
Closed
Posted
Paid on delivery
I have an STC 5G connection running on a TP-Link Archer NX200 router. The connection is behind CGNAT, meaning I do not have a real public IP. I am looking for an expert to provide a solution to get a Dedicated Static Public IP so I can remotely access my internal network (Router management, SIP devices, etc.) using my noip DDNS Conditions: I cannot upgrade to a Business SIM card. I do not want to run a local PC 24/7 as a bridge. I just need a working Static IP solution that routes traffic from the outside directly into my local network. Please propose your method and how we can implement i
Project ID: 40643637
15 proposals
Remote project
Active 2 days ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
15 freelancers are bidding on average $22 USD for this job

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
$20 USD in 1 day
6.6
6.6

Worked with all kind of servers and all panels since 2007 And currently working as linux system administrator If you need to start as soon as possible contact me And tell me more details about what you want to Tell the time and cost accurately, please contact me now, looking forward to work with you Best regards
$30 USD in 1 day
5.6
5.6

I can help you. Don’t fight CGNAT — tunnel out of it. I’ll set up a low-cost VPS with a static public IP, then configure your Archer NX200’s built-in OpenVPN client to maintain a permanent outbound tunnel to that VPS. That gives you a public entry point into your network without a business SIM and without running a local PC. Implementation: 1. Provision a minimal VPS with a static IP and install OpenVPN server. 2. Configure the Archer NX200 as the VPN client — no extra hardware, no 24/7 PC. 3. On the VPS, forward the exact ports you need through the tunnel to your router and SIP devices (e.g., 80/443 for router admin, 5060/5061 + RTP range for SIP). 4. Point your noip DDNS hostname to the VPS IP. Result: outside traffic reaches your internal network through the tunnel, bypassing CGNAT completely.
$20 USD in 7 days
4.5
4.5

Hi there, I can implement a solution to obtain a static public IP for your STC 5G connection using a VPN or tunneling method that fits within your existing setup. This will enable you to access your internal network without the need for a PC to run 24/7. I’ll ensure that the required configuration aligns with your router capabilities and your DDNS setup. Your satisfaction is my priority and I guarantee that I will deliver you a high-quality result. Regards, Ali
$10 USD in 1 day
2.3
2.3

مرحباً، يمكنني حل مشكلة CGNAT وتوفير وصول خارجي عبر IP عام ثابت باستخدام VPS مع نفق WireGuard، بدون الحاجة إلى تشغيل جهاز كمبيوتر محلي 24/7. سأقوم بإعداد التوجيه والوصول إلى الراوتر وأجهزة SIP والشبكة الداخلية، مع دمج NO-IP إذا كان مطلوباً. هل لديك VPS حالياً؟ وهل يمكن للـ Archer NX200 أو جهاز DrayTek داخل الشبكة تشغيل WireGuard أو VPN Client بشكل دائم؟ شكراً.
$20 USD in 2 days
1.8
1.8

Hi, I can help you solve the CGNAT limitation on your STC 5G + TP-Link Archer NX200 setup without requiring a Business SIM or a local PC running 24/7. I’ll first assess the available options for your STC connection and determine the most reliable architecture for obtaining a **dedicated/static public IPv4 endpoint** and securely routing inbound traffic to your internal network. Where native public IP allocation is not available through the mobile connection, I can implement a **cloud-based VPN/tunnel solution** using a VPS with a static public IP. The NX200/network can establish an outbound VPN tunnel to the VPS, allowing controlled inbound access to your router management interface, SIP devices, and other required services despite CGNAT. I can configure: * Static public IP on a suitable VPS * WireGuard/OpenVPN site-to-site tunnel * NAT/port forwarding and firewall rules * No-IP DDNS integration * Secure remote router/network access * SIP traffic and required ports * Access restrictions and security hardening * Persistent automatic reconnection This approach requires **no Business SIM and no 24/7 local PC**, while providing a stable public endpoint that can be accessed remotely. I’ll focus on a secure, maintainable setup rather than exposing unnecessary internal services directly to the internet.
$20 USD in 7 days
1.6
1.6

We could get a Free-tier Server in some cloud that provides it (I know Google Cloud does, but there are others too) and use it as an proxy to access your applications. Depending on what exactly are you wanting to achieve or which systems you need access to I can provide better solutions. EDIT: I think your router model supports OpenVPN connections. I think we can set up an VPN server on the cloud and connect that to your router. That will dismiss the need for a 24/7 computer and will give you the capability to forward requests from the public static IP to your local net.
$15 USD in 7 days
1.3
1.3

⭐⭐⭐⭐⭐ Hi, I understand you need a reliable way to remotely access your STC 5G home network behind CGNAT using the TP-Link Archer NX200, without upgrading to a business SIM or keeping a local PC running as a bridge. The main challenge is that CGNAT prevents direct inbound connections, so traditional port forwarding and DDNS solutions like No-IP will not work unless a public endpoint is introduced. I would evaluate solutions such as a cloud-based VPN tunnel, reverse proxy/VPN gateway, or compatible router-level tunneling approach that provides secure remote access to your internal devices. I have experience with network administration, VPN solutions, remote access architectures, VoIP connectivity, and troubleshooting NAT/firewall limitations. I focus on solutions that are stable, secure, and practical for real-world home and small business networks. I will first review your current router configuration and access requirements, then implement and test the selected approach, verify remote access to your router/SIP devices, and provide clear documentation so you can maintain the setup.
$30 USD in 2 days
0.0
0.0

