Skip to main content

IPv4 guide

What is CGNAT? Check your connection and options

CGNAT (Carrier-Grade NAT) lets an internet provider share public IPv4 addresses among multiple subscribers. It can limit incoming connections to a home or business network. Check your connection first, then compare a provider public IP, supported port mapping, IPv6 or a relay for the service you need.

What does CGNAT mean?

Carrier-Grade NAT, also called CGN or Large-Scale NAT, is address translation operated in the provider network. Several subscribers can appear under the same public IPv4 address. An address lookup shows the exit address seen by that destination; it does not establish that the address is dedicated to you.

How to check whether you are behind CGNAT

  1. Check the correct connection. In your router's status page, record its Internet/WAN IPv4 address. Do not use the private address assigned to your laptop. If you have two routers, identify the one connected to the provider.
  2. Compare IPv4 with IPv4. From that same connection, check the public IPv4 reported by an IP lookup. Account for a VPN, proxy, different uplink or IPv6 result. Repeat without the intermediary only if your network policy permits it.
  3. Interpret the result. A WAN address from 100.64.0.0 through 100.127.255.255 belongs to the shared 100.64.0.0/10 range and is a strong indicator. Private WAN ranges such as 10.0.0.0/8, 172.16.0.0/12 or 192.168.0.0/16 can also indicate upstream NAT. A mismatch alone cannot distinguish provider CGNAT from a second router, enterprise NAT or another intermediary.
  4. Ask the provider to confirm. Ask: “Does this service use shared IPv4 or CGNAT? Can you supply a public IPv4, inbound ports or native IPv6 for my application?” Some transition designs, such as DS-Lite, need a provider-specific check rather than this simple WAN comparison.

A matching public IPv4 is useful evidence about that path, but does not prove that a port is reachable. Check the service and firewall separately. A failed ping or port test is not a CGNAT diagnosis.

How traffic passes through CGNAT

A common NAT444 example is: device → home router NAT → provider NAT → Internet. Other provider designs place translation differently; CGNAT does not always mean exactly two NAT layers.

For a typical outbound connection, the translators keep mappings so reply packets can return to the device. A new inbound connection needs an appropriate mapping or another reachable path. Forwarding a port on the home router only configures that router; it does not configure the provider's translator. See RFC 6888 for CGN behavior and the NAT guide for the local-network distinction.

Why providers use it

Sharing conserves scarce public IPv4 addresses while keeping IPv4 connectivity available. It adds mapping, port-capacity and logging responsibilities. The shared range is defined in RFC 6598; it is different from RFC 1918 private space and is not globally routable.

What CGNAT can affect

  • Hosting, cameras and remote access: direct inbound IPv4 can fail without provider mappings, a relay or another public endpoint.
  • Gaming, voice and peer-to-peer applications: behavior depends on ports, NAT traversal and relays. CGNAT does not make every game, call or VPN fail, and a “strict NAT” label does not identify the cause by itself.
  • Shared reputation and limits: another subscriber's activity can affect address-based blocking or rate limits. Port exhaustion and mapping timeouts can also affect applications.
  • Attribution: an incident needs more than the public address. Preserve the public address, transport protocol, port and precise time with timezone so the provider can correlate its records.

RFC 6269 describes address-sharing effects. Measure the actual workload instead of assuming that all outbound services work or all inbound services fail.

Can you disable or work around CGNAT?

You normally cannot disable a provider's CGNAT in your own router. Ask for an access-service change or choose a supported path for your application.

Options for reaching a service behind shared IPv4
OptionWhat to confirmMain limit
Provider public IPv4Public address delivery, inbound-port policy and firewall; static or dynamic assignmentAvailability and cost depend on the provider. Dynamic DNS can track an address change; it does not create reachability.
Provider port mappingStatic mapping, assigned ports or PCP support for the required protocolThe provider must support it. Home-router UPnP alone cannot open its upstream NAT.
Native IPv6IPv6 at both ends, service listening address, DNS and explicit firewall permissionIPv4-only clients need a separate compatible access path.
Relay, reverse tunnel or VPN with inbound supportPublic endpoint, authentication, protocols, ports, latency and service termsAn ordinary outbound-only VPN does not expose your local service. The intermediary becomes a dependency.
Routed owned or leased IPv4 prefixAuthorized prefix, upstream acceptance and an agreed routed or tunnel handoffAssigning an address to your router is insufficient. A prefix lease does not automatically bypass your ISP's CGNAT.

PCP can request mappings where supported; it is not a switch that works on every provider network.

CGNAT versus a dedicated public IP

Shared IPv4 has provider-managed mappings shared across customers. A dedicated public IPv4 gives one customer an address under the agreed service, but still needs routing, firewall and service configuration. “Public”, “dedicated” and “static” describe different properties. None guarantees security, clean reputation, reverse DNS, geolocation or portability.

When a business needs a different design

If the required protocol, availability or inbound access cannot be delivered through the current service, document that failure and agree a different path. For a routed prefix, verify authority, announcing ASN, LOA, IRR and RPKI responsibilities, upstream filters, monitoring, abuse handling, renewal and return. Review managed IPv4 leasing only once the delivery model is viable.

Test the chosen path before relying on it

  1. Define the application, destination, protocol, port and intended client networks.
  2. Verify that the service listens locally. Configure only the required authenticated access and firewall rules; do not expose router administration or disable the firewall as a shortcut.
  3. Confirm each router/provider mapping, public endpoint or IPv6 route. Check DNS against the intended address family.
  4. Test the actual application from a separate network, such as an authorized mobile connection. A same-LAN test may use NAT loopback and does not prove external access.
  5. Record the result and time; check reconnects, address changes and recovery. If it fails, inspect listener, firewall, DNS, mappings and upstream policy in that order with the responsible operator.

Bring a clear network requirement

For a business address-space requirement, prepare the prefix size, location, upstream, delivery method, ports, availability and operating owners. Discuss the requirement with i.lease. A resource agreement and an operational network handoff need separate verification.

Choose by the service you need

For one home service, start with your provider's public-IP, IPv6 or mapping options. For larger deployments, plan the routing and resource responsibilities before obtaining addresses.

CGNAT questions

Does changing my router remove CGNAT?

Not when translation is inside the provider network. A router change can fix local double NAT, but the provider must change its own service or support an alternative path.

Can port forwarding work behind CGNAT?

Yes, if the provider supplies a usable mapping or another inbound path. A rule on the home router alone does not create a mapping in the provider network.

Will a VPN fix it?

Only if its service supplies the inbound endpoint or routing your application requires. Check inbound ports and supported protocols; an outbound-only VPN is not enough.

Is CGNAT a security guarantee?

No. Translation is not a substitute for firewall policy, authentication, patches and application security. Opening a new public path requires those controls too.

Sources and next reading