Why Our NAT VPS Is Different: Containers, Shared IPs and Network Type
Published 10/8/2026, 05:22:33 · Updated 10/8/2026, 05:22:33
They all say "NAT VPS" and they all cost a few dollars a month, but what different shops actually sell differs a lot. Here are three differences usually left off the product page.
1. A container, or a real virtual machine?
Many low-cost VPS use containers such as LXC or OpenVZ, which share the host kernel:
- you cannot change the kernel, and BBR may not be available;
- running Docker needs extra nesting and is considered an anti-pattern;
- isolation is weaker — one kernel bug can reach the host;
- overselling is easier, which is part of why it is so cheap.
We run on Proxmox VE, so every instance is a full KVM virtual machine with its own kernel:
- change the kernel, enable BBR, run Docker, load custom modules;
- clear isolation and resource boundaries;
- snapshots, whole-VM backups, self-service reinstalls and a web (VNC) console.
Containers are not bad technology, but they are a different product from an independent VM — and the price gap comes from exactly that.
2. All IPs are shared — how they are shared differs
A shared public IP is the reason NAT plans are cheap; the problem is the collateral damage it brings:
- bad-neighbour effect: one abuser on the IP gets the whole range throttled, blocked or captcha-walled;
- range-level reputation: a noisy /24 drags down every address in it;
- inherited history: recycled IPs carry the previous tenant's record, and cheap shops rarely clean them.
Our egress IP rotates automatically once a day, which caps the collateral window at about a day.
Honestly though: rotation does not remove collateral damage — a noisy neighbour in the same range can still hurt, just for far less time.
3. Is your IP a datacenter IP or an ISP IP?
The first check any risk engine runs is an ASN lookup to classify the network:
- residential ISPs (Comcast, Chunghwa Telecom) — high baseline trust;
- business ISPs (enterprise fibre, business broadband) — moderate;
- cloud / datacenter (AWS, DO, Hetzner, OVH) — high risk, often blocked outright.
Our egress runs over a Hong Kong business broadband line (HKBN business), not a datacenter IP block, so platforms are less likely to label the traffic as hosting and block it.
Again, to be clear: this only lowers the chance of being misjudged; it does not mean you can never be flagged. We make no promise about bypassing risk controls.
4. The other side of cheap: know the downsides first
- Not a China-optimised route: this is Hong Kong business broadband, not a CN2/CMI-style line; mainland access may take longer paths at peak hours with higher latency and packet loss.
- Shared bandwidth: peak-hour real throughput is below the nominal figure.
- Shared IP with port-based access: the port number is always required.
- The egress IP changes daily: allowlist workloads needing a fixed IP need another approach.
- Self-managed: you maintain the system and applications inside the instance.
5. So who is it for?
Good fit: long-running scripts, crawlers and monitoring, personal sites, SSH jump boxes, test environments — anyone who wants a real VM rather than a container on a tight budget.
Poor fit: workloads needing low mainland-China latency, a fixed dedicated IP, or managed operations.
Next steps
- See plans and pricing and the port policy
- Questions answered in the FAQ
