Category: Infrastructure & Hosting

Practical Australia and New Zealand guides on VPS, dedicated and cloud hosting, home broadband, server sizing, networking and DDoS resilience.

  • Why an Australian Game Server Can Still Give You 120–170 ms: Peering, Routing and a Player’s Troubleshooting Guide

    Why an Australian Game Server Can Still Give You 120–170 ms: Peering, Routing and a Player’s Troubleshooting Guide

    An Australian player joins a server labelled Sydney. Their speed test looks healthy, voice chat works and another player in the same city has a normal ping. Yet the game reports 120–170 milliseconds. A nearby server should usually be much faster, so what happened?

    The short answer is that internet traffic follows routing policy, not the shortest line on a map. A packet can cross several independently operated networks, take an inefficient interstate or international detour, and return by a different path. Fast access speed does not guarantee a good route to every destination.

    This guide explains the layers, documents a notable Australian Counter-Strike community incident, and gives players, ISPs and server operators a defensible troubleshooting workflow. It does not rank providers or assign fault from a single trace. Network conditions and commercial interconnections change, so the provider and network sources were checked on 29 August 2026 and should be reviewed again by 29 November 2026.

    Article map for Why an Australian Game Server Can Still Give You 120–170 ms: Peering,…, covering A speed test and a game session measure different things, Peering, transit and BGP in plain language, The KZG public repor…
    Article map: A speed test and a game session measure different things; Peering, transit and BGP in plain language; The KZG public report: important evidence, not a court verd…; Why a VPN can turn 150 ms into 30 ms.

    A speed test and a game session measure different things

    A broadband speed test normally selects a nearby, well-connected test node. That is useful for checking access speed, local congestion and gross packet loss. It does not test the route to a particular game host.

    A game packet may traverse this chain:

    1. the player's PC, Wi-Fi or Ethernet and home router;
    2. NBN, fibre, cable or a 4G/5G radio access network;
    3. the retail ISP's aggregation and national backbone;
    4. a private interconnect, internet exchange or paid transit provider;
    5. the datacentre or hosting operator's network;
    6. the game-server host and its application; and
    7. a return route that may differ from the outbound route.

    Any layer can add delay, jitter or loss. Wi-Fi contention and upload saturation are common home causes. An overloaded game process, CPU-heavy bots, plugins or an insufficient host can also increase perceived lag without changing the network ping. Conversely, a clean Ethernet test and a healthy server can still suffer when two networks exchange traffic over a poor path.

    The practical lesson is simple: test the affected destination, at the affected time, from the affected network.

    Peering, transit and BGP in plain language

    An Autonomous System, or AS, is a network that makes its own routing decisions. Border Gateway Protocol (BGP) lets these networks advertise reachability and choose paths using attributes and local policy. The BGP specification describes a policy-driven system; it is not a global latency optimiser.

    Three commercial arrangements matter here:

    • Peering exchanges traffic between the participants and their customers, usually at agreed locations and conditions.
    • Transit pays another network to reach the wider internet.
    • Internet exchange connectivity provides a place or route-server fabric where networks may establish peering, but sharing a building or exchange does not itself guarantee a direct or preferred route.

    An ISP may prefer one route because of local preference, commercial terms, capacity, resilience or the routes actually advertised. The apparent AS path may be short while the physical path is long. A router hostname that contains a city code may be stale or misleading. A one-way traceroute also says nothing definitive about the return path.

    TPG's current Group Peering Guidelines illustrate the operational and commercial dimension. They list separate principal networks for TPG Internet, iiNet/Internode and Vodafone Australia, describe peering as exchanging direct and downstream routes rather than transit routes, and set capacity, traffic, resilience and regional-advertisement expectations. The guidelines also call for “shortest exit routing” unless mutually agreed otherwise. These are published criteria for potential interconnection, not proof that every destination always follows the geographically shortest route.

    The KZG public report: important evidence, not a court verdict

    On 28 March 2023, prominent Australian Counter-Strike community KZG publicly identified TPG, Vodafone, iiNet and Internode as affected providers. Minutes later, KZG asked TPG why the traffic appeared to be going via Los Angeles. The posts took a player-impacting routing problem into the open rather than treating it as a generic game complaint.

    That report is valuable contemporaneous evidence: several retail brands were named, they belonged to the same corporate group, and the observed route appeared inconsistent with an Australian player reaching an Australian service. TPG Telecom's own company history records the 2020 merger of Vodafone Hutchison Australia and TPG, while its peering guidelines show that the brands can still use distinct autonomous systems.

    The cautious conclusion is not “the merger caused the route” or “one company was certainly at fault”. A screenshot of a forward trace cannot establish the return path, the complete BGP decision, link utilisation or which party's advertisement or preference produced the result. It can establish a reproducible symptom and give network engineers somewhere useful to begin.

    There is broader evidence that destination-specific routing problems can affect matchmaking. In August 2022, Blizzard technical support stated in an Overwatch support thread that a routing issue affecting Vodafone Australia produced high latency to its Sydney servers; the matchmaker could then select Singapore because it appeared lower latency. That is direct confirmation from the game service operator, although it concerns Overwatch rather than Counter-Strike.

    Contemporaneous Australian forum discussion also shared correspondence attributed to the GSL network operations team saying it had made mitigating changes that reduced latency while seeking cooperation for a permanent solution. Treat that Whirlpool discussion as user-published evidence, not an independently audited incident report. GSL's current network-maintained PeeringDB entry identifies Global Secure Layer, also known as GSL Networks, and lists interconnection points in multiple Australian cities and overseas. Presence in many facilities improves options; it does not force another network to select a particular path.

    Community incident reading list

    The following threads are useful for recognising symptoms and building a timeline, but they remain user reports unless a provider or service operator confirms the cause:

    • An August 2022 /r/nbn report about Vodafone NBN and CS:GO describes normal speed tests but 100 ms-plus game latency, Singapore being selected ahead of Sydney, a lower-latency result on another carrier, and a temporary improvement through a VPN. Later commenters reported Sydney or Australian servers at roughly 100–170 ms; one commenter said escalation with timestamped traces preceded a return from about 125 ms to 25 ms. These are anecdotes, not a controlled provider benchmark.
    • A 2022 Whirlpool thread on high ping to Australian servers records Internode and Vodafone users comparing affected routes and VPN results. A separate iiNet Sydney-latency thread shows that intermittent route or destination selection can complicate diagnosis.
    • The Final Fantasy XIV community's Materia routing report documents another game community analysing unexpectedly high latency to an Australian region. It concerns a different provider path and should not be used to infer the cause of the KZG incident.

    Read these beside Blizzard's operator response and the official network documents above. Their value is the repeated diagnostic pattern—destination-specific latency, route changes across networks and the need for escalation—not proof that a named ISP performs the same way today.

    Decision path for Why an Australian Game Server Can Still Give You 120–170 ms: Peering,…, covering Peering, transit and BGP in plain language, The KZG public report: important evidence, not a court verd…, Why a VPN can…
    Decision path: Peering, transit and BGP in plain language; The KZG public report: important evidence, not a court verd…; Why a VPN can turn 150 ms into 30 ms; A player-side evidence checklist.

    Why a VPN can turn 150 ms into 30 ms

    A VPN changes the problem from “home ISP to game host” into two segments: home ISP to VPN entry point, then VPN provider to game host. If the VPN has a nearby entry point and a better onward route, the detour can disappear. This is why a VPN can dramatically reduce latency even though encryption adds a little processing and encapsulation overhead.

    That result is a strong routing signal, not final proof. The VPN may also change IPv4 versus IPv6, traffic engineering, destination selection or anti-DDoS ingress. Test more than once and compare at the same time of day.

    Use a reputable paid or self-managed service with a nearby Australian point of presence. Check the game's rules and anti-cheat policy, protect the account with multi-factor authentication, and do not install cracked VPN software. A VPN is a diagnostic or temporary workaround; the durable fix belongs in routing, capacity or server placement.

    A player-side evidence checklist

    Begin with changes that do not require special access.

    1. Connect the gaming PC by Ethernet and pause cloud backups, torrents and large uploads. Check router utilisation and test for latency under load.
    2. Record the game, server region, exact local time and timezone, displayed ping, jitter or loss, ISP, access type and approximate source city. Do not publish your street address, account number or full router configuration.
    3. Test a general speed-test node, but label it as a control. Then test the actual destination supplied by the game or server operator.
    4. On Windows, run tracert /d <approved-target> and pathping /n <approved-target>. On macOS or Linux, use traceroute or mtr with ordinary rates. Only test a destination you are authorised to contact.
    5. Repeat during a normal period and the affected period. Save plain-text output and screenshots rather than relying on memory.
    6. Compare a second network, such as a phone tether on another carrier or a neighbour's separately operated ISP with permission.
    7. Optionally test a nearby reputable VPN endpoint. Record whether the route and end-to-end latency change.
    8. If possible, test IPv4 and IPv6 separately. They can use different peers and paths.

    Microsoft explains that tracert discovers a path using increasing TTL values and that some routers do not return the expected ICMP message, producing asterisks. Its pathping documentation warns that intermediate routers may drop packets addressed to themselves while continuing to forward transit traffic. Therefore, a loss percentage at one hop is meaningful only when the loss persists to later hops or the destination.

    Also avoid over-reading router names and IP geolocation. A hostname containing “lax” may indicate an operator's naming convention, and a database may place an address at a corporate office rather than the router. Pair names with latency changes, multiple traces, AS ownership and evidence from the destination side.

    Do not port-scan, flood, stress-test or try to bypass access controls. Normal ping, traceroute and low-rate MTR measurements are enough for this investigation.

    How to escalate past “your speed test is fine”

    First open a formal support ticket with the ISP. Describe it as a destination-specific latency or routing fault, not a general speed complaint. A concise report can say:

    My access service and local Ethernet test are normal, but this Australian game destination shows repeatable high latency during the attached Sydney-time windows. A second carrier and a nearby VPN produce a materially different route and lower end-to-end latency. Please escalate the evidence to your IP engineering, routing or peering team and provide the fault reference.

