- 1 dedicated IP address
- 10 devices
- 5 open ports
- 100 GBbandwidth
- 20 Mbpsspeed
Keep Tailscale for reaching your own devices. GetAStatic adds what a tailnet cannot give you: your own fixed public IPv4 that anyone can reach on any port you open, with no app on their side, and a VPN that exits from it.
GetAStatic is not affiliated with Tailscale. Funnel details from Tailscale's own docs, checked 2026-10-06.
Updated
Funnel shares a web app; a static IP takes any service.
| Feature | GetAStatic | Tailscale Funnel |
|---|---|---|
| Price | From $2/mo | Included in all plans |
| Your own public IP | Yes | No (ts.net name) |
| Ports and traffic | Any TCP or UDP port you open | Ports 443/8443/10000 only, TLS, no UDP |
| Games, VoIP, SSH | Yes | No |
| Use your own domain | Yes | No |
| Fixed outgoing IP, no VPS | Yes | No |
Tailscale details checked 2026-10-06 in Tailscale's docs. A fixed outbound IP on Tailscale needs an exit node, usually a VPS you run.
Tailscale builds a private mesh: every device runs Tailscale and gets a private 100.x.y.z address. But a friend joining a game server, a VoIP provider or a customer's browser cannot install Tailscale for you.
Funnel publishes a service to the internet, with limits. Tailscale's docs (checked 2026-10-06) say Funnel listens only on ports 443, 8443 and 10000, carries TLS traffic only, has no UDP, uses a name ending in ts.net instead of your own domain, and has bandwidth limits you cannot change.
For a fixed outbound address the usual advice is to rent a VPS and make it an exit node, and then you run and patch a server. Headscale, the self-hosted control server, also needs an address every device can always reach.
Plus for light use, Pro for most people, Ultra for full gigabit.
5× speed · 10× bandwidth · 2 IPs — only $2/mo more
GetAStatic gives you a dedicated public IPv4 in Kansas City, Missouri or San Jose, California, delivered over WireGuard. The device dials out to our node, so it works behind CGNAT, and anyone can reach the ports you open with no app and no account. It is a VPN too: the device leaves the internet from your static IP, with no VPS to build.
Tailscale keeps your devices connected; the static IP covers everything public, such as a Plex server or a game server. Pay by card or crypto, with a 7-day money-back guarantee.
Run WireGuard on the machine that hosts the public service. Tailscale can stay installed.
| Port | Protocol | Used for |
|---|---|---|
| 443 | TCP | Public web service |
| 51820 | UDP | Your own WireGuard server |
| 8080 | TCP | Headscale (example port) |
Plus lets you open 5 open ports. Pro and Ultra have unlimited open ports.
Not by itself. Tailscale addresses are private 100.x addresses inside your tailnet. For a public address you need Funnel, which is limited to web traffic on three ports, or an exit node on a VPS. A static IP over WireGuard gives you a public IPv4 directly.
No. Tailscale's docs list only ports 443, 8443 and 10000, TLS only, with no UDP (checked 2026-10-06). A static IP takes any TCP or UDP port you open, such as 25565 for Minecraft or 5060 for SIP.
Usually, on computers and servers: Tailscale keeps its 100.x addresses, and other traffic leaves through the static IP. Phones run one VPN app at a time.
Yes. Run WireGuard on the Headscale host, open its listening port, and point server_url at the static IP or a domain that resolves to it. Your devices then always find the control server.
Funnel shares one web app on a ts.net name. A static IP is your own address, takes any TCP or UDP port, and works with clients that do not use TLS, such as games, SIP and SSH.
Have more questions? See the full FAQ →