- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Give one remote worker a stable public source IP. GetAStatic is a WireGuard VPN with a dedicated IPv4, from $2/mo per worker. Add that one /32 to AWS, SSH, vendor or firewall allowlists, and it stays the same from home, hotels and mobile data.
Not affiliated with NordLayer, GoodAccess or PureVPN. Prices as listed on their sites, checked 2026-10-06.
Updated
A business VPN or the office firewall can give a whole team one exit IP. A consumer VPN can sell one person a dedicated IP. This is what each looks like for a single worker or contractor.
| Feature | Corporate VPN / office exit | Consumer dedicated-IP VPN | GetAStatic |
|---|---|---|---|
| Price per worker | $7/user + $49/mo IP | $4.45/mo (2-year plan) | $2/mo, VPN and IP included |
| Minimum seats | 5 users (NordLayer, GoodAccess) | 1 | 1 |
| Setup for one person | Admin console, user invite, gateway, then the vendor app | Personal account and the vendor app | One WireGuard config file or QR code |
| Works from hotel and mobile networks | Yes, through the vendor app | Yes, through the vendor app | Yes, plus a port 443 config and AmneziaWG for networks that block WireGuard |
| Where the IP lives | On the team gateway or office firewall, shared by every user | On the vendor's VPN server | On our node in Kansas City, Missouri and San Jose, California, one IP per worker |
Business VPN column: GoodAccess, which bills seats annually; its 5-user minimum and gateway fee apply even when only one worker needs the IP. NordLayer sells its dedicated IP server on the Core and Premium plans. Consumer column: PureVPN dedicated IP, on its 2-year plan.
A remote employee's public IP comes from whatever network they are on. Home broadband can hand out a new address after a router restart or ISP maintenance. A hotel, a coworking space and a phone hotspot each give a different one, and mobile carriers often put many customers behind one shared address, so the IP a worker had this morning may belong to strangers this afternoon.
On the other end, an AWS security group, an SSH bastion, a database firewall, a vendor's support portal or a SaaS admin console lets in only the addresses on its list. Each change becomes a ticket: the worker is locked out, someone with admin rights edits the rule, and the old address often stays because nobody is sure it is safe to delete. A list that grows this way ends up trusting addresses no one in the company uses anymore.
Dynamic DNS does not fix this. It keeps a hostname pointed at the worker's current IP, but the systems doing the checking usually take an IP or a CIDR block, not a name. An AWS security group rule, for example, accepts a single address written as /32, a CIDR range, a prefix list or another security group; there is no hostname field. Some firewalls can turn a hostname into an address object, but they re-resolve it on a timer, so access breaks for a while after each change, and a vendor's own console often has no such option.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives each worker a dedicated public IPv4 on our node in Kansas City, Missouri or San Jose, California. The work laptop runs WireGuard with the config you download from the dashboard. It dials out to the node, and from then on its internet traffic leaves from that IP. AWS, the vendor and the firewall all see the same source address, at home, in a hotel or on a hotspot.
This is outbound only. An allowlist checks where traffic comes from, so you open no ports for it: every inbound port on the IP starts closed and can stay closed. Nothing on the laptop becomes reachable from the internet.
The company can hold the account, pay for it and hand the worker a config file. The IP, the keys and the allowlist entries then stay under the company's control, which keeps offboarding short.
The example IP is from the 203.0.113.0/24 documentation range; use the one in your dashboard. The diagram under the steps shows the path the traffic takes.
remote worker (laptop, any network)
│ WireGuard tunnel, out on UDP 1194 or 443
▼
GetAStatic node, dedicated IPv4 203.0.113.10
│ source IP = 203.0.113.10
▼
AWS security group / SSH / vendor portal
allowlist: 203.0.113.10/32One config runs on one device at a time, so people in different places cannot share it. A separate IP per worker also makes logs readable: an SSH or AWS CloudTrail entry from that address points to one person, and taking away that person's access is one rule.
Yes. The contractor gets one WireGuard config and nothing else: no account on your network and no route into your office. Your systems see their traffic only where you add the IP to an allowlist. When the contract ends, regenerate the keys or remove the entries.
Usually the company. The account holder controls the IP, the configs and the billing, so access does not leave with the worker. A worker who pays for their own IP can still give you the address, but then you cannot revoke their config.
The address with /32, for example 203.0.113.10/32, and a line saying it is a static egress IP for one named user. A form that only takes ranges accepts /32 as a range of one address. Ask the vendor to remove any older addresses they hold for that person.
Have more questions? See the full FAQ →