Port forwarding on T-Mobile Home Internet

T-Mobile Home Internet cannot forward ports: homes share a public IPv4 through CGNAT, and static IPs come only with Business plans. GetAStatic gives you your own static IPv4 over WireGuard, with the ports you choose open. The gateway stays as it is.

Not affiliated with T-Mobile. Prices as listed on their sites, checked 2026-10-06.

Instant setup US-based IP

Updated

Facts

T-Mobile Home Internet at a glance

Port forwarding on Home InternetNone
Public IPv4Shared through CGNAT (464XLAT)
Static IPBusiness plans only, as an add-on: ~$15/mo (third-party reports)
IPv6Yes
GetAStaticYour own static IPv4 and the ports you open, from $2/mo

Checked .

The problem

What the T-Mobile gateway hides

T-Mobile Home Internet gives your home IPv6, but no public IPv4 of its own. IPv4 traffic goes through 464XLAT, as T-Mobile users report: the gateway translates it, and T-Mobile's carrier-grade NAT (CGNAT) shares one public IPv4 among many customers. The address a what-is-my-IP site shows belongs to T-Mobile, not to you, and it can change.

So nobody on the internet can start an IPv4 connection to your home. The gateway and its app have no port-forwarding setting. A third-party router behind the gateway has a port-forwarding page, but its rules only reach as far as the gateway. The connection still stops at T-Mobile's NAT.

T-Mobile sells a static IP only with T-Mobile Business Internet, as a paid add-on: ~$15/mo (third-party reports). Home plans have no static IP option.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Check

Check that you are behind CGNAT

This takes one minute. The full port-forwarding check works for every ISP.

  1. Open the T-Mobile gateway's web page or app and find its IPv4 address. It is not a public address. Many T-Mobile gateways show 192.0.0.x, the address range 464XLAT uses.
  2. If your own router sits behind the gateway, look at its WAN address too. A 192.168.x.x address there means double NAT.
  3. Search "what is my IP". The IPv4 it shows belongs to T-Mobile and does not match either address.

If the addresses do not match, a port forward cannot work. You need a public IPv4 from somewhere else.

Why use GetAStatic?

Why T-Mobile customers use GetAStatic

  • Works behind the T-Mobile gateway as it is: no bridge mode, no settings to change
  • Your own static IPv4 that stays the same when T-Mobile's address changes
  • Open TCP or UDP ports for Plex, Minecraft, cameras or a home server
  • No Business plan and no call to T-Mobile
How it works

Bring your own public IPv4

GetAStatic gives you a dedicated static IPv4 in Kansas City, Missouri or San Jose, California. Your server, or your own router behind the gateway, connects out to our node over WireGuard. T-Mobile allows outgoing connections, so CGNAT does not block the tunnel.

When someone connects to your IP on a port you opened, the traffic comes down the tunnel to your device. The device also sends its outgoing traffic from the same IP. Plex, game servers and allowlists all see one fixed address.

It is a VPN with your own address, not a shared exit. No other customer uses your IP.

Setup

Set it up on T-Mobile Home Internet

Run WireGuard on the machine that hosts your service. Or run it on your own router behind the gateway, and every device behind that router uses the IP.

  1. Sign up for GetAStatic and note your static IP.
  2. In the dashboard, open the ports your service needs. A new IP starts with every port closed.
  3. Download the WireGuard config. Import it into the WireGuard app on your server, PC or NAS, or into your router (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet).
  4. Turn the tunnel on. Leave the T-Mobile gateway in its default mode.
  5. Give people YOUR-IP:port. For Plex, also set "Manually specify public port" to 32400 in Remote Access.
PortProtocolUsed for
32400TCPPlex Media Server
25565TCPMinecraft Java server
19132UDPMinecraft Bedrock server
443TCPWebsite or reverse proxy (HTTPS)

Plus includes 5 open ports; Pro and Ultra have unlimited open ports. A port range counts as its size.

Good to know

Good to know

  • Speed is capped per plan, the same up and down: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. T-Mobile's upload speed changes with signal and tower load, and it is often the real limit.
  • Bandwidth counts upload plus download: 100 GB on Plus, 1 TB on Pro, 5 TB on Ultra.
  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California, not a T-Mobile or home address. Players and viewers far from the IP's city see some extra delay.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. Devices outside the tunnel stay behind T-Mobile's CGNAT.
  • Not sure it fits your setup? You have 7 days to get your money back.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Can I get a static IP from T-Mobile Home Internet?

No. T-Mobile sells a static IP only with T-Mobile Business Internet, as a paid add-on: ~$15/mo (third-party reports). Home plans share a public IPv4 through CGNAT. GetAStatic gives you a static IPv4 on any T-Mobile plan, from $2/mo.

02Does bridge mode help?

No. Users report that the T-Mobile gateway has no true bridge mode. You can turn off its Wi-Fi and plug in your own router, but that router still sits behind T-Mobile's CGNAT. Run WireGuard on that router instead, and every device behind it uses your GetAStatic IP.

03Does IPv6 help?

Only for visitors who also have IPv6. A visitor on a network without IPv6 cannot reach an IPv6 address, and many Plex and Minecraft clients still connect over IPv4. A public IPv4 works for everyone.

04Will Plex work on T-Mobile Home Internet?

Yes. Run WireGuard on the Plex machine, open port 32400 TCP in the dashboard, and set "Manually specify public port" to 32400. Remote viewers then connect directly, not through the slow Plex Relay. Details: Plex behind CGNAT.

05Will a Minecraft server work?

Yes. Open 25565 TCP for Java or 19132 UDP for Bedrock, and run WireGuard on the server. Players join with your IP. Other games: game servers behind CGNAT.

Have more questions? See the full FAQ →