- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Import one WireGuard config on your router and every device behind it, consoles and TVs included, uses your own dedicated IPv4. Open ports and forward them to any machine on your LAN.
Updated
WireGuard on a laptop gives that laptop a fixed IP. Your console, smart TV, cameras and NAS stay on the ISP's changing address, and most cannot run a VPN app.
If your ISP uses CGNAT, port forwards on the router do nothing either, because the router never had a public address to forward from.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
Our config is plain WireGuard: AllowedIPs 0.0.0.0/0, PersistentKeepalive 25, and an endpoint on UDP port 1194, with a UDP 443 variant for networks that block it. The router gets a private tunnel address from our config and connects out to our node in Kansas City, Missouri or San Jose, California. Our node then sends your static IP's traffic down the tunnel to the router.
Set the router to send all traffic through the tunnel, and every device behind it uses the static IP. Some routers can route only certain devices through the tunnel; that is router-specific and we do not support or document it.
GL.iNet: in the admin panel, open VPN → WireGuard Client and add our .conf file. Then follow GL.iNet's guide to start the connection.
OpenWrt: under Network → Interfaces, add an interface with the WireGuard VPN protocol and import our .conf into it. Then follow the OpenWrt guide to send all traffic through the tunnel and set the firewall zone.
pfSense: start under VPN → WireGuard → Tunnels and enter the details from our config. Then follow your vendor's guide to add a gateway and an address-rewriting (NAT) rule for the LAN.
OPNsense: start under VPN → WireGuard, with our server as a peer and your side as an instance. Then follow your vendor's guide for the gateway, the address-rewriting (NAT) rule and the firewall rules.
MikroTik: add the tunnel and our peer from the WireGuard menu in WinBox or WebFig. Then follow MikroTik's guide to send all traffic through the tunnel and add an address-rewriting (NAT) rule for the LAN.
UniFi's Network app can import a WireGuard client config; we have not tested it.
| Port | Protocol | Used for |
|---|---|---|
| 443 | TCP | Web server on the LAN |
| 32400 | TCP | Plex host |
| 51820 | UDP | Your own WireGuard server |
Pro or Ultra. Every device shares one speed cap, so you want headroom: 100 Mbps on Pro with 1 TB, 1 Gbps on Ultra with 5 TB.
Our setup sends the whole LAN through the tunnel. Some routers can route only certain devices through the tunnel; that is router-specific and we do not support or document it.
Yes. They need no app; behind the router they use the static IP like every other device.
No. The router makes an ordinary outgoing connection. Your ISP plan, modem and contract stay as they are.
No. It dials out to us, so CGNAT is fine. The public IP lives on our side and comes down the tunnel.
Have more questions? See the full FAQ →