Guide
What is CGNAT?
Carrier-grade NAT (CGNAT) puts hundreds of customers behind one public IPv4 address. Learn how to tell if you are behind CGNAT, what it breaks, and how to get around it.
On this page
CGNAT in one paragraph
Carrier-grade NAT is a second, network-level layer of address translation that your ISP runs. Your home router already does NAT — converting your devices' local addresses (192.168.x.x) onto one public address. CGNAT does the same thing again at the ISP's gateway, so your "public" address is actually a shared one used by hundreds or thousands of other customers. The reserved range for it is 100.64.0.0 – 100.127.255.255 (RFC 6598).
Why carriers did it
IPv4 simply ran out. Regional registries exhausted their free pools between 2011 and 2019, and mobile networks — with their billions of phones and IoT devices — were the first to feel the wall. Rather than give every customer a scarce unique IPv4 address, carriers now share one among many. The long-term fix is IPv6, which makes sharing unnecessary: see IPv6 in 2026 and IPv4 vs IPv6.
How to tell if you are behind CGNAT
- Open the IP checker and note your public address.
- Check your router's WAN status page and find its external address.
- If the router's address starts with
100.64to100.127, you are behind CGNAT — the router itself only has a shared carrier address.
Secondary signs: the checker's ISP field shows your carrier but the address behaves like a shared one (neighbors' activity affecting you), or a neighbour you know is on the same connection plan shows the same address.
What CGNAT breaks
- Inbound connections and port forwarding — there is nowhere for an outside connection to land, so you cannot host a game server, camera or web app from home.
- Shared reputation — a neighbour's spam or abuse can get the whole shared address flagged, producing unexpected CAPTCHAs or blacklisting. See IP reputation.
- Remote access — tools that need a stable public endpoint simply do not work without a tunnel.
What it does not affect: normal browsing speed, streaming and almost everything day-to-day. CGNAT is a routing nuisance, not a speed one.
How to get a real public IP
- Ask your ISP — many will allocate a unique IPv4 on request, sometimes free, sometimes a small monthly fee.
- Switch on IPv6 — it gives every device its own globally unique address and bypasses the IPv4 pool entirely. Most modern routers have it enabled by default; the checker's IPv6 row confirms it is working.
- Use a VPN when you need a different exit — it replaces your shared address with the provider's datacentre IP (which the checker will label as such).
Frequently asked questions
Is CGNAT a security risk?
The mechanism itself is not — it is the carrier's standard plumbing. The practical risk is shared reputation: a bad actor behind the same address can get it flagged, affecting everyone sharing it.
How many people share a CGNAT address?
It varies from tens to thousands depending on the carrier and area. Mobile networks, which use CGNAT most aggressively, tend toward the high end.
Does CGNAT slow down my internet?
Measurably, no. The extra translation happens on hardware built for it; any difference is in the noise compared to other network factors.
Keep reading
- What is an IP address?
- Public vs private IP addresses
- IPv4 vs IPv6
- How to hide your IP address
- How to check your IP address on a phone
- How to change your IP address
- Why does my IP address keep changing?
- How to find a website's IP address
- What is a datacenter IP?
- IPv6 privacy extensions
- What is an ASN?
- How IP geolocation works
- What is a local IP address?
- Why am I getting blocked or stuck on CAPTCHAs?
- What is IP reputation?
- How websites detect VPNs and proxies
- What is a DNS leak?
- What is a WebRTC leak?
- Proxy vs VPN
- How to check if your VPN actually works
- Static vs dynamic public IP
- How to find out who owns an IP address
- IPv6 in 2026
- Check my public IP address
Check any other IP address
Investigating a suspicious login, a spam email header or a server log entry? Run any IPv4 or IPv6 address through the same geolocation and proxy checks.