- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Dynamic DNS gives a name to an address. It cannot create a public IPv4 or get you past CGNAT, so the name resolves and the port stays closed. GetAStatic gives you a fixed public IPv4 over WireGuard with the ports you choose, from $2/mo.
Not affiliated with DuckDNS, No-IP or Dynu. DuckDNS and No-IP behavior as described in their own FAQs, checked 2026-10-07.
Updated
| Dynamic public IPv4 | DDNS: yes, it follows each change · Router forwarding: yes |
|---|---|
| Static public IPv4 | DDNS: not needed, the IP stays put · Router forwarding: yes |
| Double NAT (router WAN IP is 10.x, 172.16.x to 172.31.x or 192.168.x) | DDNS: yes, if it records the outer box's public IP · Router forwarding: only with bridge mode or a forward on both boxes |
| CGNAT (router WAN IP in 100.64.0.0/10) | DDNS: no, the address it records is shared · Router forwarding: no |
| Updater runs on a PC with a VPN on | DDNS: no, the name points at the VPN's exit address · Router forwarding: never reached through the name |
A DDNS service such as DuckDNS, No-IP or Dynu is two small parts: a DNS record (an A record such as myhome.duckdns.org) and an updater that tells the service which address to put in it. The updater runs on your router, a NAS or a PC. It either sends an address it reads locally, or sends nothing and lets the service use the address the request came from. DuckDNS works the second way when you leave its ip parameter blank.
That design works well on a line with a dynamic public IPv4. Your router holds the public address itself, the ISP changes it now and then, the updater reports the new one, and a connection to the name lands on your router. The port forward then passes it to your server. DDNS only solves the changing address. No-IP's own FAQ says it plainly: DDNS points your hostname at your current public IP, "but it does not automatically allow external access."
Behind CGNAT, the updater can only record one of two wrong addresses. If the service reads the address the request came from, it records the ISP's shared public address. Connections to it reach the ISP's NAT, which has no rule for your home and drops them. If your router sends its own WAN address, the name points at something in 100.64.0.0/10, which nobody on the internet can route to.
The core issue is layers. Each NAT layer needs its own rule for an unsolicited inbound connection. Your router's port forward is a rule on your layer. With CGNAT the outer layer belongs to the ISP, and no setting in your home reaches it.
You need three addresses: your router's WAN IP, your public IP, and the address your hostname resolves to.
All three match: check the forward, the firewall and ISP port blocks. WAN IP in 100.64.0.0/10: no DDNS or router setting will help, and the fix is below.
Your own static IP over WireGuard. No VPS.
Dedicated IPv4 from $2/mo →With CGNAT, you need a public address on a layer you control. GetAStatic gives your server or router a dedicated public IPv4 in Kansas City, Missouri or San Jose, California. The device connects out over WireGuard on UDP 1194 or 443, which CGNAT lets through like any outbound traffic. Connections to your IP on the ports you open in the dashboard come back down that tunnel. The dashboard rule does the job your router's forward cannot.
If the check showed double NAT and not CGNAT, try bridge mode on the ISP gateway first, so your router gets the public address. DDNS and a normal port forward then work, at no cost. Some ISPs also move a line off CGNAT on request.
Once the IP is fixed, the name only has to be set once. An updater on the device that runs the tunnel reports the dedicated IP, because all of that device's traffic leaves through the tunnel, so it does no harm. An updater on your router still reports the ISP address and will overwrite the record, so turn that one off. For the full case for replacing DDNS, see dynamic DNS alternative.
Example: a home server you reach as myhome.duckdns.org.
You can delete the old port forward on your router. The tunnel does not need it.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
Your router's DDNS client is sending its own WAN address, and that address is in 100.64.0.0/10, the CGNAT range. Nobody outside your ISP can reach it. Switching the client to report your public IP does not fix reachability either, because that public IP is shared with other customers.
Connecting from your LAN to your own public address needs NAT loopback (also called hairpin NAT) on the router, and many home routers do not support it. The name can work for everyone outside while failing at home. Test from a phone on mobile data instead.
Then DDNS is fine. Check that the service listens on that port, that the forward points to the server's current LAN address with the right protocol, that the server's firewall allows it, and that your ISP does not block the port. Port forwarding not working walks through each check.
Yes. Set the record to the fixed IP once. DuckDNS accepts an explicit ip value in its update URL; with the value blank it uses the address your request came from. You can also point your own domain at the DuckDNS name with a CNAME record, as their FAQ describes.
Have more questions? See the full FAQ →