Public IP · behind any NAT
Your homelab is trapped behind CGNAT. Give it a real public IP.
Your ISP put you behind carrier-grade NAT, so port forwarding does nothing and you can't host a thing. Nekotopia routes a dedicated, routable public IPv4 straight to the box in your basement, over a single outbound WireGuard tunnel. No VPS and no port forward.
Why port forwarding stopped working
IPv4 ran out, so most ISPs now share one public address across hundreds of customers using
CGNAT (carrier-grade NAT, the 100.64.0.0/10 range). You don't own the
public IP your traffic leaves from, so there's no router setting that exposes your services;
the forward has to exist on hardware you'll never touch. Mobile, Starlink, 5G home internet, and
a growing share of fibre are all CGNAT by default.
Two ways to get a real address
Both ride the same WireGuard tunnel your homelab opens outbound, so they work behind CGNAT, double-NAT, or a locked-down corporate firewall.
nSolo
Dedicated public IPv4
Free, ask the maintainer
A public IPv4 address that's yours alone, mapped to your tunnel by bidirectional NAT at your nearest regional hub. Point DNS at it and host whatever you like.
- Any protocol: TCP and UDP
- Outbound by default; flip the Inbound toggle to expose services
- Your own reverse DNS / PTR
- Addresses from our
193.143.16.0/23BYOIP block
nColo
Your own BGP-routed prefix
Free, ask the maintainer
We allocate you a routable IPv4 prefix; you run your own router, peer with the hub over WireGuard, and advertise it. Your network, on the global table.
- Routed public RIPE NCC IPv4 and IPv6 space using our ASNs
- Bring-your-own-router BGP session over the tunnel
- Run a real edge with your own ASN
- Visible on our public looking glass
How it works
Three steps, about ten minutes. No changes to your ISP router.
01
Open a tunnel
Your homelab brings up a WireGuard tunnel to the nearest of our hubs, in London and Ohio today, with more regions coming. Outbound only, so CGNAT never sees it as a server.
02
Get your address
We bind a dedicated public IPv4 (nSolo) or route your prefix (nColo) to that tunnel. Traffic to the address arrives on your box as if it were on the open internet.
03
Host anything
Point DNS at your IP and serve a website, game server, mail, SSH, a VPN, or whatever else. It runs on your hardware, at home, on a real address.
Why not just use a tunnel service or a VPS?
Each of these is good at something, but none give your own hardware a dedicated, any-protocol public IP.
| Cloudflare Tunnel / ngrok | Tailscale Funnel | VPS | Nekotopia | |
|---|---|---|---|---|
| Works behind CGNAT | Yes | Yes | N/A (it's their box) | Yes |
| Dedicated public IPv4 | Shared / hostname | Shared | Yes | Yes |
| Any protocol (TCP and UDP) | Mostly HTTP | Limited | Yes | Yes |
| Runs on your own hardware | Yes | Yes | No | Yes |
| Your own rDNS / BGP prefix | No | No | Sometimes | Yes (nColo) |
| Starting price | Free–$$ | Free–$$ | $$/mo | Free, ask the maintainer |
Put your basement on the internet
Start free on the Basic mesh. nSolo and nColo are switched on after a chat with the maintainer once you're using it. Built by one homelabber for others.