A static IP for remote workers

Give one remote worker a stable public source IP. GetAStatic is a WireGuard VPN with a dedicated IPv4, from $2/mo per worker. Add that one /32 to AWS, SSH, vendor or firewall allowlists, and it stays the same from home, hotels and mobile data.

Not affiliated with NordLayer, GoodAccess or PureVPN. Prices as listed on their sites, checked 2026-10-06.

Instant setup US-based IP

Updated

Compare

One remote worker, three ways to get a fixed IP

A business VPN or the office firewall can give a whole team one exit IP. A consumer VPN can sell one person a dedicated IP. This is what each looks like for a single worker or contractor.

FeatureCorporate VPN / office exitConsumer dedicated-IP VPNGetAStatic
Price per worker$7/user + $49/mo IP$4.45/mo (2-year plan)$2/mo, VPN and IP included
Minimum seats5 users (NordLayer, GoodAccess)11
Setup for one personAdmin console, user invite, gateway, then the vendor appPersonal account and the vendor appOne WireGuard config file or QR code
Works from hotel and mobile networksYes, through the vendor appYes, through the vendor appYes, plus a port 443 config and AmneziaWG for networks that block WireGuard
Where the IP livesOn the team gateway or office firewall, shared by every userOn the vendor's VPN serverOn our node in Kansas City, Missouri and San Jose, California, one IP per worker

Business VPN column: GoodAccess, which bills seats annually; its 5-user minimum and gateway fee apply even when only one worker needs the IP. NordLayer sells its dedicated IP server on the Core and Premium plans. Consumer column: PureVPN dedicated IP, on its 2-year plan.

The problem

The worker moves, the allowlist breaks

A remote employee's public IP comes from whatever network they are on. Home broadband can hand out a new address after a router restart or ISP maintenance. A hotel, a coworking space and a phone hotspot each give a different one, and mobile carriers often put many customers behind one shared address, so the IP a worker had this morning may belong to strangers this afternoon.

On the other end, an AWS security group, an SSH bastion, a database firewall, a vendor's support portal or a SaaS admin console lets in only the addresses on its list. Each change becomes a ticket: the worker is locked out, someone with admin rights edits the rule, and the old address often stays because nobody is sure it is safe to delete. A list that grows this way ends up trusting addresses no one in the company uses anymore.

Dynamic DNS does not fix this. It keeps a hostname pointed at the worker's current IP, but the systems doing the checking usually take an IP or a CIDR block, not a name. An AWS security group rule, for example, accepts a single address written as /32, a CIDR range, a prefix list or another security group; there is no hostname field. Some firewalls can turn a hostname into an address object, but they re-resolve it on a timer, so access breaks for a while after each change, and a vendor's own console often has no such option.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

What companies use it for

  • AWS security groups, SSH bastions and database firewalls that admit one /32 per admin
  • Vendor portals, firewall ACLs and SaaS admin consoles with a trusted-IP list
  • Contractors who need one approved IP without joining the corporate VPN
  • Traveling employees whose network changes every day, from hotel Wi-Fi to a local SIM
How it works

Give each worker their own exit IP

GetAStatic gives each worker a dedicated public IPv4 on our node in Kansas City, Missouri or San Jose, California. The work laptop runs WireGuard with the config you download from the dashboard. It dials out to the node, and from then on its internet traffic leaves from that IP. AWS, the vendor and the firewall all see the same source address, at home, in a hotel or on a hotspot.

This is outbound only. An allowlist checks where traffic comes from, so you open no ports for it: every inbound port on the IP starts closed and can stay closed. Nothing on the laptop becomes reachable from the internet.

The company can hold the account, pay for it and hand the worker a config file. The IP, the keys and the allowlist entries then stay under the company's control, which keeps offboarding short.

Setup

Set up one worker, then the allowlists

The example IP is from the 203.0.113.0/24 documentation range; use the one in your dashboard. The diagram under the steps shows the path the traffic takes.

  1. Sign up with a company email and choose a plan. Each IP in the dashboard is one worker; note who has which IP in your own records.
  2. Download that IP's WireGuard config, or show its QR code, and send it to the worker over a channel you would trust with a password. The config holds the private key.
  3. The worker installs WireGuard on the work laptop, imports the config and turns the tunnel on. A what-is-my-IP site should now show 203.0.113.10.
  4. AWS: add an inbound rule to the security group with the source 203.0.113.10/32 and a description such as "J. Rivera laptop, added 2026-10-07". SSH: a line like AllowUsers jrivera@203.0.113.10 in sshd_config, or a host firewall rule for that address.
  5. Firewalls, vendor portals and SaaS admin consoles: add 203.0.113.10/32 as a host object or in the trusted-IP setting. Then delete the worker's old home-IP entries and any wide range added as a stopgap.
  6. When the worker leaves: on the Devices tab, open the IP's details and click Regenerate next to New keys. The old config stops working and the IP stays the same, so the next hire can take it over with a fresh config.
  7. If you cancel the IP instead, remove 203.0.113.10/32 from every list first. After the paid period it goes back to our pool and can go to another customer.
remote worker (laptop, any network)
    │  WireGuard tunnel, out on UDP 1194 or 443
    ▼
GetAStatic node, dedicated IPv4 203.0.113.10
    │  source IP = 203.0.113.10
    ▼
AWS security group / SSH / vendor portal
allowlist: 203.0.113.10/32
Good to know

Good to know

  • It is a simple tool, not an enterprise zero-trust product. There is no SSO, device posture check or per-app policy; one account manages its IPs and their configs.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. For several workers, Pro includes 2 IPs, and each extra IP is $2/mo.
  • By default the laptop sends all of its internet traffic through the tunnel, so anything else done on that laptop also leaves from the company's IP.
  • It is a datacenter IP in Kansas City, Missouri or San Jose, California. Workers far from the IP's city see extra delay on every connection, and a few consumer fraud systems treat datacenter IPs more strictly than home ones.
FAQ

Questions, answered.

01Why not one shared IP for all remote staff?

One config runs on one device at a time, so people in different places cannot share it. A separate IP per worker also makes logs readable: an SSH or AWS CloudTrail entry from that address points to one person, and taking away that person's access is one rule.

02Can a contractor use it without joining our corporate VPN?

Yes. The contractor gets one WireGuard config and nothing else: no account on your network and no route into your office. Your systems see their traffic only where you add the IP to an allowlist. When the contract ends, regenerate the keys or remove the entries.

03Who should own the account, the company or the worker?

Usually the company. The account holder controls the IP, the configs and the billing, so access does not leave with the worker. A worker who pays for their own IP can still give you the address, but then you cannot revoke their config.

04What do we send a vendor who asks for our IP?

The address with /32, for example 203.0.113.10/32, and a line saying it is a static egress IP for one named user. A form that only takes ranges accepts /32 as a range of one address. Ask the vendor to remove any older addresses they hold for that person.

Have more questions? See the full FAQ →