Your site deserves a real IP. Not a borrowed one.
The wayangi Managed Router puts a dedicated public IPv4 and a dedicated public IPv6 behind your door, on whatever internet you already pay for. Fiber, CGNAT, 4G. We build it, we run it, we watch it around the clock. You plug it in.
No NAT. No port-forwarding tickets. No "sorry, static IP is business-plan only". Just an address the whole world can reach, that stays yours when you switch ISPs.
From IDR 3,000,000 / month per site · quote within one business day · no long-term lock-in required
Problems you might recognise
It's not your ISP's fault. Home and office connections in Indonesia were never designed to be reached from outside.
The shop CCTV won't open from your phone
You paid for a good NVR, but from outside the office it's always "not connected". The vendor says your internet is CGNAT and shrugs.
Blocked by the bank because your IP changed
The POS app, a vendor portal, or corporate internet banking wants a fixed IP. The one from your ISP changes every time the modem restarts.
Office phones drop or go one-way
PBXs and SIP trunks hate NAT. Callers hear you, you don't hear them. The provider blames the router, the router vendor blames the ISP.
A technician has to drive out for every issue
Servers and devices at the branch can't be reached remotely. Every incident costs a trip and hours of waiting.
All of these share one root cause: your site has no fixed public address. That is exactly what we install.
QUICK FACTS
- What it is:
- a managed MikroTik router at your site with one dedicated public IPv4 and one dedicated public IPv6, routed from AS154547 (dalang.io).
- Who it's for:
- offices, branches, clinics, server rooms, CCTV and PBX installs that need a fixed, reachable public address.
- Works on:
- any ISP in Indonesia or abroad, fiber, CGNAT, 4G/5G, up to 3 uplinks with automatic failover.
- Price:
- from IDR 3,000,000 per site per month. Extra IPv4 / IPv6 addresses and hardware quoted on request.
- Setup:
- we generate and lock the config to your router. You plug in WAN and LAN. Nothing installed on your devices.
- Order:
- [email protected] or WhatsApp dalang.io.
- 1 × dedicated public IPv4 /32
- 1 × dedicated public IPv6
- Router configured, hardened, managed
- Dual-hub tunnel: Jakarta + Singapore
- Up to 3 ISP uplinks, auto failover
- Watched 24/7 by our network team
What IDR 3 million a month actually buys
The usual way to get a fixed public IP in Indonesia is a dedicated internet line, which starts at around IDR 4.5 million a month and means replacing the connection you already have. The Managed Router gives you the addressing part on top of the internet you already pay for.
Dedicated internet with an SLA
- The usual way to get a fixed public IP in Indonesia
- You replace the line you already have, rather than adding to it
- One line, one site; the next branch pays in full again
- The IP goes away when the subscription ends
Renting a public IP over VPN
- Cheap, but what you get is a VPN username and password
- Bandwidth capped by the plan, typically 10–150 Mbps
- Configuration and upkeep are yours
- No hardware, no failover, no replacement unit
wayangi Managed Router
- Dedicated-class addressing on the internet you already pay for
- Watched 24/7 by our network team
- The IP follows you to any ISP and any building
- Up to 3 ISPs with automatic failover
- Router provisioned, managed, replaced if it fails
What you should know about cost
- Billed monthly by invoice. The final price is written in the quote before you pay anything.
- Router: use a MikroTik you already own (we provision it) or a unit from us, priced in the quote.
- Extra IPv4 or IPv6 addresses are priced per address; the base package doesn't change.
- No long-term contract. Stop any time at the end of the paid period.
- One day of CCTV, POS, or office phones being down usually costs more than a month of service.
The Managed Router is run by the network team at dalang.io, an Indonesian carrier-grade cloud and bare-metal provider trusted by more than 100 companies. We run our own AS, so the address you use is ours, not leased from a third party that can pull it back.
A static IPv4 that is actually yours
One clean /32 from our own address space, leased to you for as long as you stay. The router hands it straight to a machine on your LAN by DHCP. No port-forward table, no double NAT, no carrier-grade NAT in the way.
