
Closed
Posted
Paid on delivery
My 5G home connection is delivered through an Archer NX200 5G router and, like many 5G plans, it sits behind CGNAT. Because of this, I cannot reach my internal network from the outside world. The goal is clear: Remote Access. I need to log in reliably to my Computers, Smart Home Devices and Security Cameras, as well as a small PBX and a Draytek firewall. Dynamic DNS is already running with NOIP, yet CGNAT keeps every incoming request from ever reaching the LAN. What I’m looking for is a practical, reproducible way around that limitation: • A working solution that lets me initiate inbound connections (HTTPS, SSH, VoIP, etc.) from anywhere. • Detailed, step-by-step configuration on the Archer NX200 5G and any additional hardware, tunnel, or cloud service you recommend (e.g. WireGuard, OpenVPN, ZeroTier, Tailscale, IPv6 or similar). • Clear guidance on how to integrate the fix with NOIP/DDNS so hostnames stay updated. • Final validation that external access to each device category above is functional and secure. If you have already tamed CGNAT on 5G links, especially with TP-Link Archer or comparable routers, I’d like to see how you would implement and document the full setup so I can maintain it going forward.
Project ID: 40643850
36 proposals
Remote project
Active 16 hours ago
Set your budget and timeframe
Get paid for your work
Outline your proposal
It's free to sign up and bid on jobs
36 freelancers are bidding on average $153 USD for this job

With over a decade of experience dealing with network administration, cybersecurity and implementing Network infrastructure, I'm confident I can provide a reliable and reproducible solution to your CGNAT dilemma. My proficiency in a wide variety of vendors such as Cisco, VMware, IBM, etc., including routers like TP-Link Archer, make me the right choice for you. Regarding your specific requirements, I have successfully tackled issues similar to yours before. My expertise in VPNs would come in handy here - whether setting up WireGuard, OpenVPN or any other you prefer. I can also assure you that the end solution will integrate seamlessly with NOIP/DDNS Moreover, my abilities extend beyond just setting up the systems. I always prioritize clear documentation and training to ensure that my clients can continue maintaining their systems fluently themselves. Therefore, choosing me means choosing a flawless remote access fix with robust security without any hidden future complications. Don't leave your home network closed off from the world; let me help you "untether" your network!
$200 USD in 3 days
7.3
7.3

Hello, I’m a Senior Network & Security Engineer with 10+ years of hands-on experience designing, implementing, and migrating enterprise and service-provider networks. I specialize in Network Security, SD-WAN, routing & switching, enterprise wireless, and secure network architecture, helping companies modernize legacy networks, improve reliability, and reduce WAN costs. Core expertise: - Firewalls & Security: FortiGate, Palo Alto, Cisco ASA / Firepower IPsec & SSL VPN, site-to-site, remote access, policy design - Routing & Switching: Cisco ASR/ISR, Catalyst, Nexus, Juniper Routers (M10, MX 960) and SRX 500 (BGP, OSPF, EIGRP, IS-IS, MPLS, VLANs, STP, HSRP/VRRP) Enterprise LAN & campus design - LAN Switching (Multi-Vendor): Cisco, Juniper, Meraki, HP, Aruba, FortiSwitch Access/core design, redundancy, QoS, segmentation - Enterprise Wireless: Cisco WLC & APs, Cisco Meraki Wi-Fi, Ubiquiti, Aruba Wi-Fi, FortiAP Coverage design, roaming, security, troubleshooting - SD-WAN: Fortinet SD-WAN, Cisco SD-WAN (Viptela), Cisco Meraki (hub-and-spoke, MPLS + Internet, segmentation, HA, traffic steering) - Cloud & Hybrid Networking: AWS / Azure / GCP Site-to-site VPN, routing integration - Network Automation: Python Certifications: CCIE Enterprise Cisco Certified Specialist – Enterprise SD-WAN Implementation CCNP Data Center CCNP Security Juniper JNCIA-Junos, JNCIA-Cloud If you share your current setup and goal, I can propose a clear and practical solution. Best regards,
$30 USD in 1 day
6.6
6.6

Worked with all kind of servers and all panels since 2007 And currently working as linux system administrator If you need to start as soon as possible contact me And tell me more details about what you want to Tell the time and cost accurately, please contact me now, looking forward to work with you Best regards
$50 USD in 1 day
5.6
5.6

