- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Cloudflare Tunnel is built for websites. GetAStatic gives you a static public IPv4 of your own and a VPN that exits from it. Open any TCP or UDP port and anyone can reach you with their normal app.
GetAStatic is not affiliated with Cloudflare. Cloudflare details from its own docs and terms, checked 2026-10-06.
Updated
A tunnel is made for websites; your own IP takes every other service too.
| Feature | GetAStatic | Cloudflare Tunnel |
|---|---|---|
| Price | From $2/mo | Free (all plans) |
| Your own public IP | Yes | No |
| Public ports and protocols | Any TCP or UDP port you open | HTTP(S) hostnames; no public UDP |
| Websites | Yes | Yes |
| SSH and RDP with no extra app | Yes | Needs Cloudflare Access or WARP |
| Video streaming (Plex, Jellyfin) | Yes, within your plan's data | Limited by Cloudflare's terms |
| Needs a domain on Cloudflare | No | Yes |
Checked 2026-10-06. Visitors see Cloudflare's IPs. Other TCP, such as SSH, needs Cloudflare Access or the WARP app on each visitor's device.
Cloudflare Tunnel runs a small program, cloudflared, next to your app. It dials out to Cloudflare, so it works behind CGNAT, and it is built for websites. Visitors see Cloudflare's IPs, not an address of your own.
Everything else is harder. A public hostname carries web traffic. Raw TCP on other ports, such as SSH or RDP, needs Cloudflare Access or the WARP app on each visitor's device, and there is no public UDP, so a game server, a SIP line or your own WireGuard server cannot sit behind a free tunnel.
Media is limited too. Cloudflare's terms (checked 2026-10-06) restrict serving video and other large files through its network on the free plan, and uploads through the proxy are reported to be capped at 100 MB per request. That is why Plex and Jellyfin users often look elsewhere.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a dedicated public IPv4, delivered over WireGuard from our node in Kansas City, Missouri or San Jose, California. Open a TCP or UDP port in the dashboard, with no ticket, no app for the other side and no domain to move. The same tunnel is a VPN too, so allowlists and logins always see one address.
Pay by card or crypto, with a 7-day money-back guarantee. If you are not sure why your ports do not work today, start with how to escape CGNAT.
Run WireGuard on the machine that runs the service, or on your router to cover the whole LAN.
| Port | Protocol | Used for |
|---|---|---|
| 25565 | TCP | Minecraft Java server |
| 32400 | TCP | Plex Media Server |
| 5060 | UDP | SIP phone or PBX |
| 51820 | UDP | Your own WireGuard server |
Plus allows 5 open ports. A SIP audio (RTP) range counts as its size, so a PBX usually needs Pro or Ultra (unlimited open ports).
Yes. Open the port on your static IP, such as 32400 for Plex, 8096 for Jellyfin or 25565 for Minecraft, and people connect straight to it. See Plex behind CGNAT and game servers behind CGNAT for the steps.
Yes, but one setup is simpler. Your static IP serves websites too: point your domain at it and run a reverse proxy such as Caddy on port 443. The same IP carries the game, video, voice and SSH ports a tunnel cannot publish, so one address covers everything.
Visitors connect to the static IP, so your home address is not published. Built for a stable address, not anonymity.
No. Plans start at $2/mo, paid monthly or yearly by card or crypto. If it does not work for you, ask for a refund within 7 days.
Have more questions? See the full FAQ →