Skip to content
Fixedmark
Comparison · Checked October 2026

QGTunnel Alternative: Static IP Database Tunnels

QGTunnel is QuotaGuard's wrapper that opens local ports to databases and other TCP services through your QuotaGuard static IPs, with optional transparent DNS and encryption modes. The alternatives are a SOCKS5-capable driver, Fixie's open-source fixie-wrench, or Fixedmark's planned bm tunnel CLI, which maps explicit ports from a local config file. Fixedmark is in early access.

Fixedmark vs QGTunnel at a glance

Fixedmark values are planned launch features and pricing. QGTunnel values are taken from published vendor pages and attributed below. Checked October 2026.

Fixedmark's planned bm tunnel CLI compared with QGTunnel's published behavior
Fixedmark bm tunnel (planned)QGTunnel (published)
StatusPlanned for launch. Early access.Available with QuotaGuard plans
How it runsSeparate process, for example bm tunnel 5432:db.example.com:5432 &Wraps your start command: bin/qgtunnel <your command>
ConfigurationLocal config file only. No API call at startup.Fetched from QuotaGuard's API by default. A local .qgtunnel file is supported.
HostnamesConnect to 127.0.0.1 and set the TLS server name to the real hostTransparent mode overrides DNS so the original hostname resolves to 127.0.0.1
Plaintext protocolsUse the protocol's own TLS, such as rediss://Optional encrypted mode, end to end
Direct SOCKS5Included on every plan for drivers that support itSOCKS5 included on every QuotaGuard plan
Cost to get itStarter $9/mo shared pair, Pro $29/mo dedicated pairQuotaGuard Static from $19/mo shared pair, $219/mo dedicated pair

What QGTunnel does well

Transparent mode is the main draw. QGTunnel makes the database hostname resolve to a local port, so a Rails or Django app can keep its existing DATABASE_URL and still leave from a static IP. Its encrypted mode can also wrap protocols that have no TLS of their own, such as some Redis setups. Per QuotaGuard's guide, you only need encrypted mode when the protocol is not already encrypted.

Startup and DNS trade-offs

By default QGTunnel fetches its configuration from QuotaGuard's API when your process starts. QuotaGuard documents a fix: download the config and commit it as .qgtunnel, so startup does not depend on its website. Do that for production.

Overriding DNS inside your process can affect unrelated lookups. QuotaGuard's own blog describes Ruby Socket::ResolutionError failures on third-party API calls in transparent mode, fixed by turning transparent mode off. Without transparent mode, you point the driver at 127.0.0.1, which is how bm tunnel works.

Pick the simplest path that works

For each connection, start at the top of this list:

  • Driver supports SOCKS5 or a custom dialer, such as the MongoDB Node driver or Go's pgx: use the SOCKS5 URL directly. Nothing extra runs.
  • Driver has no proxy support and you run a long-lived process: use a local tunnel. That is bm tunnel, QGTunnel, or fixie-wrench, depending on your provider.
  • Code runs in serverless functions: a background tunnel cannot run, so use a SOCKS5-capable driver.

When to keep QGTunnel

QGTunnel is the better fit if:

  • You need a working tunnel in production today. Fixedmark is in early access.
  • You cannot change connection strings and need transparent DNS mode.
  • You connect over a protocol with no TLS and want the tunnel to encrypt it.
  • You already use QuotaGuard and your partners have its IPs allowlisted.

When bm tunnel fits better

The planned bm tunnel CLI suits teams that want:

  • A tunnel that starts from local config with no network call to a control plane.
  • No DNS changes inside the app process.
  • A dedicated IP pair at $29/mo shared by tunnels, SOCKS5, and HTTP calls.
  • Per-connection logs that show which database host each tunnel reached.

Sources

Checked October 2026. Confirm current details on the vendor's site before you decide. Prices and limits change.

Frequently asked questions

What is QGTunnel?

QGTunnel is a wrapper from QuotaGuard that opens local ports and forwards them to remote TCP services, such as databases or SFTP servers, through your QuotaGuard static IPs.

Does QGTunnel need QuotaGuard's API at startup?

By default it fetches configuration from QuotaGuard's API. QuotaGuard supports a local .qgtunnel config file in your project root, which removes that dependency.

Does bm tunnel support transparent DNS mode?

No. bm tunnel maps explicit local ports, and you point the driver at 127.0.0.1. For TLS, set the server name to the real database host so certificate checks pass.

Do I need a tunnel at all?

Not if your driver supports SOCKS5 or a custom dialer. Use the SOCKS5 URL directly. Tunnels are for drivers with no proxy support, on long-lived processes.

Make it fixed.

Fixedmark is in early access. Join the list to get dedicated static IPs when your region opens.