Static IP, CGNAT and port forwarding

What CGNAT is

By default residential ASH NET connections share public IPv4 addresses using Carrier-Grade NAT (CGNAT). Browsing, streaming, gaming, video calls and email are unaffected, but inbound connections from the internet do not work: port forwarding, hosting a server, remote access to CCTV/NVRs and some VPNs, and “strict NAT” on Xbox/PlayStation. Websites may also think you are in Auckland, because your traffic leaves from our Auckland gateway.

The fix: a static IP

A static IPv4 address is assigned to you alone and fixes all of the above. It is $10/month on any plan, no set-up fee, cancel any time. Our Home Fibre 500 PRO and 920 PRO plans include one.

  1. Email [email protected] with “Please add Static IPv4” and your reference number (or reply to any ASH NET email).
  2. It is normally live within 30 minutes to 2 hours of our confirmation, with a few minutes’ downtime. If it has not appeared after a couple of hours, restart your router.
  3. Leave the router on DHCP / Dynamic IP – the static address is applied from our side. Typing it into the router manually will break the connection.

Port forwarding once you have a static IP

Set up the forward in your router (on the HX510/VX230v: Advanced → NAT Forwarding → Port Forwarding, or Port Forwarding in the Aginet app): the external port, the internal IP address of the device (give it a DHCP reservation so it does not change) and the internal port. Test from outside your network – from a phone on mobile data, not Wi-Fi.

Occasionally a static address changes during network changes – we email you the new one. Update firewall rules, VPN and port-forwarding settings afterwards.

IPv6 is another way to reach devices at home directly – see IPv6 on ASH NET.

Still need help? Email [email protected] or log a ticket in the customer portal.