How to self-host behind CGNAT or a dynamic IP
Quick answer
If your ISP puts you behind CGNAT or gives you a dynamic IP, inbound connections can't reach your server. Fix it by getting a dedicated static public IP: request one from your ISP (if offered), rent a cloud VPS, or route a real static IP to your existing server over a WireGuard tunnel with a service like Get Real IP — which works behind any CGNAT because the tunnel is outbound.
You set up your home server, forwarded the ports, pointed your domain at your IP — and nothing connects. If that sounds familiar, your ISP is almost certainly putting you behind carrier-grade NAT (CGNAT) or handing you a dynamic IP that changes. Both quietly make self-hosting difficult. Here's why, and what actually fixes it.
Why CGNAT breaks self-hosting
Normally your router gets one public IP address, and you forward ports on it so inbound traffic reaches a device on your LAN. CGNAT changes that: your ISP shares a single public IP across dozens or hundreds of customers and gives your router only a private, carrier-side address (usually in the 100.64.0.0/10 range). There is no public IP that belongs to you, so there is nothing to forward. Incoming connections hit the ISP's NAT and get dropped, because it has no way to know that packet was meant for your server.
Port forwarding, DDNS, and UPnP all assume you have a real public IP. Behind CGNAT you don't, so they silently do nothing — which is why self-hosting behind CGNAT feels like everything is configured correctly but still doesn't work.
Why a dynamic IP is almost as bad
Even with a real (non-CGNAT) public IP, most residential ISPs hand out dynamicaddresses that change periodically. Dynamic DNS can chase the change for a hostname, but a moving address still breaks IP-based firewall rules, allowlists on services you connect to, TLS setups pinned to an IP, and — critically — email, where reverse DNS must match a stable address. And it always seems to change right when you're away from home.
How to get a real, reachable IP
There are three realistic ways to get an address the internet can actually reach:
- Ask your ISP for a static IP. Some offer it, usually on a business plan for an extra $10–30/month. It takes you off the CGNAT pool. Downsides: it's tied to your physical line (move house, lose the IP), residential blocks often have poor email reputation, and there's no failover.
- Rent a cloud VPS and host there — or build your own tunnel back home. A VPS has a real static IP, but now you're maintaining a server, or setting up and babysitting your own reverse proxy / WireGuard relay to bridge the VPS IP to the hardware at home.
- Route a dedicated static IP to your existing server over a tunnel. This is what Get Real IP does: your server (or router, or laptop) opens an outbound WireGuard tunnel — which CGNAT always allows — and we route a dedicated public IPv4 to it. Inbound traffic for that IP flows down the tunnel to your machine. No ISP negotiation, no VPS to maintain, and it works behind the strictest CGNAT because nothing has to accept an inbound connection on your ISP line.
Why the tunnel approach works behind CGNAT
CGNAT blocks inbound connections, but outbound connections are fine — that's how you browse the web at all. A WireGuard tunnel is established outbound from your server to our edge, and once it's up it's bidirectional. Your dedicated IP lives on our network, where inbound traffic can reach it, and we forward that traffic to you through the tunnel you already opened. Your ISP never has to accept a connection, so CGNAT is irrelevant.
Because it's a real routed IP (not an HTTP proxy), every protocol works — web, SSH, game servers, VoIP, email, raw TCP/UDP — and TLS terminates on your own server, so nobody in the middle sees your traffic in plaintext.
Which should you pick?
If your ISP offers a cheap static IP and you'll never move, that's the simplest path. If you need it to be portable, work behind CGNAT, run email with clean reverse DNS, or just work in a few minutes without a VPS to maintain, a dedicated-IP tunnel is the least-hassle option. Get Real IP is $8/month for your first IP, self-serve, and works on anything that runs WireGuard.
