Get Real IP

Self-hosting a static IP on a VPS: the tradeoffs

Quick answer

A VPS plus a WireGuard tunnel can route a public IP to a home server. The main tradeoffs: the simple routing setup (SNAT) rewrites every visitor to one internal IP, breaking fail2ban, rate limiting, and logs; keeping real client IPs needs policy-based routing that's fiddlier to maintain; a reverse proxy sidesteps the routing but only carries HTTP/HTTPS; and you own a server to keep patched and working. A managed routed-IP service (like Get Real IP) does the routing, preserves client IPs, carries any protocol, and leaves nothing to maintain.

Renting a VPS and running WireGuard to your home server is a common way to get a reachable public IP behind CGNAT. It works. The things worth weighing before you build it are the tradeoffs in how traffic gets forwarded — because the default, easy configuration quietly gives up something most self-hosters care about.

You lose your visitors' real IP addresses

This is the tradeoff that catches people. To get replies flowing back correctly over the tunnel, the simplest configuration uses SNAT (masquerade) on the VPS. SNAT rewrites the source address of every inbound packet to the tunnel's internal IP — so from your home services' point of view,every request looks like it came from the same internal address.

That breaks a lot of things you rely on:

You can preserve real client IPs, but it means avoiding SNAT and instead doing policy-based routing on the home side: mark the tunnel's inbound packets and add anip rule that sends their replies back through a dedicated route table. It works, but it's more moving parts to set up correctly and keep working across reboots and config changes.

The return-path problem

Underneath that is the core routing issue. Inbound traffic to the VPS public IP has to be DNAT'd down the tunnel to your home host — and the reply has to go back over the tunnel, not out your home ISP link. Left alone, the home host answers via its normal default route and the connection silently fails (asymmetric routing). Every working DIY setup solves this one of two ways: SNAT on the VPS (easy, loses client IPs) or policy-based routing at home (keeps them, more involved). There isn't a free lunch — you're picking which cost to pay.

Reverse proxy: simpler, but HTTP only

Running a reverse proxy (Caddy, Traefik, nginx) on the VPS avoids the L3 routing entirely for web traffic — it terminates HTTPS on the VPS and forwards to your service, and it can pass the client IP in a header. The ceiling is protocol: it carries HTTP and HTTPS only. Email, game servers, SSH on arbitrary ports, VoIP, and raw TCP/UDP don't fit, and TLS terminates on the VPS instead of your own machine.

Ongoing ownership

A self-managed VPS is a server you keep running: OS and WireGuard updates, firewall and security, monitoring, and re-fixing the routing when something changes. That maintenance is a recurring cost on top of the monthly fee. (One minor note: cloud VPS IPs sometimes carry a datacenter reputation that can affect deliverability for some use cases like email — worth checking for your provider and use case.)

The managed alternative

Get Real IP routes a dedicated public IPv4 to your server, router, or laptop over an outbound WireGuard tunnel (so it works behind CGNAT), with the routing handled for you:

Quick comparison

VPS + SNATVPS + policy routingVPS + reverse proxyGet Real IP
Real client IPs✗ lost✓✓ (header, HTTP)✓
Any protocol / port✓✓✗ HTTP/S only✓
Setup difficultymoderatehighmoderatelow
Server to maintainyesyesyesno
Works behind CGNAT✓✓✓✓

The DIY route trades money for time and control: you run the server and choose which routing tradeoff to accept. Get Real IP handles the routing — preserving client IPs, carrying any protocol, with no server to maintain.

Frequently asked questions

Can't I just rent a cheap VPS and get a public IP for a few dollars a month?

Yes. A VPS gives you a public IP cheaply, and it can carry traffic to a home server over a WireGuard tunnel. The IP is the easy part. The work is the routing that forwards inbound traffic down the tunnel and gets the replies back the right way, plus the tradeoffs that come with it — most notably that the simple setup hides your visitors' real IP addresses.

Why would I lose the client's real IP address?

The straightforward way to make return traffic work over a VPS tunnel is SNAT (masquerade) on the VPS. That rewrites every inbound packet's source address to the tunnel's internal IP, so your home services see all traffic as coming from one internal address. That breaks fail2ban, per-IP rate limiting, geolocation, abuse blocking, and access logs. Preserving real client IPs instead requires policy-based routing on the home side (packet marks plus a dedicated route table), which is more involved to set up and keep working.

What's the routing problem exactly?

Inbound traffic to the VPS IP has to be DNAT'd down the tunnel to your home host, and the reply must travel back over the tunnel — not out your home internet connection. If the home host answers over its normal default route, the connection breaks (asymmetric routing). You resolve it with either SNAT on the VPS (loses client IPs) or policy-based routing at home (keeps them, but is fiddlier).

Isn't a reverse proxy like Caddy or Traefik on the VPS simpler?

For websites, yes. A reverse proxy on the VPS terminates HTTPS and forwards over the tunnel, and it can pass the client IP in a header. But it only handles HTTP/HTTPS — no email, game servers, SSH on arbitrary ports, VoIP, or raw TCP/UDP — and TLS terminates on the VPS rather than your own server.

What stays my responsibility on a self-managed VPS?

The box is yours to run: OS and WireGuard updates, firewall and security, monitoring, and fixing the routing when a reboot or change breaks it. That ongoing maintenance is the recurring cost, separate from the monthly VPS fee.

Want a dedicated static IP in minutes?

Get Real IP delivers a dedicated static public IPv4 to your server, router, or laptop over an encrypted WireGuard tunnel — any protocol, any port, works behind CGNAT. $8/mo, no contract.

Start your free trial

7 days free · Cancel anytime

Related guides

Updated September 8, 2026