    Attach the timestamped traces, destination supplied by the operator, comparison network, game evidence and the result you want. Do not demand that frontline support redesign BGP; ask for escalation to the team that can compare advertisements and return paths.

    Send the same evidence to the game community or host. The server operator can check host load, provide a reverse trace or looking-glass result, and aggregate affected users by source AS and city. A forward trace from the player and a reverse or multi-vantage test from the host are far more useful together.

    If an Australian consumer or small business cannot resolve a covered phone or internet complaint with the provider, the Telecommunications Industry Ombudsman says to raise it with the provider first, keep relevant evidence, and then use its complaint process. The TIO is a dispute-resolution path, not a substitute peering engineer, so state the service impact and requested resolution clearly.

    Control and evidence map for Why an Australian Game Server Can Still Give You 120–170 ms: Peering,…, covering Why a VPN can turn 150 ms into 30 ms, A player-side evidence checklist, How to escalate past “your speed test…
    Control and evidence map: Why a VPN can turn 150 ms into 30 ms; A player-side evidence checklist; How to escalate past “your speed test is fine”; What a game-server operator should monitor.

    What a game-server operator should monitor

    Operators should not wait for a Discord argument to become their monitoring system. Build a privacy-conscious dataset containing time, source AS, broad city, game instance, end-to-end latency, loss and server health. Avoid retaining players' full addresses or unrelated personal data.

    Useful controls include:

    • probes or synthetic sessions from several major Australian access networks;
    • forward and reverse MTR captures during incidents;
    • CPU frame time, tick health, packet queues and interface utilisation beside network latency;
    • a public status page and a structured route-problem form;
    • more than one upstream or a host with credible domestic interconnection options; and
    • documented contacts for the host's NOC, transit providers and peers.

    RIPE Atlas can provide ping and traceroute measurements from distributed probes, subject to its measurement rules and available probes. A network looking glass can show routes from another vantage point. Neither replaces cooperation from the access ISP and host, but both reduce reliance on a single player's forward trace.

    Multihoming and additional transit can improve resilience and route control, but they also add cost and operational complexity. An internet-exchange port does not automatically create every bilateral peer. Anycast can be excellent for stateless front doors and DDoS absorption, but stateful real-time game sessions need architecture-specific testing before it is proposed as a cure.

    Choosing an ISP when games matter

    Published download speed is only one input. Ask players in the same city who reach the same community servers, and prefer a reversible month-to-month trial when possible. Test busy-period latency, jitter, loss and the actual destinations you use. Confirm whether support can escalate a documented routing issue rather than only repeat access-line tests.

    Do not assume a large ISP is always worse or a specialist network is always better. Routes change, hosting providers change upstreams, and one provider may be excellent to one datacentre and poor to another. The Australia and New Zealand internet-cost comparison explains why access pricing and upload speed differ; the Australia and New Zealand hosting guide covers host selection; and the Australian game-server sizing guide covers CPU, bandwidth and hosting models.

    Practical checklist for Why an Australian Game Server Can Still Give You 120–170 ms: Peering,…, covering How to escalate past “your speed test is fine”, What a game-server operator should monitor, Choosing an ISP when g…
    Practical checklist: How to escalate past “your speed test is fine”; What a game-server operator should monitor; Choosing an ISP when games matter; The defensible conclusion.

    The defensible conclusion

    When an Australian player sees 120–170 ms to an Australian game server, do not begin with “the server must be overseas” or “the ISP is lying”. First separate the home network, access link, ISP backbone, interconnection, host network, server load and return path. Compare another carrier and a nearby VPN, collect timestamped target-specific evidence, and get both network operators looking at the same incident.

    The KZG episode matters because it made a community-scale symptom visible. The lasting lesson is procedural: route problems become fixable when player reports are converted into precise, privacy-safe evidence that can reach IP engineering teams.

    Sources and review note

    Key sources were accessed on 29 August 2026: TPG Group Peering Guidelines, TPG Telecom company information, KZG's affected-provider post, KZG's Los Angeles routing question, Blizzard's Sydney routing support thread, GSL's PeeringDB entry, Microsoft tracert, Microsoft pathping, RIPE Atlas documentation, BGP-4 RFC 4271, and the TIO complaint process. The linked Reddit, Whirlpool and Final Fantasy XIV community threads are supplementary incident records, not current performance guarantees. Next scheduled source review: 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

  • Why Internet Pricing Feels So Different in Australia and New Zealand: Mobile, NBN, UFB and Server Traffic

    Why Internet Pricing Feels So Different in Australia and New Zealand: Mobile, NBN, UFB and Server Traffic

    Australian internet pricing can look contradictory. A mobile plan may advertise tens or hundreds of gigabytes at a modest price, while a household NBN service costs more than an apparently faster New Zealand fibre plan. Residential NBN is now commonly sold with unlimited data, yet an Australian VPS or colocation quote may still include a strict transfer allowance.

    Those observations are real, but they do not describe one market. Mobile radio capacity, fixed access, retail broadband and data-centre transit are different products with different cost structures. The useful question is not simply “Is Telstra or Optus charging too much?” It is: which layer owns the scarce capacity, how is it regulated, and what kind of traffic is the customer allowed to generate?

    This independent guide uses public prices and official material checked on 29 August 2026. It is not a paid ranking, and Ozlin has no disclosed affiliate relationship with the providers named. Promotional pricing, address eligibility, exchange rates and plan terms change; obtain the current Critical Information Summary or equivalent before purchasing.

    Article map for Why Internet Pricing Feels So Different in Australia and New Zealand:…, covering A dated retail snapshot, Mobile pricing is allowance marketing on shared radio netwo…, Australia's fixed-broadband floor i…
    Article map: A dated retail snapshot; Mobile pricing is allowance marketing on shared radio netwo…; Australia's fixed-broadband floor is NBN wholesale, not jus…; New Zealand UFB is also regulated infrastructure—not four f….

    A dated retail snapshot

    The examples below are representative public offers, not a claim that each product is the cheapest in its market. Australian prices include GST where the provider says so. New Zealand consumer prices include GST. Indicative AUD conversions use the Reserve Bank of Australia's 28 August 2026 reference rate of A$1 = NZ$1.2084; the RBA says its rates should not be used for commercial settlement.

    Service observed on 29 August 2026 Published recurring price Included data or access rate Important condition
    felix Unlimited mobile, Australia A$40/month Unlimited handset data, capped at up to 40 Mbps Provider says it must not be used in a modem or as a home/office internet substitute
    Telstra Basic / Essential mobile, Australia A$74 / A$84 per month 50 GB / 180 GB Flagship-network pricing; plan terms and speed treatment apply
    Rocket Plus mobile, New Zealand NZ$45/month, about A$37.24 Unlimited handset data at up to 40 Mbps 20 GB hotspot allowance; Rocket says its SIMs cannot be used in a mobile router
    Spark 75 GB / 150 GB Endless, New Zealand NZ$68 / NZ$78 per month after the July 2026 change Full-speed allowance, then reduced-speed endless data Check the current fair-use and companion-plan conditions
    Leaptel NBN 500/50 / 1000/100, Australia A$97 / A$119 per month Unlimited residential fixed-line data Prices include GST; technology and address eligibility apply
    One NZ Fibre Everyday / Fibre Max NZ$101 / NZ$116 per month, about A$83.58 / A$95.99 Unlimited residential fibre Product speed, Wi-Fi and regional wholesale network affect results

    The table immediately corrects one common assumption: low-cost unlimited mobile is not automatically cheaper in Australia than New Zealand. Rocket's standard NZ$45 40 Mbps plan converts to slightly less than felix's A$40 plan. The more persistent contrast is fixed broadband capability, especially upload: New Zealand Fibre Max products commonly expose far more upstream capacity than mainstream Australian 1000/100 residential NBN.

    Mobile pricing is allowance marketing on shared radio networks

    Australia has three national mobile network operators: Telstra, Optus and TPG Telecom. That is an oligopoly at the infrastructure layer, not a two-company monopoly. The ACCC's 2025 infrastructure report analyses those three operators and notes that TPG customers can also access sites under the Optus–TPG multi-operator core network arrangement.

    Retail competition is broader than the tower count suggests. Operator-owned secondary brands and mobile virtual network operators sell differentiated offers over the same physical networks. A premium brand may charge for coverage, support, features and brand position; a lower-priced brand may cap speed, omit capabilities or use a more limited wholesale footprint. The result is aggressive price segmentation without a fourth nationwide radio network.

    Large allowances are also cheaper to advertise than they appear. The ACCC's 2024–25 communications report estimated a median advertised mobile allowance of 42 GB and an average of 69 GB, while reported average use was only 14.5 GB per user per month. Most subscribers therefore do not consume the headline allowance. Giving many users an extra 50 GB does not mean reserving that amount for each user; the operator manages shared peak-hour radio capacity and expects statistical variation in actual demand.

    That is why “gigabytes per dollar” is an incomplete comparison. Check:

    • whether speed is capped before the allowance is exhausted;
    • coverage and congestion at the places that matter;
    • hotspot, modem and router permissions;
    • reduced-speed treatment after the full-speed allowance;
    • roaming, voice, eSIM, Wi-Fi Calling and support; and
    • whether a promotion expires after a few months.

    New Zealand has its own operator concentration and retail segmentation. Its unlimited mobile offers can now be very competitive, but “unlimited on the phone” does not necessarily mean “unlimited for the whole house.” Rocket's 40 Mbps plan includes 20 GB of hotspot use and its support material says the SIM cannot be used in a mobile router. felix permits tethering to personal devices but explicitly prohibits modem use and substitution for home or office internet. Circumventing those controls with identity, TTL or configuration tricks is a contract risk, not a savings strategy.

    Australia's fixed-broadband floor is NBN wholesale, not just Telstra retail

    Most large Australian fixed-broadband brands are retail service providers buying access from NBN Co. Their customer service, backhaul, peering, international transit, routers and provisioning differ, but they begin with a common regulated wholesale input.

