A Tailscale static IP and Funnel alternative: your own public IPv4

Keep Tailscale for reaching your own devices. GetAStatic adds what a tailnet cannot give you: your own fixed public IPv4 that anyone can reach on any port you open, with no app on their side, and a VPN that exits from it.

GetAStatic is not affiliated with Tailscale. Funnel details from Tailscale's own docs, checked 2026-10-06.

Instant setup US-based IP

Updated

Compare

GetAStatic vs Tailscale Funnel for public services

Funnel shares a web app; a static IP takes any service.

FeatureGetAStaticTailscale Funnel
PriceFrom $2/moIncluded in all plans
Your own public IPYesNo (ts.net name)
Ports and trafficAny TCP or UDP port you openPorts 443/8443/10000 only, TLS, no UDP
Games, VoIP, SSHYesNo
Use your own domainYesNo
Fixed outgoing IP, no VPSYesNo

Tailscale details checked 2026-10-06 in Tailscale's docs. A fixed outbound IP on Tailscale needs an exit node, usually a VPS you run.

The problem

Tailscale Funnel limits, and why a tailnet has no public IP

Tailscale builds a private mesh: every device runs Tailscale and gets a private 100.x.y.z address. But a friend joining a game server, a VoIP provider or a customer's browser cannot install Tailscale for you.

Funnel publishes a service to the internet, with limits. Tailscale's docs (checked 2026-10-06) say Funnel listens only on ports 443, 8443 and 10000, carries TLS traffic only, has no UDP, uses a name ending in ts.net instead of your own domain, and has bandwidth limits you cannot change.

For a fixed outbound address the usual advice is to rent a VPS and make it an exit node, and then you run and patch a server. Headscale, the self-hosted control server, also needs an address every device can always reach.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

What GetAStatic adds to a tailnet

  • Your own public IPv4 for services that friends, customers or apps must reach
  • Any TCP or UDP port you open in the dashboard: games, VoIP, SSH, remote desktop, cameras
  • A VPN that exits from your fixed IP, for allowlists, with no VPS exit node to run
  • A stable home for a Headscale or WireGuard server, from $2/mo
How it works

Add a public IP; keep the tailnet

GetAStatic gives you a dedicated public IPv4 in Kansas City, Missouri or San Jose, California, delivered over WireGuard. The device dials out to our node, so it works behind CGNAT, and anyone can reach the ports you open with no app and no account. It is a VPN too: the device leaves the internet from your static IP, with no VPS to build.

Tailscale keeps your devices connected; the static IP covers everything public, such as a Plex server or a game server. Pay by card or crypto, with a 7-day money-back guarantee.

Setup

Give one machine a public address

Run WireGuard on the machine that hosts the public service. Tailscale can stay installed.

  1. Create a GetAStatic account and copy your static IP from the dashboard.
  2. Open only the public ports you need, each as TCP or UDP.
  3. Download the WireGuard config, import it on that machine and turn the tunnel on.
  4. Set the service to listen on its port. For Headscale, set server_url in config.yaml to the static IP.
  5. Test from a device that is not on your tailnet, such as a phone on mobile data, using YOUR-IP:port.
PortProtocolUsed for
443TCPPublic web service
51820UDPYour own WireGuard server
8080TCPHeadscale (example port)

Plus lets you open 5 open ports. Pro and Ultra have unlimited open ports.

Good to know

Good to know

  • Full tunnel: the machine sends all its internet traffic through the static IP. Two VPNs that both manage routes can conflict, so test your setup.
  • Two locations: Kansas City, Missouri and San Jose, California. Users far from the IP's city see some extra delay.
  • Speed is capped by plan: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra.
  • The address is a datacenter IP, not a residential one.
FAQ

Questions, answered.

01Can Tailscale give me a static public IP?

Not by itself. Tailscale addresses are private 100.x addresses inside your tailnet. For a public address you need Funnel, which is limited to web traffic on three ports, or an exit node on a VPS. A static IP over WireGuard gives you a public IPv4 directly.

02Does Tailscale Funnel support UDP or custom ports?

No. Tailscale's docs list only ports 443, 8443 and 10000, TLS only, with no UDP (checked 2026-10-06). A static IP takes any TCP or UDP port you open, such as 25565 for Minecraft or 5060 for SIP.

03Can I run Tailscale and the static IP on one machine?

Usually, on computers and servers: Tailscale keeps its 100.x addresses, and other traffic leaves through the static IP. Phones run one VPN app at a time.

04Can I give my Headscale server a fixed public address?

Yes. Run WireGuard on the Headscale host, open its listening port, and point server_url at the static IP or a domain that resolves to it. Your devices then always find the control server.

05Why not just use Tailscale Funnel?

Funnel shares one web app on a ts.net name. A static IP is your own address, takes any TCP or UDP port, and works with clients that do not use TLS, such as games, SIP and SSH.

Have more questions? See the full FAQ →