What Is CGNAT? Carrier-Grade NAT Explained, and What It Means for Your IP

Networking guide · Last reviewed 1 October 2026 · 10 min read

CGNAT, short for carrier-grade NAT, is a technique internet providers use to put many customers behind one shared public IPv4 address. It is why your router’s internet address often isn’t the address websites see, why port forwarding stops working on some connections, and why a mobile phone’s IP is shared with thousands of other subscribers. This guide explains what CGNAT is, how it works, how to tell whether you are behind it, what it breaks, and why it matters for mobile proxies and static residential IPs.

The short version

Carrier-grade NAT (CGNAT) is address translation run by your internet provider instead of your router: many subscribers share one public IPv4 address, and the provider keeps track of which ports belong to whom. It saves scarce IPv4 addresses, but it blocks incoming connections, makes an IP address a poor identifier of one person, and means that blocking one address can affect many users. Mobile networks use it almost everywhere.

What is CGNAT?

NAT, moved from your home into the provider’s network

Network address translation (NAT) lets several devices share one IP address. Your home router already does it: phones, laptops and TVs get private addresses such as 192.168.1.20, and the router rewrites their traffic so it all leaves from the one public address your provider gave you.

Carrier-grade NAT does the same job one level up, inside the provider’s network. The IETF’s requirements document for it, RFC 6888, defines a carrier-grade NAT as a NAT-based function used to share the same IPv4 address among several subscribers, one the subscribers don’t manage. Instead of giving each home or phone its own public address, the provider gives it an internal one and translates many subscribers onto a smaller pool of public addresses.

When a home router’s own NAT sits behind the provider’s carrier-grade NAT, traffic is translated twice. That arrangement is often called NAT444, because an IPv4 address is translated to another IPv4 address, and then to a third.

Key takeaways

  • CGNAT (carrier-grade NAT, also CGN or large-scale NAT) shares one public IPv4 address among many subscribers.
  • The provider, not you, runs the translation, so you can’t open ports on it.
  • Providers use the 100.64.0.0/10 range between their NAT and your router.
  • Mobile networks rely on it heavily, so one carrier IP can front thousands of phones.
  • IPv6 removes the need for it, which is why many networks run both.

Why providers use carrier-grade NAT

IPv4 addresses ran out

IPv4 has about 4.3 billion addresses, far fewer than the number of connected devices. The regional registries that hand out addresses have largely run out of fresh IPv4 blocks, so new providers and growing networks have to buy addresses on the transfer market or share the ones they have. Carrier-grade NAT is the sharing option: a provider with one public address per hundred subscribers can keep adding customers without buying more.

The IETF’s own position is that sharing is a stopgap. RFC 6269, which catalogues the problems address sharing causes, concludes that deploying IPv6 is the only long-term way to ease pressure on the IPv4 pool. In practice, most providers now run IPv6 alongside IPv4, and carrier-grade NAT handles the IPv4 part.

How carrier-grade NAT works

Addresses and ports, shared out
Figure 1 — one request through two layers of NAT
laptop 192.168.1.20  (private, home network)
      |  home router NAT
      v
router WAN 100.64.12.7  (shared address space, provider network)
      |  carrier-grade NAT
      v
public IP 203.0.113.50, port 40211
      |
      v
website  -->  sees 203.0.113.50, shared with many other subscribers

The address between the provider’s NAT and your router comes from a range set aside for exactly this. RFC 6598 reserves 100.64.0.0/10 as “Shared Address Space” for service providers deploying carrier-grade NAT. It exists because providers couldn’t safely reuse the private ranges from RFC 1918 (such as 192.168.0.0/16) on that link: a customer’s own router might already use the same range on the home side.

Because many subscribers leave from the same public address, the NAT tells them apart by port. Each outgoing connection gets a public address and port pair, and the NAT remembers which subscriber it belongs to so the reply can find its way back. RFC 6888 requires carrier-grade NATs to support a limit on how many ports each subscriber can use, so that one heavy user can’t exhaust the pool for everyone sharing the address, and recommends holding a released port back for a short time before giving it to someone else.

Carrier-grade NAT also appears in IPv6 transition designs. DS-Lite (RFC 6333) carries a subscriber’s IPv4 traffic inside IPv6 to a provider NAT. NAT64 (RFC 6146) and 464XLAT (RFC 6877) let IPv6-only devices, common on mobile networks, still reach IPv4 websites through a translator.

How to tell if you are behind CGNAT

Compare two addresses
  1. Find your router’s WAN address. Log in to the router and look for the internet, WAN or broadband IP address.
  2. Find your public address. Search “what is my IP” from a device on the same network.
  3. Compare them. If the two match, you have your own public IP. If the router shows an address in 100.64.0.0 to 100.127.255.255, you are behind carrier-grade NAT. A different private address, such as 10.x.x.x, usually means the same thing.
  4. On a phone, assume you are behind carrier-grade NAT on mobile data unless your plan includes a public IP.