    NBN Co's published average wholesale prices from 1 July 2026 include:

    Residential wholesale tier Average monthly wholesale cost from 1 July 2026
    25/5 or 25/10 A$36.15
    50/20 A$57.60
    500/50 A$60.85
    1000/100 A$75.88

    These are wholesale access costs, not retail prices and not a complete ISP cost model. A retailer still needs network capacity beyond NBN, systems, staff, payment processing, support and margin. Many competing retailers therefore do not create the same price pressure as competing last-mile networks: they all face a substantial common input.

    NBN's product history also matters. The Ethernet bitstream service was traditionally charged through an end-user access component, AVC, plus shared network capacity, CVC. In 2017 NBN said the industry-average CVC unit price had been A$15.25 per Mbps. Insufficient purchased CVC could contribute to the notorious evening-congestion gap between an access-line speed and the throughput users actually experienced.

    The model has changed. NBN's accepted transition removes residential fixed-line and fixed-wireless CVC overage charges by 1 July 2026, with the scheduled maximum price falling to zero. This helps explain why unlimited residential data is now normal: an ISP is no longer exposed to the same wholesale overage mechanism merely because a customer downloads another block of data. The retailer must still engineer its own shared capacity, so “unlimited” never means every subscriber can sustain the port rate simultaneously.

    Australia also funds difficult regional access. The ACMA states that the 2025–26 Regional Broadband Scheme charge is A$2.17725 per month for each chargeable premises on qualifying networks, subject to the small-carrier exemption. The scheme supports long-term funding of regional, rural and remote broadband. It illustrates cross-subsidy, but it should not be portrayed as the sole or even primary explanation for a retail NBN bill.

    Decision path for Why Internet Pricing Feels So Different in Australia and New Zealand:…, covering Mobile pricing is allowance marketing on shared radio netwo…, Australia's fixed-broadband floor is NBN wholesale, not ju…
    Decision path: Mobile pricing is allowance marketing on shared radio netwo…; Australia's fixed-broadband floor is NBN wholesale, not jus…; New Zealand UFB is also regulated infrastructure—not four f…; Why Australian ADSL trained users to think in quotas.

    New Zealand UFB is also regulated infrastructure—not four fibres in every street

    New Zealand's Ultra-Fast Broadband network has natural-monopoly characteristics too. The Commerce Commission identifies Chorus, Enable, Northpower Fibre and Tuatahi First Fibre as regulated fibre providers. Chorus is subject to price-quality and information-disclosure regulation; the other local fibre companies are subject to information disclosure. Their geographic footprints do not mean four duplicate access networks compete at every address.

    The difference is therefore more precise than “Australia has a monopoly and New Zealand has competition.” The countries use different wholesale architectures, regulatory settlements, rollout histories and product profiles. New Zealand fibre plans also tend to provide much stronger upload ratios. The Commerce Commission's current Measuring Broadband New Zealand material lists Fibre Max around 880 Mbps download and 500 Mbps upload as a technology-level result, while Australian consumer gigabit offers commonly advertise 100 Mbps upstream unless a higher-upload tier is purchased.

    That upstream difference matters for cloud backup, video production, remote work, NAS access and self-hosting. Download-only price comparisons conceal it. Measure peak-hour download, upload, latency, jitter and loss over Ethernet, then separate access performance from Wi-Fi limitations.

    Why Australian ADSL trained users to think in quotas

    Australians who used broadband in the early 2000s remember small peak/off-peak quotas, excess-usage charges and shaping to dial-up-like speeds. That culture was not created by one simple technical law. International capacity, domestic long-distance transmission, limited competition on regional routes and retail product design all contributed.

    A 2004 Australian parliamentary inquiry said high-capacity links were a major cause of high broadband costs and recorded industry evidence that the first large retail price fall—from more than A$150 to roughly A$100 per month—followed a Telstra backhaul price reduction. A later inquiry heard extensive concern about non-metropolitan backhaul where competing infrastructure was weak.

    Quotas were one way to control an expensive shared resource. Other markets often leaned harder on low port speeds and high oversubscription while advertising unlimited use. Both approaches allocate scarce capacity; they simply expose the constraint differently. Australia's later NBN AVC/CVC model retained a visible capacity-purchasing logic before moving toward AVC-only residential pricing.

    Why a home connection can be unlimited while a server is metered

    Residential broadband sells statistically multiplexed access. Household demand is usually bursty, mostly downstream and concentrated around predictable hours. Popular video, software and web objects may be served from local caches or peering links. Thousands of customers can share upstream infrastructure because they do not all sustain their maximum line rate continuously.

    A public server is capable of the opposite pattern: continuous outbound traffic, symmetric transfers, international transit, backups, mirrors, media delivery or attack traffic at any hour. A 1 Gbps port running continuously for 30 days transfers about 324 TB in one direction:

    1,000,000,000 bits/s × 2,592,000 seconds ÷ 8 ≈ 324 TB

    “1 Gbps port with 10 TB included” is therefore a different product from “unmetered 1 Gbps.” A transfer quota caps total bytes; a committed Mbps service prices sustained capacity; and 95th-percentile billing samples bandwidth, discards the busiest 5% of measurements and bills the highest remaining value. Cloudflare's current WAN documentation describes five-minute sampling and that 95th-percentile method. Always read the provider's exact direction, sampling, commit and overage rules rather than assuming the port label describes the bill.

    Australian VPS examples make the distinction visible. BinaryLane currently advertises an entry server with 1,000 GB transfer at A$4.90 per month. That price is possible because the allowance, compute and expected usage are bounded; it is not the price of a permanently reserved 1 Gbps international circuit.

    Caching can reduce the origin bill. A CDN serves repeatable static content from edge locations, so fewer requests and bytes return to the origin. It does not make dynamic, uncached, game or arbitrary UDP traffic free, and provider terms still matter. For infrastructure selection, use the Australia and New Zealand hosting guide and include transfer, port rate, mitigation and overage in TCO.

    Control and evidence map for Why Internet Pricing Feels So Different in Australia and New Zealand:…, covering New Zealand UFB is also regulated infrastructure—not four f…, Why Australian ADSL trained users to think in q…
    Control and evidence map: New Zealand UFB is also regulated infrastructure—not four f…; Why Australian ADSL trained users to think in quotas; Why a home connection can be unlimited while a server is me…; When wireless home broadband is the right product.

    When wireless home broadband is the right product

    Low-cost 4G or 5G can replace NBN or UFB for some households—especially renters, one- or two-person homes, ordinary streaming and browsing, or an address with poor fixed-line options. It should be purchased as a wireless home-broadband product, or with a data SIM whose written terms permit router use. A handset-only unlimited plan is not a loophole: several providers restrict modem use, geolock their supplied gateway or tie eligibility to a service address.

    The headline download result is only the start. A useful trial measures wired upload, latency under load, jitter, packet loss and evening congestion over several days. It also checks CGNAT, IPv6, equipment-return terms, power-failure behaviour and whether alarms, voice services or inbound connections still work. Fibre generally remains more predictable, while a well-placed cellular gateway can be a practical primary or backup link where its real measurements are good.

    Ozlin's separate 4G and 5G home-internet setup guide covers plan selection, gateway placement, RSRP/RSRQ/SINR, Ethernet testing, external antennas, double NAT, security and failover. The home-server risk guide explains why CGNAT workarounds do not turn a residential link into a production platform.

    The practical conclusion

    Telstra and Optus market power is part of Australia's telecommunications history, particularly where competing infrastructure was limited. It is not a complete explanation of the 2026 price pattern.

    • Australian mobile combines three national network operators with many retail brands, MVNOs, speed tiers and allowances that exceed average use.
    • Australian fixed broadband has many retailers purchasing a large common NBN wholesale input, with access technology, wholesale pricing and national cost recovery shaping the floor.
    • New Zealand fixed broadband also uses regulated regional fibre wholesalers, but UFB's product and regulatory design commonly delivers a stronger upload profile.
    • Data-centre bandwidth prices the possibility of sustained, outbound and less-cacheable traffic, so transfer allowances and committed-capacity billing remain rational even when household plans say unlimited.

    Compare the workload rather than the marketing unit. For a phone, coverage and busy-hour radio capacity may dominate. For a household, upload, jitter and access technology matter. For a server, model sustained egress, attack exposure, peering, transit, support and the cost of exceeding the allowance. Ozlin's infrastructure and hosting services can help turn those requirements into a dated shortlist and acceptance test without exposing production network details.

    Practical checklist for Why Internet Pricing Feels So Different in Australia and New Zealand:…, covering Why a home connection can be unlimited while a server is me…, When wireless home broadband is the right product, T…
    Practical checklist: Why a home connection can be unlimited while a server is me…; When wireless home broadband is the right product; The practical conclusion; Sources and review record.

    Sources and review record

    Sources were accessed on 29 August 2026. Prices, plan terms, wholesale inputs and performance figures are scheduled for review by 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

  • Using 4G or 5G as Home Internet: An Australia and New Zealand Setup Guide

    Using 4G or 5G as Home Internet: An Australia and New Zealand Setup Guide

    Wireless home broadband can be excellent when the local radio network, plan and household workload align. It can also look perfect at lunchtime and become frustrating after dinner. The difference is rarely explained by a single “bars” icon. Tower congestion, building materials, gateway position, plan restrictions, Wi-Fi, CGNAT and the applications being used all affect the result.

    This guide is for Australian and New Zealand households considering 4G or 5G as a primary connection or backup link. It is not a guide to bypassing a carrier's device, location, fair-use or acceptable-use controls. Use a product sold for home broadband, or a data plan whose terms expressly allow a router.

    Provider terms and product availability were checked on 29 August 2026. Address eligibility, speed tiers, modem ownership, trial periods and fair-use rules change, so verify the current Critical Information Summary or equivalent before ordering.

    Article map for Using 4G or 5G as Home Internet: An Australia and New Zealand Setup G…, covering First decide whether wireless suits the workload, Buy the right product, not an apparent loophole, Run a seven-day test be…
    Article map: First decide whether wireless suits the workload; Buy the right product, not an apparent loophole; Run a seven-day test before cancelling fixed broadband; Read signal quality, not only signal bars.

    First decide whether wireless suits the workload

    Start with the household's difficult traffic, not its easiest speed test. Web browsing and buffered video tolerate variation. Video meetings, cloud gaming, competitive games, large backups, remote-desktop work and live streaming care more about upload, latency, jitter and packet loss.

