all systems operational
Get started
VPN / proxy
apps › vpn / proxy › wireguard

Your own WireGuard VPN on unmetered bare-metal.

A private, fast VPN exit that's yours alone — kernel WireGuard on an unmetered port, your own IP, and a jurisdiction you pick. No shared VPN service reading your traffic, no bandwidth meter, from $20/mo.

protocol
WireGuard
traffic
unmetered
tenancy
single-tenant
deploy
< 1 h
/ why it needs real iron

Why self-host WireGuard instead of a VPN app.

It's your box, your logs

A commercial VPN is a shared server you have to trust. Self-hosted WireGuard runs on a single-tenant machine you control — no other customers on the exit, no provider policy on what's logged. You hold the keys.

Unmetered, full-speed

Kernel WireGuard is fast, and the port is unmetered — no throttling once you've used 'your' quota, no per-GB meter. Route everything, all month, at line rate.

Pick your jurisdiction

Amsterdam or Warsaw for an EU exit, Kyiv for non-EU, Miami for the Americas. Choose where your traffic surfaces and get a stable, dedicated IP that isn't on every VPN blocklist.

One tunnel for everything

Team site-to-site, a private exit for your phone and laptop, or a secure hop to your seedbox and home lab — one small box handles it all, with clients for every platform.

/ recommended configurations

Sized for WireGuard VPN.

Starter / Production / High-load — with capacity in the metrics that matter for this app.

KyivAmsterdamWarsawMiami
Personal
personal exit · a few devices
  • CPU2 vCore
  • RAM4 GB
  • Storage40 GB NVMe
  • Port1 Gbit/s
  • Trafficunmetered
$20/mo
Deploy Personal →
Recommended
Team
team / site-to-site · dozens of peers
  • CPU4 vCore
  • RAM8 GB
  • Storage80 GB NVMe
  • Port10 Gbit/s
  • Trafficunmetered
$49/mo
Deploy Team →
Gateway
high-throughput gateway · many peers
  • CPU8 vCore
  • RAM16 GB
  • Storage160 GB NVMe
  • Port25 Gbit/s
  • Trafficunmetered
$129/mo
Deploy Gateway →
/ what’s included

On by default.

WireGuard pre-installed

Kernel WireGuard configured with a first peer ready, plus wg-easy or a simple config workflow to add devices in seconds.

Unmetered port

1–25 Gbit/s at flat pricing — route all your traffic all month with no per-GB meter and no throttle.

Your own static IP

A dedicated IPv4 (and IPv6) that's yours alone — cleaner reputation than a shared VPN pool, and it doesn't change under you.

Kill-switch friendly

Standard WireGuard configs work with client kill-switches so nothing leaks if the tunnel drops.

Any platform

Official WireGuard clients for Windows, macOS, Linux, iOS and Android — scan a QR code and you're on.

DDoS-protected

1.6 Tbit/s of always-on scrubbing keeps your exit reachable under attack.

Self-hosted WireGuard VPN hosting — your own private exit, unmetered

WireGuard is the modern VPN protocol: tiny, fast, and built into the Linux kernel, with clean clients for every platform. Running your own WireGuard server instead of subscribing to a VPN app changes the trust model completely — the exit is a single-tenant machine you control, with your keys and your IP, and no provider deciding what gets logged or throttled.

Hostfory is a natural home for it. The port is unmetered, so unlike a consumer VPN there's no 'fair-use' throttle after a few hundred gigabytes — route everything, all month, at full speed. You get a dedicated static IPv4 and IPv6 that isn't shared with thousands of other users (and isn't already on every blocklist), and you choose where your traffic surfaces: Amsterdam or Warsaw for an EU exit, Kyiv for a non-EU jurisdiction, Miami for the Americas.

One small box covers a lot of ground — a private exit for your phone and laptop, a team site-to-site tunnel, or a secure hop to your seedbox and home lab. It provisions in under an hour with WireGuard installed and a first peer ready; add devices by scanning a QR code.

ProtocolWireGuard (kernel)
Managementwg-easy / config workflow
IPDedicated IPv4 + IPv6
ClientsWin · macOS · Linux · iOS · Android
Port1–25 Gbit/s unmetered
LocationsAmsterdam · Warsaw · Kyiv · Miami
/ faq

WireGuard VPN questions, answered.

How is this different from a VPN app like NordVPN?
A consumer VPN is a shared server run by someone else, on their terms. Here the exit is your own single-tenant box — your keys, your IP, your logging policy (i.e. none unless you set it up). The trade-off is you manage it, but it's a few WireGuard configs, and we pre-install it.
Is the traffic really unmetered?
Yes — the port runs at its rated speed for a flat monthly price, with no per-GB meter and no throttle. Unlike consumer VPNs, there's no slowdown after a 'fair-use' threshold.
Do I get my own IP?
Yes — a dedicated static IPv4 and IPv6 that's yours alone. That means a cleaner reputation than a shared VPN pool and an address that doesn't rotate under you.
Can I add multiple devices and users?
Yes. Add peers in seconds via wg-easy or a config file — phones, laptops, routers, or a whole team. The Team and Gateway tiers are sized for many concurrent peers and site-to-site links.
Which client platforms are supported?
All of them — official WireGuard clients for Windows, macOS, Linux, iOS and Android. Adding a device is usually just scanning a QR code.
Can I pick where my traffic exits?
Yes — choose Amsterdam or Warsaw (EU), Kyiv (non-EU jurisdiction) or Miami (Americas). Your traffic surfaces from that PoP with its dedicated IP.
How fast is setup?
Under an hour — the server provisions with WireGuard installed and a first peer ready, so you connect immediately and add more devices as needed.
/ build your stack

Pairs with the rest of the fleet.

Deploy WireGuard VPN today.

In-stock configs provision in 1–3 hours. Migration from another host is on us.

Chat with us@hostfory