IP Address Basics

What Is CGNAT? How to Check and Fix It

What is CGNAT? Carrier-grade NAT is an extra IPv4 translation layer operated by your internet provider. It lets many customers share a smaller pool of public IPv4 addresses, but it also means your router may not own the address that websites see and cannot accept ordinary unsolicited IPv4 connections.

How CGNAT works

Your home router normally translates private addresses on your network into one public IPv4 address. With CGNAT, the provider adds another translation outside your home: your router receives an address on the provider’s internal network, and the provider’s CGN device translates your traffic again before it reaches the public internet. The IETF describes this as a carrier NAT that shares one IPv4 address among subscribers and is not managed by those subscribers in RFC 6888.

The two translation layers

A laptop might use a private LAN address, your router translates that connection to its WAN address, and the ISP translates it to a shared public IPv4 address. The return traffic works because the outbound connection created temporary mappings at both NAT layers. This is why normal browsing can feel completely ordinary even when inbound hosting is impossible. For the LAN side, see public vs. private IP addresses.

Why ISPs use it

CGNAT is mainly an IPv4 address-conservation design. IPv4 addresses are limited, while providers may serve more connections than they can give unique public IPv4 addresses. IPv6 can reduce the need for this sharing, but many services and customers still need IPv4, so providers may run both systems during the transition.

What CGNAT changes for you

The practical question is not whether CGNAT exists; it is whether an application needs someone on the internet to start a connection to your home. Outbound sessions usually work. Inbound IPv4 sessions are the part that needs a mapping on the provider’s device, which you cannot edit.

Use caseTypical resultWhy
Browsing, streaming, downloadsUsually worksYour device starts the session.
Video calls and online gamesOften works, sometimes restrictedApps may use NAT traversal or a relay; behavior depends on the application and provider.
Home server, camera, or game serverDirect IPv4 access usually failsThe provider’s NAT has no customer-controlled rule pointing the shared address to your router.
IP-based allowlists, blocks, or geolocationCan be less preciseThe public address is shared or aggregated. See why IP location can be wrong.

How to check for CGNAT

Use the connection you want to diagnose, and disconnect a VPN or proxy first. A VPN changes the public address you are comparing and can create a false result.

  1. Open Loqmi’s public IP tool and record the IPv4 address it reports. This is the address an outside service sees, not the local address on your computer or phone.
  2. Sign in to your router or gateway and open its Internet, WAN, Status, Broadband, or Connection page. Look for the IPv4 address assigned to the router’s internet-facing interface. Do not use the LAN address shown for one of your devices; if you need help identifying that, see how to find a local IP address.
  3. Compare the two IPv4 values. If the router WAN value is in 100.64.0.0/10, it is a strong CGNAT signal. That shared block runs from 100.64.0.0 through 100.127.255.255 under RFC 6598.
Quick interpretation: a matching WAN and public IPv4 usually means the router has the public address for that path; a mismatch proves that another translation or gateway is involved, but it does not by itself name that mechanism.

How to interpret the result

Use the address range and the network layout together. The 100.64.0.0/10 block is called Shared Address Space, not one of the three RFC 1918 private-use blocks. IANA lists it as not globally reachable in its IPv4 special-purpose registry.

What you observeMost useful conclusionNext action
WAN IPv4 equals Loqmi’s public IPv4CGNAT is unlikely on that IPv4 pathCheck router firewall, port rules, and ISP filtering if an inbound service still fails.
WAN IPv4 is in 100.64.0.0/10CGNAT is very likelyAsk the ISP whether it can provide a publicly routed IPv4 or native IPv6.
WAN IPv4 is in 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16An upstream NAT existsIt may be your ISP or a second router at home. Check whether an ISP gateway is also routing.
WAN IPv4 looks public but differs from LoqmiAnother upstream design may be translatingCheck for double NAT, DS-Lite, a VPN, or carrier documentation; ask the ISP to confirm.

Why a closed port is not proof

A failed outside connection can also come from a stopped service, the wrong internal address, a host firewall, a router rule for the wrong protocol, or ISP port filtering. Treat a closed port as supporting evidence only after you have compared the WAN and public addresses. CGNAT is an upstream reachability problem, not a diagnosis for every port-forwarding mistake.

