Fixed public IP for business
Fixed public IP for business is essential for VPN, remote access, and SIP trunking. Smartnett delivers dedicated IPs with 99.999% SLA. Read the full guide.

A fixed public IP for business is one of the most foundational requirements any IT administrator must address before deploying enterprise-grade infrastructure. Unlike dynamic addresses that change with every connection cycle, a static public IP remains constant, enabling predictable, policy-driven network operations. Whether you are terminating VPN tunnels, hosting a SIP trunk for VoIP, enforcing firewall allowlists for B2B partners, or running an on-premises server reachable from the public internet, a fixed address is not optional — it is a hard technical requirement. This guide explains exactly why, how dedicated internet access delivers static IPs as a native feature, and how to match each use case to the right connectivity tier.
Why a fixed public IP for business is not the same as a static home IP
Consumer broadband providers occasionally offer so-called static addresses as an add-on, but these are typically RFC-1918 private addresses translated through a carrier-grade NAT (CGNAT) layer shared across thousands of subscribers. The result is that inbound connections from the public internet never reliably reach the premise. A genuine fixed public IP for business means a routable, globally unique IPv4 (or IPv6) address assigned exclusively to your organization and announced via BGP from the ISP's autonomous system. This distinction is critical for compliance frameworks such as HIPAA, PCI-DSS, and SOC 2, all of which require documented, auditable network access controls that depend on predictable IP addressing.
Static IP vs. dynamic IP: a technical comparison
| Attribute | Static / Fixed Public IP | Dynamic IP (DHCP/CGNAT) | |---|---|---| | Address stability | Permanent until changed by admin | Changes at each DHCP renewal or session reset | | Inbound reachability | Full — any port, any protocol | Limited or blocked by CGNAT | | DNS hosting (A record) | Reliable — TTL matches address lifespan | Requires dynamic DNS service; propagation lag | | VPN termination | Native — firewall rule points to one IP | Unreliable — peer address changes unexpectedly | | SIP trunk registration | Stable — carrier authorizes single source IP | Requires SIP ALG workarounds; higher failure rate | | Firewall allowlisting for B2B | Simple — one CIDR block whitelisted per site | Impractical — partner must allowlist entire carrier range | | BGP peering | Supported with /24 or larger block | Not supported | | Compliance auditability | Full audit trail tied to fixed address | Ambiguous logs; harder to attribute traffic |
Source: IETF RFC 6877 (CGNAT), Cisco Enterprise Networking Design Guide 2023.
How dedicated internet access delivers fixed public IPs natively
Dedicated internet access (DIA) is a circuit type in which 100 percent of the provisioned bandwidth is reserved exclusively for one customer — no contention ratio, no traffic-shaping during peak hours, no shared last mile. Because the circuit is dedicated, the ISP assigns a fixed public IP block (/29 or larger, depending on the SLA tier) that is yours for the life of the contract. This is fundamentally different from business broadband products that are based on the same DOCSIS or GPON infrastructure as residential service and still route through CGNAT for many inbound use cases.
With dedicated bandwidth delivered over a fiber optic last mile, the combination produces:
- Symmetric throughput — upload equals download, typically from 300 Mbps to 10 Gbps at Smartnett's commercial tiers.
- Intra-city latency of 2–8 ms — relevant for real-time applications like VoIP and video conferencing.
- Packet loss below 0.01% — the threshold for toll-quality voice defined by ITU-T G.114.
- Jitter below 5 ms — required for SIP trunks carrying more than 50 concurrent calls.
- A fixed public IP block tied to your BGP prefix, announced from the ISP's AS.
In contrast, a shared business broadband circuit may advertise speeds of 500 Mbps down but deliver as little as 40 Mbps during peak evening hours (Ookla Speedtest Market Report, Q4 2023), and the assigned address can still sit behind CGNAT.
Fixed public IP for business: the eight use cases that require it
The table below maps each common enterprise use case to the IP addressing requirement and the connectivity tier that satisfies it.
| Use Case | Why Fixed Public IP Is Required | Minimum Bandwidth Tier | SLA Needed | |---|---|---|---| | IPsec/SSL VPN termination | Remote peers must reach a stable IP; dynamic DNS introduces failure points | 100 Mbps symmetric | 99.99% | | Remote workforce access (ZTNA overlay) | Identity-aware proxies log source IP for audit; CGNAT breaks attribution | 200 Mbps symmetric | 99.99% | | B2B partner connectivity (API/EDI) | Partners allowlist specific CIDR; any change requires a firewall change order | 100–500 Mbps | 99.99% | | SIP trunk / VoIP (PBX hosted on-prem) | SIP carrier registers the source IP; mismatch causes 403 Forbidden errors | 50–200 Mbps | 99.999% | | On-premises server hosting (web, FTP, SFTP) | DNS A record must resolve to a fixed address 24/7 | 500 Mbps–10 Gbps | 99.999% | | Payment gateway (PCI-DSS scope) | Acquirer networks allowlist merchant IP; dynamic IPs trigger fraud flags | 100 Mbps | 99.999% | | HIPAA-covered video telehealth platform | Covered entity must document all network egress points with fixed identifiers | 200 Mbps–1 Gbps | 99.999% | | Cross-border US–LATAM leased line overlay | BGP peering across border requires stable AS and IP block per region | 1–10 Gbps | 99.999% |
Source: ARIN IP addressing policies; PCI-DSS v4.0 Requirement 1.3; HIPAA Security Rule 45 CFR §164.312(a)(1).
VPN termination and remote access: the most common fixed IP driver
According to Gartner's 2024 Network Security Survey, 68 percent of enterprise IT teams cite VPN reliability as the primary reason they migrated from shared broadband to dedicated internet circuits. When a head-office firewall (Cisco ASA, Palo Alto, Fortinet FortiGate) terminates site-to-site IPsec tunnels from branch offices, every branch peer must know the head-office public IP in advance and statically configure it inside the crypto map or IKE peer statement. If that IP changes — even once — every tunnel drops simultaneously and requires manual reconfiguration across all branches.
Configuring firewall rules that depend on a fixed IP
Firewall policy engines (Palo Alto PAN-OS, Check Point, Cisco FTD) allow zone-based policies where the source or destination is an explicit IP object. When you have a fixed public IP for business, the workflow is:
- Define an address object:
10.0.0.0/24(internal) → NAT →203.0.113.10(fixed public IP). - Share
203.0.113.10with every B2B partner's security team. - Partners create an inbound allowlist rule for
203.0.113.10on their edge firewall. - All outbound API calls, EDI transactions, and SFTP transfers originate from the same address — no change orders, no SLA breaches.
With dynamic addressing, step 2 is replaced with
Written by
Eng. Roberto Mendoza Carrillo
Network Engineering — Smartnett
Telecommunications Engineer (UPIICSA-IPN). 12 years designing SD-WAN architectures and dedicated links for corporate clients in Mexico. Cisco CCNP and MikroTik MTCRE certified.