Hi there, Your CGNAT is blocking inbound access to your Archer NX200, so remote SIP and router management won’t reach your LAN directly. I’ve solved this exact Linux, VPN, and SIP connectivity problem by setting up a secure public endpoint or tunnel-based bypass that preserves No-IP access without a 24/7 PC. I’ll map the best method for STC 5G, test the router’s WAN behavior, then implement a clean path using VPN or a dedicated public IP relay so traffic routes into your network reliably. Best regards, Marko
$25 USD in 3 days
0.0
0.0

We have over 5 years experience with similar projects for home networking solutions. You're looking to bypass CGNAT on your STC 5G connection to obtain a dedicated static public IP for remote access without upgrading to a Business SIM or running a local PC 24/7. To address your needs, I would explore options such as utilizing a VPN service or a tunneling solution that can provide a static IP while maintaining direct traffic flow to your internal network. This approach ensures you can manage your router and SIP devices effectively without additional hardware. Deliverables: * Initial assessment of your current setup * Recommendation for a suitable VPN or tunneling service * Configuration of the solution for static IP assignment * Testing to ensure seamless remote access * Documentation for future reference I am happy to share relevant examples of similar projects I have completed. Let’s discuss the best approach for your situation. Regards, Ryan
$14 USD in 7 days
0.0
0.0

Hello, I can help you solve the STC 5G CGNAT limitation and provide reliable remote access to your internal network without upgrading to a Business SIM or keeping a PC running 24/7. My recommended approach is to use a small VPS with a dedicated static public IPv4 as the Internet-facing endpoint, connected securely to your TP-Link Archer NX200 through a WireGuard tunnel. **Implementation:** * Configure a VPS with a dedicated static public IP. * Set up and secure WireGuard on the VPS. * Establish an outbound VPN tunnel from your local network, bypassing STC CGNAT. * Configure routing and firewall/NAT rules for your internal LAN. * Enable secure remote access to router management, SIP devices, and required services. * Configure No-IP DDNS where appropriate. * Test connectivity from an external network and verify SIP functionality. * Provide documentation of the final configuration. This solution avoids the need for a Business SIM and eliminates the requirement for a local PC to run continuously. I have strong experience with routing, VPNs, NAT, firewalls, and network troubleshooting. I will first verify the NX200 firmware and VPN capabilities and then implement the most reliable architecture for your environment. Available to start immediately.
$25 USD in 7 days
0.0
0.0

Your Archer NX200 can maintain an outbound OpenVPN tunnel, so CGNAT can be bypassed without a business SIM or a 24/7 PC. I will first confirm the exact firmware and required SIP/RTP ports, then configure a small VPS with a static IPv4, the NX200 as OpenVPN client, and controlled DNAT/firewall rules through the tunnel. No-IP can point to the VPS, although its address is already static. I will test access from an external network and provide a rollback-ready configuration and diagram. The VPS/static-IP subscription must be in your account. Please fund the $30 milestone before configuration; I can start immediately.
$30 USD in 1 day
0.0
0.0

Hi, I can help with this. Since the STC 5G connection is behind CGNAT, No-IP/DDNS and normal port forwarding on the NX200 will not work directly. TP-Link also confirms that port forwarding cannot solve CGNAT when the ISP controls the upstream NAT. My recommended solution is to use a small cloud VPS with a dedicated public IPv4 address as the VPN gateway. I would configure the VPS as the public endpoint and establish a persistent VPN tunnel from the local network to it. This avoids the need for a public IP on the STC connection and does not require a PC to stay online. From there, we can route only the required traffic back to your LAN, allowing secure remote access to router management, SIP devices and other internal services. I would also configure appropriate firewall rules and avoid exposing the router or SIP devices directly to the Internet wherever possible. The implementation would include: VPS with dedicated public IPv4 Secure VPN tunnel between VPS and your network Routing/NAT configuration Firewall rules Access to required LAN subnets/devices No-IP DDNS if you still want to use it Connectivity testing from an external network This approach keeps your existing STC 5G connection and avoids requiring a Business SIM or an always-on local computer. Best regards,
$20 USD in 7 days
0.0
0.0

**Your STC 5G CGNAT is the problem — not No-IP DDNS.** Because the Archer NX200 is behind CGNAT, pointing No-IP directly at the connection won't give you reliable inbound access. I would solve this without requiring a Business SIM or a PC running 24/7. My preferred architecture is: ```text Internet ↓ Static Public IP ↓ Small VPS ↓ WireGuard VPN Tunnel ↓ STC 5G / CGNAT ↓ TP-Link Archer NX200 ↓ Router + SIP + Internal Devices ``` The VPS acts as the public entry point while the VPN tunnel provides a secure path back through the CGNAT connection. I can configure the routing so you can securely reach the required internal services, including router management and SIP devices, while keeping the rest of the network protected. I'll handle: • VPS + static public IP configuration • WireGuard VPN • CGNAT traversal • Routing/NAT configuration • No-IP DDNS integration where appropriate • SIP connectivity considerations • Firewall/security rules • Remote-access testing • Documentation so you can maintain it afterward The important part is that **no always-on local PC is required**. I'd first verify the NX200's available VPN/routing capabilities and then implement the cleanest architecture around it. **Bid: $30** **Delivery: 3–5 days**
$30 USD in 5 days
0.0
0.0

Riyadh, Saudi Arabia
Payment method verified
Member since Jul 30, 2025
$10 USD
$10-12 USD
$10 USD
$30-250 USD
$10-30 USD
$10-30 USD
£250-750 GBP
$250-750 USD
$10-30 CAD
₹12500-37500 INR
$10-30 USD
₹600-1500 INR
$250-750 USD
$30-250 USD
$25-50 AUD / hour
€750-1500 EUR
₹2000000-2400000 INR
$15-25 USD / hour
$25-50 USD / hour
$30-250 CAD
$25-50 USD / hour
$30-250 USD
₹37500-75000 INR
₹1500-12500 INR
$30-250 USD