A static IP and open ports on 5G home internet

Port forwarding fails on 5G home internet because your address is shared with other customers. GetAStatic gives you your own public IPv4 over WireGuard, with no change to the gateway.

Not affiliated with T-Mobile, Verizon, AT&T, Rogers, Bell or Telus. Facts as listed on their sites, checked 2026-10-06.

Instant setup US-based IP

Updated

Facts

5G and fixed-wireless home internet at a glance

T-Mobile Home InternetCGNAT. No port forwarding. Business static IP: ~$15/mo (third-party reports). T-Mobile guide
Verizon 5G HomeCGNAT on many lines, as users report; Verizon does not say. The gateway's port-forward page works only with a public WAN IPv4. Verizon guide
AT&T Internet AirCGNAT on some lines, as users report; AT&T does not say. The hub's NAT/Gaming rules work only with a public WAN IPv4. AT&T guide
Rogers, Bell, Telus (Canada)Fixed-wireless plans commonly use CGNAT. A static IP usually means a business plan.
GetAStaticYour own static IPv4 and open ports on any of them, from $2/mo

Checked .

The problem

Why port forwarding does nothing on 5G home internet

T-Mobile Home Internet puts consumer plans behind carrier-grade NAT (CGNAT), and users report the same on Verizon 5G Home and AT&T Internet Air. Your gateway does not get a public IPv4 of its own, and the carrier shares one public address among many homes. A port-forwarding rule stops at the carrier's NAT, so outside traffic never arrives. Nothing in the gateway app can change that.

The Verizon gateway even has a port-forwarding page, but a rule there never sees outside traffic behind CGNAT. The T-Mobile Home Internet guide covers that gateway, and port forwarding not working? shows how to check your own line.

Canada: Rogers, Bell and Telus fixed-wireless and 5G home plans commonly use CGNAT too. A static IP usually means a business plan. Our IPs are in the US, so the extra delay from most of Canada is small.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why use GetAStatic on 5G

  • Works with the carrier's gateway in its default mode: no bridge mode, no IP passthrough
  • Your own public IPv4 that stays the same when the 5G address changes
  • Open TCP or UDP ports in the dashboard, with no ticket
  • No call to the carrier and no business plan
How it works

Bring your own public IPv4

GetAStatic gives you a public IPv4 that does not depend on your ISP. Your server, or your own router behind the gateway, dials out to our node in Kansas City, Missouri or San Jose, California over WireGuard. Outgoing connections pass through CGNAT without trouble.

When someone connects to your IP, the traffic comes back down that tunnel to your device. The whole device uses the IP, for incoming and outgoing traffic.

The tunnel cannot make your connection faster than it is. 5G upload speed and jitter change with signal and tower load, and that sets the ceiling for anything you host.

Setup

Set it up on a home server

A typical home server needs a few ports. These four fit on any plan:

  1. Sign up for GetAStatic.
  2. In the dashboard, open the ports your services listen on. A new IP starts with every port closed.
  3. Download your WireGuard config.
  4. Import it into WireGuard on the machine that runs your services, or on your own router to cover every device behind it.
  5. Give people YOUR-IP:port, or point a domain name at your IP.
PortProtocolUsed for
443TCPWebsite or reverse proxy (HTTPS)
32400TCPPlex Media Server
25565TCPMinecraft Java server
51820UDPYour own WireGuard server for remote access

For Plex, also set "Manually specify public port" to 32400 in Remote Access. For satellite internet, see the Starlink page.

Good to know

Good to know

  • Speed is capped per plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Your 5G upload may be lower than that.
  • Bandwidth counts upload plus download: 100 GB on Plus, 1 TB on Pro. It resets monthly; going over pauses the tunnel until the reset or an upgrade.
  • Plus allows 5 open ports; Pro and Ultra have unlimited open ports. A port range counts as its size.
  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California, not a residential one.
  • One config runs on one device or router at a time; on a router, every device behind it shares the IP. Devices outside the tunnel stay behind the carrier's CGNAT.
FAQ

Questions, answered.

01Can I put my own router behind the T-Mobile or Verizon gateway?

Yes. Plug your router into the gateway and run WireGuard on it (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet). Every device on your router then uses the static IP, including consoles and TVs that cannot run WireGuard.

02Does it work with the gateway in its default mode?

Yes. WireGuard only makes outgoing connections, which the gateway already allows. You do not need bridge mode, IP passthrough or any setting change.

03Will my games or Plex be slower?

Remote viewers and players are limited by your 5G upload speed and your plan's speed cap, whichever is lower. Traffic also travels through Kansas City, Missouri or San Jose, California, so people far from the IP's city see extra delay.

04Does it work in Canada on Rogers, Bell or Telus?

Yes. The tunnel works on any connection that can reach the internet, CGNAT included. Your IP is a US address, so sites and services see a US location.

05Do I need to call my ISP?

No. Nothing changes on the carrier's side, so there is no request to make and no plan to upgrade.

Have more questions? See the full FAQ →