- Dedicated, never shared, never recycled mid-contract
- Inbound and outbound through our AS
- Need more? Add /32s to the same router
A dedicated public IPv6, side by side
One static, globally-routable IPv6 address from our AS, delivered to your LAN right next to the IPv4. Reachable from anywhere on the v6 internet, even if your ISP has never heard of IPv6.
- Dedicated, static, yours for the subscription
- Same address no matter which ISP is up
- Need more? Extra IPv6 addresses on request
We run it, so you don't have to
Config generated per site from our control plane, locked to your router's serial, hardened before it ever touches the internet. We poll both tunnels every 60 seconds and reach in through the tunnel when something needs fixing.
- We see each tunnel as connected, degraded, or offline
- Throughput per hub charted over the last 24 hours
- Daily and monthly traffic recorded; ask us any time for the numbers
Live in four steps. Most of them are ours.
We allocate your site
A site ID, your dedicated public IPv4, your dedicated public IPv6, and a WireGuard identity registered on both hubs. Done before you finish your coffee.
We provision the router
A one-time config is imported on a supported MikroTik. It refuses any other serial, sets a per-site admin password, reports back to us, then deletes itself.
You plug in your ISPs
Up to three uplinks in the WAN ports. Any ISP, any NAT. They only carry encrypted tunnels; the router probes each one and fails over by itself.
You plug in your LAN
The machine you choose on the LAN receives the public IPv4 and IPv6 from the router automatically. It is on the internet. That's the whole install.
Not sure it fits your site? Send us the city and the ISP you use and we'll answer today.
Carrier-grade under the hood
Show the technical details for your IT team ▾
The same design we run for our own carrier customers, packaged for a single site. Here is what the router does when nobody is looking.
Two hubs, two tunnels, zero drama
The router holds a WireGuard tunnel to Jakarta (primary) and Singapore (backup, plus fast international inbound) at the same time. A connection that arrives via one hub is answered via the same hub, so nothing breaks when a path flaps.
ISP failover that notices before your users do
Each uplink gets its own reachability probe and a recursive default route. If the primary ISP stalls without going link-down, the router notices in seconds and moves the tunnels to the next line. Your public IP never changes.
No NAT. No leaks. No surprises.
Your public addresses are used as-is on the LAN. Traffic from them is only ever allowed into the tunnels. If both tunnels are down it is dropped, never silently pushed out through the local ISP with a different source.
Hardened before it ships
Nothing listens on the ISP side. Telnet, FTP, web UI, and API are off. Management reaches the router only through the tunnel from our NOC, or from your LAN over SSH and WinBox for an on-site technician.
Full public, both directions
Unlike our per-device IPv6 tier, which is inbound-only, this product routes outbound traffic through our AS too. What the world sees when your site connects out is the same dedicated IP the world uses to reach you.
Hardware you already trust
MikroTik hEX (RB750Gr3), hAP ax2, hAP ax3, RB5009, RB4011, RB3011, and CCR2004. We can supply the unit or provision a board you already own.
Built for the places a "dynamic IP" quietly breaks
Offices whose ISP won't sell them a static IP
Site-to-site VPN concentrators, IP-allowlisted bank and vendor portals, remote access to an on-prem ERP. Move buildings or switch ISPs and the IP comes with you.
CCTV, NVR, and building systems
Reach recorders and controllers directly instead of through a vendor's cloud relay that goes away when the vendor does. Put the NVR on the public address and forget about port-forwarding.
SIP trunks and PBX that just register
No NAT means no SIP ALG surprises, no one-way audio, no STUN dance. Your PBX registers from a real address, and your trunk provider stops blaming your router.
On-prem servers on a consumer line
Host from your own rack behind CGNAT fiber. Web, mail, game servers, Git, anything that binds a socket is reachable on IPv4 and IPv6.
Multi-branch retail, clinics, warehouses
One router per branch, one fixed IP per branch, whichever local ISP was cheapest to pull in. Head office allowlists a stable set of addresses and forgets about it.
Labs and dev teams
A real IPv4 and IPv6 for your staging box, reachable from the outside, without filing a ticket for a port. Add more addresses as the lab grows.
More than one branch? Ask for multi-site pricing, one quote for every location.