    Wireless home broadband is often worth testing when:

    • fibre or a good fixed-line service is unavailable, slow or expensive at the address;
    • a renter needs a reversible installation;
    • usage is mainly browsing and streaming with modest upload demand;
    • a second carrier would provide useful failover for remote work; or
    • a temporary premises needs service without waiting for a fixed installation.

    Keep fibre or another stable fixed service when predictable upload, very low jitter, a static address, monitored alarms, medical equipment, business continuity or public inbound services are requirements. Carrier product pages themselves warn about these boundaries. Optus says its 5G home service does not support a static IP, fixed-line telephony, back-to-base alarms or medical alert services. One NZ notes that its wireless service requires mains power and may be unavailable during an outage, including for emergency calling. These are product limitations, not minor setup details.

    Buy the right product, not an apparent loophole

    The cheapest “unlimited mobile” offer may be designed only for a handset. Router, hotspot, location and fair-use rules vary. Check the written terms before buying hardware around a plan.

    Current official examples illustrate the differences:

    Product characteristic checked on 29 August 2026 What the provider says Practical consequence
    Telstra 5G Home Internet The supplied home modem is fixed to the nominated address; moving it outside the home area can trigger a severe speed cap. A modem supplied for the plan may need to be returned after early cancellation. Recheck eligibility before moving and retain packaging and return instructions.
    Optus 5G Home Internet Requires the Optus modem and SIM, is service-qualified by address and does not support a static IP. Speed depends on congestion, location, placement and other conditions. Do not assume bring-your-own equipment, portability or inbound IPv4.
    One NZ wireless broadband Requires a One NZ modem, restricts the SIM to that device and the service to the registered location. Continuous 5G coverage is not guaranteed. Treat the gateway as fixed customer equipment and verify the current network-guarantee conditions.
    Spark wireless broadband Availability is selected by address and usage; a compatible Spark modem is required for its 4G/5G wireless plans. Use the address checker and confirm the exact supplied or supported gateway before purchase.

    This is not a complete market comparison. It shows why “put any SIM in any router” is unsafe purchasing advice. Also check minimum term, modem repayment or non-return fees, data cap, speed cap, fair use, cancellation process, cooling requirements and whether an external antenna is supported.

    Run a seven-day test before cancelling fixed broadband

    Treat the first week as a small site survey. Keep the old service active and build a test sheet with the same locations and times each day.

    1. Test at least three plausible gateway positions: windows on different sides of the premises, an elevated open shelf and the place where Ethernet can reach the main router.
    2. Test morning, afternoon and the evening busy period. A single best result is not representative.
    3. Connect one computer by Ethernet to the cellular gateway. This separates the mobile link from household Wi-Fi.
    4. Record download, upload, idle latency, latency during upload and download, jitter and packet loss.
    5. Repeat the real workload: a video meeting, VPN session, game, large upload and 4K stream if those matter.
    6. Reboot the gateway and confirm that service, IPv6 and any VPN reconnect correctly.
    7. Record outages and band or cell changes rather than averaging them away.

    Use median results to describe normal service and p95 latency or the worst ordinary busy-period samples to expose instability. Do not compare an Ethernet result from one provider with a distant Wi-Fi result from another.

    If several carriers are plausible, test more than one. A phone can identify whether a network deserves a gateway trial, but it is not a controlled substitute: phone and gateway modems may support different bands, antennas, carrier aggregation and thermal behaviour.

    Decision path for Using 4G or 5G as Home Internet: An Australia and New Zealand Setup G…, covering Run a seven-day test before cancelling fixed broadband, Read signal quality, not only signal bars, Gateway placement is…
    Decision path: Run a seven-day test before cancelling fixed broadband; Read signal quality, not only signal bars; Gateway placement is a cellular and Wi-Fi problem; External antennas and outdoor CPE: useful, not magical.

    Read signal quality, not only signal bars

    Many gateways expose RSRP, RSRQ and SINR. RSRP describes reference-signal power; RSRQ adds a quality view; SINR compares the wanted signal with interference and noise. RSSI alone includes other received energy and can look strong while quality is poor.

    Teltonika's published guidance gives useful orientation rather than a universal guarantee: RSRP at or above about -80 dBm is described as excellent, -80 to -90 dBm as good, and below -100 dBm as poor; SINR above about 20 dB is described as excellent, 13–20 dB as good and values near or below 0 dB as poor. Different modems, bands and networks report differently, and tower load can still limit throughput with apparently good radio figures.

    Use the numbers comparatively. If moving a gateway one metre improves SINR and busy-period upload consistently, that is more useful than chasing an absolute threshold. Record the serving band or cell when the interface exposes it, but avoid locking bands unless the gateway and carrier support it and repeated measurements show a stable benefit. An unsupported lock can remove useful carrier aggregation or emergency fallback.

    Gateway placement is a cellular and Wi-Fi problem

    The best cellular position is often close to a window facing a useful tower. Spark's setup guidance tells customers to place its Max Wireless modem near a window in the direction of the best 5G cell. Optus likewise recommends a window position. Test several windows: coated glass, concrete, metal cladding, terrain and neighbouring buildings can change the result.

    Do not cook the modem to improve signal. Avoid a sealed cupboard, direct summer sun and the top of another hot device. Leave airflow around it and use a stable power supply. A position that is excellent for the cellular link may be poor for Wi-Fi coverage through the rest of the home.

    The clean solution is often:

    cellular gateway near the best window → Ethernet → centrally placed household router or access points

    If the carrier gateway must remain the router, use wired or mesh access points for distant rooms. If it supports bridge or IP-passthrough mode, a separate router may take over routing and Wi-Fi, but support varies and carrier updates can change behaviour. Avoid creating double NAT accidentally; document which device provides DHCP, firewalling and port mappings.

    External antennas and outdoor CPE: useful, not magical

    An external MIMO antenna can help when the indoor signal is weak or obstructed and the gateway exposes compatible antenna ports. It can also make things worse through the wrong connector, unsupported frequency range, poor polarisation, long lossy coaxial cable or aim at a congested cell.

    Prefer short approved cable runs and equipment designed for the carrier's bands. A purpose-built outdoor CPE keeps the radio close to the antenna and brings Ethernet indoors, avoiding much coaxial loss. Outdoor work must follow electrical, lightning, waterproofing, strata, rental and local installation requirements. Do not improvise a roof installation around power lines; use a qualified installer where the location or regulations require it.

    Change one variable at a time and retest across busy periods. A larger antenna is not proof of more capacity: it cannot create spectrum or remove congestion at the tower.

    Expect CGNAT and plan around it

    Many mobile and wireless-broadband services use carrier-grade NAT. The gateway receives an address that is not a dedicated public IPv4 address, so ordinary inbound port forwarding cannot reach the household. A dynamic-DNS record does not change that upstream translation.

    Before purchase, ask whether the plan provides:

    • public IPv4, CGNAT or an optional business/static-IP service;
    • native IPv6 and whether its delegated prefix remains stable;
    • inbound filtering; and
    • restrictions on VPN protocols or business/server use.

    Outbound HTTPS, modern remote-work VPNs and most consumer applications usually operate through CGNAT, but test the actual employer VPN, console, voice application and peer-to-peer game. For private remote access, an authenticated mesh VPN or outbound tunnel may be appropriate. Do not expose router administration, a NAS or remote desktop directly to the internet merely to defeat a connectivity problem.

    If a public server is the objective, use the home-server risk guide and compare a hosted VPS. Wireless home broadband is a consumer access product, not automatically a production hosting platform.

    Control and evidence map for Using 4G or 5G as Home Internet: An Australia and New Zealand Setup G…, covering Gateway placement is a cellular and Wi-Fi problem, External antennas and outdoor CPE: useful, not magical, Ex…
    Control and evidence map: Gateway placement is a cellular and Wi-Fi problem; External antennas and outdoor CPE: useful, not magical; Expect CGNAT and plan around it; Secure the gateway before moving the household onto it.

    Secure the gateway before moving the household onto it

    The Australian Signals Directorate's consumer guidance recommends changing default router credentials, disabling WAN remote management, installing firmware updates, replacing end-of-life routers, using WPA3 where available (or WPA2 as a minimum), reviewing connected devices and disabling unused services such as WPS, UPnP and port forwarding.

    Apply that baseline to the cellular gateway and any separate router:

    • change the administrator password and store it in a password manager;
    • install provider/manufacturer firmware and enable supported automatic updates;
    • disable internet-facing administration, Telnet, unused SSH/SNMP, WPS and unneeded UPnP;
    • use WPA3 or WPA2 with a long unique Wi-Fi passphrase;
    • put guests and poorly supported IoT devices on an isolated guest network;
    • back up the known-good configuration without including it in public tickets or screenshots;
    • check connected devices and firmware at least every six months; and
    • replace equipment that no longer receives security updates.

    Do not install cracked firmware or random modem-unlock packages. Apart from breaching terms or radio rules, modified images can add backdoors to the device that protects the entire household network.

    Add failover deliberately

    A 4G/5G link is valuable as a second path when it uses a different carrier and failure domain from the fixed service. A dual-WAN router can check reachability and fail over automatically, but test stateful sessions: meetings and VPNs may reconnect because the public address changes.

    For important home work:

    • choose a backup carrier with independent coverage where practical;
    • connect the gateway, router and access point to an appropriately sized UPS;
    • configure health checks against more than one reliable destination;
    • alert on failover so an unnoticed outage does not consume a capped backup plan;
    • test restoration to the primary path; and
    • keep an ordinary phone connection available for emergency communication.

    A carrier gateway still depends on tower power, backhaul and local congestion. Two devices on the same network are not two independent links.

    A practical go/no-go scorecard

    Do not cancel fixed broadband until the wireless trial passes the household's real requirements.