What CGNAT breaks

Problems catalogued in RFC 6269
AreaWhat happens
Incoming connectionsPort forwarding, hosting a server, remote access and some peer-to-peer apps don’t work, because you don’t control the public address.
Online gamingConsoles often report a strict or moderate NAT type, which can limit matchmaking and voice chat.
IP blockingIf a site or mail service blocks one abuser’s address, everyone sharing it is blocked too.
GeolocationYou appear wherever the provider’s NAT is, which can be in a different city.
TraceabilityAn IP address alone no longer identifies one subscriber; providers must log ports and times as well.

RFC 6269 puts the blocking problem plainly: penalty-box responses to abuse don’t work when many people share an address, because blocking the abuser punishes everyone else behind it. The same document notes that a subscriber behind a carrier-grade NAT geolocates to wherever the NAT’s address block appears to be, which may not be where the subscriber is.

CGNAT vs a static IP

Shared and changing, or yours and fixed
Behind CGNATStatic public IP
Who uses the addressYou and other subscribers at the same timeOnly you
Does it change?It can, when the provider’s NAT maps you to a different public addressNo, it stays until you give it up
Incoming connectionsNot possible without help from the providerYes: port forwarding, servers and remote access work
ReputationShared with everyone on the addressBuilt only by your own traffic
AllowlistingUnreliable, since the address isn’t yours aloneWorks: services can trust one fixed address

If you need an address that stays the same, for example to be allowlisted by a partner’s firewall, to run a server, or to keep the same identity on an account for weeks, carrier-grade NAT works against you. The fix is a static public IP from your provider, a server with its own address, or, for online work that should look like a home user, a static residential proxy: a fixed residential IP that stays assigned to you. ProxyEmpire’s static residential proxies give you one fixed residential IP per proxy, sold in a fixed list of countries with country-level targeting.

Does CGNAT slow down your internet?

Latency, port limits and security

Usually not in a way you would notice. Rewriting an address and port is simple work for the provider’s equipment, and a well-sized carrier-grade NAT adds very little delay. When CGNAT does feel slow, the cause is normally one of three things:

  • Where the NAT sits. Traffic has to pass through the provider’s NAT before reaching the internet, and if that box is far from you, every connection takes a longer path.
  • Port limits. Each subscriber gets a limited number of ports. An app that opens a very large number of connections at once, such as a torrent client or a busy scraper, can hit the limit, and new connections then fail or stall until ports are freed.
  • Overloaded equipment. If the provider has put too many subscribers on too little NAT capacity, everyone on it can see slower connections at busy times.

On security, carrier-grade NAT is not a firewall, though it has a side effect that looks like one: unsolicited incoming connections can’t reach your devices, because the NAT has no mapping for them. That doesn’t replace a firewall or updates on your own devices. Sharing an address doesn’t make you anonymous either: as RFC 6269 points out, an IPv4 address alone no longer identifies one subscriber, so providers that need to trace traffic log the port and time as well.

CGNAT on mobile networks

Why a phone’s IP is shared

Mobile carriers have far more devices than public IPv4 addresses, and phones move between cell towers constantly, so carriers put mobile data behind carrier-grade NAT almost everywhere. A single public carrier IP can front a large number of phones at once, and the address your phone gets can change when it reconnects. Many carriers also give phones IPv6 addresses and use NAT64 or 464XLAT for the IPv4 sites that remain.

That sharing is the reason mobile IPs are treated gently by websites. Because a carrier address can stand for many real subscribers, blocking it outright risks blocking many legitimate visitors, so sites tend to be cautious about banning mobile addresses and lean on other signals instead. It is also why a mobile IP looks like an ordinary phone user: it is literally the address that thousands of ordinary phone users share.

CGNAT and proxies

Mobile, rotating and static IPs
  • Rotating mobile proxies route your traffic out through real mobile carrier connections, so the website sees a carrier IP from behind the carrier’s NAT, shared with ordinary subscribers. That is why mobile proxies suit the hardest targets. ProxyEmpire’s rotating mobile proxies cover 4M+ mobile IPs in 174 countries, with targeting by country, city and carrier included at no extra charge.
  • Sticky sessions on mobile keep the same carrier IP while the connection stays up. Because the carrier can reassign addresses when a device reconnects, a mobile IP is steady for a session, not forever.
  • Static residential proxies need an address that stays the same for weeks, so a home connection behind carrier-grade NAT, whose public IP is shared and can move, is a poor base for one. A static residential IP should be one fixed address that only you use; see what static residential proxies are.
  • Dedicated mobile proxies give you a whole mobile connection to yourself instead of a shared pool, with unlimited bandwidth and full IP rotation. See ProxyEmpire’s dedicated 4G and 5G mobile proxies.

Working with or around CGNAT

Options if it gets in your way
  • Use IPv6. Most networks behind carrier-grade NAT also offer IPv6, which gives each device a globally reachable address. Apps and services that support IPv6 avoid the problem entirely.
  • Ask for a public IP. Many broadband providers will switch you off carrier-grade NAT, sometimes for a fee or on a business plan.
  • Use an outbound tunnel. Remote-access tools and tunnels that connect out from your network to a relay work behind carrier-grade NAT, because they don’t need incoming ports.
  • Host elsewhere. Put anything that must accept incoming connections on a server with its own public address.

