Port forwarding on Verizon 5G Home Internet

Verizon's 5G gateways have a Port Forwarding page. A rule works only if the gateway's WAN address is a public IPv4. If it is, you are done. If not, GetAStatic gives you a static IPv4 over WireGuard with your chosen ports open, from $2/mo.

Not affiliated with Verizon. Facts as listed on Verizon's support pages, checked 2026-10-07.

Instant setup US-based IP

Updated

Facts

Verizon 5G Home Internet at a glance

Port forwarding on the gatewayYes. Advanced > Security & Firewall > Port Forwarding in the admin page
Admin pagemynetworksettings.com, or 192.168.1.1 (ARC-XCI55AX, WNC-CR200A) and 192.168.0.1 (ASK-NCQ1338, ASK-NCQ1338FA)
IP passthroughYes. The address Verizon assigns goes to the device on the LAN2 port, and Wi-Fi turns off
Public IPv4 on the WANNot documented by Verizon. Check your gateway (steps below)
Static IPNot listed for 5G Home. Verizon Business Internet lists a reserved public static IP
GetAStaticA static IPv4 and the ports you open, on any WAN address, from $2/mo

Checked .

The problem

A Port Forwarding screen does not prove you have a public IP

Verizon documents port forwarding on its 5G Home equipment. On the Internet Gateway models (ARC-XCI55AX, ASK-NCQ1338FA and WNC-CR200A), open the admin page, click Advanced, then Security & Firewall > Port Forwarding. A rule takes an application name, the inbound and outbound ports, the destination device and the protocol, then Apply Changes. On the 5G Home Router, use System Settings > Port Forwarding.

A rule tells the gateway one thing: when a connection arrives on its WAN side on port X, send it to this device on your network. That is ordinary router NAT, and it is the part you control.

The rule only acts on traffic that reaches the gateway, and that depends on the IPv4 address Verizon gives the gateway's WAN side. If it is public, the rule does its job. If it is shared or private, a second NAT inside Verizon's network sits in front, with no rule for your home. The connection ends there, and your rule looks broken even though every field is right.

Many users report a shared address on 5G Home, but Verizon's support pages do not say which kind of address a line gets. Check your own before you change anything. A WAN address in 100.64.0.0/10 (100.64.0.0 to 100.127.255.255) is carrier-grade NAT (CGNAT, RFC 6598). A 10.x, 172.16.x to 172.31.x or 192.168.x address is private. With nothing of yours in front of the gateway, that NAT is Verizon's too.

Your own static IP over WireGuard. No VPS.

Dedicated IPv4 from $2/mo →
Check

Check the WAN address and test the port

Do these in order. The first two tell you whether the block is at your end or at Verizon's.

  1. Log in to the gateway's admin page and open System Status, which shows the internet (WAN) connection, and note its IPv4 address. On the WNC-CR200A the WAN settings are also under Advanced > Network Settings > Network Connections > Broadband Connection.
  2. On a device using the gateway, open the CGNAT check or search "what is my IP". If that address matches the gateway's WAN address, the WAN is public. If it does not match, or the WAN address is in 100.64.0.0/10 or a private range, inbound IPv4 stops before your gateway.
  3. Make sure the service answers on your own network. On the host, list listening ports with "ss -ltnp" on Linux or "netstat -ano" on Windows. The service must listen on 0.0.0.0 or the host's LAN address, not only 127.0.0.1, and the host firewall (Windows Defender Firewall, ufw, firewalld) must allow the port.
  4. Check the rule points at the host's current LAN address. A DHCP address can change after a restart, so give the host a fixed one first.
  5. If your own router is behind the Verizon gateway and not in IP passthrough, you have two NATs in your home. Forward the port on the gateway to your router, then on your router to the host.
  6. Test from outside your home. Use the port check, or a phone with Wi-Fi turned off.

If the WAN address is public and the port check shows the port open, Verizon's own port forwarding works and you probably do not need GetAStatic for this.

Why use GetAStatic?