Managed router vs. the alternatives
| Managed router | Renting a public IP over VPN | Static IP from your ISP | |
|---|---|---|---|
| Public IPv4 | 1 dedicated IPv4, more on request | 1 IPv4 from the provider pool | Usually one, if offered at all |
| Public IPv6 | 1 dedicated IPv6, more on request | Rarely offered | Depends on ISP, often dynamic |
| Covers | Whole site, via the router | One VPN connection | Whole site |
| Bandwidth | Follows your ISP capacity on site | Capped by plan, typically 10–150 Mbps | Per your internet plan |
| Changing ISP | Same IP | Same IP | New IP |
| ISP failover | Up to 3 uplinks, automatic | None | Tied to one line |
| Install | Router provisioned and managed by us | You configure it yourself on a router or PC | ISP-provided CPE |
| Management & support | Watched 24/7, faulty unit replaced | Chat support; the device is your problem | ISP support, limited to their line |
| Price | from IDR 3,000,000/mo per site | IDR 75,000–400,000/mo | Varies, often business plans only |
Need IPv6 for a single device rather than a whole site? The wayangi per-device tier starts at $5/month.
When something goes wrong, this is what happens
You're paying to not think about the router. Here is what we commit to when things break.
We usually know first
Both tunnels and your router are polled every 60 seconds. If something drops, our team sees it before you get to report it.
24/7 support
WhatsApp us any time, nights and holidays included. A dalang.io network engineer answers, not a bot.
Faulty unit? Replaced.
Router dead or defective? We ship a pre-provisioned replacement. You plug it in, your IP stays the same.
No pointless site visits
Almost everything is handled through the tunnel from our NOC. You don't wait for someone to drive out for things fixable remotely.
Questions we get before the first order
Straight answers, no sales script. Anything not covered here, ask us on WhatsApp.
Someone sells a public IP for IDR 100,000. Why is this IDR 3 million?
Because it is not the same product. For IDR 100,000 you get a VPN username and password for one connection, with capped bandwidth, and the configuration and upkeep are yours. Here you get a router we provision and manage for the whole site: two nodes in Jakarta and Singapore, failover across up to three ISPs, 24/7 monitoring, and a replacement unit if it fails. The fair comparison is not IP rental but a dedicated internet line with an SLA, which starts at around IDR 4.5 million a month.
Do I need to install anything on my computers?
No. The router does everything. The machine you pick gets the public addresses from the router automatically. Nothing to run, nothing to update.
Which ISPs does it work with?
Any. Fiber, cable, 4G/5G, satellite, CGNAT or not. The uplinks only carry outbound UDP for the tunnels. PPPoE lines work with a small adjustment we make during provisioning.
Can I get more than one address?
Yes. Additional IPv4 or IPv6 addresses can be added to an existing site from our side without touching the router's core config. Each one lands on a machine of your choosing on the LAN.
Does my whole office network become open to the internet?
No. Only what you plug into this router's LAN ports gets a public address, for example the NVR, a server, or your existing office router. Everything else stays on your local network as before. Anything you expose can be protected with firewall rules on the router, tailored to your needs; just tell us during setup.
What happens if your Jakarta hub goes down?
The router already has a live tunnel to the Singapore hub and shifts traffic there. Your addresses stay the same. When both hubs are unreachable, public traffic is dropped rather than leaked through the local ISP.
Who owns the router and who has the password?
The hardware can be yours or supplied by us. Each site gets its own admin password, generated at provisioning and shared with you. We manage it through the tunnel; you can log in from the LAN any time.
How is this different from wayangi's $5 IPv6 tier?
The per-device tier is an agent on one machine, IPv6 only, inbound only. The managed router covers a whole site, includes a dedicated IPv4, routes both directions through our AS, and comes with hardware management and monitoring.
How do I order?
Message us on WhatsApp or email [email protected] with your site location, the ISPs you have, and how many addresses you need. We confirm pricing within one business day, ship or provision the router, and you plug it in.
One router. One real IP. Any ISP. Ours to manage.
Dedicated IPv4 + IPv6, dual-hub tunnel, managed and monitored. From IDR 3,000,000 per month per site. Tell us where the site is and we'll quote it today.
Or call +62 895-4032-00032 · DALANG PTE. LTD. · operating dalang.io