Hi, I reviewed your requirement to bypass CGNAT on a 5G Archer NX200 so you can reliably reach computers, smart home devices, security cameras, a PBX, and a Draytek firewall from anywhere. I’ll provide a practical, step-by-step setup using Network Monitoring, VPN, and Network Administration approaches, focusing on WireGuard/OpenVPN/Tailscale-style connectivity to initiate inbound HTTPS, SSH, and VoIP while pairing it with your existing NOIP Dynamic DNS updates. I’ll validate each device category end-to-end and keep the configuration clean, secure, and easy to maintain as your “remote access” baseline. Let’s discuss here now.
$150 USD in 7 days
5.2
5.2

As someone deeply familiar with Linux configurations and network management, I am confident in my ability to devise a proper solution to fix your CGNAT problem. Over my 8+ years in the field, I've dealt with a range of IT hurdles and understand the unique challenges that come with connecting internal networks to the outside world. My proficiency with essential tools like WireGuard, OpenVPN, and ZeroTier, combined with thorough knowledge of TP-Link Archer and similar routers, enable me to deliver step-by-step guidance tailored specifically to your setup. Furthermore, I'm well-versed in cloud services such as AWS, GCP, and DigitalOcean along with DNS management sites like NOIP/DDNS. This means that not only can I provide you with a clear integration process for your existing systems but also guarantee reliability moving forward. And as Cybersecurity is paramount for any remote access solution would implement robust security protocols without barring performance. The result: guaranteed access to every device category - computers, smart home devices, security cameras, PBX, and Draytek firewall - while ensuring top-notch security for your network. Opting for my services means gaining a technical partner who will continue providing comprehensive support even after project completion. Feel free to check out the positive feedback left by my satisfied clients as an assurance that you're putting your project in safe hands of a capable professional.
$150 USD in 2 days
4.4
4.4

The real challenge here isn't picking a tunnel, it's making sure the Archer NX200 can actually hold a persistent outbound connection without dropping it every time the carrier rotates your IP or the modem resets. Most 5G gateways aren't built for this. I'd run WireGuard from a cheap VPS back to the Archer, then reverse-proxy everything through that tunnel. If the Archer can't run WireGuard natively I'd drop a Pi or similar behind it to hold the tunnel and forward ports. Once I take a look at what the Archer supports and whether you've got a spare device or VPS already, I can map out the exact config and test it end to end. Built similar setups for CGNAT ISPs before, including the VPS work at ffulb.com. Can start whenever.
$166 USD in 3 days
3.9
3.9

Hi, I am a network and systems engineer with 8 years of rich experience in software and infrastructure troubleshooting, with a background in Linux, VPNs, VoIP, and secure remote access. I am familiar with WireGuard, OpenVPN, Tailscale, ZeroTier, IPv6, DDNS, NOIP, Asterisk PBX, network security, firewall configuration, and remote-access networking. For your 5G CGNAT setup, I can design a reliable remote-access path using a VPN overlay or VPS-based WireGuard tunnel, then configure routing and firewall rules so your computers, cameras, smart devices, PBX, and Draytek network can be reached securely from outside. I can also document how DDNS fits into the final setup and validate HTTPS, SSH, and VoIP access end-to-end. I'm an individual freelancer and can work on any time zone you want. Please contact me with the best time for you to have a quick chat. Looking forward to discussing more details. Thanks. Emile.
$250 USD in 7 days
3.5
3.5

Hi there, I see you're facing challenges with CGNAT blocking external access to your devices on the Archer NX200. I've successfully configured similar setups using WireGuard and OpenVPN to allow reliable inbound connections for users, turning CGNAT barriers into non-issues. I can provide a step-by-step guide to configure your router along with recommendations for additional hardware or services that fit your needs. In a previous project, I documented the full configuration for a client in a similar situation, enabling them to securely access their home network remotely. I can deliver this complete solution for $500 in 5 days. What specific devices or applications do you need help accessing remotely?
$110 USD in 5 days
3.1
3.1

