On this page

A VPS makes a good personal VPN if you pick it for the job: KVM virtualization, unmetered bandwidth, IPv4 and IPv6,
Choosing an offshore VPS for VPN use also means accepting two limits: a server that only you use is not anonymous, and some services refuse VPN traffic. This guide covers both sides, then the server, the exit country, the software and the setup.
Your own VPN vs a commercial VPN, honestly
When you host your own VPN, you move trust from a VPN company to yourself and your host. That buys control and costs anonymity:
| Point | Your own VPN on a VPS | Commercial VPN |
|---|---|---|
| Who carries your traffic | Your host's network; ours does not log or inspect it | The VPN company's servers |
| Logging rules | Yours to set; WireGuard itself writes no connection logs | The provider's policy, which you have to trust |
| Exit IP address | Used by you alone, so sites can recognize you from visit to visit | Shared by many users, so your traffic blends in |
| Locations | One | Typically many, switchable in an app |
| Upkeep | You patch and watch the server | The provider does |
| Cost | From $2.39 | Set by the provider |
In short, a personal VPN hides your browsing from the
Streaming is the other limit: services may detect and refuse VPN traffic. Netflix, for example, shows "You seem to be using a VPN or proxy" when it does, and a VPS address can be affected, so do not rent one only to stream.
What makes a good VPS for VPN use
- KVM virtualization. WireGuard lives inside the Linux kernel. On KVM you run your own kernel, so it is available on any current distribution.
Container-based plans share the host's kernel and may not let you use it. - Unmetered bandwidth. A VPN carries everything you do online, so a traffic quota turns video calls and large downloads into a bill. Ours is
1 Gbps , unmetered under fair use. - IPv4 and IPv6. With both on the server, the tunnel can carry all your traffic. Without IPv6, your devices' IPv6 connections either fail or, if misconfigured, go around the tunnel. Every VPS here has one dedicated IPv4 address and a /64 IPv6 range.
- A jurisdiction you trust. The server's country decides which court can order the host to act, and what the host holds decides what it could hand over. An account here is an email address and a password, with no identity check, as our
no-KYC VPS page explains. - Low latency to you. Every packet makes the round trip through the server, so distance adds to every click.
- Rules that allow VPNs. Read the host's acceptable use policy before you order. Our acceptable use policy welcomes VPNs, proxies and Tor relays, including exit relays.
Choosing the exit country
Which is the best location for a VPN server? There is no single answer. Decide with three questions, in this order:
- Where are you? For everyday use, the closest location feels fastest. Below about
50 ms of round trip, interactive use feels instant. - Where do you need to appear? Sites see your server's country. If you need an address in a particular region, that settles it.
- Which legal climate do you prefer? Each location page explains the law, the takedown rules and data retention. If intelligence alliances matter to you, six of our seven locations are outside the 14 Eyes: see what the 14 Eyes mean for a server.
| Location | London | Frankfurt | Singapore | |
|---|---|---|---|---|
| Netherlands (Amsterdam) | ||||
| Switzerland (Zürich) | ||||
| Iceland (Reykjavík) | ||||
| Bulgaria (Sofia) | ||||
| Romania (Bucharest) | ||||
| Moldova (Chișinău) | ||||
| Malaysia ( |
From the UK and western Europe, Amsterdam and Zürich are closest. From
Legal climates differ too. The Netherlands has had no general
Why 1 vCPU and 1 GB is enough for a WireGuard VPS
WireGuard is small by design. Its authors say it is meant to be implemented in very few lines of code, and it runs inside the kernel rather than as a separate program. On the
- Dinghy, $2.39
a month 1 vCPU ,1 GB RAM ,25 GB NVMe . Enough for WireGuard on your own devices.- Sloop, $3.49
a month 1 vCPU ,2 GB RAM ,40 GB NVMe . Room for a DNS resolver or an ad blocker next to the VPN.- Cutter, $5.49
a month 2 vCPU ,4 GB RAM ,70 GB NVMe . A second core when several people share the tunnel for large transfers.
The CPU sets the ceiling on throughput, because the server encrypts and decrypts every packet.
WireGuard or OpenVPN?
Both are open source. For a personal VPS, WireGuard is the simpler default; OpenVPN keeps one clear use case.
| Point | WireGuard | OpenVPN |
|---|---|---|
| Transport | UDP only | UDP or TCP |
| Cryptography | A fixed set: Curve25519, ChaCha20, Poly1305, BLAKE2s | Negotiated over TLS, using the OpenSSL library |
| Where it runs | Inside the Linux kernel | A |
| Setup | Exchange public keys, like SSH keys | Usually a certificate authority and a certificate per device |
| Disguising the VPN | Not a design goal | Can run over TCP, which helps where UDP is blocked |
Choose WireGuard unless you need TCP. On a hotel or office network that blocks UDP, OpenVPN over TCP may connect where WireGuard cannot, since WireGuard explicitly does not support tunneling over TCP. WireGuard also roams: both ends send data to the most recent address they authenticated, so a phone moving from wg show
Is running your own VPN legal?
In most countries, yes. A VPN is an encrypted connection to a server you rent. What you do through it is judged by the same laws as without it: a VPN changes your route, not your rights. Some governments restrict VPNs; in Russia, for example, Freedom House reports expanded blocking of VPNs and orders to remove VPN apps from app stores. Check the rules where you live and where you travel.
On our side, VPNs are allowed in all seven locations. One rule matters if you share the server: traffic from everyone on your VPN leaves through your server's IP address, so spam, scans or attacks by anyone you let in count as coming from your server under our acceptable use policy. Give access only to people you trust.
Set up a VPS for VPN use in 15 minutes
- Order the server. Pick the Dinghy plan in your chosen location, with
Debian 13 ,Ubuntu 24.04 LTS or Alpine Linux. It is live about60 seconds after you order, paid from your balance. - Harden it. Log in over SSH, install updates, switch to
key-only logins and turn on a firewall, as in our hardening guide. - Install WireGuard and create keys. One key pair for the server and one for each device.
- Configure the tunnel. Give it a private address range, open its UDP port (51820 is the usual choice) and turn on IP forwarding and NAT.
- Add your devices. Route all IPv4 and IPv6 traffic through the tunnel, and use a DNS resolver reached through it.
Our WireGuard setup tutorial has the exact commands. If you run your own DNS resolver on the server, bind it to the tunnel only: an open resolver on the public interface can be abused for amplification attacks, which our acceptable use policy forbids.
Frequently asked questions
Can I use a VPS as a VPN?
Yes. Install WireGuard or OpenVPN on a Linux VPS and route your devices' traffic through it; the sites you visit then see the server's IP address instead of yours. Choose KVM virtualization, unmetered bandwidth and a location close to you. On our VPS plans, VPNs, proxies and Tor relays are all allowed.
Is it safe to host your own VPN?
Yes, if you maintain it. Keep the server patched, log in with SSH keys only, open just the SSH and VPN ports, and protect each device's private key. The main risks are a neglected server and sharing access with people whose traffic you cannot vouch for, because everything they do leaves through your server's IP address.
Is a self-hosted VPN better than a commercial VPN?
For control, yes: you set the logging rules and pick the country. For anonymity, no: your exit address belongs to you alone, while a commercial VPN mixes your traffic with that of many other users. A
How much RAM does a VPN server need?
Very little. WireGuard runs inside the Linux kernel, so
Which country is good for a VPN server?
One that is close to you, where you need your address to appear and whose legal climate you accept. On our model, Amsterdam is about
Offshore VPS, dedicated, RDP and GPU servers in seven jurisdictions.