CGNAT FAQ

Short answers
What does CGNAT stand for?

Carrier-grade network address translation: NAT run by an internet provider to share one public IPv4 address among many subscribers.

Is CGNAT bad?

It is a trade-off. It lets providers connect more customers with scarce IPv4 addresses, but it blocks incoming connections and means you share your public IP and its reputation with others.

What is the 100.64.0.0/10 range?

The Shared Address Space reserved by RFC 6598 for the link between a provider’s carrier-grade NAT and customers’ routers. Seeing it on your router’s WAN side means you are behind CGNAT.

Does CGNAT affect gaming?

It can. Consoles behind carrier-grade NAT often report a strict or moderate NAT type, and you can’t forward ports. IPv6 or a public IP usually fixes it.

Do all mobile networks use CGNAT?

Almost all use it for IPv4, and many pair it with IPv6 and NAT64 or 464XLAT. A public IPv4 address on mobile is usually an extra.

Can I get around CGNAT?

Use IPv6, ask your provider for a public IP, or use an outbound tunnel to reach your network from outside.

Why are mobile proxies harder to block?

Their IPs are carrier addresses shared behind CGNAT by many real subscribers, so blocking one risks blocking many legitimate users.

Is carrier-grade NAT the same as double NAT?

Not quite. Double NAT is any two NAT layers; carrier-grade NAT is the provider-run layer, which together with your router makes a double NAT.

References

Primary documentation
  1. IETF — RFC 6888, “Common Requirements for Carrier-Grade NATs (CGNs)” (2013). rfc-editor.org/rfc/rfc6888
  2. IETF — RFC 6598, “IANA-Reserved IPv4 Prefix for Shared Address Space” (2012). rfc-editor.org/rfc/rfc6598
  3. IETF — RFC 6269, “Issues with IP Address Sharing” (2011). rfc-editor.org/rfc/rfc6269
  4. IETF — RFC 1918, “Address Allocation for Private Internets”. rfc-editor.org/rfc/rfc1918
  5. IETF — RFC 6333, “Dual-Stack Lite Broadband Deployments Following IPv4 Exhaustion”. rfc-editor.org/rfc/rfc6333
  6. IETF — RFC 6146, “Stateful NAT64”. rfc-editor.org/rfc/rfc6146
  7. IETF — RFC 6877, “464XLAT”. rfc-editor.org/rfc/rfc6877

Real carrier IPs, from behind real carrier NAT

4M+ mobile IPs in 174 countries with carrier targeting at no extra charge, rotating or sticky sessions, dedicated 4G and 5G mobile proxies, and 24/7 support from real people. The $1.97 trial includes 100 MB of residential and 50 MB of mobile traffic.

Flexible Pricing Plan

logo purple proxyempire

Our state-of-the-art proxies.

Experience online freedom with our unrivaled web proxy solutions. Pioneering in collecting location specific data at scale, our premium, ethically-sourced network boasts a vast pool of IPs, expansive location choices, high success rate, and versatile pricing. Advance your digital journey with us.

🏘️ Rotating Residential Proxies
  • 30M+ Premium Residential IPs
  •  170+ Countries
    Every residential IP in our network corresponds to an actual desktop device with a precise geographical location. Our residential proxies aare fast and reliable, with 99.9% uptime, and work for a wide range of use cases. You can use Country, Region, City and ISP targeting for our rotating residential proxies.

See our Rotating Residential Proxies

📍 Static Residential Proxies
  • 19 Countries
    Buy a dedicated static residential IP from one of the 19 countries that we offer proxies in. Keep the same IP for a month or longer, while benefiting from their fast speed and stability.

See our Static Residential Proxies

📳 Rotating Mobile Proxies
  • 4M+ Premium Mobile IPs
  •  170+ Countries
    Access millions of clean mobile IPs with precise targeting including Country, Region, City, and Mobile Carrier. Get far fewer IP blocks and CAPTCHAs with our 4G and 5G proxies.

See our Mobile Proxies

📱 Dedicated Mobile Proxies
  • 5+ Countries
  • 50+ Locations
    Get your own dedicated mobile proxy in one of our supported locations, with unlimited bandwidth and unlimited IP changes on demand. A great choice when you need a small number of mobile IPs and a lot of proxy bandwidth.

See our 4G & 5G Proxies

🌐 Rotating Datacenter Proxies
  • 197,000+ IPs Premium IPs
  •  62 Countries
    On a budget and need to do some simple scraping tasks? Our datacenter proxies are the perfect fit! Get started with as little as $2

See our Datacenter Proxies

proxy locations

30M+ rotating IPs

99% uptime - high speed

99.9% uptime.

dedicated support team

24/7 Dedicated Support.

fair price

Fair Pricing.

🏠 Residential Proxies Rotating / Static / Unlimited
📱 Mobile Proxies Rotating and Dedicated
🖥️ Datacenter Proxies Rotating
🌍 IP Pool 30M+ residential + 4M+ mobile IPs
📶 Uptime 99.9% · Live status
💳 Payment Card · PayPal · Crypto · Bank transfer
💬 Support 24/7 live chat · [email protected]