Reach your home computer behind CGNAT: RDP, SSH and VNC

GetAStatic gives your home machine a fixed public IPv4 over WireGuard, even when your ISP blocks port forwarding or keeps changing your address. From work or the road, connect to YOUR-IP.

Instant setup US-based IP

Updated

The problem

Why you can't reach your home computer

Remote Desktop, SSH and VNC all need the home machine to accept an incoming connection. Usually you forward a port on the router to the PC. But if your ISP uses carrier-grade NAT (CGNAT), your router never gets a public address, so there is nothing to forward from.

Even without CGNAT, a home IP that changes every few days breaks saved connections, and dynamic DNS is one more thing that can fail the day you are away.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why use a static IP for remote access

  • One address that never changes: save it once in your RDP or SSH client
  • Works when home internet is behind CGNAT, Starlink or 5G
  • Every port starts closed; open only SSH, or only your own WireGuard port
  • Plus at $2/mo covers a few remote-access ports and light traffic
How it works

A fixed IPv4 that leads to your home machine

GetAStatic gives you a dedicated static IPv4 over WireGuard. The home machine, or your router, runs WireGuard and dials out to our node, which works through CGNAT. When you connect to YOUR-IP from outside, the connection comes down the tunnel to the machine.

The safest pattern opens one port only: your own WireGuard server, on the same machine that runs the GetAStatic tunnel. Your laptop connects to that, then uses Remote Desktop or VNC across it, so no login screen is ever on the internet.

Setup

Setup example: SSH or Remote Desktop to a home machine

Pick the ports for the tools you use, and open as few as you can.

  1. Sign up for GetAStatic and note your IP address in the dashboard.
  2. Turn on the remote-access service on the home machine: Remote Desktop in Windows settings (Pro edition), the SSH server on Linux or Mac, or your VNC server.
  3. In the dashboard, open its port on your IP: for example 22 TCP for SSH, or 51820 UDP for your own WireGuard server.
  4. Download the config, import it into WireGuard on the home machine, and set the tunnel to start automatically so it returns after a restart.
  5. From outside, connect to YOUR-IP: ssh you@YOUR-IP for SSH, or YOUR-IP in the Remote Desktop app.
PortProtocolUsed for
51820UDPYour own WireGuard server (recommended; reach RDP and VNC through it)
22TCPSSH (keys only)
3389TCPWindows Remote Desktop
3389UDPRemote Desktop, optional: smoother screen updates
5900TCPVNC

An open RDP port is found and attacked with password guesses within hours. If you open 3389 anyway, use a long unique password, keep Network Level Authentication on, and sign in with a non-admin account. For SSH, turn off password login and use keys only.

Good to know

Limits and requirements

  • The whole home machine uses the IP. All of its internet traffic exits from Kansas City, Missouri or San Jose, California. That is fine for a server; on a PC you also use every day, websites see a US datacenter address and distant sites may feel slower.
  • Speed is capped at 20 Mbps on Plus and 100 Mbps on Pro, in both directions. SSH and desktop sessions need little.
  • Windows Home cannot host Remote Desktop. You need Windows Pro, or a VNC server or another remote-access tool.
  • The machine must be on and connected. We cannot wake a sleeping or powered-off computer.
  • The address is a datacenter IP (Fork Networking), not a residential one.
FAQ

Questions, answered.

01Is this safer than port forwarding?

Opening a port here is the same exposure as opening it on a router: anyone can reach it. What is safer is the pattern. Open only your own WireGuard server port and use RDP or VNC through it, so the login screen is never public.

02Do I need to leave the computer on?

Yes. It has to be running with WireGuard connected. Turn off sleep on it, because a sleeping machine cannot answer.

03Does it work if my home internet is Starlink or 5G?

Yes. The home machine dials out to GetAStatic, so CGNAT on Starlink, 5G or LTE does not stop it. Nothing changes on the ISP side.

04Can I reach more than one machine at home?

Yes. Run WireGuard on your router (OpenWrt, pfSense, OPNsense, MikroTik, GL.iNet) and point a port at each machine. Or give each machine its own IP: Pro includes 2, and extra IPs are $2/mo each.

05Which plan do I need?

Plus ($2/mo) is enough for two or three remote-access ports and light traffic. Choose Pro ($4/mo) if the same machine also hosts things that need more ports or data.

Have more questions? See the full FAQ →