If you have looked through the Starlink router settings for a port forwarding option, you will not find one. Starlink’s default IPv4 connection uses CGNAT, which blocks unsolicited inbound traffic before it can reach your router. For everyday browsing and streaming, CGNAT may not get in your way.
However, things are likely to get more complicated when you attempt to host a game server, access a NAS or PC remotely, or run a self-hosted service. In this guide, we will break down the options Starlink users have for getting around CGNAT, what each one requires, and who they are best suited for.
Open Ports Behind Starlink CGNAT With PureVPN
PureVPN’s Port Forwarding add-on lets you open selected ports through the VPN connection instead of Starlink’s CGNAT. Just follow these steps to get started:
- Sign up for PureVPN and add Port Forwarding to your plan.
- Download and install the PureVPN app, then sign in with your account.
- Open the Member Area, go to Subscriptions, and select Configure next to Port Forwarding.
- Choose Enable specific ports, enter the ports you want to open, and select Apply Settings.
- Connect to a location that supports Port Forwarding for your configured port forwarding rules to apply to the VPN connection.
Why Port Forwarding Fails on Starlink
Port forwarding does not work on Starlink for two reasons. Its default IPv4 connection uses CGNAT, meaning inbound ports are blocked before the traffic reaches your local network. The Starlink router also does not support port forwarding rules of its own.
Your connection is assigned an IPv4 address from the 100.64.0.0/10 range rather than a public IPv4 address of its own. Because the public-facing NAT is handled on Starlink’s network, a forwarding rule on your router cannot open the corresponding inbound port there.
So adding a third-party router does not remove CGNAT by itself. That said, Starlink does support port forwarding when you have a public IPv4 address assigned to an eligible service and use a third-party router with port forwarding support.
When Starlink CGNAT Becomes a Problem
Starlink’s CGNAT mainly causes problems when something outside your network needs to connect directly to a device or service inside it. Here are three common examples:
Hosting Games and Game Servers
Hosting a game server requires other players to connect back to a device on your network. Starlink’s CGNAT blocks those inbound connections from reaching a normally forwarded port. Peer-to-peer and player-hosted games can also face similar issues when one player needs to accept incoming traffic, depending on how the game handles connections.
Accessing Home Devices Remotely
A NAS, PC, camera system, or another home device may need to accept a direct connection from outside your network. Starlink’s CGNAT prevents that inbound IPv4 traffic from reaching a forwarded port on your router. The device can still work normally at home while remaining unreachable through a direct remote connection.
Running Self-Hosted Services
Self-hosted web apps, media servers, dashboards, and home-lab services can work normally inside your local network but still be inaccessible from the internet. External users or devices need an inbound path to the service. Starlink’s CGNAT blocks that path before the traffic reaches your router, so a normal forwarding rule cannot expose it externally.
Ways to Work Around CGNAT on Starlink
There are several ways to make inbound connections possible on Starlink, but the requirements are different for each one. The table below gives you a quick comparison before we look at them in more detail:
| Method | Why It Works | What You Need |
| Public IPv4 Address | Provides a public IPv4 address so inbound traffic can reach a compatible router | Eligible Starlink package + third-party router with port forwarding support |
| VPN With Port Forwarding | Routes supported inbound traffic through the VPN instead of Starlink’s CGNAT | VPN service with port forwarding capability |
| IPv6 Connection | Connects over IPv6 instead of the CGNATed IPv4 path | IPv6 support + suitable router and firewall controls |
| Reverse Tunnel or VPS | Receives traffic at an external endpoint and forwards it to your local service | Reverse tunnel service or public VPS |
Get a Public IPv4 Address
Starlink offers a public IPv4 option on eligible services. It gives your connection a publicly reachable IPv4 address instead of using the default CGNAT policy, which makes conventional port forwarding possible.
You will still need a third-party router with port forwarding support because the Starlink router does not provide forwarding controls of its own. A public IPv4 address is not the same as a static IP, and Starlink does not currently offer static IP addresses.
Forward Ports Through a VPN
A VPN with port forwarding gives inbound traffic another route instead of relying on Starlink’s CGNAT. The VPN service accepts traffic on a supported port and passes it through the VPN connection to your device.
You can use this approach for game servers, remote access, and self-hosted services behind Starlink CGNAT. PureVPN offers Port Forwarding as an add-on, and we will cover the steps for configuring it later in the guide.
Connect Over IPv6
Starlink provides native IPv6 connectivity and delegates a /56 IPv6 prefix to compatible routers through DHCPv6-PD. IPv6 traffic does not use the CGNATed IPv4 path, giving devices another way to communicate without relying on a public IPv4 address.
Both the hosted service and the device connecting to it need IPv6 support, and inbound traffic is still subject to firewall rules. Starlink WiFi routers do not provide IPv4 or IPv6 firewall-rule controls, so managing inbound IPv6 access may require a third-party router or firewall.
Set Up a Reverse Tunnel or VPS
A reverse tunnel starts from inside your Starlink network and connects to an external endpoint. Incoming traffic reaches that endpoint first and travels back through the existing tunnel to your local service, so there is no need to open an inbound port through Starlink’s CGNAT.
With a VPS, you control the public endpoint yourself and connect it back to your local service through a tunnel such as WireGuard or reverse SSH. Both approaches require an external endpoint and a connection back to the service on your Starlink network.
Frequently Asked Questions
Yes. Starlink’s default IPv4 configuration uses CGNAT and assigns addresses from the 100.64.0.0/10 range. Under this policy, inbound ports are blocked before traffic reaches your local network.
Not through Starlink’s default CGNAT connection using normal router port forwarding. You can use a public IPv4 address with a compatible third-party router, or forward ports through a VPN that supports port forwarding. IPv6 and reverse tunnels or VPSs are other options when you need inbound access without conventional IPv4 port forwarding.
Yes, Starlink offers an optional public IPv4 policy on eligible services. The address is reachable from the internet and can be enabled through the Starlink account dashboard where the option is available.
No. Starlink currently does not provide static IP addresses. Even when you have a public IPv4 address, it can change as Starlink makes changes to its network or, for mobile users, when the service moves between locations.
No. Bypass Mode turns off the Starlink router’s WiFi and lets a third-party router manage your network. It does not change Starlink’s IPv4 policy, so a connection using the default CGNAT policy will still remain behind CGNAT.
Yes. Starlink supports third-party routers with most kits, although the connection method depends on the hardware you have. Some kits require Bypass Mode or an Ethernet adapter, while others provide a direct Ethernet connection.







