Your IP address:
Provider:
...

What is CGNAT? Shared IPs and port forwarding

Carrier-grade NAT (CGNAT) is IPv4 address translation performed inside an Internet provider’s network. It lets multiple subscribers share one public IPv4 address. Outgoing connections often work normally, but incoming access to a server at home may be unavailable without a provider-supported arrangement.

CGNAT versus your home router

Your home router may already translate devices such as 192.168.1.20 to its external address. With CGNAT, the provider translates that external address again to a shared public IPv4 address. There are now two translation tables between a remote server and your device. You can configure only the home table; a port-forwarding rule on your router cannot create a matching rule in the provider’s equipment. This extra layer may go unnoticed while browsing, yet matter greatly when someone tries to connect to your home.

How to look for it

Find the IPv4 address of the router’s external interface on its status page. Compare it with the address displayed by the 2ip IP information tool. If they differ and a VPN or second home router does not explain the difference, provider-side translation is possible. Providers often use 100.64.0.0/10, shared address space running from 100.64.0.0 to 100.127.255.255. It is defined in RFC 6598 and is distinct from the RFC 1918 private blocks. Absence of that particular range does not rule out CGNAT because operators can use another address plan.

Why a port check can fail

A local check may find that your application is listening, while an outside port check cannot reach it. With CGNAT, an incoming packet first reaches the provider’s shared address, and the provider needs a mapping to know which subscriber should receive it. Before blaming CGNAT, verify the actual service, its TCP or UDP port, the home firewall and the router rule. VPNs, cloud proxies and extra routers can create similar symptoms. A port check is only one observation, not a complete application health test.

Options to discuss with your ISP

Ask whether a public IPv4 address and inbound connections are available, and whether the address is fixed or dynamic. If both ends support IPv6, you may publish the service over IPv6 with carefully limited firewall rules. Some applications instead make an outgoing protected connection to a relay; this adds trust and security considerations. Do not expose an entire device simply to obtain a successful port test. CGNAT does not by itself mean that ordinary Internet access is broken, and it does not hide a subscriber’s identity from their provider.