    Question Pass condition to define before testing
    Evening performance Required download and upload remain usable across several busy periods
    Interactive quality Latency under load, jitter and loss support meetings, games and VPNs
    Coverage The gateway stays on a usable cell/band without frequent dropouts
    Plan fit Router, location, data, speed and fair-use terms permit the intended use
    Addressing CGNAT/IPv6 behaviour is compatible with required applications
    Equipment Gateway can be placed safely, cooled and connected by Ethernet
    Security Supported firmware, strong administration and segmented Wi-Fi are configured
    Continuity Power, voice/alarm implications and failover are understood and tested
    Cost Plan, modem, antenna, cabling, UPS and any second link beat the alternative over the intended term

    The honest outcome may be “wireless is good enough,” “wireless is an excellent backup,” or “keep fibre.” All three are successful tests. The related Australia and New Zealand internet-cost article explains why mobile allowance pricing, fixed-access wholesale costs and data-centre traffic cannot be compared as one market.

    Practical checklist for Using 4G or 5G as Home Internet: An Australia and New Zealand Setup G…, covering Secure the gateway before moving the household onto it, Add failover deliberately, A practical go/no-go scorecard…
    Practical checklist: Secure the gateway before moving the household onto it; Add failover deliberately; A practical go/no-go scorecard; Sources and review record.

    Sources and review record

    Sources were accessed on 29 August 2026. Product terms, availability, equipment and security guidance are scheduled for review by 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

  • Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated and Colocation

    Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated and Colocation

    The best server is not the one with the largest specification sheet. It is the one whose location, network, operating model and failure plan fit the workload. A Sydney VPS may be ideal for a small Australian website, while a New Zealand organisation with data-location requirements may prefer an Auckland or Wellington service. A busy game community may care more about single-thread CPU performance, packet loss and attack mitigation than about virtual CPU count. A regulated application may need contractual support, evidence and tested recovery that a low-cost unmanaged server does not include.

    Ozlin Info currently operates workloads on OVHcloud infrastructure in Sydney and uses Proxmox at a high level as part of its virtualisation experience. That operational background informs this guide, but no production IP address, host name, panel address, network topology or security control is disclosed here.

    This is an independent market guide, not a paid ranking. Ozlin has no disclosed affiliate relationship with the providers named below. Product availability, tax treatment and routing can change, so obtain a written quote and run workload-specific tests before committing.

    Article map for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Choose the service model before the brand, A dated price snapshot, not a permanent price list, Australian and trans-Tasman…
    Article map: Choose the service model before the brand; A dated price snapshot, not a permanent price list; Australian and trans-Tasman providers worth shortlisting; Public cloud and New Zealand data-location options.

    Choose the service model before the brand

    A VPS divides a physical host into isolated virtual servers. It is inexpensive, quick to rebuild and usually gives root or administrator access. The trade-off is that storage, CPU scheduling and the host failure domain remain partly shared. Ask whether CPU is dedicated or burstable, what storage redundancy exists, and whether snapshots are backups or only convenient restore points.

    Public cloud infrastructure exposes compute, storage, networking and managed services through APIs. AWS, Microsoft Azure, Google Cloud and Oracle Cloud Infrastructure all operate Australian regions; AWS also opened its New Zealand region in 2025. Public cloud is useful for automation, managed databases, short-lived capacity and architectures that truly use multiple failure zones. It is not automatically cheaper. Instance runtime, disks, snapshots, public IPv4, support and outbound data should all enter the model.

    A dedicated server gives one customer the physical machine. It can deliver predictable CPU, memory, local NVMe and a large transfer allowance at an attractive monthly price. The customer still needs a plan for disk failure, hardware replacement, remote access, spare capacity and restore time. A single dedicated server is not a high-availability architecture merely because the components are powerful.

    Colocation places customer-owned hardware in a provider's facility. It offers the most hardware control and can make sense for specialised storage, GPU or long-lived workloads. It also shifts procurement, firmware, spares, freight, remote hands, power density and hardware disposal back to the customer. A low rack price can become expensive after power, cross-connects, transit, addresses and support are added.

    A dated price snapshot, not a permanent price list

    The following examples were observed on official provider pages on 29 August 2026. Australian prices are shown in AUD. Voyager publishes New Zealand dollars; the indicative AUD figures use the Reserve Bank of Australia's 28 August 2026 reference rate of A$1 = NZ$1.2084. The RBA cautions that its rates are not for commercial settlement. GST, card conversion and supplier tax treatment still need to be checked on the actual quote.

    Provider and example Advertised price GST and term Network/transfer shown Important omissions or caveats
    OVHcloud Advance-1 2026, selected AU configuration A$185.99/month plus A$185.99 setup Ex GST; configuration and commitment affect price Public bandwidth selectable within the product range; private network capability varies Region, hardware, IPv4, support and setup must be confirmed in cart
    Kimsufi KS-B in Sydney A$16.79/month plus A$16.79 setup Ex GST; setup advertised as waived on 12+ month commitment 500 Mbps; APAC page states 25 TB/month Entry hardware and support scope are limited; verify stock and recovery expectations
    Streamline Sydney i7-7700K example A$180/month Tax treatment and contract should be confirmed at checkout 15 TB on a 10 Gbps port advertised Older CPU; compare storage, DDoS, IPv4 and support on the final order
    Streamline Sydney Xeon E-2286G example A$320/month Confirm tax and term 30 TB on a 10 Gbps port advertised Provider network and latency statements require route testing from real users
    Voyager NZ VPS entry plan NZ$10.08, about A$8.34/month Ex NZ GST Provider advertises unlimited bandwidth Fair-use and cross-border tax conditions need review; entry plan is 1 vCPU/1 GB/15 GB
    Voyager NZ dedicated entry plan NZ$225, about A$186.20/month Ex NZ GST Provider advertises unmetered service subject to its terms Auckland location; confirm remote hands, replacement and address allocation
    Voyager device colocation NZ$190, about A$157.23/month Ex NZ GST Shared 1 Gbps PIR and a /29 advertised Power and form-factor limits matter; rack, cross-connect and support needs may change TCO
    Servers Australia, Micron21, Twisted Servers, Intergrid, Datacom Quote required Obtain an itemised GST quote Varies by facility and service Include power, rack units, transit, cross-connects, remote hands and support

    The table is deliberately not a benchmark. The OVH and Streamline examples are not identical machines, and a 10 Gbps port with a transfer quota is not the same commercial product as a lower-rate unmetered port. For public cloud, use each provider's current calculator with the same workload hours, disk type, snapshots, address count, support tier and outbound traffic instead of comparing a headline VM rate.

    Decision path for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering A dated price snapshot, not a permanent price list, Australian and trans-Tasman providers worth shortlisting, Public clo…
    Decision path: A dated price snapshot, not a permanent price list; Australian and trans-Tasman providers worth shortlisting; Public cloud and New Zealand data-location options; Decision matrix.

    Australian and trans-Tasman providers worth shortlisting

    OVHcloud operates a broad bare-metal range in Sydney. Its Australian pages describe anti-DDoS protection as included with dedicated servers, and its game range adds game-oriented filtering. That is valuable for internet-facing services, but it should be described as built-in and comparatively strong—not infinite or guaranteed to stop every attack. Product and regional conditions, false positives, application-layer attacks, mitigation behaviour and traffic allowances remain relevant. Ozlin's operational lesson is equally important: provider mitigation does not replace server hardening. Patch the operating system and management plane, restrict administrative access, use least privilege and backups, and never install cracked or “nulled” software whose integrity cannot be verified. Such packages can carry credential stealers, web shells or other backdoors and turn a server into part of someone else's botnet.

    Kimsufi and So You Start are OVHcloud's lower-cost lines. Kimsufi can be attractive for labs, replicas, personal services and workloads that tolerate entry-level hardware and a narrower service envelope. The Australian page currently shows Sydney stock and a 25 TB monthly APAC transfer condition. So You Start can bridge the gap toward more capable dedicated hardware, but availability and current pricing are often configuration-dependent. Neither label should be treated as a promise of the same SLA, replacement process, network options or support as a higher-tier product. Model the cost of downtime and an independent backup before celebrating the monthly saving.

    Streamline Servers and GSL Networks advertise dedicated systems across Sydney, Melbourne, Brisbane, Adelaide, Perth and Auckland. Streamline attributes its offering to low-latency routing, DDoS protection and GSL's international network; these are provider claims and should be verified with route measurements from the actual ISPs and cities that matter. Its dated prices can be higher than a budget bare-metal plan, but a fair TCO comparison must hold CPU generation, RAM, storage, traffic, port speed, mitigation, support and contract term constant. For latency-sensitive games or trans-Tasman audiences, a week of representative ping, jitter, loss and route testing is more persuasive than a network map.

    Servers Australia offers colocation and connectivity around major Australian locations and into New Zealand. Its public colocation material is best used to start a requirements conversation; pricing is quote-based. Ask for the exact facility, usable power, A/B feeds, rack depth, cross-connect and transit pricing, remote-hands minimums, delivery procedure and termination costs.

    Micron21 is a Melbourne operator offering data-centre, cloud, connectivity and DDoS-related services. Certifications, facility tier language and protection capabilities on its site are provider statements: request the scope, current certificate, SLA and service design that apply to the proposed product rather than transferring a company-wide claim to one rack or VM.

    Twisted Servers is a useful Perth option. Its data-centre page identifies Equinix PE2 and a Western Australian presence, which may reduce latency for WA users and make local hands easier than an east-coast deployment. Perth does not automatically improve international paths to every destination; measure the relevant Australian and overseas routes.

    Intergrid advertises instant cloud, bare metal and colocation across Sydney, Brisbane, Melbourne, Perth, Adelaide and Auckland. It also states Tier 3 facilities, DDoS protection, an international network and a 100% network-uptime SLA. Those are attributed provider claims, and its own page contains inconsistent “six” and “seven” city wording, so this guide lists only the six named locations and recommends confirming the applicable SLA and exclusions in writing.

    Voyager adds a practical New Zealand VPS, virtual data centre, dedicated and colocation shortlist. Its public entry prices are unusually clear, and it advertises New Zealand hosting, 99.98% environmental uptime and unlimited or unmetered connectivity on relevant products. Check fair-use terms, support hours, architecture and tax treatment. A single Auckland VPS and a redundant virtual data centre solve different availability problems even when both are called cloud.

