WireGuard port forwarding without running your own VPS

The VPS-plus-WireGuard recipe works, but you build and maintain it. GetAStatic runs the server side for you: a dedicated public IPv4, ports you open from a dashboard, and nothing to patch.

Instant setup US-based IP

Updated

Compare

VPS + WireGuard vs GetAStatic

Same end result: a public IPv4 whose ports reach your home machine.

FeatureVPS you runGetAStatic
Monthly costA few dollars + your timeFrom $2/mo
Setup timeAn hour+: keys, NAT rulesMinutes: one config
Maintenance and patchingYours: updates, firewallNone: we run it
Your own IPv4Yes, one per VPSYes, dedicated to you
Open portsAny, with NAT rules you write5 on Plus, unlimited on Pro
Also a VPN for the deviceOnly if you set it upYes, traffic leaves from your IP

VPS prices change with the host, the region and the traffic you use.

The problem

The do-it-yourself recipe

The guides all follow one plan. Rent a small cloud server, install WireGuard on it and connect your home machine. Then write firewall rules so traffic to the server's public IP is sent down the tunnel to your home.

That means a key pair for each side, forwarding switched on, and address-rewriting (NAT) rules for each port and for the replies, plus a keepalive and rules that survive a reboot. After that, the server is yours to patch like any public machine.

Pricing

Choose your plan

Plus for light use, Pro for most people, Ultra for full gigabit.

Plus
$2/mo

 

  • 1 dedicated IP address
  • 10 devices
  • 5 open ports
  • 100 GBbandwidth
  • 20 Mbpsspeed
Ultra
$10/mo

 

  • 2 dedicated IP addresses
  • Unlimited devices
  • Unlimited open ports
  • 5 TBbandwidth
  • 1 Gbpsspeed
  • Inbound + outbound access
  • Instant activation
  • 7-day money-back guarantee
  • Cancel anytime
Add-ons, per IP addressCustom hostname $5·Addtl. IP $2/mo (Ultra $7/mo)·Gigabit Speed (Plus & Pro) $5/mo·SMTP $25
Why use GetAStatic?

What GetAStatic takes off your hands

  • No iptables or nftables rules: open a TCP or UDP port in the dashboard, with no ticket
  • No server to patch, reboot or watch
  • Your own IPv4, never shared with another customer, and a VPN that exits from it
  • The home side only dials out, so CGNAT, Starlink and 5G home internet are fine
How it works

How to get a public IPv4 without a VPS

GetAStatic gives you the same end result with the server side run for you: a dedicated public IPv4 in Kansas City, Missouri or San Jose, California, a WireGuard config we generate, and a dashboard where you open or close ports per IP. Your home machine connects out on UDP 1194 or 443 (443 for networks that block 1194), and the keepalive is already set. See what is in the config.

It is a VPN too: your device's traffic leaves from that IP. One standard config works on PCs, servers, routers and phones. Get your IP from $2/mo and open your first port in minutes, with a 7-day money-back guarantee.

Setup

Set it up

Example: a web server, SSH, and your own WireGuard server, all on one home machine.

  1. Sign up for GetAStatic. Your static IP shows in the dashboard.
  2. Open the ports you need on that IP, for example 443 TCP, 22 TCP and 51820 UDP.
  3. Download the WireGuard config and import it into WireGuard on the machine that runs the services (or on your router).
  4. Turn the tunnel on. Check that a what-is-my-IP site shows your new address.
  5. Point people, apps and DNS records at YOUR-IP:port.
PortProtocolUsed for
443TCPWeb server (HTTPS)
22TCPSSH
51820UDPYour own WireGuard server

Plus allows 5 open ports; Pro and Ultra have unlimited open ports. A range counts as its size.

Good to know

Good to know

  • Two locations: Kansas City, Missouri and San Jose, California. Users far from the IP's city see more delay.
  • Speed and data are capped by plan, from 20 Mbps and 100 GB on Plus to 1 Gbps and 5 TB on Ultra. Upload and download both count.
  • It is a datacenter IP, like a VPS address, not a home IP.
  • We run the node for you: there is no root or shell, and no software of yours runs on it.
FAQ

Questions, answered.

01How do I get a public IPv4 without a VPS?

Get a static IP that is delivered over WireGuard. GetAStatic gives you a dedicated public IPv4 and a config. Import the config on your server or router and open the ports you need on the dashboard. The tunnel connects out, so it works behind CGNAT, and there is no server for you to run.

02Is a VPS cheaper?

Sometimes, if your time is free. A VPS gives you root and any location. You also set up the tunnel, write a NAT rule for each port, and patch the server. GetAStatic starts at $2/mo, with a 7-day money-back guarantee.

03Can I keep my VPS setup and use this too?

Yes. The two tunnels are independent. Our config sends all of a device's traffic through our tunnel, so run them on different devices, or make sure the VPS tunnel only carries its own subnet.

04How is this different from a VPN provider's port forwarding?

Most VPN providers share each IP among many users and give you one random high port, if any. Here the IP is yours alone, and you choose the ports, TCP or UDP, including 22, 80 and 443.

05Can I run my own WireGuard server behind it?

Yes. Open 51820 UDP (or whatever port your server uses) and set your clients' endpoint to YOUR-IP:51820. Your server's tunnel then runs inside ours.

Have more questions? See the full FAQ →