When GetAStatic helps on Verizon 5G Home

  • Your gateway's WAN address is not public, so a correct forwarding rule never receives a connection
  • You want an address that stays the same when Verizon's changes
  • You host a game server, Plex, cameras or a website and need specific TCP or UDP ports open
  • You want to keep the Verizon gateway in its default mode and skip IP passthrough
How it works

When the rule is right but nothing arrives

If your WAN address is public, fix the local cause the checks point to. Verizon does not list a static IP for 5G Home, so the address may change; a dynamic DNS name that follows it is enough for most home servers.

If the WAN address is not public, no setting on the gateway helps. DMZ Host sends inbound traffic to one device and IP passthrough hands the WAN address to your router, but both still wait for connections that cannot reach that address. One way out is a Verizon business plan: Verizon lists a reserved public static IP for its Business Internet (5G and LTE). The other is an address from outside Verizon's network.

GetAStatic is that address: a VPN with a dedicated static IPv4 in Kansas City, Missouri or San Jose, California. Your host or your own router connects out to our node over WireGuard on UDP 1194 or 443. Outgoing connections pass through any NAT, so the tunnel is not blocked. Connections to your IP on the ports you opened come back down it, and the gateway's forwarding rules no longer matter.

Setup

Set it up behind a Verizon gateway

Run WireGuard on the machine that hosts the service, or on your own router behind the gateway.

  1. Sign up for GetAStatic and note your static IP in the dashboard.
  2. Open the ports your service uses, TCP or UDP. A new IP starts with every port closed, and nothing opens on its own: there is no UPnP.
  3. Download the WireGuard config. Import it into the WireGuard app on the host (Windows, macOS, Linux, or a NAS that runs WireGuard or Docker), or into your router (OpenWrt, pfSense, OPNsense, MikroTik or GL.iNet).
  4. Turn the tunnel on. The Verizon gateway can stay in its default mode, and you can delete the old forwarding rule.
  5. Run the port check against your new IP and port. Then give people YOUR-IP:port, or point a domain name at the IP.

Plus includes 5 open ports; Pro and Ultra have unlimited open ports. A port range counts as its size.

Good to know

Good to know

  • Speed is capped per plan, the same up and down: 20 Mbps on Plus, 100 Mbps on Pro, 1 Gbps on Ultra. Your 5G upload speed changes with signal, and it is often the lower limit.
  • Bandwidth counts upload plus download: 100 GB on Plus, 1 TB on Pro, 5 TB on Ultra.
  • The IP is a datacenter address in Kansas City, Missouri or San Jose, California, not a Verizon or home address. Users far from the IP's city see some extra delay.
  • All traffic of the device running the tunnel goes through it, so outgoing connections use the new IP too.
  • Each IP is one WireGuard config, active on one device at a time. Run it on a router and every device behind it shares the IP; the plan card's device figure is a guide, not a cap. A PlayStation or Xbox cannot run WireGuard, so for a console the tunnel must run on a router in front of it.
  • Not sure it fits? You have 7 days to get your money back.
Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
FAQ

Questions, answered.

01Is every Verizon 5G Home line behind CGNAT?

Verizon's support pages do not say, so do not assume it either way. If the gateway's WAN IPv4 matches what a what-is-my-IP site shows, your address is public and port forwarding on the gateway can work.

02Does IP passthrough fix port forwarding?

Only if the address is public. IP passthrough hands the address Verizon assigns to the device on the LAN2 port, so your own router can do the forwarding. If that address is shared or private, your router gets the same unreachable address and its rules fail the same way.

03Should I use DMZ Host instead of a port forward?

Usually not. DMZ Host sends every unsolicited inbound connection to one device, which exposes all of its ports. It has the same limit as a forward: if the WAN address is not public, nothing arrives. Forward only the ports you need.

04My port forward works. Do I need GetAStatic?

Probably not for this problem. If the WAN address is public and an outside test reaches your service, Verizon's own forwarding is enough. GetAStatic helps when the address cannot accept connections, or when you want an IP that does not change.

05Why does my public IP fail when I test from home?

Connecting to your own public IP from inside your network needs NAT loopback, and some gateways do not do it. Test from outside: the port check, or a phone with Wi-Fi turned off.

Have more questions? See the full FAQ →