Explainer29 September 20267 min read

What is CGNAT? Carrier-grade NAT and what it means for proxies

What is CGNAT? How carrier-grade NAT puts many users on one shared IP address, what 100.64.0.0/10 is, and how to tell if your own connection is behind it.

CGNAT (carrier-grade NAT) is a way for an internet provider to put many customers behind one public IPv4 address. Your router receives an address from a shared internal range, usually 100.64.0.0/10, and the provider's equipment translates it to a public address that many other subscribers use too. Websites see that shared address, not one that is yours alone.

That has a few consequences worth knowing about if you use proxies: for the reputation of an exit IP, for why sites hesitate to block some addresses, and for whether you can safely allowlist your own IP. This page covers how CGNAT works, who uses it, what it changes, and a two-minute test for your own connection.

What is CGNAT for?

IPv4 has room for about 4.3 billion addresses, and the regional internet registries ran out of fresh blocks during the 2010s. A provider that keeps adding customers cannot give each of them a public IPv4 address any more, so it shares.

IPv6 is the long-term fix, with enough addresses for every device. Many networks now run both: native IPv6 for sites that support it, and CGNAT for everything that still needs IPv4.

How does carrier-grade NAT work?

You already use NAT at home. Your phone and laptop get private addresses such as 192.168.1.20, and your router translates them to its own WAN address on the way out.

CGNAT adds a second translation, at the provider:

  1. Your device sends a request from its private address.
  2. Your router translates it to its WAN address. Under CGNAT, that WAN address is not public: it comes from the shared range.
  3. The provider's CGNAT equipment translates it again, to a public address and a port number from a slice of ports set aside for you.
  4. The website sees the public address and that port.

Because the traffic crosses three address spaces (your home network, the provider's shared range, the public internet), engineers sometimes call this NAT444. The public address is shared by many subscribers at once, and the port is what tells their connections apart. How many subscribers share one address depends on the provider, and providers rarely publish it.

One practical result: to trace an action back to one subscriber, a provider needs the public address, the source port and the exact time. That is why RFC 6302 asks website operators to log source ports as well as addresses.

What is 100.64.0.0/10?

100.64.0.0/10 is the shared address space set aside by RFC 6598 in April 2012. It runs from 100.64.0.0 to 100.127.255.255, a little over four million addresses, and it is reserved for one job: the link between a provider's CGNAT equipment and its customers' routers.

It exists because the usual private ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16) are already in use inside people's homes. If a provider used 192.168.1.0/24 on its side, it would clash with the customer's own network. A separate range avoids that.

Addresses in this range are never routed on the public internet. An ASN lookup shows it: Team Cymru's whois answers NA for 100.64.0.1, and RIPEstat labels the block "Shared Address Space". Some providers do the same job with a private range such as 10.0.0.0/8 instead, so a WAN address outside 100.64.0.0/10 does not rule CGNAT out.

Who uses CGNAT?

  • Cellular carriers. Phones on cellular data almost always share public IPv4 addresses this way.
  • Many broadband providers. It is common on newer fibre networks, fixed wireless, satellite, and in regions that received fewer IPv4 addresses. Some providers put every customer behind CGNAT; some only newer customers. Some will give you a public IPv4 address on request or for a fee.
  • Anywhere a provider is short of addresses. The technique is the same whatever the network.

What CGNAT means for proxies

One address, many people, one reputation

Websites and IP databases track reputation per address. Behind CGNAT, one address carries the traffic of many unrelated people, so its record is shared. A captcha you get may have been earned by someone else behind the same address yesterday. It works the other way too: the address may have a long history of ordinary browsing that makes it look trustworthy.

If you check an exit's reputation with the steps in how to check proxy IP quality, keep this in mind. A shared address with a patchy record is not the same thing as a dirty proxy IP.

Why sites are careful about blocking CGNAT addresses

Blocking one CGNAT address blocks every subscriber behind it, and most of them are ordinary customers. Sites that recognise an address as shared tend to lean on other tools: rate limits, cookies, browser checks and captchas, and short blocks over long ones. Some reputation databases mark addresses they believe are shared, or belong to cellular networks. Sites differ and none publish their rules, so treat this as a tendency.

The same logic explains a pattern you may have seen: a site that answers with 429 Too Many Requests even though you sent very little. When a site counts requests per address, it counts everyone behind that address. Fixing 429 Too Many Requests covers what to do about it.

