many payment gateways and corporate banking portals let you restrict API keys or logins to listed IPs.
- SaaS with IP restrictions — Google Workspace context-aware access, Microsoft Entra named locations, GitHub Enterprise or Okta IP allowlists.
- Cloud firewall rules — AWS security groups, Azure NSGs or database firewalls that should only accept your team.
- Partner APIs and SFTP — logistics, ERP or B2B partners that require a static source IP before they open access.
- Distributed teams — staff in several countries who need one consistent, local egress location for a regional back office, so security systems see the same place every day.
Home and mobile connections change IP often, and office IPs disappear when people travel. A VPS IP stays the same for as long as you keep the service.
Option A vs Option B: VPN gateway or jump host
A WireGuard gateway routes browser and API traffic through the fixed IP; a jump host is simpler when the team only needs SSH, SFTP or a remote desktop.
| WireGuard VPN gateway | SSH / RDP jump host | |
|---|---|---|
| Best for | Web dashboards, SaaS, APIs from laptops | Servers, SFTP, databases, one shared Windows desktop |
| What leaves from the fixed IP | All traffic you route (split or full tunnel) | Only sessions started on or via the jump host |
| Client software | WireGuard app (Windows, macOS, Linux, iOS, Android) | SSH client or Remote Desktop client |
| Performance | Very low overhead, kernel-level | Depends on RDP/SSH session |
| Per-user revocation | Remove the peer's key | Remove the SSH key / Windows account |
Option A: WireGuard gateway on a JUSTG VPS (hands-on)
WireGuard on Ubuntu or Debian takes about ten minutes and gives every teammate the server's fixed IP as their egress address.
1. Install WireGuard, enable IP forwarding and create the server keys:
apt update && apt install -y wireguard
echo 'net.ipv4.ip_forward=1' > /etc/sysctl.d/99-wg.conf && sysctl --system
cd /etc/wireguard && umask 077
wg genkey | tee server.key | wg pubkey > server.pub
2. Create the server configuration (replace eth0 with your interface from ip a):
# /etc/wireguard/wg0.conf (server, public IP 203.0.113.10, NIC eth0)
[Interface]
Address = 10.8.0.1/24
ListenPort = 51820
PrivateKey = <server.key>
PostUp = iptables -t nat -A POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
PostDown = iptables -t nat -D POSTROUTING -s 10.8.0.0/24 -o eth0 -j MASQUERADE
# one [Peer] per team member
[Peer]
PublicKey = <alice.pub>
AllowedIPs = 10.8.0.2/32
3. Create a key pair per teammate (wg genkey | tee alice.key | wg pubkey > alice.pub) and give them a client file:
# alice.conf (laptop)
[Interface]
Address = 10.8.0.2/32
PrivateKey = <alice.key>
DNS = 1.1.1.1
[Peer]
PublicKey = <server.pub>
Endpoint = 203.0.113.10:51820
# split tunnel: only the allowlisted services go through the fixed IP
AllowedIPs = 198.51.100.0/24
# full tunnel instead: AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
4. Start the service, open the port and verify:
systemctl enable --now wg-quick@wg0
ufw allow 51820/udp
wg show # handshakes and traffic per peer
curl -4 https://ifconfig.me # run on the client: should print 203.0.113.10
Split tunnel vs full tunnel: list only the allowlisted destination ranges in AllowedIPs when possible. Everything else (video calls, personal browsing) then goes direct, which keeps the VPS bandwidth for business traffic. For SaaS behind large CDNs whose IPs change, use a full tunnel during work sessions.
Finally, give the partner or service your server IP (here 203.0.113.10) and, if they support it, the IPv6 address too.
Option B: SSH or RDP jump host
If the allowlisted systems are servers rather than websites, a jump host is the least moving parts: everyone connects to the VPS, and the VPS connects onward.
# ~/.ssh/config on each team member's laptop
Host jump
HostName 203.0.113.10
User ops
IdentityFile ~/.ssh/id_ed25519
Host partner-sftp
HostName sftp.example.com
ProxyJump jump
Now ssh partner-sftp or sftp partner-sftp reaches the partner from 203.0.113.10. For browser-only portals, a Windows VPS used as a shared remote desktop works too: staff log in over RDP and open the portal in the VPS browser, so the bank or SaaS always sees the same IP and the same machine. Give each person their own Windows account rather than sharing one login.
Security hardening and 2FA
A fixed IP that unlocks your company's systems is a high-value target, so lock the gateway down before you add it to any allowlist.