Hi there, I see you’re facing issues with CGNAT on your 5G connection, and I have practical suggestions for overcoming this challenge. I recommend implementing a solution using WireGuard or Tailscale, which can create secure tunnels for remote access. I will provide you with detailed, step-by-step instructions for configuring your Archer NX200 router and any additional necessary hardware or services, ensuring seamless integration with your existing NOIP/DDNS. Your satisfaction is my priority and I guarantee that I will deliver you a high-quality result. Regards, Ali
$140 USD in 1 day
2.3
2.3

I propose setting up a secure VPN solution on your TP-Link Archer NX200 router to enable reliable remote access to your network despite CGNAT restrictions. By utilizing WireGuard or OpenVPN, we can establish encrypted tunnels for inbound connections, bypassing CGNAT blocks. Pairing this with NOIP for dynamic DNS resolution will ensure seamless access management. Thorough testing will be conducted to validate external access to your devices, guaranteeing functionality and security. With my expertise in addressing CGNAT challenges and optimizing TP-Link Archer routers, I am committed to providing a long-term, efficient, and secure remote access solution to meet your current and future needs.
$225 USD in 5 days
2.1
2.1

Hi there, The hard part is navigating CGNAT restrictions while ensuring secure external access to your devices. To tackle this, I propose setting up a VPN solution like WireGuard or Tailscale, which can effectively bypass CGNAT by establishing a secure tunnel for your devices. Phase one would involve configuring your Archer NX200 5G router to allow outbound connections and setting up the VPN server. Phase two will include integrating this with NOIP to keep your hostnames updated and testing access to ensure each device is reachable and secure. Have you considered which devices you'll prioritize for remote access first? Looking forward to discussing the details in chat.
$140 USD in 7 days
2.0
2.0

مرحباً، لدي خبرة في الشبكات وVPN وحلول تجاوز CGNAT، ويمكنني إعداد وصول آمن ومستقر إلى أجهزتك عبر WireGuard أو Tailscale/ZeroTier حسب الأنسب لشبكتك. هل لديك VPS بعنوان IP عام حالياً؟ وهل يدعم اتصال 5G لديك IPv6؟ وهل تريد الوصول إلى الـ PBX والكاميرات عبر VPN فقط أم تحتاج أيضاً إلى فتح خدمات معينة مباشرةً للإنترنت؟ يمكنني إعداد الحل بالكامل، اختباره، وتزويدك بخطوات واضحة لإدارته لاحقاً. شكراً.
$80 USD in 2 days
1.8
1.8

Hello, I can help you turn the Archer NX200 5G setup into a reliable remote-access solution despite CGNAT. The practical path is to move the inbound edge to a VPN/tunnel endpoint that has a public address, then route only the required services through it securely. I would document and implement the full setup step by step, including: - Archer NX200 5G configuration and any required WAN/LAN changes - A stable remote-access design using WireGuard, Tailscale, ZeroTier, OpenVPN, or IPv6 where available - Integration with NOIP/DDNS so hostnames remain consistent - Secure access patterns for computers, smart home devices, cameras, PBX, and the Draytek firewall - Validation of HTTPS, SSH, VoIP, and device reachability from outside I’ll keep the instructions practical and reproducible so you can maintain the solution long-term, not just get it working once. If you want, I can also tailor the design around the least amount of extra hardware possible or optimize for maximum security and simplicity. Best regards.
$250 USD in 4 days
1.3
1.3

Hello, "CGNAT on my Archer NX200 5G router blocks inbound traffic, so I cannot reach my internal network from outside." I will install a lightweight WireGuard server on a cheap Linux VPS, route the Archer’s WAN to it, and bind the tunnel to NoIP so each device (PCs, cameras, PBX) is reachable via a stable hostname while keeping the traffic encrypted. Do you have a spare Ethernet port on the Archer NX200 for a dedicated VPN gateway, or would you prefer a cloud‑hosted tunnel? Looking forward to working with you. Bojan
$250 USD in 2 days
1.4
1.4

Hi, A well-designed network setup makes remote access seamless, and with that in mind, I will implement a dedicated static IP solution to bypass CGNAT on your 5G network. My approach uses a cloud VPS tunnel to route external inbound traffic to your SIP devices and router management portal. Let me know if your Archer NX200 router supports WireGuard client mode natively. Recently, I worked on a similar project, SecureRoute Hub, a remote access setup designed to bypass cellular CGNAT without localized hardware. I personally configured a cloud VPS with static IP routing, deployed WireGuard VPN tunnels, set up iptables port forwarding, and integrated No-IP DDNS to allow direct inbound traffic to internal IP phones and local devices. I look forward to discussing the project further and helping bring your vision to life. Best, Ariba
$140 USD in 7 days
0.0
0.0

