nekotopia.io

a community for home labbers and retro geeks

Public IP · behind any NAT

Your homelab is trapped behind CGNAT. Give it a real public IP.

Your ISP put you behind carrier-grade NAT, so port forwarding does nothing and you can't host a thing. Nekotopia routes a dedicated, routable public IPv4 straight to the box in your basement, over a single outbound WireGuard tunnel. No VPS and no port forward.

Create a free account → See the live BGP looking glass basic tier free · public IP free, ask the maintainer

Why port forwarding stopped working

IPv4 ran out, so most ISPs now share one public address across hundreds of customers using CGNAT (carrier-grade NAT, the 100.64.0.0/10 range). You don't own the public IP your traffic leaves from, so there's no router setting that exposes your services; the forward has to exist on hardware you'll never touch. Mobile, Starlink, 5G home internet, and a growing share of fibre are all CGNAT by default.

Two ways to get a real address

Both ride the same WireGuard tunnel your homelab opens outbound, so they work behind CGNAT, double-NAT, or a locked-down corporate firewall.

nSolo

Dedicated public IPv4

Free, ask the maintainer

A public IPv4 address that's yours alone, mapped to your tunnel by bidirectional NAT at your nearest regional hub. Point DNS at it and host whatever you like.

  • Any protocol: TCP and UDP
  • Outbound by default; flip the Inbound toggle to expose services
  • Your own reverse DNS / PTR
  • Addresses from our 193.143.16.0/23 BYOIP block

nColo

Your own BGP-routed prefix

Free, ask the maintainer

We allocate you a routable IPv4 prefix; you run your own router, peer with the hub over WireGuard, and advertise it. Your network, on the global table.

  • Routed public RIPE NCC IPv4 and IPv6 space using our ASNs
  • Bring-your-own-router BGP session over the tunnel
  • Run a real edge with your own ASN
  • Visible on our public looking glass

How it works

Three steps, about ten minutes. No changes to your ISP router.

01

Open a tunnel

Your homelab brings up a WireGuard tunnel to the nearest of our hubs, in London and Ohio today, with more regions coming. Outbound only, so CGNAT never sees it as a server.

02

Get your address

We bind a dedicated public IPv4 (nSolo) or route your prefix (nColo) to that tunnel. Traffic to the address arrives on your box as if it were on the open internet.

03

Host anything

Point DNS at your IP and serve a website, game server, mail, SSH, a VPN, or whatever else. It runs on your hardware, at home, on a real address.

Why not just use a tunnel service or a VPS?

Each of these is good at something, but none give your own hardware a dedicated, any-protocol public IP.

  Cloudflare Tunnel / ngrok Tailscale Funnel VPS Nekotopia
Works behind CGNATYesYesN/A (it's their box)Yes
Dedicated public IPv4Shared / hostnameSharedYesYes
Any protocol (TCP and UDP)Mostly HTTPLimitedYesYes
Runs on your own hardwareYesYesNoYes
Your own rDNS / BGP prefixNoNoSometimesYes (nColo)
Starting priceFree–$$Free–$$$$/moFree, ask the maintainer
AS213811 + AS61081our own ASNs, RIPE NCC member
2 live regionsWireGuard hubs, London & Ohio
193.143.16.0/23BYOIP space for nSolo
Public looking glassreal routes, real BGP

Put your basement on the internet

Start free on the Basic mesh. nSolo and nColo are switched on after a chat with the maintainer once you're using it. Built by one homelabber for others.