- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
GetAStatic gives your home machine a fixed public IPv4 over WireGuard, even when your ISP blocks port forwarding or keeps changing your address. From work or the road, connect to YOUR-IP.
Updated
Remote Desktop, SSH and VNC all need the home machine to accept an incoming connection. Usually you forward a port on the router to the PC. But if your ISP uses carrier-grade NAT (CGNAT), your router never gets a public address, so there is nothing to forward from.
Even without CGNAT, a home IP that changes every few days breaks saved connections, and dynamic DNS is one more thing that can fail the day you are away.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a dedicated static IPv4 over WireGuard. The home machine, or your router, runs WireGuard and dials out to our node, which works through CGNAT. When you connect to YOUR-IP from outside, the connection comes down the tunnel to the machine.
The safest pattern opens one port only: your own WireGuard server, on the same machine that runs the GetAStatic tunnel. Your laptop connects to that, then uses Remote Desktop or VNC across it, so no login screen is ever on the internet.
Pick the ports for the tools you use, and open as few as you can.
| Port | Protocol | Used for |
|---|---|---|
| 51820 | UDP | Your own WireGuard server (recommended; reach RDP and VNC through it) |
| 22 | TCP | SSH (keys only) |
| 3389 | TCP | Windows Remote Desktop |
| 3389 | UDP | Remote Desktop, optional: smoother screen updates |
| 5900 | TCP | VNC |
An open RDP port is found and attacked with password guesses within hours. If you open 3389 anyway, use a long unique password, keep Network Level Authentication on, and sign in with a non-admin account. For SSH, turn off password login and use keys only.
Opening a port here is the same exposure as opening it on a router: anyone can reach it. What is safer is the pattern. Open only your own WireGuard server port and use RDP or VNC through it, so the login screen is never public.
Yes. It has to be running with WireGuard connected. Turn off sleep on it, because a sleeping machine cannot answer.
Yes. The home machine dials out to GetAStatic, so CGNAT on Starlink, 5G or LTE does not stop it. Nothing changes on the ISP side.
Yes. Run WireGuard on your router (OpenWrt, pfSense, OPNsense, MikroTik, GL.iNet) and point a port at each machine. Or give each machine its own IP: Pro includes 2, and extra IPs are $2/mo each.
Plus ($2/mo) is enough for two or three remote-access ports and light traffic. Choose Pro ($4/mo) if the same machine also hosts things that need more ports or data.
Have more questions? See the full FAQ →