What CGNAT actually is

The internet was designed around IPv4 addresses, and there are only about 4.3 billion of them. The regional registries ran out of fresh IPv4 blocks years ago, so ISPs have had two ways to keep connecting new customers:

  • Home NAT, which you already have: your router gives every device a private address and shares the single public address your ISP assigns. This has been standard since the early days of home broadband.
  • Carrier-grade NAT: the ISP adds its own large NAT in its network. Your router now receives a shared address from the 100.64.0.0/10 range instead of a public one, and the ISP translates many customers onto a smaller pool of public addresses.

From the internet's point of view, you're one of many subscribers sitting behind the same public IP. That saves the ISP addresses, but it removes your ability to accept unsolicited inbound IPv4 traffic, because the ISP's NAT has no idea which customer it belongs to.

Who uses CGNAT in the US

  • 5G and LTE home internet: T-Mobile Home Internet uses CGNAT for IPv4 and provides IPv6. Other cellular home internet services commonly work the same way, because mobile networks were built around CGNAT from the start.
  • Satellite: Starlink residential service uses CGNAT for IPv4, with IPv6 available.
  • Some fiber and fixed-wireless providers: newer regional fiber builders, WISPs and rural co-ops sometimes use CGNAT because they couldn't get large IPv4 allocations.
  • Major cable and fiber ISPs (Xfinity, Spectrum, Cox, AT&T Fiber, Verizon Fios) have generally given residential customers a public IPv4 address, though it is usually dynamic. Don't assume — test.

How to check if you're behind CGNAT

Step 1: find your public IP

Open ipinfo.io or whatismyip.com and note the IPv4 address, for example 73.12.45.67.

Step 2: find your router's WAN IP

Log in to your router (see how to log in to your router) and look for WAN, Internet, Internet Status or Broadband. Note the IPv4 address the router received from the ISP. On app-managed gateways, the app's network details screen usually shows it.

Step 3: compare

  • Same address: no CGNAT. You have a real public IPv4 address.
  • WAN address between 100.64.0.0 and 100.127.255.255: you're behind CGNAT.
  • WAN address is 192.168.x.x, 10.x.x.x or 172.16–31.x.x: your router is behind another router, usually the ISP's gateway. That's double NAT, which you can fix with bridge mode or IP passthrough — see modem vs router.
  • Different public-looking addresses: some ISPs use other ranges internally. Ask the ISP directly whether your service uses CGNAT.

You can also run a traceroute to any public site (tracert 1.1.1.1 on Windows, traceroute 1.1.1.1 on macOS). A 100.64–100.127 address appearing in the first couple of hops after your router is another strong hint.

What CGNAT breaks, and what still works

Doesn't work (over IPv4)

  • Port forwarding of any kind — see port forwarding.
  • Hosting game servers or lobbies that need inbound connections.
  • Direct remote access to a NAS, Plex, Home Assistant or security DVR without a relay.
  • Running a VPN server (WireGuard, OpenVPN) on your router or at home.
  • Dynamic DNS hostnames pointing to your home.

You may also see more CAPTCHAs or occasional blocks, because sites see many users behind the same address and one bad actor can affect its reputation.

Still works

  • Web browsing, streaming, video calls and downloads.
  • VPN client apps connecting out to a work or commercial VPN.
  • Cloud-connected cameras, doorbells and smart-home devices, which use the vendor's servers as a relay.
  • Most online games, sometimes with a Moderate or Strict NAT type.

How to get around CGNAT

Option 1: ask your ISP for a public IP

Call or chat with support and ask whether your plan can get a public IPv4 address. Some providers do it free on request, some charge a monthly add-on, and some only offer it on business plans. 5G home internet services typically don't offer public IPv4 on residential plans.

Option 2: a static IP or business plan

If you need a stable address for remote access, cameras or a small server, a business plan with a static IP solves CGNAT and dynamic addressing at once, at a higher monthly cost.

Option 3: tunnels and mesh VPNs

These work over outbound connections, so CGNAT doesn't stop them:

  • Tailscale or ZeroTier: install on your devices and reach your home network privately from anywhere. The easiest option for personal remote access.
  • Cloudflare Tunnel: publish a web service (Home Assistant, a self-hosted app) through Cloudflare without opening any ports.
  • Cloud VPS + WireGuard: rent a small virtual server with a public IP, connect your home to it with WireGuard, and forward ports on the VPS. Most flexible, most technical — it works for game servers too.

IPv6: the long-term fix

IPv6 has enough addresses for every device to have its own globally reachable address, so no carrier-grade NAT is needed. T-Mobile Home Internet, Starlink and most major US ISPs provide IPv6. If both ends support it, connections can bypass CGNAT entirely. Two caveats: many remote networks (some workplaces, hotels, mobile carriers) still lack IPv6, and your router's IPv6 firewall blocks inbound traffic by default, so you open specific ports in the IPv6 firewall rather than using classic port forwarding.

Frequently asked questions

Which US internet providers use CGNAT?

It is most common on 5G and fixed-wireless home internet: T-Mobile Home Internet places customers behind CGNAT for IPv4 (with native IPv6), and other cellular home internet services commonly do the same. Satellite service such as Starlink's residential plans also uses CGNAT for IPv4. Some smaller fiber, fixed-wireless and rural providers use it to stretch limited IPv4 address blocks. The large cable and fiber providers have historically assigned a public IPv4 address to residential customers, but policies vary by provider, plan and region, so the reliable answer comes from the test below.

How do I know if I'm behind CGNAT?

Compare two numbers. First, look up your public IP on a site such as ipinfo.io. Second, log in to your router and find the WAN or Internet IP address it received from the ISP. If they match, you have a real public IPv4 address. If the router's WAN address is in 100.64.0.0 – 100.127.255.255, you're behind CGNAT. If it's a private address like 192.168.x.x or 10.x.x.x, you're probably behind another router of your own or an ISP gateway (double NAT), which you can usually fix yourself.

What doesn't work behind CGNAT?

Anything that needs inbound IPv4 connections: port forwarding, hosting game servers, direct remote access to a NAS or Plex server, running a VPN server at home, and services that expect a stable public address. Consoles may also report a Strict or Moderate NAT type. Browsing, streaming, video calls, VPN client apps and cloud-connected cameras and smart-home devices keep working, because those connections are started from inside your home.

How do I get out of CGNAT?

Ask your provider first: some ISPs will move you to a public IP on request, or offer a public or static IP as a paid add-on or business plan. If they won't, use IPv6 where your service supports it, or a tunnel that doesn't need inbound IPv4: a mesh VPN such as Tailscale or ZeroTier for private access, Cloudflare Tunnel for publishing a web service, or a small cloud server running WireGuard that relays traffic to your home. Plex and some game platforms can also fall back to relayed connections.

Is CGNAT bad for gaming?

It can be. Most online games work, but you're more likely to see a Strict or Moderate NAT type, which can lengthen matchmaking, prevent you from hosting lobbies, and cause voice chat failures with some players. Latency itself is usually not worse because of CGNAT. If NAT type matters to you, ask your ISP about a public IP or check whether your console and games can use IPv6.