What Is CGNAT? How to Check and Fix It
What is CGNAT? Carrier-grade NAT is an extra IPv4 translation layer operated by your internet provider. It lets many customers share a smaller pool of public IPv4 addresses, but it also means your router may not own the address that websites see and cannot accept ordinary unsolicited IPv4 connections.
How CGNAT works
Your home router normally translates private addresses on your network into one public IPv4 address. With CGNAT, the provider adds another translation outside your home: your router receives an address on the provider’s internal network, and the provider’s CGN device translates your traffic again before it reaches the public internet. The IETF describes this as a carrier NAT that shares one IPv4 address among subscribers and is not managed by those subscribers in RFC 6888.
The two translation layers
A laptop might use a private LAN address, your router translates that connection to its WAN address, and the ISP translates it to a shared public IPv4 address. The return traffic works because the outbound connection created temporary mappings at both NAT layers. This is why normal browsing can feel completely ordinary even when inbound hosting is impossible. For the LAN side, see public vs. private IP addresses.
Why ISPs use it
CGNAT is mainly an IPv4 address-conservation design. IPv4 addresses are limited, while providers may serve more connections than they can give unique public IPv4 addresses. IPv6 can reduce the need for this sharing, but many services and customers still need IPv4, so providers may run both systems during the transition.
What CGNAT changes for you
The practical question is not whether CGNAT exists; it is whether an application needs someone on the internet to start a connection to your home. Outbound sessions usually work. Inbound IPv4 sessions are the part that needs a mapping on the provider’s device, which you cannot edit.
| Use case | Typical result | Why |
|---|---|---|
| Browsing, streaming, downloads | Usually works | Your device starts the session. |
| Video calls and online games | Often works, sometimes restricted | Apps may use NAT traversal or a relay; behavior depends on the application and provider. |
| Home server, camera, or game server | Direct IPv4 access usually fails | The provider’s NAT has no customer-controlled rule pointing the shared address to your router. |
| IP-based allowlists, blocks, or geolocation | Can be less precise | The public address is shared or aggregated. See why IP location can be wrong. |
How to check for CGNAT
Use the connection you want to diagnose, and disconnect a VPN or proxy first. A VPN changes the public address you are comparing and can create a false result.
- Open Loqmi’s public IP tool and record the IPv4 address it reports. This is the address an outside service sees, not the local address on your computer or phone.
- Sign in to your router or gateway and open its Internet, WAN, Status, Broadband, or Connection page. Look for the IPv4 address assigned to the router’s internet-facing interface. Do not use the LAN address shown for one of your devices; if you need help identifying that, see how to find a local IP address.
- Compare the two IPv4 values. If the router WAN value is in
100.64.0.0/10, it is a strong CGNAT signal. That shared block runs from100.64.0.0through100.127.255.255under RFC 6598.
How to interpret the result
Use the address range and the network layout together. The 100.64.0.0/10 block is called Shared Address Space, not one of the three RFC 1918 private-use blocks. IANA lists it as not globally reachable in its IPv4 special-purpose registry.
| What you observe | Most useful conclusion | Next action |
|---|---|---|
| WAN IPv4 equals Loqmi’s public IPv4 | CGNAT is unlikely on that IPv4 path | Check router firewall, port rules, and ISP filtering if an inbound service still fails. |
WAN IPv4 is in 100.64.0.0/10 | CGNAT is very likely | Ask the ISP whether it can provide a publicly routed IPv4 or native IPv6. |
WAN IPv4 is in 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 | An upstream NAT exists | It may be your ISP or a second router at home. Check whether an ISP gateway is also routing. |
| WAN IPv4 looks public but differs from Loqmi | Another upstream design may be translating | Check for double NAT, DS-Lite, a VPN, or carrier documentation; ask the ISP to confirm. |
Why a closed port is not proof
A failed outside connection can also come from a stopped service, the wrong internal address, a host firewall, a router rule for the wrong protocol, or ISP port filtering. Treat a closed port as supporting evidence only after you have compared the WAN and public addresses. CGNAT is an upstream reachability problem, not a diagnosis for every port-forwarding mistake.
