See both directions
Review inbound and outbound bandwidth, packet rates, and application usage to spot activity that looks suspicious. Aegis provides visibility for your investigation, without automatic intrusion alerts or blocking.
Every LayerOne VPS is a real virtual machine: a 2.5 Gbps port, Enterprise SAS SSD, always-on DDoS, dedicated IPv4, and hourly credit billing from $0.0034/hr. Hosted in Tampa on Intel Xeon Skylake-SP or better.
See what reaches your VPS and what leaves it. LayerOne Aegis brings network traffic, application insights, open-port checks, and DDoS activity into your client area, alongside the firewall controls that help you reduce exposure.
Review inbound and outbound bandwidth, packet rates, and application usage to spot activity that looks suspicious. Aegis provides visibility for your investigation, without automatic intrusion alerts or blocking.
Check observed open TCP and UDP ports and identified services. Use the findings to review what your applications make reachable.
Included L3/L4 DDoS mitigation, attack alerts, and inbound and outbound firewall rules help you protect the services you run.
You get an isolated guest, root on the OS you chose, and the network to put it on the public internet. The same control model ships on Nano through Max.
Each VPS is its own virtual machine: kernel, users, firewall, package manager, and long-running services. vCPU oversubscription stays conservative so bursty workloads remain responsive.
Application files, databases, logs, and package installs live on enterprise SAS SSDs. Optional backup storage covers snapshots and backups; still copy anything irreplaceable off the server.
A dedicated IPv4 on a multi-homed Tampa BGP network, with a 2.5 Gbps port and always-on L3/L4 DDoS mitigation. You still own the host firewall. Extra IPv4 is an hourly add-on.
Pick a template at checkout, or upload a custom ISO. After boot you get root credentials by email and can install Docker, systemd services, or a control panel of your own.
Nano is not a cut-down product. CPU, RAM, and disk change with the plan. The control model and network do not.
Enable or remove add-ons while the server is live. No long-term contract on the extras.
See add-on ratesStart, stop, reinstall, upgrade, and recover without opening a ticket. Use the dashboard when you want a visual workflow or automate the same server actions through the API.
Start, stop, restart, reinstall, and upgrade from the service page. Billing, credit, and payment methods live in the same shell.
Open the dashboardOut-of-band access when a firewall rule, SSH config, or boot issue blocks remote login. Recover without rebuilding first.
Deploy, inspect, power-cycle, and destroy with a bearer key. Locked until hourly billing is unlocked on an active account. 5,000 requests/month included, then $1.00 per 100,000 overage.
API referenceA VPS is not only a deploy button. Visibility, out-of-band access, and a support path are what you use when customers are already on the box.
Allow or deny inbound and outbound traffic from the service page after deployment. Rules apply before traffic reaches the guest OS, while LayerOne protects assigned addresses from spoofing.
Buy backup storage from Images at $1.00 per 10 GB per month, billed hourly. Snapshots and backups share the pool. Restore in place or deploy a new VPS from a backup. Keep an off-server copy of anything you cannot replace.
Rebuild from a template on the service page when the guest is beyond repair. Take a backup first; a reinstall erases the disk.
99.9% uptime SLA, a public status page, and service credits when we miss the target. Redundant power, network, and storage in Tampa.
Read the SLACreate isolated LANs for your own servers. Members can communicate privately, and nothing enters or leaves unless you route it through a firewall you control. Connect a server to more than one private network when needed.
Why configure a VNetTickets go to the people who run the hosts, the network, and billing. Platform monitoring and ticket intake run 24/7, without a scripted first line.
Contact supportIf it runs on a normal Linux or BSD VPS, it belongs here. Start on the resources you need today and move up when the workload proves it.
Reverse proxies, app servers, queues, and a small database on one box. Split later when traffic or reliability needs it.
Minecraft, Valheim, Factorio, and voice tools with public ports, included mitigation, and enough RAM to keep the tick rate honest.
Game server hostingVaultwarden, Nextcloud, Pi-hole, Gitea, and Home Assistant on a machine that stays up when home internet does not.
Homelab hostingWireGuard, OpenVPN, reverse tunnels, and DNS filtering on a server you control, with a stable public address.
WireGuard VPN hostingPython, Node, or Go bots, cron, and tiny APIs. Pico or Nano is enough for most of these, billed from about $2.50/month.
Discord bot hostingA realistic environment for package builds, preview deploys, demos, and internal tools that should not live on a laptop.
Use the same workflows your team already knows. Provision infrastructure, configure hosts, and run container workloads without waiting on manual setup.
Manage VPS infrastructure as code.
Run containers and Cluster API workflows.
Configure Linux servers over SSH.
CPU and RAM usually decide the tier. Storage confirms it. Transfer is a 2 TB account pool plus up to 500 GB per server each month, prorated by time provisioned. Pricing lists CPU, RAM, disk, and hourly rates from $0.0034/hr.
Isolated KVM, a 2.5 Gbps port, Intel Xeon Skylake-SP or better, Enterprise SAS SSD, full root SSH, a browser console, dedicated IPv4, always-on DDoS mitigation, a hypervisor firewall, and a 99.9% uptime SLA.
Yes. Buy backup storage from Images at $1.00 per 10 GB per month, billed hourly from account credit. The pool is organization-wide; Images lists this tenant's backups. Snapshots restore only the source server. Backups can deploy a new VPS. Canceling takes effect on the 1st; copies stay seven days, then every copy in the organization is deleted. Keep an off-server copy of anything you cannot replace.
Use the browser console from the client portal. It is out-of-band access for firewall, SSH, and boot problems, so you can recover without rebuilding first.
Yes. Open the server in the client portal and use the Network tab. Set inbound and outbound policy plus ordered allow or deny rules. They apply before traffic reaches the guest OS, while LayerOne keeps anti-spoofing protection enabled for assigned IPs.
Debian, Ubuntu, AlmaLinux, Rocky Linux, Alpine Linux, FreeBSD, Windows, and pfSense at deploy time, or a custom ISO. We email root credentials when the VM is online, usually in under 60 seconds.
Yes. The client API deploys, inspects, power-cycles, and destroys instances using the same paths as the portal. It stays locked until hourly billing is unlocked on an active account.
Every General Compute VPS includes a 2.5 Gbps port. Transfer starts with a 2 TB free account pool each UTC calendar month. Each server earns up to 500 GB over the month, prorated by time provisioned. Extra transfer is $3.00/TB per calendar month via Extra Bandwidth blocks or usage beyond the pool. Resize for CPU and RAM; buy transfer when traffic spikes.
Yes. Create isolated VNets from Network in the client portal. Members on the same VNet can talk to each other. The platform blocks traffic entering or leaving the VNet, and there is no platform NAT. An account can create 10 virtual networks by default. A VM may attach to more than one VNet; the platform does not route between them. Setup guide.
Pick a plan, pick an OS, and the machine is online in under 60 seconds. No setup fees, hourly credit billing, and engineer support if something on the platform goes sideways.