A Proton VPN port forwarding alternative for a fixed IP and port

Proton VPN forwards one assigned port on shared P2P servers, and that port usually changes when you reconnect. GetAStatic gives you a dedicated US IPv4 and ports you choose, from $2/mo, so people and firewalls reach the same IP:port every time.

Not affiliated with Proton AG or Proton VPN. Facts as listed on protonvpn.com, checked 2026-10-06.

Instant setup US-based IP

Updated

Compare

Proton VPN port forwarding vs GetAStatic

Two different jobs: a forwarded port on a privacy VPN, and a fixed address for a server.

FeatureProton VPN port forwardingGetAStatic
PriceAll paid plansFrom $2/mo
PurposePrivacy VPN; forwarding helps P2P and gamingA fixed IPv4 for servers and allowlists
Your own IPNo (shared P2P servers)Yes, one IPv4 that only you use
Port behaviorAssigned by the server; usually changes on reconnectChosen by you; fixed until you close it
Ports you can openOne per connection5 on Plus, unlimited on Pro
Fixed IP:port endpointNoYes

Proton includes port forwarding on all paid plans, on P2P servers, in its Windows, macOS and Linux apps and in manual setups. Facts from Proton's support pages, checked 2026-10-06.

The problem

When Proton's port forwarding is the right tool

Proton VPN is a privacy VPN first. Port forwarding is an extra on its paid plans: connect to a P2P server, turn the feature on, and the server picks a random port and opens it for incoming traffic. The Windows app shows that port in its sidebar. Proton lists it for Windows, macOS and Linux, and for manual OpenVPN or WireGuard setups that request the port over NAT-PMP.

This works well for apps that can adapt to whatever port they are given. A BitTorrent client tells trackers and peers its current port, so a new number after a reconnect costs nothing. Proton's own guide uses a torrent client as its example for that reason.

It stops fitting when someone else stores the address. Proton's support page says the port number usually changes when you reconnect, and the exit IP belongs to a shared P2P server, so it changes when you pick another server. On manual setups, Proton's NAT-PMP guide says the mapping lasts 60 seconds unless a loop script keeps renewing it. A friend's saved game server, an SSH shortcut or a partner's firewall rule then points at an old IP:port.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

When a fixed IP:port matters

  • Self-hosted services such as a web app, Nextcloud or a home lab dashboard that people bookmark
  • Game server administration: RCON, a server list entry, friends who saved the address once
  • A partner, webhook sender or monitoring service that must always connect to the same IP:port
  • Firewall allowlists, and software where changing the listening port means a restart or a config edit
How it works

When GetAStatic is the better choice

GetAStatic starts from the address, not from privacy. You get one IPv4 that only your account uses, and you decide which TCP or UDP ports are open on it in the dashboard. A port you open has the same number on the IP and on your device: open 27015 and your server listens on 27015. Nothing renews it from the client side, and it stays open until you close it or cancel.

That makes it the better fit when the other side cannot follow a moving port: a server people connect to by IP:port, a firewall that only admits one source address, or software where changing the listening port means a restart or a config edit. The tunnel connects out from your side, so this works behind CGNAT too; see a game server behind CGNAT and self-hosting on a static IP.

It is a WireGuard VPN as well: while the tunnel is on, the device's outbound traffic leaves from the same IP, which is what an allowlist sees. Plus costs $2/mo with 5 open ports; Pro costs $4/mo with 2 IPs and unlimited open ports. Pay by card or crypto, with a 7-day money-back guarantee.

Setup

Move a service from a Proton port to a fixed one

Your laptop can keep its privacy VPN. The tunnel goes on the machine or router that hosts the service.

  1. Write down the port your service listens on now, and any script that copies Proton's assigned port into the app's settings.
  2. Choose a plan and sign up. Open the service's port on your IP in the dashboard, and choose TCP, UDP or both.
  3. On the host, turn off Proton VPN: two full-tunnel VPNs on one machine can fight over the default route. Import the WireGuard config and turn the tunnel on.
  4. Set the app to listen on the port you opened, and remove the port-update script. It has nothing left to update.
  5. Test from outside with the port check while the app is running, then give out YOUR-IP:port or add YOUR-IP to the allowlist.
PortProtocolUsed for
27015TCP+UDPA Source engine dedicated server (game traffic and RCON)
2456-2457UDPA Valheim dedicated server (a range counts as its size)
8443TCPA self-hosted web app or admin panel

Plus opens up to 5 ports per IP; Pro and Ultra have no limit.

Good to know

Good to know

  • Built for a stable address, not anonymity. Every visitor to an open port sees the same IP, by design.
  • Ports start closed, and there is no UPnP or NAT-PMP. An app that asks the network for a port gets nothing; you open each port yourself in the dashboard.
  • Two locations: Kansas City, Missouri and San Jose, California, USA. It is a datacenter IP, not a residential one.
  • Speed is capped per plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Monthly data is capped too.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. Extra IPs are $2/mo.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Do I have to stop using my privacy VPN?

No. GetAStatic only needs to run on the machine or router that hosts the service. Your laptop and phone can keep whatever VPN they use now; keep two full tunnels off the same machine, because they can conflict.

02My torrent client works fine with a changing port. Why would a fixed port matter?

For torrents it often does not: the client announces its current port to trackers and peers. A fixed port matters when a person or a system saves your address, such as a game server list, an SSH config or a partner's firewall rule.

03Does a port I open stay open on its own?

Yes. Ports are opened on our side from the dashboard, so no client has to renew a lease. Inbound connections reach you whenever your tunnel is up, and the port stays open until you close it.

04Can a firewall allowlist my address?

Yes. The IPv4 is yours alone and does not rotate, and outbound traffic from the tunnel uses it too, so one allowlist entry covers you. See a static IP for IP whitelisting.

05The port check says closed. What is wrong?

Usually nothing is listening yet. A port shows open only while an app accepts connections on it. Start the app, confirm the tunnel is on and the port is open in the dashboard for the right protocol, then test again. See port forwarding not working.

Have more questions? See the full FAQ →