BGP over GRE & VPN

Always on IP

Keep the same IP. Even when the network underneath it changes.

Give critical applications, APIs, VPNs and services a provider-independent static IP that remains reachable across ISP failures, connectivity changes and disaster-recovery events.  Powered by Total Uptime’s global BGP network with GRE or IPsec connectivity, fully managed by our engineers. 

BGP Anycast

Provider-Independent Static IP

IPv4 / IPv6

GRE / IPsec 

Always-On BGP Network Architecture

The resilience gap

Two ISPs do not automatically mean application resilience.

Redundant circuits keep you online, but when your public IP changes, critical systems can still break.  Many applications, APis, VPN’s, firewall rules, and allowlists depend on a consistent IP address.

VPN's

VPN tunnels may need to be rebuilt.

API allowlists

API’s can block new IP’s.

Firewall rules

Security rules may need updates.

User access

Users and partners may lose access.

One IP identity. Multiple ways to reach it.

Always-On IP separates your public IP identity from the underlying internet provider. Total Uptime announces the IP across our network while your environment connects to us using standard GRE or IPsec tunnels over your existing internet links.  If an ISP, path or location changes, the public IP identity does not have to. Critical applications, VPNs and trusted integrations can remain reachable through the same address while traffic follows an available path. 

IP

Static IP anywhere

A fixed, portable public IP delivered over any ISP even where BGP or static addressing isn’t offered.

BYO

Bring your own IP

Already own address space? We announce your IPv4 or IPv6 prefixes on our global network.

HA

Redundant tunnels

No single point of failure: active-active GRE/VPN tunnels from multiple POPs, to any availability target.

Up and running in four steps

Always-On IP is a managed routing service designed for technical teams that need provider-independent addressing without building and operating the full BGP stack themselves. 

IP assignment or BYOIP

Use Total Uptime-provided address space where appropriate, or bring approved customer-owned prefixes and ASN information when the deployment requires it. 

GRE or IPsec connectivity

Establish one or more tunnels from the customer environment to Total Uptime network POPs over standard internet connections.

BGP routing

Total Uptime announces the relevant IP space through its global network and manages the routing-side architecture.

Failover

When a path fails, traffic can follow an available route while the public IP identity stays consistent. Configure redundant tunnels, ISPs and POPs to remove individual connectivity dependencies.

Total Uptime vs. the alternatives

Most options force you to own a /24, run BGP yourself, or lock your IPs inside a single cloud. Total Uptime doesn’t.

Why Always-On IP

Provider-independent

Keep the same network identity without tying it to one ISP or one access circuit. 

Fully managed BGP

Total Uptime designs and operates the routing architecture, including the network-side BGP components, monitoring and support. 

Fast routing-layer failover

Use routing-based path changes measured in seconds rather than relying only on DNS updates or manual reconfiguration. 

Works across diverse connectivity

Use resilient addressing over standard internet links, including environments where traditional BGP or durable provider static IPs are difficult to obtain. 

Where Always-On IP fits

Use it wherever a changing IP can become an availability problem.

ISP failover

Keep applications and services reachable when the primary internet connection fails.

VPN and API continuity

Maintain the trusted IP identity used by partner VPNs, source-IP allowlists and security policies.

Disaster recovery

Move service delivery to a DR site or alternate environment without unnecessarily changing the public-facing network identity.

Multi-site operations

Standardize resilient static addressing across branches, stores, healthcare sites, hospitality, gaming or other distributed estates. 

Cloud and data-center migration

Change underlying infrastructure while reducing the disruption created by public IP renumbering.

Hard-to-connect locations

Extend durable static addressing to sites using broadband, cable, 5G or satellite where conventional BGP may not be practical.

Frequently asked questions

What is Always-On IP?

Always-On IP is Total Uptime’s managed provider-independent static IP service. It is designed to preserve a consistent public IP identity across ISP, network-path and infrastructure changes using managed BGP with GRE or IPsec connectivity. 

An ISP static IP is normally tied to that provider and connection. Always-On IP is designed to separate the public network identity from an individual ISP so the same address can remain reachable through alternate connectivity paths. 

That is a core use case. With redundant connectivity and routing designed correctly, traffic can move to an available path while the public IP identity remains consistent. 

No. Always-On IP solves a different layer of the availability problem. It provides resilient connectivity and IP continuity for IP-bound traffic. DNS/GSLB can still be used for global traffic steering, multi-site application failover and other application-delivery policies. 

Not necessarily. Total Uptime manages the BGP-side architecture. Deployment options depend on the customer environment, addressing model and whether customer-owned IP space is being used. 

Yes. GRE is commonly used for routed connectivity, while IPsec can be used where encrypted tunnel delivery or environmental constraints make it the better fit. 

BYOIP can be supported for approved customer-owned prefixes, subject to routing and deployment requirements. 

Typical use cases include ISP failover, partner VPN continuity, source-IP allowlisted APIs, disaster recovery, multi-site operations, migrations and locations where durable static IP addressing is difficult to obtain. 

Customer success

Trusted by IT Teams Worldwide

Real organisations. Real resilience. Real results.

Rated by the people who use us.

Prove it before you depend on it.

Run a controlled connectivity-failure proof of concept with a Total Uptime engineer. We will help you test whether a critical application, VPN or whitelisted service remains reachable through an ISP or path failure using the same Always-On IP.