# Fixed Global IP Address

Optional feature for assigning two fixed global (public) IP addresses to a VPG.

## Overview

Soracom Virtual Private Gateways can optionally be configured with two fixed global (public) IP addresses. These IP addresses are unique to each VPG, and when enabled, all internet-bound traffic will appear to originate from one of these addresses.

![VPG Fixed Global IP Address](https://docs.soracom.io/_astro/fixed-global-ip-address.DmmdZy1T_Z1DH2gG.webp)

In applications where devices are configured to send data over the Internet to a specific destination, the Fixed Global IP Address option allows you to easily define an allowed and denied list for incoming traffic at the destination, ensuring that no unauthorized traffic reaches the destination host. Moreover, the Fixed Global IP Address option applies to all Air for Cellular and Arc devices attached to the corresponding VPG, so no additional configuration is required when scaling up to a large number of devices. Just add an Air or Arc device to an appropriate group, and internet-bound data will automatically appear to originate from one of the fixed IP addresses.

When combined with Soracom Beam, data forwarded by Beam will also appear as originating from one of the two IP addresses, allowing you to freely mix and match devices and communication protocols, offload encryption, and manage endpoint configuration directly within Beam while also maintaining security.

> [!NOTE]
>
> At this time, the source IP address applies only to Air for Cellular and Arc devices, and does not apply to Air for Sigfox or Air for LoRaWAN devices.

> [!NOTE]
>
> When enabling or disabling the Fixed Global IP Address option for a VPG, the IP addresses assigned to the VPG will be changed. Existing connections, such as SSH sessions or data transfers, will need to be reconnected.

## Enabling Fixed Global IP Address

> [!WARNING]
>
> The Fixed Global IP Address option will incur fees. Refer to the [Pricing & Fee Schedule](https://docs.soracom.io/en/pricing) for more information.

You can enable the Fixed Global IP Address option for a VPG from the User Console.

1. Sign in to the **[User Console](https://console.soracom.io/?coverage_type=g)**. From the **☰ Menu**, open the **VPG** screen.

2. From the list of VPGs, click the **name** of the VPG you want to configure to open its settings page.

3. Click the **Assign a static IP Address** button.

   ![Assign a static IP Address](https://docs.soracom.io/_astro/assign-ip-address.Bhhu_cTP_1HHOqC.webp)

4. Click **Enable** to confirm enabling the option.

   ![Enable Fixed Global IP Address option](https://docs.soracom.io/_astro/enable-fixed-global-ip.Dbh1Sdfj_2kwFb0.webp)

The IP addresses assigned to the VPG will be visible. For your convenience, you can copy each IP address in order to add them to your firewall rules or other security policies.

![Copy IP Addresses](https://docs.soracom.io/_astro/copy-ip-address.Dla6vvu-_Z1mHXRB.webp)

## Disabling Fixed Global IP Address

You can also disable a VPG's Fixed Global IP Address option from the User Console.

1. Sign in to the **[User Console](https://console.soracom.io/?coverage_type=g)**. From the **☰ Menu**, open the **VPG** screen.

2. From the list of VPGs, click the **name** of the VPG you want to configure to open its settings page.

3. Click the **Change to a dynamic IP Address** button.

   ![Change to a dynamic IP Address](https://docs.soracom.io/_astro/disable-fixed-global-ip.CUgKMmQS_Z147CfI.webp)

4. Click **Disable** to confirm disabling the option.

> [!NOTE]
>
> **Important!** Disabling the Fixed Global IP Address option will permanently remove the static IP addresses from the VPG. If you re-enable the Fixed Global IP Address option again, a new set of IP addresses will be assigned to the VPG. It is not possible to re-enable the option and resume using the previously assigned IP addresses. You will need to make sure that your firewall rules or other security policies are updated with the new IP addresses.
>
> In addition, be aware that disabling the Fixed Global IP Address option may interrupt ongoing connections, such as SSH sessions or data transfers.
