- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Check your router's WAN IP. If it is between 100.64.0.0 and 100.127.255.255, your ISP uses CGNAT and no router setting will open the port. GetAStatic is a WireGuard VPN with your own static public IPv4 and the ports you choose open, from $2/mo.
Updated
| Same as what-is-my-IP | Public IP. Port forwarding can work; check the rule and firewall. |
|---|---|
| 100.64.x.x to 100.127.x.x (100.64.0.0/10) | CGNAT (RFC 6598). Only your ISP or a tunneled IP can fix it. |
| 10.x, 172.16.x to 172.31.x, 192.168.x | Double NAT, or CGNAT on some mobile ISPs. Try bridge mode first. |
| 169.254.x.x or blank | The router has no connection from the ISP. Restart the modem. |
You add a port forward, a port checker still says closed, and nobody outside can connect. Often the rule is fine. The block is somewhere else: on the computer, in front of your router, or at your ISP.
A common cause today is CGNAT. Your ISP gives your router an address from the shared range 100.64.0.0/10 and turns it into a public IP that many homes share. A connection from outside stops at the ISP's NAT, which has no rule for your home, so your router never sees it.
The second is double NAT. The ISP's gateway or a second router sits in front of yours and gives it a private address. Here you can often fix it yourself, with bridge mode or a forward on both boxes.
Work down the list in order.
Behind CGNAT, the fix is a public address your ISP does not control. Plans and prices are below.
Your own static IP over WireGuard. No VPS.
Dedicated IPv4 from $2/mo →The fix that works on any ISP is a public IPv4 that does not depend on your ISP. GetAStatic gives you a dedicated static IP in Kansas City, Missouri or San Jose, California. Your device dials out over WireGuard, which CGNAT allows, and connections to the ports you open come back down the tunnel. Your ISP and router settings stay as they are.
Or ask your ISP. Some move you off CGNAT on request, some sell a static IP add-on, and many 5G and satellite plans offer neither or only with a business plan. Starlink and T-Mobile Home Internet have their own guides.
We fix reachability, not your ISP: your line still has CGNAT, and services you host answer on your new IP instead. For every other option, see all the ways around CGNAT.
Run WireGuard on the machine that hosts the service, or on your router.
You can remove the old port forward on your router. The tunnel does not need it.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
It means CGNAT. 100.64.0.0/10 (100.64.0.0 to 100.127.255.255) is the shared address space for carrier-grade NAT, set aside in RFC 6598. It is not a fault, and it is not your public IP. Port forwarding on your router cannot work while you have it.
Both put two layers of NAT between you and the internet. With double NAT, the outer layer is a box in your home, such as the ISP's gateway, and your WAN IP is private (10., 172.16 to 172.31, or 192.168.). Bridge mode usually fixes it. With CGNAT, the outer layer is inside the ISP's network and only the ISP can remove it. Some mobile ISPs use 10. addresses for CGNAT too, so if bridge mode changes nothing, treat it as CGNAT.
Many CGNAT ISPs give each home real IPv6 addresses but share IPv4. So an IPv6 test passes, and inbound IPv6 may even work, while IPv4 connections from outside fail. Visitors on IPv4, and many games and apps, still cannot reach you. A public IPv4 fixes that side.
Usually not. Most VPNs share their IPs and do not pass inbound connections to you. A VPN with your own dedicated IP and open ports does. That is what GetAStatic is: a WireGuard VPN and a static IPv4 in one plan.
No. Dynamic DNS keeps a name pointed at your current IP, but behind CGNAT that IP is shared, so connections to it still stop at your ISP. Why dynamic DNS fails behind CGNAT.
Have more questions? See the full FAQ →