By default Starlink uses CGNAT for IPv4 (100.64.0.0/10), which blocks all inbound ports. The Starlink router can't port forward. You need a third-party router plus a public IP.
1. Use the maker’s cloud or P2P app (easiest)
You need: a camera or recorder that has one. Most do: Reolink’s UID/P2P, Lorex Cloud, Hik-Connect, eufy’s app. Skip if: your recorder has no cloud option, or you don’t want video going through the maker’s servers.
- Turn off DDNS and port-forward settings in the camera or recorder. They can’t work here.
- Turn on the cloud/P2P/UID option (the name varies by maker).
- Add the device in the maker’s phone app by scanning its QR code or entering its ID.
- Test from your phone on cellular, with Wi-Fi off.
2. Tailscale (works with almost anything)
You need: one always-on device at home that can run Tailscale (a small computer, a NAS, some routers), and the Tailscale app on your phone. Skip if: fix 1 works for you; it’s simpler.
Tailscale builds a private link between your devices. It doesn’t need an open port: devices punch through NAT on their own and fall back to Tailscale’s relays when they can’t. Tailscale’s own write-up on NAT traversal covers CGNAT directly.
- Install Tailscale on the home device and sign in.
- Turn on “subnet router” for your home network range, so your phone can reach the cameras through it. Approve it in the Tailscale admin page.
- Install Tailscale on your phone with the same account.
- Open the camera or recorder’s local address (or the maker’s app in local mode) from your phone on cellular.
3. IPv6 (sometimes)
Starlink gives the WAN an IPv6 /64 by SLAAC, and IPv6 works on all Starlink routers. If the camera or recorder has a global IPv6 address and your phone has IPv6 too, you may be able to reach it directly. It depends on the router’s firewall, the camera’s IPv6 support and your phone carrier, so treat it as a bonus, not a plan. Leaving a recorder open to the internet also means keeping its firmware and password strong.
When to skip all three
- You only need alerts and clips, not live view: most cloud cameras already send those.
- You were going to pay for a plan with a public IPv4 address just for cameras: try fix 1 or 2 first. They cost nothing extra.
Questions people ask
Can I port forward on Starlink?
Not on Residential. The Starlink router can’t port forward, and IPv4 runs behind CGNAT, which blocks inbound ports. Starlink says public IPv4 comes only with its Local and Global Priority plans.
Is Tailscale free?
Tailscale has a free personal plan; check its current limits on tailscale.com. We don’t earn anything from it.
Will IPv6 fix it?
Sometimes. Starlink gives every connection an IPv6 range, so a camera or recorder with IPv6 can be reachable directly, if the phone you view from also has IPv6 (many cellular carriers do) and the router allows it. It’s the least predictable fix of the three.
What about VPNs for work?
This page is about cameras. Work VPNs, hosting and gaming behind CGNAT are a different problem with different fixes.
Sources
- Starlink Help: What IP address does Starlink provide?, read in search results, checked Oct 5, 2026
- Starlink Help: Can I port forward with the Starlink router?, read in search results, checked Oct 5, 2026
- Tailscale Docs: Connection types, checked Oct 5, 2026
- Tailscale blog: How NAT traversal works, checked Oct 5, 2026
- Reolink Support: How to Enable UID for Reolink Products, checked Oct 5, 2026
- Hikvision USA: What options do I have for remote access, other than Hik-Connect?, checked Oct 5, 2026