Get Real IP

How to check if you're behind CGNAT

Quick answer

Compare your router's WAN IP (in the router admin page) with your public IP as seen from the internet. If they don't match, you're behind CGNAT. A dead giveaway: a router WAN address in the 100.64.0.0–100.127.255.255 range, which is reserved specifically for carrier-grade NAT. If you're behind it, inbound connections can't reach you — bypass it with a static IP from your ISP or a dedicated-IP tunnel.

If hosting and port forwarding just won't work no matter what you try, the cause is usually carrier-grade NAT (CGNAT) — your ISP sharing one public IP across many customers so you never get your own. Here's how to confirm it in about two minutes.

The two-minute test

Compare two numbers:

  1. Your router's WAN IP. Log into your router's admin page and find the WAN / internet address it received from your ISP.
  2. Your public IP as seen from the internet. From any device on your network, check what the outside world sees — for example:
    curl https://api.ipify.org

If the two addresses match, you have a real public IP on your line (it may still be dynamic, but it's yours). If they don't match, there's carrier equipment between you and the internet — you're behind CGNAT.

The dead giveaway: the 100.64.0.0/10 range

Look at your router's WAN IP. If it falls in 100.64.0.0 to 100.127.255.255, that's conclusive: that block (100.64.0.0/10) is reserved by RFC 6598 specifically for carrier-grade NAT. Seeing an address there means your ISP has placed you behind CGNAT and you do not have your own public IP.

Ordinary private ranges on your WAN (10.x.x.x, 192.168.x.x,172.16–31.x.x) can also indicate an extra layer of NAT, though those sometimes just mean a modem in bridge-vs-router mode. The 100.64/10 range specifically points at carrier NAT.

Another quick signal

Try forwarding a port and reaching it from outside your network (e.g. from mobile data, not your home Wi-Fi). If a correctly configured port forward is still unreachable from outside, and your WAN IP doesn't match your public IP, CGNAT is almost certainly the reason.

Which ISPs use CGNAT?

CGNAT is most common on mobile carriers, satellite internet, and newer fibre providers — but practices vary by plan, region, and even individual circuit, so treat this as "commonly, check yours" rather than a guarantee. The two-minute test above is always the real answer for your line.

Providers frequently reported to use CGNAT include:

If your provider is on this list, don't assume — run the test. And if you are behind CGNAT, the fix is the same regardless of ISP: get a static IP from them if they offer one, or route a dedicated static IP to your server over a tunnel that works behind any CGNAT.

"But my ISP gives me IPv6 — am I set?"

Increasingly, ISPs that put you behind CGNAT on IPv4 do hand out real, publicly routable IPv6. That's genuinely useful — IPv6 traffic isn't NAT'd, so inbound connections can reach you over v6. But there's a catch that trips people up: the IPv6 prefix your ISP delegates is almost always dynamic. It's leased to your router (via DHCPv6-PD), and it typicallychanges when your router reboots, when the lease renews, or when the ISP renumbers — the same moving-target problem as a dynamic IPv4.

For casual use that's fine. But anything that depends on the address staying put breaks when it rotates: DNS records point at the old prefix, firewall allowlistsstop matching, TLS/HSTS and reverse DNS (PTR) assume a stable address, andemail — which leans heavily on a consistent IP with good reputation and matching PTR — is effectively impossible on a shifting residential prefix.

If you want the benefits of IPv6 without the churn — a static IPv6 range that never changes, with reverse DNS you control — you can get a dedicated static IPv6 range (and IPv4) routed to your network from Get Real IP. Your address stays fixed regardless of what your ISP does to your delegated prefix.

What to do if you're behind CGNAT

You have two paths:

Frequently asked questions

How do I know if I am behind CGNAT?

Compare two addresses: your router's WAN IP (in its admin page) and your public IP as seen from the internet (from a site like an IP checker). If they don't match, or your router's WAN IP is in the 100.64.0.0–100.127.255.255 range, you're behind carrier-grade NAT.

What is the 100.64.0.0/10 range?

It is the address block reserved specifically for carrier-grade NAT (RFC 6598). If your router received a WAN address in 100.64.0.0 to 100.127.255.255, your ISP has placed you behind CGNAT and you do not have your own public IP.

What can I do if I am behind CGNAT?

Either ask your ISP to remove you from CGNAT / add a static IP (if they offer it), or bypass it with a tunnel. Get Real IP routes a dedicated static public IP to your server over an outbound WireGuard tunnel, which works behind CGNAT because your server initiates the connection.

Why do ISPs use CGNAT?

IPv4 addresses are scarce, so ISPs — especially mobile carriers and newer fibre providers — share one public IPv4 across many customers to conserve addresses. It works fine for browsing but blocks inbound connections, which breaks hosting and remote access.

My ISP gives me IPv6 — do I still need anything?

Often the IPv6 your ISP delegates is dynamic — the prefix changes when your router reboots or the lease renews, the same moving-target problem as a dynamic IPv4. That's fine for casual use, but DNS, firewall allowlists, TLS, reverse DNS, and email all depend on a stable address. If you want IPv6 without the churn, a dedicated static IPv6 range (and IPv4) from Get Real IP stays fixed regardless of what your ISP does to your delegated prefix.

Want a dedicated static IP in minutes?

Get Real IP delivers a dedicated static public IPv4 to your server, router, or laptop over an encrypted WireGuard tunnel — any protocol, any port, works behind CGNAT. $8/mo, no contract.

Start your free trial

7 days free · Cancel anytime

Related guides

Updated September 4, 2026