AT&T Internet Air port forwarding that still does not work

A NAT/Gaming rule on the All-Fi Hub only works when the hub holds the public IPv4 the internet sees. If it does not, the block is upstream. GetAStatic gives you your own static IPv4 over WireGuard, with the ports you choose open, from $2/mo.

Not affiliated with AT&T. Facts as listed on AT&T's support pages, checked 2026-10-07.

Instant setup US-based IP

Updated

Facts

Port forwarding on the Internet Air All-Fi Hub

Hubs AT&T lists for Internet AirBGW530, BGW830 and CGW450 All-Fi Hubs
Where the setting isHub settings at 192.168.1.254, then Firewall, then NAT/Gaming. The Device Access Code is printed on the hub.
Warning on NAT/GamingBGW530 and BGW830: enable port forwarding on your account first. CGW450: restart the hub.
Custom rule fieldsService Name, Global Port Range, Base Host Port, Protocol, then Needed by Device
Public IPv4 or CGNATAT&T's hub pages do not say. Users report both on Internet Air.
GetAStaticYour own static IPv4 and the ports you open, from $2/mo

Checked .

The problem

The rule is saved and the port is still closed

You followed AT&T's page: Custom Services, the port in both Global Port Range fields, the device under Needed by Device, Save. The entry shows under Hosted Applications. A port checker still says closed, and nobody outside can connect.

The NAT/Gaming rule is one hop in a longer path. A connection from outside has to reach the public IPv4 the internet sees, get through any NAT in front of the hub, match the hub's rule, land on the right local address, pass that device's firewall and find a program listening on the port. A break at any hop looks the same from outside: closed, or a timeout.

AT&T's support pages for the Internet Air hubs explain the menu, but they do not say whether a line gets its own public IPv4. Users report both: some Internet Air lines get a public address, and others share one with other customers through carrier-grade NAT (CGNAT). On a shared address the rule can be perfect and still never see a packet.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Check

Find the hop that fails

Work from the hub outward. Each step rules out one layer.

  1. Clear any warning on the NAT/Gaming page first (see the box above).
  2. Check the rule itself. AT&T recommends one entry per port, with the same number in both Global Port Range fields. Base Host Port is the port the program listens on, and Protocol must match it: Minecraft Bedrock uses UDP, a web server uses TCP. Needed by Device must be the device's current local address. If that address changed after a restart, the rule points at nothing, so give the device a fixed local address.
  3. Test inside your home. From a second device on the same Wi-Fi, connect to the server's local address and port, such as 192.168.1.70:25565. If that fails, the hub is not the problem. Start the program, make it listen on all interfaces instead of 127.0.0.1, and allow the port in Windows Defender Firewall, ufw or firewalld.
  4. Compare two addresses. Find the IPv4 address the hub itself has on its broadband or status page. Then run the port check from a device on the hub, which shows the public IPv4 the internet sees and tests the port.
  5. Read the hub's address. If it matches the public address, your line has its own IPv4 and the earlier steps hold the fault. If it is between 100.64.0.0 and 100.127.255.255 (100.64.0.0/10), AT&T's network shares your address through CGNAT. If it starts with 10., 172.16 to 172.31 or 192.168., the NAT is upstream of the hub. AT&T's BGW530 and BGW830 pages show the hub holds the SIM and connects to the 5G network itself, so no box in your home sits in front of it.
  6. If you plugged your own router into the hub, that is double NAT inside your home. Point the hub's rule at your router, then forward the port again on your router to the server.

If the hub's address and the public address differ, the block is inside AT&T's network. No setting on the hub or on your router reaches it.

Why use GetAStatic?

Why Internet Air customers use GetAStatic

  • Works with the All-Fi Hub as it is: no NAT/Gaming rules and no account setting to change
  • Your own static IPv4 that stays the same if the address AT&T gives your line changes
  • TCP and UDP ports you open in a dashboard, for game servers, Plex, cameras or a website
  • Works the same on a public or a shared AT&T address, so you do not need to know which one you have
How it works

What GetAStatic changes in the packet path

With GetAStatic, an inbound connection no longer starts at AT&T. A visitor connects to your static IPv4 in Kansas City, Missouri or San Jose, California. Our node checks the port against the ones you opened in the dashboard and sends the packet down a WireGuard tunnel that your device opened outbound, on UDP 1194 or 443. To the All-Fi Hub that tunnel is ordinary outgoing traffic. The shared address, AT&T's NAT and the NAT/Gaming page all drop out of the path.

One part of the path stays the same: your device. The program must be listening, and the device firewall must allow the port on the WireGuard interface. The device also sends its outgoing traffic from the same IP, so allowlists and game servers see one fixed address.

If your hub holds the public IPv4, you may not need us: fix the hop that failed. We fit when the address is shared, or when you want one that does not depend on AT&T.

Setup

Set it up behind the All-Fi Hub

  1. Sign up for GetAStatic. Your static IP shows in the dashboard.
  2. Open the ports your program uses, TCP or UDP. Every port starts closed. Plus includes 5 open ports; Pro and Ultra have unlimited open ports. A port range counts as its size.
  3. Import the WireGuard config on the machine that runs the program (Windows, macOS, Linux, or a NAS through Docker), or on your own router behind the hub (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet). Synology DSM has no built-in WireGuard, so on a Synology run it in Docker or on the router.
  4. Turn the tunnel on. The hub needs no change, and the old NAT/Gaming entry plays no part, so you can delete it.
  5. Allow the port on the WireGuard interface in the device firewall. Then test YOUR-IP:port with the port check.
Good to know

Good to know

  • Speed is capped per plan, the same up and down: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Internet Air upload changes with signal and tower load, and it is often lower than the cap.
  • Bandwidth counts upload plus download: 100 GB on Plus, 1 TB on Pro, 5 TB on Ultra.
  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California. Players and viewers far from the IP's city see some extra delay.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. A PlayStation or Xbox cannot run WireGuard, so it needs a router in front of it that does.
  • There is no UPnP and no automatic port mapping. A game or app that opens its own ports on the hub needs those ports opened in the dashboard.
  • Not sure it fits your setup? You have 7 days to get your money back.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01What does the warning on the NAT/Gaming page mean?

AT&T's pages for the BGW530 and BGW830 hubs say that if a warning appears there, you should enable port forwarding on your account and then continue. The CGW450 page says to restart the hub instead. The pages do not describe the account setting further, so if you cannot find it, ask AT&T support.

02What is Base Host Port in a custom service?

It is the port on your device that receives the traffic. Global Port Range is the port people connect to from outside. AT&T's instructions set Base Host Port to the first port of the Global Port Range, so outside and inside use the same number. Keep them the same unless your program listens on a different port.

03Is AT&T Internet Air always behind CGNAT?

AT&T does not say so on its hub support pages, and users report both public and shared addresses on Internet Air. Check your own line: compare the hub's IPv4 address with the public one, or run the CGNAT check.

04Can I use my own router with the All-Fi Hub?

Yes. Plug it into the hub and you have two NAT layers in your home, so a port needs a rule on the hub pointing to your router and a second rule on the router. Or run WireGuard with your GetAStatic config on that router, and every device behind it uses the static IP with no forwarding rules at all.

05Does the hub need any setting for the tunnel?

No. WireGuard connects out to our node on UDP 1194 or 443, and the hub passes outgoing traffic by default. You do not need NAT/Gaming, the account setting or any change on the hub.

Have more questions? See the full FAQ →