- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
A NAT/Gaming rule on the All-Fi Hub only works when the hub holds the public IPv4 the internet sees. If it does not, the block is upstream. GetAStatic gives you your own static IPv4 over WireGuard, with the ports you choose open, from $2/mo.
Not affiliated with AT&T. Facts as listed on AT&T's support pages, checked 2026-10-07.
Updated
| Hubs AT&T lists for Internet Air | BGW530, BGW830 and CGW450 All-Fi Hubs |
|---|---|
| Where the setting is | Hub settings at 192.168.1.254, then Firewall, then NAT/Gaming. The Device Access Code is printed on the hub. |
| Warning on NAT/Gaming | BGW530 and BGW830: enable port forwarding on your account first. CGW450: restart the hub. |
| Custom rule fields | Service Name, Global Port Range, Base Host Port, Protocol, then Needed by Device |
| Public IPv4 or CGNAT | AT&T's hub pages do not say. Users report both on Internet Air. |
| GetAStatic | Your own static IPv4 and the ports you open, from $2/mo |
Checked .
You followed AT&T's page: Custom Services, the port in both Global Port Range fields, the device under Needed by Device, Save. The entry shows under Hosted Applications. A port checker still says closed, and nobody outside can connect.
The NAT/Gaming rule is one hop in a longer path. A connection from outside has to reach the public IPv4 the internet sees, get through any NAT in front of the hub, match the hub's rule, land on the right local address, pass that device's firewall and find a program listening on the port. A break at any hop looks the same from outside: closed, or a timeout.
AT&T's support pages for the Internet Air hubs explain the menu, but they do not say whether a line gets its own public IPv4. Users report both: some Internet Air lines get a public address, and others share one with other customers through carrier-grade NAT (CGNAT). On a shared address the rule can be perfect and still never see a packet.
Your own static IP over WireGuard. No VPS.
Dedicated IPv4 from $2/mo →Work from the hub outward. Each step rules out one layer.
If the hub's address and the public address differ, the block is inside AT&T's network. No setting on the hub or on your router reaches it.
With GetAStatic, an inbound connection no longer starts at AT&T. A visitor connects to your static IPv4 in Kansas City, Missouri or San Jose, California. Our node checks the port against the ones you opened in the dashboard and sends the packet down a WireGuard tunnel that your device opened outbound, on UDP 1194 or 443. To the All-Fi Hub that tunnel is ordinary outgoing traffic. The shared address, AT&T's NAT and the NAT/Gaming page all drop out of the path.
One part of the path stays the same: your device. The program must be listening, and the device firewall must allow the port on the WireGuard interface. The device also sends its outgoing traffic from the same IP, so allowlists and game servers see one fixed address.
If your hub holds the public IPv4, you may not need us: fix the hop that failed. We fit when the address is shared, or when you want one that does not depend on AT&T.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
AT&T's pages for the BGW530 and BGW830 hubs say that if a warning appears there, you should enable port forwarding on your account and then continue. The CGW450 page says to restart the hub instead. The pages do not describe the account setting further, so if you cannot find it, ask AT&T support.
It is the port on your device that receives the traffic. Global Port Range is the port people connect to from outside. AT&T's instructions set Base Host Port to the first port of the Global Port Range, so outside and inside use the same number. Keep them the same unless your program listens on a different port.
AT&T does not say so on its hub support pages, and users report both public and shared addresses on Internet Air. Check your own line: compare the hub's IPv4 address with the public one, or run the CGNAT check.
Yes. Plug it into the hub and you have two NAT layers in your home, so a port needs a rule on the hub pointing to your router and a second rule on the router. Or run WireGuard with your GetAStatic config on that router, and every device behind it uses the static IP with no forwarding rules at all.
No. WireGuard connects out to our node on UDP 1194 or 443, and the hub passes outgoing traffic by default. You do not need NAT/Gaming, the account setting or any change on the hub.
Have more questions? See the full FAQ →