- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Port forwarding fails on 5G home internet because your address is shared with other customers. GetAStatic gives you your own public IPv4 over WireGuard, with no change to the gateway.
Not affiliated with T-Mobile, Verizon, AT&T, Rogers, Bell or Telus. Facts as listed on their sites, checked 2026-10-06.
Updated
| T-Mobile Home Internet | CGNAT. No port forwarding. Business static IP: ~$15/mo (third-party reports). T-Mobile guide |
|---|---|
| Verizon 5G Home | CGNAT on many lines, as users report; Verizon does not say. The gateway's port-forward page works only with a public WAN IPv4. Verizon guide |
| AT&T Internet Air | CGNAT on some lines, as users report; AT&T does not say. The hub's NAT/Gaming rules work only with a public WAN IPv4. AT&T guide |
| Rogers, Bell, Telus (Canada) | Fixed-wireless plans commonly use CGNAT. A static IP usually means a business plan. |
| GetAStatic | Your own static IPv4 and open ports on any of them, from $2/mo |
Checked .
T-Mobile Home Internet puts consumer plans behind carrier-grade NAT (CGNAT), and users report the same on Verizon 5G Home and AT&T Internet Air. Your gateway does not get a public IPv4 of its own, and the carrier shares one public address among many homes. A port-forwarding rule stops at the carrier's NAT, so outside traffic never arrives. Nothing in the gateway app can change that.
The Verizon gateway even has a port-forwarding page, but a rule there never sees outside traffic behind CGNAT. The T-Mobile Home Internet guide covers that gateway, and port forwarding not working? shows how to check your own line.
Canada: Rogers, Bell and Telus fixed-wireless and 5G home plans commonly use CGNAT too. A static IP usually means a business plan. Our IPs are in the US, so the extra delay from most of Canada is small.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a public IPv4 that does not depend on your ISP. Your server, or your own router behind the gateway, dials out to our node in Kansas City, Missouri or San Jose, California over WireGuard. Outgoing connections pass through CGNAT without trouble.
When someone connects to your IP, the traffic comes back down that tunnel to your device. The whole device uses the IP, for incoming and outgoing traffic.
The tunnel cannot make your connection faster than it is. 5G upload speed and jitter change with signal and tower load, and that sets the ceiling for anything you host.
A typical home server needs a few ports. These four fit on any plan:
| Port | Protocol | Used for |
|---|---|---|
| 443 | TCP | Website or reverse proxy (HTTPS) |
| 32400 | TCP | Plex Media Server |
| 25565 | TCP | Minecraft Java server |
| 51820 | UDP | Your own WireGuard server for remote access |
For Plex, also set "Manually specify public port" to 32400 in Remote Access. For satellite internet, see the Starlink page.
Yes. Plug your router into the gateway and run WireGuard on it (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet). Every device on your router then uses the static IP, including consoles and TVs that cannot run WireGuard.
Yes. WireGuard only makes outgoing connections, which the gateway already allows. You do not need bridge mode, IP passthrough or any setting change.
Remote viewers and players are limited by your 5G upload speed and your plan's speed cap, whichever is lower. Traffic also travels through Kansas City, Missouri or San Jose, California, so people far from the IP's city see extra delay.
Yes. The tunnel works on any connection that can reach the internet, CGNAT included. Your IP is a US address, so sites and services see a US location.
No. Nothing changes on the carrier's side, so there is no request to make and no plan to upgrade.
Have more questions? See the full FAQ →