- Buy a second IP on your VPS ([PUBLIC_IP])
- Do NOT set it up on any local interface. Instead, set up a Wireguard server which will let you use the IP on the other end of the tunnel, and set up IP forwarding and proxy ARP such that the VPS will present it to the provider network as if it was local. Example:
cat > /etc/wireguard/wg0.conf <<EOF [Interface] ListenPort = ... PrivateKey = ... [Peer]
AllowedIPs = [PUBLIC_IP]/32