How to bypass the restriction on Megaphone IP access between its subscribers?

MegaFon has a non-obvious limitation for subscribers of its mobile network, which is described, for example here:
The service is not provided the possibility of direct IP connection between two subscribers using the IP addresses assigned to the North-West branch of OJSC "MegaFon"

(about "Static IP address")

That is, if two certain devices are on the network using the megafonovsky modem, then see each other, they will not be able, from the word altogether. Despite the fact that other networks to each of them you can get through without problems.

How can I bypass this restriction?

I want to find a good solution, since most of the network at MegaFon and the IP was specifically ordered to access the server from any remote office, to do without third-party VPN (before some time I tried to work through Zerotier, for example).

The Megaphone is the service "Virtual private network (IP VPN)", but described it very common words, it is not entirely clear what is proposed, whether to buy their equipment or prices or technical details not given; but the technical support is some sort of heresy about what a static IP is VPN.
July 2nd 19 at 17:10
July 2nd 19 at 17:12
July 2nd 19 at 17:14
Just pick up any wired provider, buy white IP, raise up your VPN for a long time and forget about problems. If you go bad pptp, then l2tp is, in principle, work anywhere.
Yes, that solution was considered but, unfortunately, the building was not a single provider, and for us to stretch optics agreed for a very heavy bag. - nikita.Stracke commented on July 2nd 19 at 17:17
But with L2tp is not so smooth. Ufanet have some strange NAT, which l2tp somehow breaks the connection. - Laney_Stros commented on July 2nd 19 at 17:20
July 2nd 19 at 17:16
In like MegaFon is connected as physical or as legal.face?
IMHO the easiest way to place on kalakasan gateway or deploy a gateway in the cloud.
Connected as legal.face.
About the gateway could not throw the link to an example of the configuration of such scheme or finished service? Was configured/ordered, and the gugleniya issues apparently not what I need. - nikita.Stracke commented on July 2nd 19 at 17:19
: The same peg( colocation ), is the placement of its equipment on the node "provider", i.e. you set the gateway, and your ISP optics for you to pull is not necessary. Similarly, you can put linux in the cloud( digitalocean for example ) and configure a gateway on it, and all clients are connected to it. It is analogue to the vpn but your own. - Laney_Stros commented on July 2nd 19 at 17:22
thanks, I meant an example implementation of the gateway — for example, how is it different from your VPN server in the same DO. - nikita.Stracke commented on July 2nd 19 at 17:25
: VPN is in some sense a special case of the gateway. If there is no need to authenticate clients or to encrypt traffic, you can do without it. - hailee_Parker26 commented on July 2nd 19 at 17:28