    Public cloud and New Zealand data-location options

    AWS, Azure, Google Cloud and OCI are strongest candidates when the workload benefits from managed services, policy APIs, temporary scaling or multiple availability zones. Their bills require disciplined tagging, budgets, egress modelling and architecture. Read the provider's shared-responsibility documentation and Ozlin's AWS and Azure cloud-security checklist before assuming a managed control covers the application or data.

    For New Zealand placement, AWS Asia Pacific (New Zealand) launched with three Availability Zones. Catalyst Cloud documents regions in Porirua and Hamilton, creating a locally operated alternative with OpenStack-based services. Datacom lists facilities in Auckland, Hamilton, Wellington and Christchurch and is relevant for data-centre, private-cloud and colocation conversations. Microsoft, Google and Oracle location portfolios change over time, so use their official region lists and verify that the exact service—not merely the company—exists in the intended region.

    Platform Relevant documented footprint on 29 August 2026 Commercial comparison
    AWS Sydney, Melbourne and New Zealand regions; AWS documents three Availability Zones in each Broad managed-service/API range; model compute, disks, snapshots, IPv4, support and egress in the official calculator
    Microsoft Azure Australia East, Australia Southeast and New Zealand North, with service and zone availability varying by region Strong Microsoft identity/data ecosystem; verify the precise service, reservation and outbound-data line
    Google Cloud Sydney (australia-southeast1) and Melbourne (australia-southeast2) Strong data, Kubernetes and managed-service options; use the product-by-region list and calculator rather than assuming parity
    Oracle Cloud Infrastructure Australia East (Sydney) and Australia Southeast (Melbourne) Relevant for Oracle workloads and general IaaS; both documented regions currently list one availability domain, so design failure domains explicitly
    Catalyst Cloud Porirua and Hamilton regions in New Zealand NZ-operated OpenStack option; compare service catalogue, support, network and workload portability
    Datacom Facilities listed in Auckland, Hamilton, Wellington and Christchurch Relevant to colocation/private-cloud and managed requirements; obtain an itemised quote and facility-specific scope

    This is a capability comparison, not a price ranking. Public-cloud prices change by service, purchase option and traffic direction too often for one small VM to represent the bill. Re-run the official calculators with the same 730 monthly hours, storage performance, snapshots, IP count, support plan and measured egress.

    Data location is not a complete privacy conclusion. Replication, backups, support access, logs, subprocessors and customer configuration can move or expose data beyond the compute region. Record the real data flows and obtain advice for contractual or regulatory decisions.

    Decision matrix

    Priority VPS Public cloud Dedicated Colocation
    Lowest entry cost Usually strong Strong for tiny or temporary use; egress may dominate later Budget ranges can be strong Usually weak after hardware and setup
    Rapid scaling and APIs Moderate Strong Limited to provisioned machine Slowest unless spare hardware exists
    Predictable raw compute cost Moderate Requires careful modelling Often strong Strong only at stable, sustained utilisation
    Hardware control Low Low High within supplier options Highest
    Managed services Limited Strong Customer or third party Customer or third party
    Latency-sensitive games Test noisy-neighbour and CPU Can work, but cost/CPU class matters Often strong with the right network Strong for mature operators
    DDoS exposure Product-specific Product and service-specific Product-specific; OVH/Streamline advertise mitigation Transit and mitigation contract-specific
    Operational burden Moderate Can be high despite managed components High Highest
    Data-location evidence Ask for host/backup locations Region and service documentation usually available Facility known; backups still matter Facility and hardware known; support paths still matter
    Control and evidence map for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Public cloud and New Zealand data-location options, Decision matrix, Build a comparable TCO and related revie…
    Control and evidence map: Public cloud and New Zealand data-location options; Decision matrix; Build a comparable TCO; A defensible selection process.

    Build a comparable TCO

    Use the same workload assumptions for every candidate:

    monthly TCO = compute or rack + storage + backups + outbound traffic + public IPs + support + licences + remote hands + power + expected failure/downtime allowance

    For a dedicated server, annualise setup and expected replacement downtime. For colocation, include hardware purchase, freight, rails, PDUs, spares and disposal. For public cloud, model normal and incident months, because log retention, snapshots and egress can jump during recovery. For a New Zealand quote converted to AUD, retain both the supplier currency and an exchange-rate buffer.

    Then run evidence-producing tests: latency from real user ISPs; packet loss and jitter during peak periods; storage latency under the real queue depth; sustained CPU behaviour; restore time; mitigation escalation; and support response through the channel you would use during an incident.

    A defensible selection process

    1. Classify the workload, data, recovery target, expected traffic and attack exposure.
    2. Shortlist locations based on users and dependencies, not company headquarters.
    3. Obtain itemised quotes covering tax, term, setup, addresses, transfer, port rate, support and exit.
    4. Compare 12- and 36-month TCO under normal, growth and incident scenarios.
    5. Pilot using production-like traffic without importing sensitive data unnecessarily.
    6. Harden the operating system, hypervisor or control panel before exposure; remove defaults, restrict administration, monitor changes and test backups.
    7. Record why the choice was made and set a review date.

    Ozlin can help translate these requirements into a provider-neutral architecture and migration plan through its infrastructure and technology services. The commercial decision should remain traceable to measurements and contract terms rather than a logo or a single monthly price.

    Practical checklist for Australia and New Zealand Server Hosting Guide: VPS, Cloud, Dedicated…, covering Decision matrix, Build a comparable TCO, A defensible selection process and related review points.
    Practical checklist: Decision matrix; Build a comparable TCO; A defensible selection process; Sources and review record.

    Sources and review record

    Sources were accessed on 29 August 2026. Prices and regional availability are scheduled for review by 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

  • How to Size a Game Server in Australia: Minecraft, Counter-Strike and Hosting Models

    How to Size a Game Server in Australia: Minecraft, Counter-Strike and Hosting Models

    Player slots are a sales unit, not a hardware specification. A quiet 64-slot server and a full 64-player modded event can have completely different CPU, memory and network demands. Minecraft chunk generation, a Counter-Strike map plugin, bots, database calls and downloads all change the workload. Australian and New Zealand players then add geography, ISP routing, traffic quotas and attack exposure to the calculation.

    The defensible method is to choose a starting configuration, run the real server build, collect tick and network measurements under representative concurrency, and adjust. This article's configurations are Ozlin starting test baselines, not performance guarantees.

    Ozlin also brings direct operational context: on one 64-player Counter-Strike 2 zombie-escape environment, Ozlin has observed outbound traffic peak at roughly 150 Mbps. That is a field observation for that map/plugin/player mix, not a universal 64-slot requirement. Ozlin has also found Zriot-style zombie-bot workloads materially CPU-intensive on the server. Human slots and bot count must therefore be tested as separate load dimensions.

    Article map for How to Size a Game Server in Australia: Minecraft, Counter-Strike and…, covering Define the workload before assigning cores, Minecraft starting test profiles, Counter-Strike 2 starting test profiles and…
    Article map: Define the workload before assigning cores; Minecraft starting test profiles; Counter-Strike 2 starting test profiles; Calculate transfer from a measured rate.

    Define the workload before assigning cores

    Capture more than the maximum player count:

    • typical, planned-event and maximum concurrent users (CCU);
    • game and exact server build;
    • tick or simulation target;
    • maps, world size, view/simulation distance and chunk-generation plan;
    • plugins, mods, scripting runtimes and databases;
    • bot type and count;
    • voice, replay, anti-cheat and logging;
    • FastDL, Workshop or mod-distribution method;
    • backup size, frequency and restore objective;
    • expected player cities and ISPs; and
    • DDoS exposure, community visibility and moderation model.

    Measure the busy period, not a fresh empty server. Retain a reproducible test world/map and plugin set so an upgrade can be compared with the previous build.

    Minecraft starting test profiles

    Paper's troubleshooting guidance emphasises strong single-thread performance and recommends at least four threads, while its bundled spark profiler helps find tick problems. More cores do not automatically repair one overloaded main thread. World generation, entities, hoppers, redstone, view distance and plugins can dominate.

    Planned Java/Paper CCU Ozlin starting CPU baseline Starting memory Commissioning focus
    5–10 4 modern high-speed threads 4–6 GB Java heap; about 8 GB system total Pregenerate nearby world, cap view/simulation distance, profile plugins
    20–40 4–6 modern high-speed threads 8–12 GB heap; about 16 GB system total Test exploration, farms, backups and database activity at once
    50–100 6–8+ high-speed threads 12–24 GB heap; about 32 GB system total Pregeneration, entity controls, profiling, tuned proxy/sharding decisions and load rehearsal

    These are not minimum requirements published by Mojang or Paper. They are starting points for a controlled test. Avoid assigning an enormous heap “just in case”: garbage collection and memory pressure can worsen pauses. Leave memory for the operating system, filesystem cache, panel agent, backup and database. Use supported Java versions and current Paper documentation for the selected game build.

    Run spark or the documented profiler during a real busy period. Watch mean tick time and long-tail stalls, not only average CPU percentage. A 25% total CPU graph on a four-core VM can conceal one saturated main thread. Record chunk generation, entity and plugin contributors before buying more RAM.

    Counter-Strike 2 starting test profiles

    Counter-Strike server behaviour depends on tick processing, map, player count, plugins, bots and networking. Valve's developer wiki describes CS2's 64-tick/subtick networking at a high level, but community documentation and the game itself evolve; validate the current dedicated-server build.

    Planned slots Ozlin starting CPU baseline Starting memory Commissioning focus
    12–24 4 modern high-speed cores About 8 GB system RAM Stable frame/tick processing, map change, logging, plugins and peak packets
    32–64 6–8 modern high-speed cores About 16 GB system RAM Full-player rehearsal, complex maps, plugins, database calls and sustained network capture
    32–64 with heavy zombie mode or many bots Begin above the corresponding human profile and reserve dedicated CPU headroom 16 GB+ depending on plugins/assets Test bot count, AI update cost, map and human CCU independently; profile server frame time

    Do not size a Zriot zombie-bot server by human slots alone. Bots perform server-side decision and movement work; adding twenty bots can change CPU demand even if no additional internet client joins. Create a test matrix such as 0/10/20/40 bots crossed with low and high human CCU. Capture server-frame or tick health, the busiest core, plugin timings and network output. Reduce or reschedule expensive bot logic before assuming that more vCPUs will help.

