- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
We connect to your port from outside your network.
Updated
Looking up your public IPv4…
This check runs over IPv4; we cannot see your IPv6 address here. IP to ISP by DB-IP.
We open one TCP connection to the port you choose on your public IPv4, wait up to 3 seconds, and close it. We send no data. There are four possible results.
Open: something accepted the connection. Your forward probably works, but check that it is your app and not the router's own admin page, which some routers serve on 80, 443 or 8080.
Closed (refused): a device answered and said nothing is listening. Usually that is your router or host, so traffic reaches you: the forward points at the wrong LAN IP or port, or the app is not running, is bound to 127.0.0.1 instead of 0.0.0.0, or is blocked by the host firewall. Some ISP gateways answer the refusal themselves, so run the CGNAT check if the rule looks right. On Windows, a network set to "Public" blocks most incoming connections.
No response (timed out): the connection was dropped silently. Common causes are CGNAT or double NAT, a firewall, a forward that points at a device that is off, or an ISP port block. Xfinity's published list, for example, blocks 25, 135 to 139 and 445 in both directions and 1080 inbound, and many ISPs block 25 and 80 on residential plans.
Unreachable: a router on the path sent back 'unreachable', often because the forward points at a device that is off.
First find out whether you have a public address. If your router's WAN IP matches your public IP, you are not behind CGNAT. Then, if a high port such as 25565 tests open and port 80 does not, the ISP or the router's own admin page is holding 80. If the WAN IP is different, run the CGNAT check: no forward rule on your router can work behind CGNAT.
GetAStatic gives you a dedicated public IPv4 over WireGuard. The machine that runs your service (or your router) dials out to our node in Kansas City, Missouri or San Jose, California, so CGNAT cannot block it, and your ISP never sees the inbound connection, so its port blocks do not apply. You open the ports you need in the dashboard; every other port stays closed.
A static IP tunnel does not fix everything. If the app is not listening, or the host firewall blocks it, the result is the same with or without us. Work through steps 1 and 2 below first.
Most failed forwards come down to one of these six steps. Stop at the first one that fails.
| Port | Protocol | Used for |
|---|---|---|
| 25565 | TCP | Minecraft Java Edition |
| 32400 | TCP | Plex Media Server |
| 8123 | TCP | Home Assistant |
| 22 | TCP | SSH |
| 443 | TCP | HTTPS website or reverse proxy |
| 3389 | TCP | Windows Remote Desktop |
The tool above covers step 5. A static IPv4 tunnel from GetAStatic fixes steps 3 and 6, and makes step 4 unnecessary when WireGuard runs on the host itself. It does not fix steps 1 and 2: those are on your machine.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
Closed means a device answered. Usually that is your router or host, so traffic reaches your network: the forward points at the wrong LAN IP or port, or the app is not running, is bound to 127.0.0.1, or is blocked by the host firewall (on Windows, check the network is not set to Public). Some ISP gateways answer the refusal themselves, so run the CGNAT check if the rule looks right.
Start the server, enter 25565 in the checker above and run it. Open means outside players can reach it. No response usually means CGNAT, a firewall, or a forward to the wrong machine. Bedrock uses UDP 19132, which this tool cannot test.
Many residential ISPs block port 25, and many block inbound 80. Port 25 blocks are mostly outbound, which stops you sending mail. This tool tests inbound. Xfinity's published list blocks 25, 135 to 139 and 445 in both directions. If your WAN IP matches your public IP and a high port tests open but 80 does not, the ISP or your router's admin page is holding 80.
No. Under CGNAT the ISP shares your public address with other customers, so a forward on your router never sees outside traffic. You need a public IP from the ISP, or a tunnel that gives you one, such as a static IPv4 over WireGuard from GetAStatic.
No. A closed UDP port and a working one look the same from outside, because most UDP services do not answer a stranger. For WireGuard, check for a recent handshake instead: the peer shows one as soon as traffic gets through.
We use your IP address only to show it to you and to test the port you choose. We test only your own address, one port per request. We never store the port you test. We only count which kind of result came up, for example 'open' or 'no response', like any page view. Normal web-server logs apply.
Have more questions? See the full FAQ →