# /etc/ssh/sshd_config.d/hardening.conf
PasswordAuthentication no
PermitRootLogin no
KbdInteractiveAuthentication yes
AuthenticationMethods publickey,keyboard-interactive
apt install -y fail2ban libpam-google-authenticator
# in /etc/pam.d/sshd: add auth required pam_google_authenticator.so
# and comment out @include common-auth
# then run google-authenticator as user ops to enroll the TOTP app
systemctl restart ssh && systemctl enable --now fail2ban
- SSH keys only (Ed25519), no root login, TOTP 2FA for admins, fail2ban against brute force.
- Firewall: allow only 22/tcp (or your custom SSH port) and 51820/udp; consider restricting SSH to the WireGuard subnet once the tunnel works.
- Windows jump hosts: enable Network Level Authentication, change the default RDP port, use strong unique passwords plus an account lockout policy, and keep Windows Update on.
- One key per person; revoke immediately when someone leaves (delete their
[Peer]and runwg syncconf wg0 <(wg-quick strip wg0)). - Still use 2FA on the target service itself. An IP allowlist is an additional layer, not a replacement for passwords and MFA.
Logging and accountability
Because the whole team shares one IP, your own logs are what tell you who did what.
wg showlists each peer's last handshake and transferred bytes; script it hourly into a log file.journalctl -u sshand/var/log/auth.logrecord SSH logins; on Windows, check Security event ID 4624 for logons.- Map WireGuard addresses (10.8.0.2, 10.8.0.3 …) to named people in a simple inventory.
- Keep logs only as long as needed and tell staff what is logged — respect local privacy law.
Choosing Tokyo vs Seoul vs Moscow (and Johannesburg)
Pick the country the target service expects your company to be in, then the location closest to most of your team.
| Location | IP / network | Typical allowlist use | Notes |
|---|---|---|---|
| Tokyo, Japan | Native Japanese IP, Asia-optimized route | Japanese SaaS, banks, marketplaces' seller back offices, APAC teams | OpenAI, Claude and Gemini APIs available |
| Seoul, South Korea | Native Korean IP on KT, Asia-optimized route | Korean portals, payment dashboards, Korean partner APIs | AI APIs available; Korean residential IPs for enterprises on request |
| Moscow, Russia | Native Russian IP, China Telecom CN2 GIA to China | Russian banks, 1C and Russian partner systems, marketplace back offices | Not suitable for OpenAI/Claude/Gemini APIs; some Western services block Russian IPs |
| Johannesburg, South Africa | Native South African IP, Asia-optimized | South African and African partner systems | Cloud VPS coming soon; dedicated servers available from $199/mo |
Korean residential IPs for enterprises: some Korean services treat datacenter IPs differently from home broadband. For large or enterprise teams with a legitimate need for a Korean residential (home-broadband) egress IP, JUSTG can provide Korean residential IPs on request — contact sales via ticket for a quote. A residential IP does not bypass identity verification or any platform's rules. More on locations: Japan VPS, Korea VPS, native IP.
Which JUSTG plan fits
A WireGuard gateway for 5–20 people runs comfortably on an entry or lower-mid JUSTG cloud VPS; a shared Windows desktop needs more RAM.
- Linux WireGuard / SSH gateway — JUSTG Tokyo Cloud VPS, JUSTG Seoul Cloud VPS or JUSTG Moscow Cloud VPS from $19.99/mo (1 core / 512 MB is enough for a small team).
- Windows RDP jump host — choose 2 cores and 4 GB RAM or more, scaling toward the 7-core / 24 GB plan ($169.99/mo) for many concurrent sessions.
- Several fixed IPs (e.g. one per department or client) — add extra IPs anytime via Upgrade options, or use a dedicated server with up to a full /24.
- Custom configurations — CPU, RAM, disk, bandwidth, IP blocks or Korean residential IPs on request; contact sales via ticket for a custom quote.
FAQ
How can my remote team get a static IP for an IP allowlist?
Rent a VPS with a dedicated IPv4 and route the team through it with WireGuard or an SSH/RDP jump host. JUSTG cloud VPS in Tokyo, Seoul and Moscow include one static native IPv4 plus free IPv6 from $19.99/mo, which you add to the allowlist once.
Which VPS provider offers a fixed Korean IP?
JUSTG offers the JUSTG Seoul Cloud VPS with native Korean IPs on the KT network from $19.99/mo, and Korean residential IPs for enterprise customers on request through sales.
Will the VPS IP address change?
No, the IPv4 assigned to your JUSTG VPS stays the same while the service is active.
Is a VPN gateway safe for accessing a bank dashboard?
It can be, if you harden it: key-based access, 2FA, firewall, one key per person and logging. Keep MFA enabled on the bank side as well, and follow your bank's terms for API and portal access.
Ready to give your team one stable egress address? Start with a JUSTG Tokyo Cloud VPS, JUSTG Seoul Cloud VPS or JUSTG Moscow Cloud VPS, and open a ticket for multi-IP or residential IP needs.