    Zombie escape creates another special case. Large maps, many moving entities, custom effects and mass player movement can cause bursty updates. Ozlin's approximately 150 Mbps observed peak means a 100 Mbps port would not provide enough instantaneous capacity for that environment. A 1 Gbps port creates headroom, but its existence says nothing about the monthly transfer quota, congestion, provider shaping or route quality.

    Decision path for How to Size a Game Server in Australia: Minecraft, Counter-Strike and…, covering Minecraft starting test profiles, Counter-Strike 2 starting test profiles, Calculate transfer from a measured rate and r…
    Decision path: Minecraft starting test profiles; Counter-Strike 2 starting test profiles; Calculate transfer from a measured rate; Test routes from players, not from the administrator's desk.

    Calculate transfer from a measured rate

    For decimal terabytes of one-direction traffic:

    TB ≈ Mbps × active hours × 0.00045

    This follows from megabits per second × seconds ÷ eight, using decimal units. One continuous 1 Mbps stream for 30 days is about 0.324 TB.

    Use a representative average or p95 over the defined active window, not the single highest graph spike. For example, if measurements—not a guess—show 65 Mbps p95 during six busy hours per day across 30 days, the planning value is:

    65 × 180 × 0.00045 ≈ 5.27 TB outbound

    If the service really sustained 150 Mbps for those same 180 hours, it would be about 12.15 TB. Ozlin's 150 Mbps value is a peak observation, so applying it as a month-long average would overstate ordinary transfer. Add inbound traffic, updates, backups, FastDL and monitoring separately, then apply a growth and incident margin.

    For a provider advertising “15 TB on a 10 Gbps port”, 10 Gbps describes possible port rate while 15 TB describes allowed transfer under the contract. For “1 Gbps unmetered”, inspect fair-use and shaping language. A traffic quota, port speed, latency, jitter, loss and DDoS mitigation are six distinct properties.

    Not all Australian server products are traffic-capped. Some publish quotas, some advertise unmetered service, and public cloud commonly meters egress. Compare the exact product and location. The Australia and New Zealand hosting guide provides a broader provider matrix.

    Test routes from players, not from the administrator's desk

    Measure round-trip latency, jitter and loss from the cities and access networks where players actually live. A Sydney server may be excellent for east-coast users and suboptimal for Perth or New Zealand depending on routing. An Auckland or Perth deployment can improve a local audience without improving every international path.

    Run tests at evening peak and during events. Capture route changes and loss over time. A low average ping with periodic loss can feel worse than a slightly higher stable ping. Avoid relying on ICMP alone if a network deprioritises it; combine it with application telemetry and player reports.

    DDoS protection deserves explicit questions: which game and transport protocols are covered, whether mitigation is always-on, how false positives are handled, what happens above plan limits, whether application-layer floods are included, and how support escalates an incident. No provider protection makes an unpatched game server safe.

    Slots hosting, VPS, dedicated or colocation?

    Pay-by-slots game hosting

    This is suitable when a community wants a managed game instance without owning the operating system. A provider may expose TCAdmin, Pterodactyl or another panel for configuration, scheduled tasks and backups. Advantages include fast setup, game-aware support and no host patching. Limits can include no root/SSH/RDP access, constrained plugins, shared CPU, fixed backup policies and limited network visibility.

    Ask whether CPU allocation is dedicated, what happens during noisy-neighbour load, which locations and DDoS controls apply, and whether files/data can be exported. A panel label does not reveal the underlying hardware.

    VPS

    A VPS offers root access and flexible automation at low entry cost. It suits smaller servers, test instances, proxies and supporting services. Confirm CPU scheduling, sustained clock behaviour, storage performance and traffic. A plan advertising many vCPUs can lose to fewer faster dedicated cores for a main-thread-heavy game.

    Dedicated server

    Dedicated hardware is often the practical step for large communities, multiple instances or demanding mods. It provides predictable cores, memory and local storage, but the operator owns patching, backups, monitoring, recovery and most application security. One host is still one failure domain. Keep external backups and rehearse rebuilding the service.

    Colocation

    Colocation makes sense when stable demand justifies owned hardware and someone can manage spares, firmware, remote hands, power and logistics. It is rarely the cheapest first experiment. Price rack space, power, transit, mitigation, addresses, remote hands and hardware depreciation together.

    Decision factor Slots hosting VPS Dedicated Colocation
    Root control Usually none Yes Yes Yes, including hardware
    Launch effort Lowest Moderate High Highest
    CPU predictability Provider-specific Provider-specific Stronger Strongest under your design
    Custom panels/services Limited Flexible Flexible Flexible
    Hardware responsibility Provider Provider Provider replaces under contract Customer
    Best starting use Small/standard communities Labs and moderate servers Large or multiple workloads Mature, stable operations

    TCAdmin and Pterodactyl are management layers. Pterodactyl Wings uses containers and exposes CPU/memory limits; TCAdmin can select servers and provision products by slots through billing integrations. Neither product guarantees the CPU underneath, low latency or competent backup. Read the host's allocation and support terms.

    Control and evidence map for How to Size a Game Server in Australia: Minecraft, Counter-Strike and…, covering Calculate transfer from a measured rate, Test routes from players, not from the administrator's desk, Slots h…
    Control and evidence map: Calculate transfer from a measured rate; Test routes from players, not from the administrator's desk; Slots hosting, VPS, dedicated or colocation?; Budget the supporting services.

    Budget the supporting services

    Backups: Separate configuration, world/map data, databases and replaceable game binaries. Keep at least one copy outside the game host and test a restore. Snapshot-only backup on the same storage is not enough.

    Monitoring: Record service health, CPU per core, memory, disk latency/capacity, tick or frame time, player count, packet loss, traffic rate and backup status. Alerts need an owner and response procedure.

    Updates: Stage game, plugin, mod and panel updates before major events. Keep a rollback artifact and protect administrative credentials with MFA or a restricted management path where supported.

    Content distribution: Steam Workshop is the preferred distribution path where the game and content support it. FastDL may still be required for some legacy or custom-server assets; serve only intended static files, use correct MIME types, prevent script execution and monitor bandwidth. Do not expose backups, configuration or credentials through a directory lister.

    Community controls: SourceBans or equivalent systems, Discord integrations and web panels handle personal data and privileged actions. Patch them, minimise permissions, use supported software and define retention. Never deploy cracked/nulled plugins, panels or game assets: unknown code can add web shells, credential theft or botnet functionality, and copyright risk is not a technical strategy.

    Operations: Moderation, abuse handling, incident response, DDoS escalation and restore time often cost more than the VM. Include them in the hosting decision and publish separate community terms where appropriate. Ozlin's projects page describes the broader community and technical context without exposing production internals.

    Commission, measure, then scale

    1. Build the exact game, map/world, plugins and bot configuration on a test host.
    2. Generate representative load or hold a controlled event.
    3. Record per-core CPU, memory, tick/frame health, p95 and peak network, loss, disk and temperatures.
    4. Identify whether the limit is one thread, memory, storage, network rate, quota or software.
    5. Change one major variable at a time and repeat.
    6. Test backup restore, update rollback and host rebuild.
    7. Recalculate monthly transfer and 12-month TCO from measurements.
    8. Set capacity alerts below the player-visible failure point.

    The right answer may be a managed 20-slot product, a fast dedicated CPU, or several isolated instances. The evidence should show why. Ozlin's infrastructure services can help turn player goals and operational constraints into a measurable hosting plan without treating slot count as a promise.

    Practical checklist for How to Size a Game Server in Australia: Minecraft, Counter-Strike and…, covering Slots hosting, VPS, dedicated or colocation?, Budget the supporting services, Commission, measure, then scale and…
    Practical checklist: Slots hosting, VPS, dedicated or colocation?; Budget the supporting services; Commission, measure, then scale; Sources and review record.

    Sources and review record

    Sources were accessed on 29 August 2026. Game builds, panel documentation, provider terms and Ozlin measurement baselines are scheduled for review by 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.

  • Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea

    Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea

    Running a server at home is excellent for learning. A small lab can teach Linux, containers, backups, monitoring and networking for less than a formal course. That does not automatically make a residential connection a sensible production platform for a public website, game service, file host or customer application.

    The problem is not that home hosting never works. It is that one inexpensive-looking computer inherits the limits of the house around it: consumer broadband, one power feed, domestic cooling, a shared router, changing addresses, household devices and an operator who also needs to sleep. A cloud VPS can fail too, but its network, power and replacement model are designed around hosted services. The honest comparison is total service risk, not “hardware already owned versus a monthly invoice.”

    This guide focuses on Australian residential broadband and uses public information checked on 29 August 2026. ISP addressing, plan speeds, acceptable-use rules and electricity prices change, so verify the current terms for the actual address before relying on any example.

    Article map for Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea, covering The few cases where a residential connection may be justifi…, Public IPv4 may not exist at your router, Tunnels, mesh VPNs an…
    Article map: The few cases where a residential connection may be justifi…; Public IPv4 may not exist at your router; Tunnels, mesh VPNs and relays solve different problems; Residential upload is the scarce direction.

    The few cases where a residential connection may be justified

    A home server can be reasonable when it is a non-critical lab, a private service reached through an authenticated overlay network, a local media or backup appliance, or a short-lived test with no customer dependency. It can also be useful for testing how a legitimate consumer service behaves from an ordinary residential network.

    Some streaming or registration platforms distinguish residential from data-centre addresses to manage licensing, fraud and abuse. That can create a genuine testing requirement, but it is not permission to evade geolocation, account, automation or anti-abuse rules. A public streaming site does not inherently need a residential IP. Check the platform contract, content rights and ISP acceptable-use policy; do not sell access to a household connection as a “clean residential proxy” or use it to disguise automated registrations.

    If the requirement is simply “customers must reach a reliable website,” residential identity is normally a disadvantage rather than a feature. Start with the Australia and New Zealand hosting guide and compare a VPS, dedicated server or colocation service first.