Troubleshoot common symptoms

Match the symptom to the layer you control before changing settings.

SymptomPossible causeWhat to do
Router port forward looks correct, but remote access failsCGNAT or double NATRepeat the WAN/public comparison. If the WAN is private or shared, a home rule cannot reach the provider’s NAT.
Game reports strict or moderate NATRestricted NAT behavior, CGNAT, or local firewallDo not label it CGNAT from the game message alone; compare addresses and check the game’s relay or NAT-traversal requirements.
Your public IP is on a blocklist or triggers extra verificationAnother subscriber may share the egress IPv4Contact the service first, then ask the ISP about a different or dedicated public IPv4. An IP flag alone does not show that your device is compromised.
IP location points to another cityCarrier egress or database limitationUse the site’s location as an estimate; CGNAT can make the shared egress point less representative of your home.

Choose a fix that matches your goal

If CGNAT does not interfere with what you do online, leaving it in place is reasonable. If you need reachability, choose the smallest change that gives the required path.

Your goalPractical optionCheck before relying on it
Host an IPv4 service at homeRequest a public IPv4 from the ISPAsk whether it is routed to your router and whether inbound traffic is permitted; “static” alone is not enough.
Reach a service from IPv6 networksUse native IPv6 and a deliberate firewall ruleBoth ends need IPv6, and your router and service still need authentication and filtering. See how to enable IPv6 on a router.
Reach one private service without opening home IPv4Use an outbound tunnel or application relayIt adds a third-party or server dependency; expose only the intended service and protect it.
Your ISP supports customer port mappingsAsk whether PCP is enabledPCP is designed to let a host request NAT mappings, but consumer plans and providers do not all expose it.
CGNAT is not a security control. It may reduce unsolicited IPv4 reachability as a side effect, but it is not a replacement for a router firewall, device updates, strong authentication, or careful port-forwarding. If you move to a public address, review those controls before exposing anything.

After an ISP change, revisit Loqmi’s IP tool and compare the WAN value again. Then test the service from a different network. You can use Loqmi’s speed test to compare throughput and latency before and after the change, but a speed test cannot determine whether CGNAT is present.

Key takeaways

  • CGNAT is ISP-operated IPv4 NAT that lets multiple customers share public addresses.
  • Compare your router’s WAN IPv4 with the public IPv4 shown by Loqmi; 100.64.0.0/10 is a strong signal.
  • A mismatch can also mean double NAT, a VPN, or another provider design, so use the range and network layout together.
  • Normal outbound use may be fine, while direct inbound IPv4 hosting and port forwarding usually need a public IPv4, IPv6, PCP, or a tunnel.

Frequently asked questions

Does CGNAT make my internet slower?

Not automatically. CGNAT changes how IPv4 connections are translated, but ordinary browsing, streaming, and downloads can work normally. You may notice problems with an application that needs inbound connections or many simultaneous mappings. If speed or latency is poor, test your Wi-Fi, access link, and ISP congestion separately instead of treating CGNAT as the explanation by default.

Can a VPN remove CGNAT?

A VPN does not remove the ISP's CGNAT from your line. It creates an outbound tunnel, which can route around the inbound limitation if the VPN service supplies a reachable address or relay. Check that the service supports the protocol and inbound behavior you need, and treat the VPN provider as an additional security and availability dependency.

Will IPv6 always solve a CGNAT problem?

IPv6 can provide a separate path that does not use IPv4 CGNAT, but both ends of the connection must support IPv6 and your router firewall still has to allow the service. Some networks provide IPv6 only for outbound use or filter unsolicited traffic. Confirm the address, routing, and firewall policy before publishing a service.

Is a dynamic public IPv4 enough for port forwarding?

Usually, yes: port forwarding needs a publicly reachable address, not necessarily a permanent one. A dynamic address can change, so a hostname with dynamic DNS may help applications find you. Ask the ISP whether the address is truly routed to your router and whether inbound ports are filtered; a product labelled static is not proof of either condition.

Sources

Related articles