A residential exit may sit behind CGNAT

A residential proxy sends your request out through a household connection. If that household's provider uses CGNAT, the address the website sees is the provider's shared address. For you, that can mean:

  • Reputation you did not earn, good or bad, as above.
  • A rough location. The country is normally right. The city can point to wherever the provider's CGNAT equipment sits, which may be a regional hub some distance away.
  • An address that changes under a sticky session. CGNAT equipment normally keeps one subscriber on the same public address for a while, but it can reassign it. Write any login step so it can run again. Rotating vs sticky proxies has more on sessions.

From the outside you usually cannot tell for certain whether an exit is behind CGNAT. Some IP databases guess, with mixed accuracy. If one exit behaves oddly, sample a few more and compare before drawing conclusions.

For the record: ProxyPanda sells residential, ISP and datacenter proxies, and no cellular proxies. If you need one address that stays put for weeks, static ISP and datacenter IPs are rented for a term, with the country, region and city chosen when you order.

Is my own connection behind CGNAT?

It is worth knowing for three reasons:

  • IP allowlisting. The dashboard lets you add the IPs you connect from to a service's allowlist, after which HOST and PORT alone work. Behind CGNAT your public address is shared and can change. Allowlisting it would let anyone else behind that address use your service without a password, and it would stop working for you when the address moves. Use your username and password instead.
  • Incoming connections. Port forwarding for a game server or a home camera will not work, because the public address is not yours.
  • Captchas at home. If sites keep asking you to prove you are human, a shared address is one possible reason.

The test

  1. Find your router's WAN address. Log in to the router's admin page and look for "WAN IP", "Internet IP" or "External IP" on its status page. Use the router, not your computer: some VPN and mesh-networking tools give your computer an address from 100.64.0.0/10 on their own.
  2. Find the address websites see. Run this from the same network:
curl -s https://api.ipify.org; echo
  1. Compare them. This script does the comparison and names the likely case. It uses only the Python standard library:
import ipaddress
import urllib.request

SHARED = ipaddress.ip_network("100.64.0.0/10")

wan = ipaddress.ip_address(input("WAN IP from your router's status page: ").strip())
with urllib.request.urlopen("https://api.ipify.org", timeout=30) as reply:
    public = ipaddress.ip_address(reply.read().decode().strip())

print(f"router WAN: {wan}    seen by websites: {public}")
if wan == public:
    print("Same address: no carrier-grade NAT on your IPv4 connection.")
elif wan in SHARED:
    print("WAN address is in 100.64.0.0/10: you are behind CGNAT.")
elif wan.is_private:
    print("WAN address is private: CGNAT, or another router in front of yours.")
else:
    print("Two different public addresses: something upstream translates your traffic.")

If the WAN address is private, check whether your router plugs into another router (a provider's modem-router, say) before blaming the provider. Two routers in a row give the same result.

No router access? Try a traceroute

traceroute -n 1.1.1.1

On Windows, run tracert -d 1.1.1.1 instead. A hop in 100.64.0.0/10 right after your own router is a strong hint of CGNAT. It is only a hint, because some providers use those addresses inside their network without translating anything. The WAN comparison above is the firmer test.

api.ipify.org reports your IPv4 address. CGNAT is an IPv4 matter: on IPv6, a household normally gets its own block of addresses.

Quick answers

Is CGNAT bad? For everyday browsing you mostly will not notice it. The costs are a shared reputation, no incoming connections, and an address you cannot safely allowlist.

Is 100.64.0.0/10 a private address? Not in the RFC 1918 sense. It is shared address space reserved for providers, and it is never routed on the public internet. Python's ipaddress module reports it as neither private nor global, which matches.

Can I get out of CGNAT? Ask your provider. Some give a public IPv4 address on request, sometimes for a fee, and some do not offer it at all.

Does a proxy or VPN get around CGNAT? It changes the address websites see. Your own connection still passes through CGNAT to reach the proxy or VPN server. Proxy vs VPN compares the two.

Next step

If you are setting up a new proxy service, run the test above first, then choose username and password or an allowlist based on the answer. Rates for each line are on the pricing page, and a small top-up is enough to try one. Questions about a strange result go to Discord.

Got a follow-up question?

Ask it in Discord. The answer helps whoever reads the thread next.

Join the Discorddiscord.gg/proxypanda
Start with $5Ask in Discord