All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.
Technical Inquiry: VPS/Dedicated Server with BCP38/uRPF Exception for Controlled Internal Testing
Dear Team,
I am reaching out to inquire about a VPS or small dedicated server for a specialized project with specific networking requirements.
Technical Requirement:
Our implementation involves transmitting packets with custom source headers (IP Header Modification / IPHM). To support this, we require an environment where BCP38 (ingress filtering) and strict uRPF are disabled for our instance.
Legitimacy & Assurance:
To address any security or policy concerns, I would like to emphasize:
All destination IP addresses involved in our testing are owned and managed by us, meaning the traffic remains strictly within our own private infrastructure.
The traffic is low-bandwidth and targeted. It will not impact network stability or trigger any DDoS alerts.
Should the initial setup meet our technical needs, we plan to scale the project and procure multiple additional instances in the near future.
Our Question:
Could you please advise whether your network policy permits this configuration, or if you are able to whitelist our instance for this specific purpose?
Desired Specifications:
Virtualization: KVM preferred
Location: Flexible (open to Europe or other regions)
Resources: 1–2 vCPU, 2GB+ RAM, 15GB+ SSD (minimum)
I would be happy to provide further technical details privately upon request. Please feel free to reply here or reach out via DM.
Thank you for your time and consideration. I look forward to your response.
Comments
What kind of "internal" testing needs a publicly accessible spoof capable server?
Either way, you could try your luck with @MAXKO_Hosting , they can do spoofage in Serbia & Bulgaria
so, spoofed DDoS...
No, we do not conduct DDoS attacks.
Dear Valued Client @jams
Thank you for contacting our Technical Operations and Network Architecture Team regarding your hosting requirements and for taking the time to detail the technical scope of your project.
We have thoroughly evaluated your request for an environment operating with Network Ingress Filtering disabled—specifically regarding BCP 38 (RFC 2827) compliance and Unicast Reverse Path Forwarding (uRPF) checks—to facilitate custom IP header modification (IPHM). While we appreciate the context provided regarding your ownership of the destination IP space, low-bandwidth profile, and potential future deployment scaling, we must inform you that we are unable to accommodate this configuration on our network infrastructure.
To ensure complete transparency, we wish to outline the structural, operational, and regulatory constraints that necessitate this position.
Network Integrity & Regulatory Compliance Frameworks
Our global routing policy and edge infrastructure are designed in strict accordance with the mutually agreed norms for routing security (MANRS) and Tier-1/Tier-2 upstream transit provider mandates. BCP 38 is a foundational security standard implemented across our entire border, core, and access switching layers.
Strict Source Address Validation (SAV): Disabling uRPF or relaxing ingress filtering on individual interfaces or VLAN segments introduces severe architectural risks. Even within isolated virtualized environments (such as KVM), allowing arbitrary source IP generation bypasses our automated anti-spoofing controls.
Upstream Transit Mandates: Our network perimeter is continuously monitored by automated upstream filtering systems. Upstream transit partners enforce zero-tolerance policies regarding egress packets whose source IPs do not originate from allocated prefixes. Traffic violating these parameters is automatically dropped at the provider edge and triggers automated security alerts that jeopardize our global AS (Autonomous System) reputation.
Hardware & Virtualization Abstraction Limits
While KVM virtualization provides dedicated virtual hardware abstractions, packet encapsulation and framing ultimately pass through our shared physical network interface cards (pNICs) and top-of-rack (ToR) switches.
Layer 2 / Layer 3 Filtering Infrastructure: Our anti-spoofing ACLs (Access Control Lists) are enforced at the hardware switchport and hypervisor bridge levels. Selectively removing these filtering mechanisms for specific instances is technically infeasible without compromising the isolation guarantees of neighbor tenants sharing the same physical host and switch infrastructure.
Exceptions Policy: We do not offer custom exceptions, IP encapsulation overrides, or source-header whitelisting on standard virtual private servers or entry-level dedicated server products.
Summary & Next Steps
Because our routing stack cannot safely support arbitrary IP header modifications or unverified source address transmission, we cannot grant the required exceptions or fulfill your server order for this use case.
We understand this may require you to seek a specialized provider capable of delivering custom bare-metal deployments with dedicated, isolated cross-connects or BGP session privileges. We sincerely appreciate your interest in our services and wish you full success in bringing your project to fruition elsewhere.
Sincerely,
Technical Operations & Network Engineering Team
Infrastructure Security & Transit Policy Division
PS: I did not read a single word of this AI excretion.