The bottleneck is CGNAT blocking inbound connections to your LAN on the Archer NX200 5G. This stems from the router and 5G ISP setup that disallows direct port mappings. I will architect a VPN or tunnel solution like WireGuard combined with your existing NOIP DDNS to enable reliable access to HTTPS, SSH, VoIP, and PBX systems. Configuration will focus on the Archer interface plus a lightweight cloud or on-prem intermediary for persistent external reachability. Final testing will confirm secure access to all device categories with thorough documentation provided. What current remote access methods have you tried besides NOIP, and what were their limitations?
$500 USD in 7 days
0.0
0.0

You need reliable remote access over a 5G connection behind CGNAT on an Archer NX200, with NOIP DDNS already in place. I’ll deliver a practical, step-by-step configuration to enable inbound access to your LAN for HTTPS, SSH, VoIP/PBX services, smart home devices, and security cameras, without relying on static port forwards that CGNAT blocks. Approach: establish an outbound VPN/tunnel from the LAN to a reachable endpoint (e.g., WireGuard-based or a similar CGNAT-friendly overlay), integrate NOIP updates so your DNS stays consistent, then route or securely expose only the required services (including your Draytek firewall and small PBX). I’ll include verification steps per device category and a hardening checklist (firewall rules, least-privilege access, key management, and monitoring) so external access is both functional and secure.
$30 USD in 5 days
0.0
0.0

I would love to chat about your project ⚠️THE WORST THAT CAN HAPPEN IS YOU WALK AWAY WITH A FREE CONSULTATION⚠️. We work with a select group of clients to provide focused support and better results. Your need for reliable remote access through CGNAT is clear, and I can help you achieve that. Our approach includes a comprehensive, practical solution that allows you to initiate inbound connections to your devices seamlessly. We’ll provide detailed, step-by-step configuration guidance for your Archer NX200 5G router and recommend any necessary hardware or services like WireGuard, OpenVPN, or similar. Integration with NOIP/DDNS will be straightforward, ensuring your hostnames remain updated. Expect thorough validation of external access to all devices, ensuring functionality and security. IF YOU'RE NOT HAPPY YOU DON'T PAY. So, feel free to message me. Check out my portfolio for similar successful implementations: [Your Portfolio Link].
$150 USD in 7 days
0.0
0.0

I'm one of a very few people who is really able to solve this issue, i faced this problem many times and i was able to beat it for different use cases, i can make you reach your LAN from any external network on the planet, let's go!
$190 USD in 7 days
0.0
0.0

I can help implement a practical remote-access solution for your Archer NX200 5G connection without requiring a Business SIM or a PC running 24/7. I would first verify the current CGNAT setup and the NX200's available networking capabilities, then determine whether WireGuard, Tailscale, ZeroTier, or a VPS-based tunnel is the most suitable approach. The solution would be designed around your existing network and the devices you need to access, including computers, cameras, smart-home devices, PBX, and the DrayTek firewall. I’ll configure the required routing, firewall rules, tunnel, and DNS/DDNS integration, then test external connectivity to each required device category. I’ll also provide clear documentation of the configuration so you can maintain the setup after completion. Bid: $125 fixed Timeline: 3–5 days
$100 USD in 3 days
0.0
0.0

Riyadh, Saudi Arabia
Payment method verified
Member since Jul 30, 2025
$13 USD
$10 USD
$30-250 USD
$30 USD
$10-30 USD
$30-250 USD
₹1500-12500 INR
€2-6 EUR / hour
$250-750 USD
$250-750 USD
$25-50 USD / hour
$30-250 CAD
$30-250 USD
$25-50 USD / hour
$10-30 USD
$250-750 USD
₹100-400 INR / hour
$25-50 USD / hour
$10-30 USD
$3000-5000 USD
$8-15 USD / hour
₹12500-37500 INR
₹75000-150000 INR
$250-750 USD
$250-750 CAD