Get Real IP

How to self-host behind CGNAT or a dynamic IP

Quick answer

If your ISP puts you behind CGNAT or gives you a dynamic IP, inbound connections can't reach your server. Fix it by getting a dedicated static public IP: request one from your ISP (if offered), rent a cloud VPS, or route a real static IP to your existing server over a WireGuard tunnel with a service like Get Real IP — which works behind any CGNAT because the tunnel is outbound.

You set up your home server, forwarded the ports, pointed your domain at your IP — and nothing connects. If that sounds familiar, your ISP is almost certainly putting you behind carrier-grade NAT (CGNAT) or handing you a dynamic IP that changes. Both quietly make self-hosting difficult. Here's why, and what actually fixes it.

Why CGNAT breaks self-hosting

Normally your router gets one public IP address, and you forward ports on it so inbound traffic reaches a device on your LAN. CGNAT changes that: your ISP shares a single public IP across dozens or hundreds of customers and gives your router only a private, carrier-side address (usually in the 100.64.0.0/10 range). There is no public IP that belongs to you, so there is nothing to forward. Incoming connections hit the ISP's NAT and get dropped, because it has no way to know that packet was meant for your server.

Port forwarding, DDNS, and UPnP all assume you have a real public IP. Behind CGNAT you don't, so they silently do nothing — which is why self-hosting behind CGNAT feels like everything is configured correctly but still doesn't work.

Why a dynamic IP is almost as bad

Even with a real (non-CGNAT) public IP, most residential ISPs hand out dynamicaddresses that change periodically. Dynamic DNS can chase the change for a hostname, but a moving address still breaks IP-based firewall rules, allowlists on services you connect to, TLS setups pinned to an IP, and — critically — email, where reverse DNS must match a stable address. And it always seems to change right when you're away from home.

How to get a real, reachable IP

There are three realistic ways to get an address the internet can actually reach:

  1. Ask your ISP for a static IP. Some offer it, usually on a business plan for an extra $10–30/month. It takes you off the CGNAT pool. Downsides: it's tied to your physical line (move house, lose the IP), residential blocks often have poor email reputation, and there's no failover.
  2. Rent a cloud VPS and host there — or build your own tunnel back home. A VPS has a real static IP, but now you're maintaining a server, or setting up and babysitting your own reverse proxy / WireGuard relay to bridge the VPS IP to the hardware at home.
  3. Route a dedicated static IP to your existing server over a tunnel. This is what Get Real IP does: your server (or router, or laptop) opens an outbound WireGuard tunnel — which CGNAT always allows — and we route a dedicated public IPv4 to it. Inbound traffic for that IP flows down the tunnel to your machine. No ISP negotiation, no VPS to maintain, and it works behind the strictest CGNAT because nothing has to accept an inbound connection on your ISP line.

Why the tunnel approach works behind CGNAT

CGNAT blocks inbound connections, but outbound connections are fine — that's how you browse the web at all. A WireGuard tunnel is established outbound from your server to our edge, and once it's up it's bidirectional. Your dedicated IP lives on our network, where inbound traffic can reach it, and we forward that traffic to you through the tunnel you already opened. Your ISP never has to accept a connection, so CGNAT is irrelevant.

Because it's a real routed IP (not an HTTP proxy), every protocol works — web, SSH, game servers, VoIP, email, raw TCP/UDP — and TLS terminates on your own server, so nobody in the middle sees your traffic in plaintext.

Which should you pick?

If your ISP offers a cheap static IP and you'll never move, that's the simplest path. If you need it to be portable, work behind CGNAT, run email with clean reverse DNS, or just work in a few minutes without a VPS to maintain, a dedicated-IP tunnel is the least-hassle option. Get Real IP is $8/month for your first IP, self-serve, and works on anything that runs WireGuard.

Frequently asked questions

Can I self-host if my ISP uses CGNAT?

Yes. CGNAT blocks inbound connections because your public IP is shared with other customers, but you can bypass it. Get Real IP gives your server a dedicated static public IP over an outbound WireGuard tunnel, which works behind the strictest CGNAT because your server initiates the connection. You can also ask your ISP for a static IP add-on if they offer one.

Does a dynamic IP stop me from self-hosting?

Not entirely — dynamic DNS can keep a hostname pointed at a changing IP. But dynamic IPs break TLS certificates pinned to an address, firewall allowlists, and email reverse-DNS, and they change at the worst times. A static IP removes that whole class of problems.

Is this the same as port forwarding?

No. Port forwarding only works if you already have a real, reachable public IP on your router. Behind CGNAT you have no such IP to forward, so port forwarding silently does nothing. A tunnel to a dedicated static IP gives you an address you can actually forward and route.

Do I need special hardware?

No. Any device that runs a WireGuard client works — a Linux box, a NAS, a laptop, or a router like pfSense, OPNsense, or GL.iNet. You do not need a managed appliance.

Want a dedicated static IP in minutes?

Get Real IP delivers a dedicated static public IPv4 to your server, router, or laptop over an encrypted WireGuard tunnel — any protocol, any port, works behind CGNAT. $8/mo, no contract.

Start your free trial

7 days free · Cancel anytime

Related guides

Updated September 4, 2026