Reach your NAS from anywhere at your own IP

GetAStatic gives your NAS a public IPv4 address over WireGuard. Your files, photos and media server answer at your own address, even behind CGNAT.

Instant setup US-based IP

Updated

The problem

Why your NAS cannot be reached from outside

You forward a port to the NAS and it still cannot be reached from outside. The usual cause is CGNAT: your ISP shares one public IP among many homes, so incoming connections stop at the ISP. Starlink, 5G home internet and many cable and fiber ISPs work this way.

Synology QuickConnect and myQNAPcloud get around it by relaying your traffic through the vendor's servers. The relay can be slow, and you still have no address of your own.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why NAS owners pick GetAStatic

  • A direct connection to your own address instead of a vendor relay
  • Works on Starlink, 5G home internet and other CGNAT connections
  • Every port starts closed, so only what you choose is reachable
  • One IP for the web UI, the phone apps and Plex or Jellyfin
How it works

Give the NAS its own public IP

GetAStatic gives you a dedicated static IPv4. WireGuard runs on the NAS or on your router and dials out to our node in Kansas City, Missouri or San Jose, California, so CGNAT does not get in the way. Connections to the ports you open come down the tunnel.

Synology: DSM does not include WireGuard, and VPN Server has no WireGuard option. Community packages can add it, without Synology support.

QNAP: the QVPN app can import a WireGuard config; check that incoming connections reach your app.

TrueNAS SCALE: WireGuard is in the system, but the web UI cannot run it as a client, so use your router instead.

Unraid: it has a built-in WireGuard client; check that incoming connections reach your app.

On any NAS, the dependable route is your router: run WireGuard there (OpenWrt, pfSense, OPNsense, MikroTik, GL.iNet) and forward the open ports to the NAS.

Setup

Set up remote access

  1. Sign up for GetAStatic and note your static IP.
  2. In the dashboard, open only the ports you need. For private file access, 51820 UDP is enough.
  3. Import the WireGuard config on the NAS or router and turn it on. On a router, forward each open port to the NAS.
  4. On the NAS, turn on HTTPS, two-factor login, the firewall and auto block for failed logins.
  5. From outside, open https://YOUR-IP:5001 (Synology) or YOUR-IP:port. In Plex, tick "Manually specify public port" and enter 32400.
PortProtocolUsed for
5001TCPSynology DSM and its apps (HTTPS)
443TCPQNAP, TrueNAS or Unraid web UI, or a reverse proxy
32400TCPPlex Media Server
8096TCPJellyfin
51820UDPYour own WireGuard server: the safe way to reach files

Plus (5 open ports, 100 GB a month, 20 Mbps) fits a couple of ports and light use; Pro (unlimited open ports, 1 TB, 100 Mbps) suits Plex or Jellyfin and more ports. Every byte you sync or stream counts, and the speed cap is the same in both directions.

Good to know

Security and limits

  • Never open file-sharing ports (SMB, NFS, AFP) to the internet. To reach shared folders from outside, run your own WireGuard server on 51820 UDP and connect to it first.
  • Do not open the admin web UI without HTTPS and two-factor login.
  • The device running WireGuard sends all its traffic through the IP. On the NAS, cloud backups and updates leave through Kansas City, Missouri or San Jose, California too and count against your bandwidth; on a router, so does your whole home network.
  • Going over the monthly bandwidth pauses the tunnel until it resets or you upgrade.
  • It is a datacenter IP, not a home IP, which is fine for remote access.
FAQ

Questions, answered.

01Should I use QuickConnect or a static IP?

QuickConnect relays traffic through Synology's servers when a direct link fails. A static IP is your own address, reached directly. You can keep both on.

02Do I need a domain name?

No. https://YOUR-IP:5001 works, with a certificate warning. A DNS A record pointing a name you own at the IP makes a trusted certificate easy.

03Will Synology Photos and Synology Drive work?

Yes. Enter your IP or hostname as the server address instead of a QuickConnect ID. The Synology Drive desktop client also needs port 6690 TCP.

04What is the safest way to reach my files?

Your own WireGuard server. Open 51820 UDP, run a WireGuard server on the router or NAS (QNAP QVPN and Unraid include one), and connect to it. Shared folders then open as at home, and SMB never touches the internet.

Have more questions? See the full FAQ →