    Public IPv4 may not exist at your router

    Traditional port forwarding assumes the router owns a public IPv4 address. Many residential services instead use carrier-grade NAT, or CGNAT, where multiple subscribers share public IPv4 addresses and the ISP performs another translation outside the home. RFC 6598 defines a dedicated shared-address range for this purpose.

    Current Australian examples show why the ISP must be checked rather than assumed. Aussie Broadband says CGNAT is typically enabled by default and documents opt-out or static-IP paths. Superloop's residential Critical Information Summary dated 31 May 2025 says CGNAT is used where available, documents an opt-out path and lists one static IPv4 option at A$5 per month including GST. Those are provider-specific snapshots, not a promise that every ISP, access technology or future plan offers the same remedy; obtain the current CIS for the plan being purchased.

    Compare the router's WAN address with the address reported by an external service. A WAN address in private or shared space, or a different upstream address, suggests another NAT layer. Do not expose an administration page merely to test it.

    Dynamic DNS is not CGNAT traversal. DDNS updates an A or AAAA record when a routable address changes. Cloudflare's documentation describes monitoring the address and updating the DNS record through an API or client. If unsolicited packets cannot reach the subscriber through CGNAT, pointing a hostname at the shared address does not create a forwarding rule in the ISP's network.

    IPv6 can provide globally routable addresses without IPv4 NAT, but it does not remove the need for a stateful firewall. Confirm prefix stability, inbound filtering, client IPv6 support and a safe update process for dynamic AAAA records. Opening IPv6 while testing only IPv4 rules is a common way to create an unreviewed second exposure path.

    Tunnels, mesh VPNs and relays solve different problems

    An overlay product such as Radmin VPN or another mesh VPN can be useful for private access between enrolled devices. NAT traversal may establish a direct encrypted path; when that fails, a relay can add latency, throughput limits and an external dependency. This is suitable for administration or a small trusted group, not automatically for an anonymous public service.

    A reverse tunnel initiates an outbound connection from home to an edge provider. Cloudflare Tunnel, for example, documents outbound-only origin connections without opening an inbound router port. That reduces origin exposure and works behind CGNAT, but the connector, account, DNS, access policy and edge provider become part of the service. The origin still needs patches, least privilege and authentication. Protocol support and source-IP behaviour must be verified for the application.

    A VPS can also act as a WireGuard, TCP or application relay. Now both the home system and VPS must be patched, monitored and backed up; bandwidth crosses two links; client addresses may need explicit forwarding; and the relay bill may approach the price of hosting the workload there. Draw the complete data path before declaring tunnelling “free.”

    Decision path for Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea, covering Tunnels, mesh VPNs and relays solve different problems, Residential upload is the scarce direction, A DDoS attack can take…
    Decision path: Tunnels, mesh VPNs and relays solve different problems; Residential upload is the scarce direction; A DDoS attack can take the household offline; A consumer “DMZ host” is not network segmentation.

    Residential upload is the scarce direction

    Headline broadband speed usually emphasises download. A public server primarily sends data upstream. Concurrent game updates, video, backups and household video calls can contend for the same queue, increasing latency and packet loss before a monthly transfer total looks unusual.

    Measure wired sustained upload, p95 latency under load, jitter and packet loss at busy times. Test with the real application, not one speed-test burst. A 50 Mbps upstream cannot deliver 50 Mbps of dependable application traffic after protocol overhead, contention and the headroom needed by the household. Traffic shaping can improve fairness but cannot create upstream capacity.

    Ozlin has observed one 64-player CS2 zombie-escape environment peak around 150 Mbps outbound under its particular map and plugin mix. That does not define all game servers, but it demonstrates why a residential uplink can fail on instantaneous demand even when average monthly traffic seems manageable. The Australian game-server sizing guide explains how to measure this rather than size from slot count alone.

    A DDoS attack can take the household offline

    A local firewall can discard packets after they arrive. It cannot restore a residential access link whose upstream capacity has already been consumed. A volumetric attack against the public address may therefore disrupt work, calls, entertainment, cameras and every other household service—not just the intended server. Changing a dynamic IP may provide temporary relief, but DNS history, game listings or another direct protocol can reveal it again.

    ASD's denial-of-service guidance recommends planning with upstream providers, resilient capacity, monitoring, CDNs and cloud-based mitigation before an incident. A CDN can help an HTTP service when the origin address is concealed and origin firewall rules accept only authorised edge traffic. It does not automatically protect arbitrary UDP, game, voice, mail or remote-administration protocols, and a DNS-only record can reveal the same origin address.

    Ask the ISP what happens under attack: whether it offers mitigation, rate-limits or null-routes the address, how long recovery takes, and whether abuse traffic affects the account. If availability matters, this conversation should occur before publication.

    A consumer “DMZ host” is not network segmentation

    On many home routers, the setting labelled DMZ host or exposed host forwards essentially all otherwise-unmapped inbound TCP and UDP traffic to one internal device. TP-Link's current explanation explicitly distinguishes this from a true DMZ. It should not be used as a shortcut when the operator is unsure which ports are required.

    Even precise port forwarding increases attack surface. If the public server shares a flat LAN with laptops, phones, network storage, printers, smart TVs, cameras and home-automation devices, compromise can create a foothold behind the router. It does not make every device instantly public, but it places an attacker on a network that was probably designed for convenience and discovery rather than hostile east-west traffic.

    Use a real isolated VLAN or physical segment with default-deny rules between the server, management devices and household/IoT networks. Disable UPnP when automatic inbound mappings are unnecessary. Expose only the required service ports, keep router administration private, use a host firewall and supported software, and never install cracked or nulled panels, plugins or server packages. Unknown privileged code can convert the home server—and sometimes vulnerable routers or IoT devices—into part of someone else's botnet.

    Control and evidence map for Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea, covering A DDoS attack can take the household offline, A consumer “DMZ host” is not network segmentation, Electricity, he…
    Control and evidence map: A DDoS attack can take the household offline; A consumer “DMZ host” is not network segmentation; Electricity, heat and cooling are recurring costs; Power, maintenance and recovery still need an owner.

    Electricity, heat and cooling are recurring costs

    An average load runs for 8,760 hours each year:

    annual kWh = average watts ÷ 1,000 × 8,760

    The AER's 2026–27 residential Default Market Offer flat usage caps for the three NSW distribution areas are 33.14–35.01 cents per kWh, including GST. They are safety-net tariff caps, not a prediction of any reader's bill; market offers, solar, time-of-use periods and location change the result.

    Average continuous load Annual energy Illustrative NSW electricity cost Excluded costs
    30 W mini PC 262.8 kWh A$87–A$92/year storage, UPS losses, cooling and broadband
    100 W compact server 876 kWh A$290–A$307/year same exclusions
    300 W rack server 2,628 kWh A$871–A$920/year same exclusions
    500 W server/GPU system 4,380 kWh A$1,452–A$1,533/year same exclusions

    Almost all consumed electricity becomes heat in the room. A garage or cupboard that is acceptable in winter may throttle disks, batteries and CPUs during a Sydney summer. Domestic air conditioning adds energy and another failure dependency. Measure inlet temperature, humidity, fan noise and power at the wall across seasons. Do not defeat server fan controls or electrical protections to make retired rack hardware tolerable beside a bedroom.

    Use this TCO rather than “the machine was free”:

    hardware + UPS + incremental electricity + cooling + public-IP/tunnel fees + replacement parts + off-site backup + administration and outage cost − residual value

    Power, maintenance and recovery still need an owner

    NBN states that mains-powered equipment connected to its network will not work during a power outage unless each required item has suitable backup. A UPS must cover the server, storage, router, access equipment and any tunnel dependency at the premises; runtime decreases as batteries age. It should trigger an orderly shutdown, not merely delay an uncontrolled one.

    Residential plans may not include business repair targets, proactive monitoring, redundant carriers or a service-level agreement. Firmware updates can reboot the router, a family member can unplug equipment, and a failed disk may wait until the operator returns home. Backups stored beside the server share theft, fire, flood and electrical risk. Maintain encrypted off-site backups and test restoration to different hardware.

    Operational minimums include patch windows, service and certificate monitoring, central logs, configuration backup, spare storage, a documented rebuild, remote access that does not expose management ports, and an out-of-band way to learn that the house is offline.

    If you still need a home-hosted service

    Proceed only when the consequence of failure is acceptable and the residential location is genuinely required. A defensible starting architecture is:

    1. confirm the ISP contract, public IPv4/IPv6 behaviour, static-address cost, upload capacity and abuse response;
    2. place the server on an isolated network with default-deny access to household and IoT devices;
    3. prefer an authenticated private overlay for administration and private services;
    4. for public HTTP, use an outbound tunnel or protected reverse proxy, hide and restrict the origin, and expose no router or server management UI;
    5. run supported software as a non-root service identity, minimise plugins, enable MFA where available and rotate scoped credentials;
    6. deploy UPS-backed graceful shutdown, temperature and availability alerts, rate limits and tested off-site recovery; and
    7. document a migration trigger—traffic, uptime, security, temperature or support load—at which the service moves to hosted infrastructure.

    For most public services, the cleaner design is a small VPS or protected dedicated server, with the home lab used for development and backups that do not contain the only copy. Colocation becomes attractive when owned hardware, power density and remote hands matter. Ozlin's infrastructure and hosting services can help compare the full path without publishing private network details.

    Home hosting is valuable as a laboratory. It becomes a poor bargain when customer availability, household safety or an irreplaceable residential connection is placed behind the same inexpensive router.

    Practical checklist for Why Hosting a Public Server on Home Broadband Is Usually a Bad Idea, covering Electricity, heat and cooling are recurring costs, Power, maintenance and recovery still need an owner, If you still…
    Practical checklist: Electricity, heat and cooling are recurring costs; Power, maintenance and recovery still need an owner; If you still need a home-hosted service; Sources and review record.

    Sources and review record

    Sources and prices were accessed on 29 August 2026. ISP addressing, tunnel behaviour and electricity figures are scheduled for review by 29 November 2026.

    AI assisted with source discovery, drafting and copyediting; Ozlin Info remains responsible for publication.