Troubleshoot common symptoms
Match the symptom to the layer you control before changing settings.
| Symptom | Possible cause | What to do |
|---|---|---|
| Router port forward looks correct, but remote access fails | CGNAT or double NAT | Repeat the WAN/public comparison. If the WAN is private or shared, a home rule cannot reach the provider’s NAT. |
| Game reports strict or moderate NAT | Restricted NAT behavior, CGNAT, or local firewall | Do not label it CGNAT from the game message alone; compare addresses and check the game’s relay or NAT-traversal requirements. |
| Your public IP is on a blocklist or triggers extra verification | Another subscriber may share the egress IPv4 | Contact the service first, then ask the ISP about a different or dedicated public IPv4. An IP flag alone does not show that your device is compromised. |
| IP location points to another city | Carrier egress or database limitation | Use the site’s location as an estimate; CGNAT can make the shared egress point less representative of your home. |
Choose a fix that matches your goal
If CGNAT does not interfere with what you do online, leaving it in place is reasonable. If you need reachability, choose the smallest change that gives the required path.
| Your goal | Practical option | Check before relying on it |
|---|---|---|
| Host an IPv4 service at home | Request a public IPv4 from the ISP | Ask whether it is routed to your router and whether inbound traffic is permitted; “static” alone is not enough. |
| Reach a service from IPv6 networks | Use native IPv6 and a deliberate firewall rule | Both ends need IPv6, and your router and service still need authentication and filtering. See how to enable IPv6 on a router. |
| Reach one private service without opening home IPv4 | Use an outbound tunnel or application relay | It adds a third-party or server dependency; expose only the intended service and protect it. |
| Your ISP supports customer port mappings | Ask whether PCP is enabled | PCP is designed to let a host request NAT mappings, but consumer plans and providers do not all expose it. |
After an ISP change, revisit Loqmi’s IP tool and compare the WAN value again. Then test the service from a different network. You can use Loqmi’s speed test to compare throughput and latency before and after the change, but a speed test cannot determine whether CGNAT is present.
Key takeaways
- CGNAT is ISP-operated IPv4 NAT that lets multiple customers share public addresses.
- Compare your router’s WAN IPv4 with the public IPv4 shown by Loqmi;
100.64.0.0/10is a strong signal. - A mismatch can also mean double NAT, a VPN, or another provider design, so use the range and network layout together.
- Normal outbound use may be fine, while direct inbound IPv4 hosting and port forwarding usually need a public IPv4, IPv6, PCP, or a tunnel.
Frequently asked questions
Does CGNAT make my internet slower?
Not automatically. CGNAT changes how IPv4 connections are translated, but ordinary browsing, streaming, and downloads can work normally. You may notice problems with an application that needs inbound connections or many simultaneous mappings. If speed or latency is poor, test your Wi-Fi, access link, and ISP congestion separately instead of treating CGNAT as the explanation by default.
Can a VPN remove CGNAT?
A VPN does not remove the ISP's CGNAT from your line. It creates an outbound tunnel, which can route around the inbound limitation if the VPN service supplies a reachable address or relay. Check that the service supports the protocol and inbound behavior you need, and treat the VPN provider as an additional security and availability dependency.
Will IPv6 always solve a CGNAT problem?
IPv6 can provide a separate path that does not use IPv4 CGNAT, but both ends of the connection must support IPv6 and your router firewall still has to allow the service. Some networks provide IPv6 only for outbound use or filter unsolicited traffic. Confirm the address, routing, and firewall policy before publishing a service.
Is a dynamic public IPv4 enough for port forwarding?
Usually, yes: port forwarding needs a publicly reachable address, not necessarily a permanent one. A dynamic address can change, so a hostname with dynamic DNS may help applications find you. Ask the ISP whether the address is truly routed to your router and whether inbound ports are filtered; a product labelled static is not proof of either condition.