QGTunnel Alternative: Static IP Database Tunnels
QGTunnel is QuotaGuard's wrapper that opens local ports to databases and other TCP services through your QuotaGuard static IPs, with optional transparent DNS and encryption modes. The alternatives are a SOCKS5-capable driver, Fixie's open-source fixie-wrench, or Fixedmark's planned bm tunnel CLI, which maps explicit ports from a local config file. Fixedmark is in early access.
Fixedmark vs QGTunnel at a glance
Fixedmark values are planned launch features and pricing. QGTunnel values are taken from published vendor pages and attributed below. Checked October 2026.
| Fixedmark bm tunnel (planned) | QGTunnel (published) | |
|---|---|---|
| Status | Planned for launch. Early access. | Available with QuotaGuard plans |
| How it runs | Separate process, for example bm tunnel 5432:db.example.com:5432 & | Wraps your start command: bin/qgtunnel <your command> |
| Configuration | Local config file only. No API call at startup. | Fetched from QuotaGuard's API by default. A local .qgtunnel file is supported. |
| Hostnames | Connect to 127.0.0.1 and set the TLS server name to the real host | Transparent mode overrides DNS so the original hostname resolves to 127.0.0.1 |
| Plaintext protocols | Use the protocol's own TLS, such as rediss:// | Optional encrypted mode, end to end |
| Direct SOCKS5 | Included on every plan for drivers that support it | SOCKS5 included on every QuotaGuard plan |
| Cost to get it | Starter $9/mo shared pair, Pro $29/mo dedicated pair | QuotaGuard Static from $19/mo shared pair, $219/mo dedicated pair |
What QGTunnel does well
Transparent mode is the main draw. QGTunnel makes the database hostname resolve to a local port, so a Rails or Django app can keep its existing DATABASE_URL and still leave from a static IP. Its encrypted mode can also wrap protocols that have no TLS of their own, such as some Redis setups. Per QuotaGuard's guide, you only need encrypted mode when the protocol is not already encrypted.
Startup and DNS trade-offs
By default QGTunnel fetches its configuration from QuotaGuard's API when your process starts. QuotaGuard documents a fix: download the config and commit it as .qgtunnel, so startup does not depend on its website. Do that for production.
Overriding DNS inside your process can affect unrelated lookups. QuotaGuard's own blog describes Ruby Socket::ResolutionError failures on third-party API calls in transparent mode, fixed by turning transparent mode off. Without transparent mode, you point the driver at 127.0.0.1, which is how bm tunnel works.
Pick the simplest path that works
For each connection, start at the top of this list:
- Driver supports SOCKS5 or a custom dialer, such as the MongoDB Node driver or Go's pgx: use the SOCKS5 URL directly. Nothing extra runs.
- Driver has no proxy support and you run a long-lived process: use a local tunnel. That is
bm tunnel, QGTunnel, orfixie-wrench, depending on your provider. - Code runs in serverless functions: a background tunnel cannot run, so use a SOCKS5-capable driver.
When to keep QGTunnel
QGTunnel is the better fit if:
- You need a working tunnel in production today. Fixedmark is in early access.
- You cannot change connection strings and need transparent DNS mode.
- You connect over a protocol with no TLS and want the tunnel to encrypt it.
- You already use QuotaGuard and your partners have its IPs allowlisted.
When bm tunnel fits better
The planned bm tunnel CLI suits teams that want:
- A tunnel that starts from local config with no network call to a control plane.
- No DNS changes inside the app process.
- A dedicated IP pair at $29/mo shared by tunnels, SOCKS5, and HTTP calls.
- Per-connection logs that show which database host each tunnel reached.
Sources
Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.
Related guides
- ComparisonQuotaGuard alternativeQuotaGuard Static and Shield published plans next to Fixedmark's planned $29 dedicated pair.
- Use casePostgres and MySQLAllowlist two IPs on RDS, Cloud SQL, or a self-hosted database and connect through SOCKS5 or a local tunnel.
- Use caseMongoDB AtlasReplace 0.0.0.0/0 in your Atlas IP access list with two dedicated IPs, using the Node driver's SOCKS5 support.
- Use caseSFTP allowlistingReach bank, payroll, and EDI SFTP servers that only accept allowlisted IPs, through SOCKS5 or a local tunnel.
- IntegrationHerokuStatic outbound IPs for Common Runtime dynos, and a pair that moves with you.
Frequently asked questions
What is QGTunnel?
QGTunnel is a wrapper from QuotaGuard that opens local ports and forwards them to remote TCP services, such as databases or SFTP servers, through your QuotaGuard static IPs.
Does QGTunnel need QuotaGuard's API at startup?
By default it fetches configuration from QuotaGuard's API. QuotaGuard supports a local .qgtunnel config file in your project root, which removes that dependency.
Does bm tunnel support transparent DNS mode?
No. bm tunnel maps explicit local ports, and you point the driver at 127.0.0.1. For TLS, set the server name to the real database host so certificate checks pass.
Do I need a tunnel at all?
Not if your driver supports SOCKS5 or a custom dialer. Use the SOCKS5 URL directly. Tunnels are for drivers with no proxy support, on long-lived processes.
Make it fixed.
Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.