Put a static public IP on your router

Import one WireGuard config on your router and every device behind it, consoles and TVs included, uses your own dedicated IPv4. Open ports and forward them to any machine on your LAN.

Instant setup US-based IP

Updated

The problem

One device at a time does not scale

WireGuard on a laptop gives that laptop a fixed IP. Your console, smart TV, cameras and NAS stay on the ISP's changing address, and most cannot run a VPN app.

If your ISP uses CGNAT, port forwards on the router do nothing either, because the router never had a public address to forward from.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

Why people run GetAStatic on the router

  • One config covers every device, including ones that cannot run WireGuard
  • Inbound ports reach any LAN host through a normal port forward
  • The router dials out, so CGNAT, Starlink and 5G home internet are fine
  • A standard WireGuard file: no custom firmware or plugin from us
How it works

Run the tunnel on the router

Our config is plain WireGuard: AllowedIPs 0.0.0.0/0, PersistentKeepalive 25, and an endpoint on UDP port 1194, with a UDP 443 variant for networks that block it. The router gets a private tunnel address from our config and connects out to our node in Kansas City, Missouri or San Jose, California. Our node then sends your static IP's traffic down the tunnel to the router.

Set the router to send all traffic through the tunnel, and every device behind it uses the static IP. Some routers can route only certain devices through the tunnel; that is router-specific and we do not support or document it.

GL.iNet: in the admin panel, open VPN → WireGuard Client and add our .conf file. Then follow GL.iNet's guide to start the connection.

OpenWrt: under Network → Interfaces, add an interface with the WireGuard VPN protocol and import our .conf into it. Then follow the OpenWrt guide to send all traffic through the tunnel and set the firewall zone.

pfSense: start under VPN → WireGuard → Tunnels and enter the details from our config. Then follow your vendor's guide to add a gateway and an address-rewriting (NAT) rule for the LAN.

OPNsense: start under VPN → WireGuard, with our server as a peer and your side as an instance. Then follow your vendor's guide for the gateway, the address-rewriting (NAT) rule and the firewall rules.

MikroTik: add the tunnel and our peer from the WireGuard menu in WinBox or WebFig. Then follow MikroTik's guide to send all traffic through the tunnel and add an address-rewriting (NAT) rule for the LAN.

UniFi's Network app can import a WireGuard client config; we have not tested it.

Setup

Set it up

  1. Sign up for GetAStatic and note your static IP.
  2. In the dashboard, open the ports you need on that IP.
  3. Download the WireGuard config. If your router's network blocks UDP 1194, use the port 443 config (Devices tab, "Trouble connecting?").
  4. Import it on the router as described above and send all traffic through the tunnel.
  5. For each open port, add a port forward on the router from the WireGuard interface to the LAN host that runs the service.
  6. From a device behind the router, open a what-is-my-IP site. It should show your static IP.
PortProtocolUsed for
443TCPWeb server on the LAN
32400TCPPlex host
51820UDPYour own WireGuard server
Good to know

Limits to know

  • With all traffic sent through the tunnel, the whole LAN's traffic goes via Kansas City, Missouri or San Jose, California, and the plan's speed cap covers all of it: 100 Mbps on Pro, 1 Gbps on Ultra.
  • Monthly bandwidth counts everything that crosses the tunnel, upload and download, from every device.
  • One config is one tunnel. Two routers need two IPs: Pro includes 2, or add one for $2/mo.
  • It is a datacenter IP, not a residential one.
  • We cannot support every router model. For your router's menus, follow its vendor's documentation.
FAQ

Questions, answered.

01Which plan suits a whole home?

Pro or Ultra. Every device shares one speed cap, so you want headroom: 100 Mbps on Pro with 1 TB, 1 Gbps on Ultra with 5 TB.

02Can I leave some devices out?

Our setup sends the whole LAN through the tunnel. Some routers can route only certain devices through the tunnel; that is router-specific and we do not support or document it.

03Do game consoles and smart TVs work?

Yes. They need no app; behind the router they use the static IP like every other device.

04Do I need to change anything with my ISP?

No. The router makes an ordinary outgoing connection. Your ISP plan, modem and contract stay as they are.

05Does my router need a public IP?

No. It dials out to us, so CGNAT is fine. The public IP lives on our side and comes down the tunnel.

Have more questions? See the full FAQ →