- Residential IPv4
- Shared (CGNAT), inbound blocked
- Public IPv4
- Opt-in, Priority plans only (from $55/mo)
- Static IP
- Not offered
- IPv6
- Every plan, 56 prefix-length prefix
What CGNAT breaks, and what it doesn’t
With CGNAT, many customers share one public IPv4 address. Starlink puts Residential and Roam plans on it, with addresses from 100.64.0.0/10, and its default policy blocks every inbound connection (checked Oct 5, 2026).
| Task | Behind CGNAT | Why |
|---|---|---|
| Zoom, Teams, Meet, Slack | Works | You start the connection. |
| Most work VPNs | Usually works | Outbound, if the VPN supports NAT traversal. Check yours. |
| Cloud file sync, email, web | Works | Outbound. (Outbound mail on port 25 and SMB on 445 are blocked for everyone.) |
| Hosting a site, game server or Plex at home | Fails | Visitors have to connect in. |
| Remote desktop into your home PC | Fails directly | Inbound. Works through a tunnel. |
| Port forwarding | Does nothing | The ports you open are on your router, not on the shared address. |
One more limit matters for busy home offices: Starlink caps CGNAT plans at 1,200 sessions (open connections) at once, and says hitting it can drop VoIP calls, freeze video meetings and disrupt gaming or VPNs (checked Oct 5, 2026). A normal household rarely gets near it; a house full of devices, torrents or a small office can.
Check if you’re behind CGNAT (2 minutes)
- Open your router’s status page (or the Starlink app’s network details) and note the WAN IPv4 address.
- Search “what is my IP” on a phone connected to your Wi-Fi.
- If the router’s address starts with
100.64to100.127, or the two addresses don’t match, you’re behind CGNAT.
Your four options, easiest first
1. A tunnel you start from inside (best for most people)
Mesh VPNs like Tailscale or ZeroTier, and Cloudflare Tunnel, connect out from your home device to a service, and you reach your home through it. No public IP, no port forwarding, works on Residential. Good for remote desktop, a home file server, Home Assistant, or a small web app.
2. IPv6
Every Starlink plan gets native IPv6 with a 56 prefix-length prefix delegated to your router. Devices on IPv6 aren’t behind CGNAT. The catch: whoever connects in also needs IPv6, and you have to allow the traffic in your router’s firewall. The Starlink router itself has no firewall rules (checked Oct 5, 2026), so this needs your own router in bypass mode.
3. A hosted relay or VPS
Rent a small server with a public IP and point a WireGuard tunnel from home to it. It’s option 1 run by you. Good if your employer won’t allow third-party tunnel services.
4. A public IPv4 on a Priority plan
A public IPv4 is optional and only on Local Priority and Global Priority plans. You turn it on yourself: in your starlink.com account, edit “IP Policy”, choose “Public IP”, save and reboot (checked Oct 5, 2026). Local Priority starts at $55/mo for 50 GB of priority data and $155/mo for 500 GB (Starlink, checked Oct 5, 2026). Starlink’s terms say Residential plans aren’t permitted for business use, so a Priority plan is also the right plan if the connection runs a business (plan comparison).
Port forwarding on Starlink
The Starlink router can’t port forward at all (checked Oct 5, 2026). To forward ports you need both a Priority plan with a public IP and a third-party router, with the Starlink router in bypass mode. On Residential, port forwarding on your own router does nothing, because the CGNAT in front of it never sends the connection in.
IT For your IT person: addressing and limits
- IPv4: CGNAT,
100.64.0.0/10, inbound blocked by default policy; Residential/Roam limit of 1,200 sessions concurrent TCP/UDP sessions (oldest dropped). - IPv6: native on all plans; 56 prefix-length delegated via DHCPv6-PD plus a /64 on the WAN via SLAAC. Prefix may change on relocation or software update.
- Public IPv4: Local/Global Priority only, opt-in under IP Policy; not static; reserved 24 h.
- Blocked outbound for all customers: TCP/25, TCP/445. MTU 1500.
- Starlink router: no port forwarding, no firewall rules (IPv4 or IPv6). Bypass mode hands off to a third-party router; exiting bypass requires a factory reset.
Which option should you use?
| You need to… | Use | Wrong choice when |
|---|---|---|
| Reach your own PC or files from anywhere | Tailscale or similar tunnel | Your employer forbids third-party tunnel software on work devices. |
| Run a work VPN to the office | Nothing extra (outbound) | It’s a site-to-site VPN or uses PPTP/L2TP. See VPN types. |
| Host a public website or game server | Cloudflare Tunnel, or a VPS relay | The service needs raw UDP ports for many strangers (some game servers): use a hosted server. |
| Customers connect to equipment at your business | Priority plan public IP + your own router | You can get fiber or cable with a static IP. Take it. |
When this is the wrong choice
- Buying a Priority plan only for a work VPN. Most work VPNs connect out and don’t need a public IP. Ask IT first.
- Relying on a public IP staying the same. It can change; use dynamic DNS.
- Opening ports on Residential. It can’t work behind CGNAT, whatever the router says.
- Needing a true static IP for a firewall allow-list. Starlink doesn’t sell one. Fiber or cable business service usually does.
Questions people ask
Does Starlink use CGNAT?
Yes, for IPv4 on Residential and Roam plans: your router gets a shared address from 100.64.0.0/10, and inbound connections are blocked (Starlink support, checked Oct 5, 2026).
Can I get a static IP on Starlink?
No. Starlink doesn’t offer static IPs. A public IPv4 is available on Local Priority and Global Priority plans, but it can change after a move or software update; Starlink holds it for 24 h across reboots (checked Oct 5, 2026).
Can I port forward on Starlink?
Not with the Starlink router, which has no port-forwarding or firewall rules. You need a Priority plan with a public IP and your own router in bypass mode. On Residential, use a tunnel or IPv6 instead.
Will a public IP fix my work VPN?
Usually you don’t need one: most work VPNs connect outward and work behind CGNAT. Starlink says a public IP may help an incompatible VPN but doesn’t guarantee it. Check your VPN type first.
Is IPv6 enough to get around CGNAT?
Often, yes. Every Starlink plan gets a 56 prefix-length IPv6 prefix, and devices on it are reachable without NAT, if the device connecting in also has IPv6 and your router’s firewall allows it. Many hotel and office networks still don’t have IPv6, so a tunnel is the safer bet for reaching home from anywhere.
Sources
- What IP address does Starlink provide? (Starlink support), checked Oct 5, 2026
- IP Address (Starlink support), checked Oct 5, 2026
- What are CGNAT session limits and how do they affect my connection? (Starlink support), checked Oct 5, 2026
- How do I set my IP address to a public IP? (Starlink support), checked Oct 5, 2026
- DHCP Configuration (Starlink support), checked Oct 5, 2026
- Can I port forward with the Starlink router? (Starlink support), checked Oct 5, 2026
- What is bypass mode? (Starlink support), checked Oct 5, 2026
- Starlink US marketing availability API: Local Priority fixed site (invitationTypeCode=6), checked Oct 5, 2026
- Service Plan Descriptions (US, published 2026-10-05), checked Oct 5, 2026