The address comes from 23.187.152.0/24, announced to the internet by AS396500 — our own autonomous system. We are the registered operator, not a reseller sitting on somebody else's pool.
The address is assigned to you alone. Proxy services hand you an exit from a shared pool — your traffic leaves alongside everyone else's, and so does their reputation. Yours is yours.
Because it is dedicated, the address has one owner and one traffic history. That is the property an allowlist actually depends on, and the reason we are explicit that this is not an anonymity product.
Processors and banks commonly require a fixed source IP on file before enabling production access. Give them one address that will not change.
Filing and reporting endpoints frequently gate access by source IP. A rotating cloud address fails that check every time it moves.
Partner systems that allowlist inbound connections need a source they can pin. One address, registered once, for the life of the integration.
AWS Lambda, Zapier and similar platforms hand out changing egress addresses by default. Route the outbound leg through your own address instead.
Nothing migrates. The machine stays where it is — your VPS, your rack, your office. A WireGuard tunnel attaches the address to it. Works behind NAT.
Traffic your server sends leaves from your TunnelNet address, so the vendor sees the IP you registered with them — not your hosting provider's shared range.
Check the address your traffic actually leaves from before you hand the number to a partner. The technical guide shows exactly how, and why you should not skip it.
If you need more than one address, or your vendor has requirements we have not covered here, email support@tunnelnet.io and describe the integration. If TunnelNet is not the right answer we will say so — the guides already tell you when a cheaper option will do.