Port forwarding not working? Find the cause in six steps

Check your router's WAN IP. If it is between 100.64.0.0 and 100.127.255.255, your ISP uses CGNAT and no router setting will open the port. GetAStatic is a WireGuard VPN with your own static public IPv4 and the ports you choose open, from $2/mo.

Instant setup US-based IP

Updated

Facts

What your router's WAN IP tells you

Same as what-is-my-IPPublic IP. Port forwarding can work; check the rule and firewall.
100.64.x.x to 100.127.x.x (100.64.0.0/10)CGNAT (RFC 6598). Only your ISP or a tunneled IP can fix it.
10.x, 172.16.x to 172.31.x, 192.168.xDouble NAT, or CGNAT on some mobile ISPs. Try bridge mode first.
169.254.x.x or blankThe router has no connection from the ISP. Restart the modem.
The problem

Why an open port can still show closed

You add a port forward, a port checker still says closed, and nobody outside can connect. Often the rule is fine. The block is somewhere else: on the computer, in front of your router, or at your ISP.

A common cause today is CGNAT. Your ISP gives your router an address from the shared range 100.64.0.0/10 and turns it into a public IP that many homes share. A connection from outside stops at the ISP's NAT, which has no rule for your home, so your router never sees it.

The second is double NAT. The ISP's gateway or a second router sits in front of yours and gives it a private address. Here you can often fix it yourself, with bridge mode or a forward on both boxes.

Check

Am I behind CGNAT? Find the cause

Work down the list in order.

  1. Is the service listening? Connect to it on the host at 127.0.0.1 and the port, or list listening ports with "netstat -an" on Windows or "ss -ltnu" on Linux.
  2. Check the router rule and the firewall: the forward must point to the host's current local IP with the right port and protocol, the host firewall must allow it, and you must test from outside, such as a phone on mobile data or the free port check.
  3. Check for double NAT: if your router's WAN IP starts with 10., 172.16 to 172.31, or 192.168., another box sits in front of it, so use bridge mode on that box or forward the port on both.
  4. Check for CGNAT: if "what is my IP" differs from the router's WAN IP and the WAN IP is in 100.64.0.0/10 (100.64.0.0 to 100.127.255.255), your ISP uses CGNAT. The free CGNAT check does this for you.
  5. Check for ISP port blocks: some ISPs block inbound 25 and sometimes 80, so try a high port such as 8443 or 25000.
  6. If it is CGNAT, no router setting will help: get a fixed IPv4 over WireGuard from GetAStatic and open the port there, or ask your ISP for a public IP.

Behind CGNAT, the fix is a public address your ISP does not control. Plans and prices are below.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

What GetAStatic gives you when the port will not open

  • A dedicated public IPv4 that is yours alone, on any ISP, with CGNAT or double NAT
  • TCP and UDP ports you open in the dashboard: 5 open ports on Plus, unlimited open ports on Pro
  • No router port forward, no bridge mode, no business plan
  • Your visitors connect to the IP directly, with nothing to install
How it works

What to do next

The fix that works on any ISP is a public IPv4 that does not depend on your ISP. GetAStatic gives you a dedicated static IP in Kansas City, Missouri or San Jose, California. Your device dials out over WireGuard, which CGNAT allows, and connections to the ports you open come back down the tunnel. Your ISP and router settings stay as they are.

Or ask your ISP. Some move you off CGNAT on request, some sell a static IP add-on, and many 5G and satellite plans offer neither or only with a business plan. Starlink and T-Mobile Home Internet have their own guides.

We fix reachability, not your ISP: your line still has CGNAT, and services you host answer on your new IP instead. For every other option, see all the ways around CGNAT.

Setup

Get a reachable IP in five minutes

Run WireGuard on the machine that hosts the service, or on your router.

  1. Choose a plan and sign up. Your static IP shows in the dashboard.
  2. Open the port your service uses, TCP or UDP. Every new IP starts with all ports closed.
  3. Download the WireGuard config and import it into the WireGuard app on the host. Turn the tunnel on.
  4. Test from outside your network with your new IP and the port. A port checker should now show it open.

You can remove the old port forward on your router. The tunnel does not need it.

Good to know

Good to know

  • We do not change your ISP connection. Your line keeps CGNAT; only traffic for your new IP goes around it.
  • If the check shows double NAT, not CGNAT, you may not need us: bridge mode on the ISP gateway can give your router the public IP.
  • Speed is capped per IP by plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra.
  • All traffic for the IP passes through Kansas City, Missouri or San Jose, California. Users far from the IP's city see some extra delay.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01What does a 100.64 IP address on my router mean?

It means CGNAT. 100.64.0.0/10 (100.64.0.0 to 100.127.255.255) is the shared address space for carrier-grade NAT, set aside in RFC 6598. It is not a fault, and it is not your public IP. Port forwarding on your router cannot work while you have it.

02What is the difference between double NAT and CGNAT?

Both put two layers of NAT between you and the internet. With double NAT, the outer layer is a box in your home, such as the ISP's gateway, and your WAN IP is private (10., 172.16 to 172.31, or 192.168.). Bridge mode usually fixes it. With CGNAT, the outer layer is inside the ISP's network and only the ISP can remove it. Some mobile ISPs use 10. addresses for CGNAT too, so if bridge mode changes nothing, treat it as CGNAT.

03IPv6 works but IPv4 does not. Why?

Many CGNAT ISPs give each home real IPv6 addresses but share IPv4. So an IPv6 test passes, and inbound IPv6 may even work, while IPv4 connections from outside fail. Visitors on IPv4, and many games and apps, still cannot reach you. A public IPv4 fixes that side.

04Will a normal VPN fix port forwarding?

Usually not. Most VPNs share their IPs and do not pass inbound connections to you. A VPN with your own dedicated IP and open ports does. That is what GetAStatic is: a WireGuard VPN and a static IPv4 in one plan.

05Does dynamic DNS help behind CGNAT?

No. Dynamic DNS keeps a name pointed at your current IP, but behind CGNAT that IP is shared, so connections to it still stop at your ISP. Why dynamic DNS fails behind CGNAT.

Have more questions? See the full FAQ →