A PIA port forwarding alternative: a static US IP with ports you choose

PIA forwards a port it assigns, and not on its US servers. GetAStatic is a WireGuard VPN with your own static US IPv4, from $2/mo. You choose the TCP and UDP ports, and they stay open until you close them.

Not affiliated with Private Internet Access. Prices as listed on privateinternetaccess.com, checked 2026-10-06.

Instant setup US-based IP

Updated

Compare

PIA port forwarding vs GetAStatic

Two tools built for different jobs, compared on inbound connections.

FeaturePIA port forwardingGetAStatic
Pricefrom $2.03/mo (3-year plan)From $2/mo
PurposePrivacy VPN on shared serversA stable US address with inbound ports
Your own IPShared server IP; dedicated IP is a paid add-onYes, in every plan
Port behaviorAssigned automaticallyChosen by you, TCP or UDP
US inbound availabilityNot on US serversYes: Kansas City & San Jose, USA
Endpoint persistenceKept alive by the app; normally expires after 2 monthsSame IP and port until you close it
Typical usePrivate browsing; P2P on non-US serversServers, SSH, games and logins on a US IP

PIA's price is its VPN plan, which includes port forwarding ($11.95/mo month to month). Port facts from PIA's help center and its official connection scripts, checked 2026-10-06.

The problem

What PIA port forwarding gives you

In the PIA desktop app the switch is Settings, then Network, then Request Port Forwarding. When you connect to a location that supports it, PIA's gateway hands your session a port on the server's VPN IP, and the app shows the number in its IP widget. You copy that number into qBittorrent, a game server or whatever needs to accept connections. The IP in front of it is the server's, shared with other PIA users.

Two rules shape what you can do with it. PIA's help center says port forwarding is available only on supported locations and not on US server locations; its own connection scripts say it is disabled server-side in the United States. And the port is assigned automatically, so you cannot ask for 25565, 22 or the port a camera app expects. You reconfigure the app to whatever number PIA gives you.

The port also needs looking after. PIA's Linux scripts re-bind it every 15 minutes and have to stay running, or the port can time out; the app does this for you. PIA's developer notes say a port normally expires after 2 months, after which a new one has to be requested.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

When a static US IP fits the job better

  • A game server or SSH on a port number you pick, at a US address friends and scripts save once
  • A P2P client's listening port that you set once and leave alone
  • A router, NAS or Linux box that holds the address, not only a phone or PC running a VPN app
  • The same US address at every bank or work login, see a static US IP for logins
How it works

A dedicated IP is not the same as an inbound port

PIA does sell a dedicated IP, ~$2.50/mo (third-party reports): one static address no other PIA user shares, offered in about a dozen US locations and several other countries. It fixes the IP. It does not fix inbound. PIA's own connection script marks every US dedicated IP as having no port forwarding, and outside the US the port is still assigned rather than chosen. The help center also says the dedicated IP works in the PIA app, not in manual router configurations, allows one per subscription, and locks its location once you redeem the token.

GetAStatic is built the other way round: the address is the product. Every plan includes a static IPv4 in Kansas City & San Jose, USA that only you use. Ports start closed. You open TCP or UDP ports, or ranges, in the dashboard and choose each number yourself: 5 open ports on Plus, unlimited open ports on Pro. A port stays open until you close it, with nothing to re-bind.

The tunnel is a standard WireGuard config that connects out on UDP 1194 or 443, so it works behind CGNAT and runs on OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet routers, in Docker, or on a Linux server. PIA is built for privacy, with many users behind each server IP; GetAStatic is built for a stable address, not anonymity. Pay by card or crypto, with a 7-day money-back guarantee.

Setup

Move a service off a PIA forwarded port

This example moves a P2P client or a game server that today listens on the port PIA assigned.

  1. Write down the port your app listens on now. In qBittorrent it is under Tools, Options, Connection, "Port used for incoming connections".
  2. Choose a plan and sign up. Your static US IPv4 appears in the dashboard.
  3. Open the port you want on that IP, TCP, UDP or both. It can be the app's default port rather than the number PIA handed out.
  4. Download the WireGuard config and import it on the machine or router that runs the app. Turn PIA off on that machine first: two full-tunnel VPNs on one device can fight over the default route.
  5. Set the app's listening port to the one you opened, then test it from outside with the port check.
PortProtocolUsed for
6881TCP+UDPA BitTorrent client's listening port
27015TCP+UDPA Source-engine game server
22TCPSSH into a home server

Plus opens up to 5 ports; Pro and Ultra have no limit.

Good to know

Good to know

  • Two locations: Kansas City, Missouri and San Jose, California, USA. It is a datacenter IP, not a residential one. Users far from the IP's city see some extra delay.
  • Built for a stable address, not anonymity. Anyone who connects to an open port sees the same IP every time.
  • Speed is capped per plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Monthly data is capped too.
  • There is no UPnP or automatic port mapping. Only the ports you open in the dashboard accept connections.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. Extra IPs are $2/mo.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Why is port forwarding missing on PIA's US servers?

PIA's help center says port forwarding is not available on US server locations, and its connection scripts say it is disabled server-side in the United States. To get a forwarded port on PIA you connect to a server outside the US. GetAStatic IPs are in Kansas City & San Jose, USA, and every plan can open inbound ports. Checked 2026-10-06.

02Does a PIA dedicated IP support port forwarding?

Not in the US. PIA's own connection script reports no port forwarding for US dedicated IPs. Outside the US a dedicated IP can request a port, but PIA still assigns the number. A dedicated IP fixes the address, not which ports reach you.

03Can I choose the port number?

Yes. You pick the number and TCP or UDP when you open it in the dashboard, as single ports or ranges; a range counts as its size. Use the app's default, such as 25565 for Minecraft Java or 22 for SSH, so nothing has to be reconfigured. Plus opens up to 5; Pro and Ultra have no limit.

04Can the static IP run on my router instead of an app?

Yes. It is a standard WireGuard config, so it runs on OpenWrt, pfSense, OPNsense, MikroTik and GL.iNet routers as well as Windows, macOS, Linux, phones and Docker. See a game server behind CGNAT.

Have more questions? See the full FAQ →