A Synology QuickConnect alternative with your own IP

QuickConnect reaches your NAS directly, by hole punching or through Synology's relay, and only for Synology apps. GetAStatic gives the NAS a dedicated public IPv4 over WireGuard, from $2/mo, so any service answers at one fixed IP and port.

Not affiliated with Synology. QuickConnect facts from Synology's Knowledge Center, checked 2026-10-06.

Instant setup US-based IP

Updated

Compare

Synology QuickConnect vs GetAStatic

QuickConnect finds a way to your NAS for Synology's apps. A dedicated IP is an address for anything you run.

FeatureSynology QuickConnectGetAStatic
Dedicated public IPv4No (relay or hole punch)Yes, yours alone
What clients connect toA QuickConnect ID or quickconnect.to linkYour IP and port, or your own domain
Services reachableSynology apps onlyAny TCP or UDP port you open
Plex, Home Assistant, containersNot supported, per SynologyYes, on the ports you open

QuickConnect is included with DSM; GetAStatic starts at $2/mo. Synology's list of QuickConnect services excludes all third-party services and apps, SMB, the NAS's VPN Server and Web Station sites.

The problem

How QuickConnect reaches your NAS

A Synology app or browser that uses your QuickConnect ID first asks Synology's QuickConnect server where the NAS is. If the NAS answers on its LAN or WAN address, the client connects straight to it. If not, the server helps both sides punch a hole through their NAT, and Synology says that link performs close to a direct WAN connection.

When hole punching fails too, which is common behind CGNAT or a strict firewall, traffic goes through a Synology relay server. Synology's help page says relayed connections may be slow due to longer network latency, and recommends port forwarding for better performance. You do not pick the path. It depends on the network at both ends, so the same upload can be quick from the office and crawl from a phone hotspot. The CGNAT check shows whether your home line is the reason.

The other limit is scope. Synology publishes the list of packages that work over QuickConnect. All third-party services and apps are left out, and so are SMB, Hyper Backup to a remote Synology, the NAS's VPN Server and sites hosted in Web Station.

QuickConnect is fine when you only use Synology's own apps, such as Synology Photos, Drive and File Station, want nothing to configure, and would rather not manage exposed ports. It is included with DSM, and for casual access from a phone it often does the job.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Why use GetAStatic?

When GetAStatic fits better

  • Plex, Jellyfin, Vaultwarden or any container that QuickConnect does not carry
  • One fixed IP and port that clients, scripts and firewall allowlists can rely on
  • Your own domain on a plain A record, with your own certificate in DSM
  • The same path on every connection, with no relay fallback to land on
How it works

What a dedicated IP changes for a Synology

GetAStatic gives you a dedicated public IPv4 in Kansas City, Missouri or San Jose, California. A WireGuard tunnel connects out from your network to our node, so CGNAT and a missing port forward stop mattering. Connections to the ports you open on that IP come down the tunnel to the NAS. Every port starts closed.

Because it is an ordinary address, anything that expects a host and a port works: the Plex app on a TV, Hyper Backup at a friend's house sending to your Hyper Backup Vault, an rsync job, a reverse proxy in front of your containers. Point an A record for your own domain at the IP once; it does not change, so the record never needs updating.

The route is the same every time: client, our node, your tunnel, your NAS. It is not a direct link, and users far from the IP's city see some extra delay, but it does not switch between direct and relayed depending on where you connect from.

Setup

Where the tunnel runs on a Synology

DSM ships no WireGuard client; its VPN Server package offers PPTP, OpenVPN and L2TP/IPSec. So the tunnel runs on the router in front of the NAS, or in a container on the NAS.

  1. Sign up for GetAStatic and open only the ports you need on your IP, as TCP or UDP.
  2. Router option (the most dependable): import the WireGuard config on an OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet router, then forward each open port to the NAS's LAN address.
  3. Container option: on models with Container Manager, a WireGuard client container can run the tunnel on the NAS itself. DSM ships no WireGuard kernel module, so pick an image that runs WireGuard in userspace, or add the community kernel package, which Synology does not support. Expect more fiddling than the router option.
  4. Bring the tunnel up, then test each port from outside your home with the port check.
  5. In each app, replace the QuickConnect ID with your IP or domain. QuickConnect can stay enabled for the Synology apps that use it.
PortProtocolUsed for
5001TCPDSM over HTTPS; Hyper Backup Vault also uses it
6281TCPHyper Backup Vault, for backups sent from another Synology
443TCPA reverse proxy for container apps on your own domain

Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap.

Good to know

Good to know

  • A public IP does not make the NAS safer than QuickConnect. Every open port is reachable by anyone, so open as few as you can and never SMB, AFP or NFS. Turn on 2-factor login and HTTPS, and set the DSM firewall (Control Panel > Security > Firewall) and auto block (Control Panel > Security > Protection).
  • Whatever runs the tunnel sends all its traffic through the IP, and that counts toward monthly data: 100 GB on Plus, 1 TB on Pro. Speed caps apply up and down: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra.
  • Two locations: Kansas City, Missouri and San Jose, California, USA. It is a datacenter IP, built for a stable address, not anonymity.
  • No free trial; there is a 7-day money-back guarantee.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Is QuickConnect insecure?

No. Synology's white paper describes end-to-end encryption between the NAS and the client. A fixed IP is a different way in, not a safer one, and every port you open needs the same care.

02Does Plex work over QuickConnect?

No. Plex is a third-party package, and Synology lists all third-party services and apps as unsupported. With a fixed IP, open 32400 TCP for Plex; see Plex behind CGNAT.

03Do I still need Synology DDNS?

No. DDNS exists to follow an address that changes. Your IP stays the same, so one A record at any DNS provider is enough, or you can use the IP itself.

04What does it cost compared with QuickConnect?

QuickConnect is included with DSM. Plus costs $2/mo for one IP and 5 open ports; Pro costs $4/mo for 2 IPs and unlimited open ports.

Have more questions? See the full FAQ →