Gateway regions: choose where your traffic exits
Everything you route through Reach leaves from a gateway in one of six regions — Singapore, Hong Kong, Taiwan, Europe, US-West or Australia — and the sites you visit see that region's IP. Reach picks a sensible default and switches away from a gateway that stops responding; you can pin any region yourself.
The regions
| Region | Good for |
|---|---|
| Singapore (SG) | The default for most accounts; low latency across South-East Asia and Australia |
| Hong Kong (HK) | Lowest latency from mainland China and East Asia |
| Taiwan (TW) | A second East-Asian exit; useful alongside HK for users in China |
| Europe (EU) | Services that expect a European visitor, or teams with EU partners |
| US-West | North American SaaS tools and consoles |
| Australia (AU) | An Australian IP while you're overseas — banks, myGov and services that insist on an Australian address; teams that need an Australian egress IP to whitelist |
From Australia, pick any of the five overseas regions and a routed browser appears from outside Australia; from abroad, the Australian region gives you an Australian IP. Reach is still not a pick-any-country VPN — these six are the menu (see How Reach differs from a VPN).
Team admins can limit which regions their members see — see Group policy & TCP forwards.
How a gateway is chosen
- Desktop — the tray's Gateway submenu lists the regions available to your account with a live latency reading next to each (measured every 30 seconds, e.g. HK ~90ms). Your account's default region is used until you pick one; a manual pick is remembered across restarts. The Gateway: line in the menu shows the active region (Ctrl+Shift+click it to reveal the exit IP).
- Android — the Gateways tab has auto-select on by default, which picks the fastest gateway for you; turn it off to pin a region.
- iOS — the Gateways screen marks the recommended gateway BEST; gateways aimed at mainland-China access carry a CN badge.
What changes when you switch
- Your exit IP changes. Each region has its own fixed address — the one that shows up in server logs and IP allowlists. See What is an egress IP?. Teams that whitelist the gateway IP should pick one region and stay on it.
- Open connections are re-established on the new gateway; a page reload is usually all that's needed.
- Sharing a PC pins you to a relay-capable gateway: while a share is active, the picker greys out regions that can't carry it. See Share this PC.
Related
- Connection modes — how the client reaches the gateway on restrictive networks
- Using Reach in mainland China — which region to pick from inside China
- Static egress IP — one team-wide IP to allowlist
Common questions
Which region should I pick?
Leave the default (or auto-select on Android) unless you have a reason: HK or TW from inside China, EU or US-West when a service expects a visitor from there, AU when you're abroad and need an Australian IP, SG otherwise.
Can I get an Australian IP?
Yes — pick the Australia region. It's there for Australians overseas who need to look local to a bank, government portal or Australian-only service, and for teams that want an Australian egress IP to whitelist. From inside Australia it changes nothing about your location, so the overseas regions are the ones that matter there.
Does the gateway IP ever change?
Each region's exit IP is fixed. If a region is ever re-homed we announce it in the changelog; team admins using cloud firewall automation have their rules updated automatically.