Public edge for private infrastructure

Private services.
Public reachability.

ClearNAT gives services behind NAT a stable public endpoint through a controlled edge, while your application stays on your own machine.

IPv4 RAW TCP presentationFail-closed controller design
route / raw-tcpEDGE READY
01
ClearNAT edgelis1.clearnat.net:61344
A
Your serviceclient :8080
Stable endpointPublic IPv4 + port
Encrypted pathWireGuard overlay
Crash-awareDurable operations
Built for controlled exposure

One public route. Your infrastructure stays yours.

ClearNAT separates public reachability from workload hosting. The edge owns exposure; your client machine owns the application.

01 / ROUTE

Stable public node

Receive a ClearNAT node, allocated public port and DNS name for the service you choose to expose.

02 / AGENT

Small client footprint

Download the agent configuration for your route, keep the app on your own host, and bind only the intended client port.

03 / CONTROL

Fail-closed lifecycle

Exposure is modeled as durable state. Suspension and recovery prioritize removing reachability before reporting a safe terminal state.

Three steps

From private port to public endpoint.

STEP 01

Create your account

Sign in to the client portal and view the routes assigned to your ClearNAT account.

STEP 02

Download agent config

Install the ClearNAT agent on the private host and use the route-specific configuration from your dashboard.

STEP 03

Serve the client port

Your public ClearNAT node forwards approved traffic through the overlay to the configured client port.

Ready to present ClearNAT?

Open the client portal and walk through the complete customer experience.

Open client portal