Corporate VPN gateway in the EU
One stable European address your team connects through, so the terminal server and the accounting base never have to face the open internet.
Who it is for
A team spread across several countries
Everyone works from a different home connection with a different address, and half the systems they need are behind an IP allow list.
A company that had to publish RDP to get working
Port 3389 is open to the internet because there was no other way, and the logs are full of login attempts.
An office and a cloud that need to be one network
The file server is in the office, the application is in a data centre, and the two only meet over the public internet.
What you can run on it
- WireGuard, the default choice: fast, small config, reconnects instantly on a mobile network
- OpenVPN when a client device or an auditor requires it
- IPsec/IKEv2 for native clients on iOS, macOS and Windows with no software to install
- wg-easy, Firezone, Netbird or Headscale if you want a control panel and per-user access
- A self-hosted mesh coordination server, so your network map does not live in someone else's US SaaS
- Site-to-site tunnels between an office, a second office and this data centre
- A gateway in front of a Windows terminal server, so RDP is reachable only inside the tunnel
- Split or full tunnelling, and your own DNS resolver for internal names
Sized by how many people connect
A VPN gateway is bound by bandwidth and by connection count rather than by CPU, so these sizings are generous on purpose. Additional static IPv4 addresses can be added to any of them, and IPv6 is included.
What is and is not included
- This is a gateway to your own infrastructure. It is not a consumer VPN service and not a way to appear to be somewhere you are not.
- Reselling access to end users, open proxies and residential-style exit networks are outside our acceptable use policy. If your product is a VPN service for the public, talk to us about IPv4 space and transit instead - that is a different offer with a different contract.
- An OpenVPN Access Server licence is not included. The community OpenVPN server, WireGuard, Firezone and Headscale are all free.
- We do not manage your key material or your user list unless you buy server administration. You hold the keys.
- Port speed is shared. If you intend to push sustained gigabit through the tunnel, say so before you order so we can price it honestly rather than argue about it later.
Choosing a protocol without reading a white paper
- WireGuard is the right default. Fewer moving parts, less code to audit, and it survives a phone switching from wifi to mobile without dropping the session.
- OpenVPN is slower and heavier, but it runs over TCP 443, which is sometimes the only port a hotel or corporate network leaves open.
- IPsec/IKEv2 needs no client software on iOS, macOS or Windows, which matters when the people connecting are not technical.
- A static address is the point for whitelisting. Client banks, payment gateways, ERP clouds and some government services only accept connections from an approved address, and a distributed team has none.
- Two locations, Prague and Covilha, are two independent entry points on separate grids and separate upstreams under one AS - so a bad day at one site is not a day without access.
- Do not put the VPN and the thing it protects on the same host if you can avoid it. A EUR 15 gateway in front of the server is the cheapest security control on this page.
Publishing the port versus a gateway
| Service published to the internet | Behind a DCXV gateway | |
|---|---|---|
| Who can reach the login prompt | Every scanner on the internet | Only devices holding a key |
| What the logs look like | Constant credential stuffing | Quiet, so a real anomaly is visible |
| Working from a home connection | Address changes, allow lists break | One stable EU address for everyone |
| Access to systems with no public IP | Not possible | Reachable inside the tunnel |
| Revoking one person | Change a shared password | Delete one key |
| Cost | Nothing, until the incident | From EUR 15/mo |
Standing it up
Say who connects and to what
Number of people, the offices involved, and which systems need to be reachable. That is enough to pick a size.
We hand over the gateway
A cloud VM with a static address in Prague or Covilha, deployed in minutes, with root access and the protocol of your choice ready to configure.
Connect a first device and test it
One laptop, one tunnel, one system behind it. Confirm the route and the DNS before anyone else is involved.
Close the front door
Once everyone is inside the tunnel, stop publishing the service. That step is the one that actually pays for the gateway, and it is the one most often skipped.
Why choose us
- Tier III certified facilities, 99.982% facility SLA
- Own network, AS204057, IPv4 and IPv6 dual-stack
- 24/7/365 support with ~10 minute average response
- Cyprus company, EU jurisdiction, GDPR-native since 2007
FAQ
- How much does a corporate VPN server cost?
From EUR 15 per month for a gateway sized for up to 25 tunnels (2 vCPU, 4 GB RAM, 40 GB NVMe, one static IPv4). Up to 100 tunnels is EUR 18.43, and a size intended for site-to-site links plus remote staff is EUR 36.88. Billing is monthly with no minimum term, and IPv6 is included
- Which protocol should I choose: WireGuard, OpenVPN or IPsec?
WireGuard for almost every case: it is faster, the configuration is small enough to read, and a session survives a phone moving from wifi to mobile data. Choose OpenVPN when you need to pass through a network that only allows TCP 443, and IPsec/IKEv2 when the people connecting should not have to install anything, since iOS, macOS and Windows all support it natively
- Can I use it to get a static IP address for client-bank whitelisting?
Yes, and it is one of the most common reasons customers buy one. Your gateway has its own static European IPv4 address, so every person connecting through it reaches the bank, the payment gateway or the ERP cloud from that one approved address rather than from whatever their home connection was assigned today
- Can I resell VPN access to end users?
Not on this product. It is a gateway to your own infrastructure, and reselling access to the public, open proxies and residential-style exit networks are outside our acceptable use policy. If you operate a legitimate VPN service, the offer you want is IPv4 space and transit: we are an approved RIPE NCC broker and can supply clean addressing with a reputation check before the deal, which is a separate contract
- Can I connect an office to the data centre with a site-to-site tunnel?
Yes. A site-to-site tunnel between an office router and the gateway makes the two one network, so an application in Prague or Covilha can reach a file server in the office without either being published to the internet. Several offices can join the same gateway
- Do you keep logs of VPN traffic?
We do not inspect or log the contents of your tunnels. The gateway is your server with your root access, so what it logs is what you configure it to log. Standard infrastructure records such as network flow data for abuse handling are covered by the privacy policy
If you require assistance or have additional questions, please contact the managers or write to the support team at support@dcxv.com
Cloud servers from €15/mo
Order Now