Reach Home Assistant from outside, even behind CGNAT

GetAStatic gives your Home Assistant a real public IPv4 over WireGuard. Open one port, set your external URL, and the app works away from home.

Instant setup US-based IP

Updated

The problem

Why port forwarding does nothing

You forward port 8123 on your router, set an external URL, and the Home Assistant app still cannot connect when you leave the house.

Your ISP probably uses CGNAT. Many homes share one public IP, and your router gets a private address behind it. Incoming connections stop at the ISP and never reach your router, so a port forward has nothing to forward. Starlink, 5G home internet, and many cable and fiber ISPs work this way.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why Home Assistant users pick GetAStatic

  • A real public IP for your Home Assistant, not a shared relay
  • The same IP works for your other self-hosted services
  • Run your own WireGuard server on it and keep Home Assistant private
  • Plus ($2/mo) is enough: Home Assistant traffic is tiny
How it works

Give Home Assistant a public IP

GetAStatic gives you a static IPv4 address. The machine running Home Assistant (or your router) connects out to our node in Kansas City, Missouri or San Jose, California over WireGuard, and connections to your IP on the ports you open come back down that tunnel.

Home Assistant Cloud by Nabu Casa is the official option. It is a monthly subscription that funds the Home Assistant project, and it includes the Alexa and Google Assistant integrations. If you only want remote access, or you want a public IP you can also use for other services, a static IP is the other route.

Setup

Set up remote access

If Home Assistant runs in Docker or on a Linux machine, run WireGuard on that machine. On Home Assistant OS (Green, Yellow, a Raspberry Pi), run WireGuard on your router and forward the port to Home Assistant; the community WireGuard client add-on does not support a full-tunnel config like ours.

  1. Sign up for GetAStatic and note your static IP.
  2. In the dashboard, open the port Home Assistant listens on: 8123 TCP for most installs. New Home Assistant OS installs since 2026.8 use 80 instead.
  3. Download the WireGuard config and import it on the Home Assistant machine or your router. Turn the tunnel on.
  4. In Home Assistant, go to Settings → System → Network and set the Home Assistant URL for the internet to http://YOUR-IP:8123 (with your port), or to an https:// hostname that points at your IP.
  5. Open the companion app away from home. It uses that external URL.
PortProtocolUsed for
8123TCPHome Assistant web UI and app
443TCPHTTPS reverse proxy (optional)

We recommend HTTPS for a dashboard on the internet. Put a reverse proxy with a Let's Encrypt certificate in front, open 443 TCP instead of 8123, and add the proxy to use_x_forwarded_for and trusted_proxies in Home Assistant's http settings.

Good to know

Limits and safety

  • Anything you open is open to the whole internet. Use HTTPS, a strong password, and two-factor login on your Home Assistant account.
  • Safer option: keep 8123 closed, open 51820 UDP for your own WireGuard server at home, and connect to that first. Then only your devices can reach Home Assistant.
  • The speed cap applies per IP. Home Assistant uses very little, so Plus (20 Mbps) is plenty.
  • Traffic goes through Kansas City, Missouri or San Jose, California, so the app may feel a bit slower far from the IP's city.
  • The IP is a datacenter IP, not a home IP.
  • This does not replace the Alexa or Google Assistant integrations in Home Assistant Cloud.
FAQ

Questions, answered.

01Is this an alternative to Nabu Casa?

For remote access, yes. For the voice assistant integrations (Alexa, Google Assistant) it is not; those come with Home Assistant Cloud.

02Will the Home Assistant companion app work?

Yes. Set the external URL in Home Assistant to your IP or hostname, and the app uses it when you are away from home.

03Do I need a domain name?

No. You can use the IP directly. A hostname makes HTTPS certificates easier. A custom reverse DNS name ($5 one-time) is optional and not needed for this.

04Is port 8123 open to the whole internet?

Only if you open it. Every port starts closed. If you open it, use HTTPS and strong login, or keep it closed and reach Home Assistant through your own WireGuard server.

Have more questions? See the full FAQ →