Guide
What Is CGNAT, and How Can I Check for It?
Carrier-grade NAT lets an ISP share public IPv4 addresses across subscribers. Comparing your router's WAN address with the public address gives useful clues, but a website alone cannot confirm your provider's setup.
Last reviewed: October 3, 2026
Quick reference
Addresses to compare
- Shared IPv4 space
- 100.64.0.0–100.127.255.255 (100.64.0.0/10), reserved for shared service-provider networks.
- Router WAN / Internet IPv4
- The address assigned to your router's upstream connection; do not use its LAN address.
- Public IPv4
- The address an internet service sees for an IPv4 connection through that same router.
- Confirmation
- Your ISP can confirm CGNAT and whether public IPv4 or usable IPv6 is available.
Advertisement
Guide
Check step by step
- Use a device connected through the router you are checking. Ensure a VPN, proxy or relay is not changing the route used for the comparison; otherwise the result describes that service.
- Read WAN IP or Internet IPv4 in the router's status page. A 192.168… address shown under LAN is not the value to compare.
- Obtain the public IPv4 from the same connection. If your browser shows IPv6, use an IPv4-only request such as the curl command below.
- Compare the addresses and ranges. A shared-space WAN address with a different public IPv4 is strong evidence of upstream NAT, commonly CGNAT. Ask your ISP to confirm.
Request public IPv4
curl -4 --fail --silent --show-error --max-time 10 https://showip.net/ip
Example output
192.0.2.40
This is a documentation-only example. Your result should be an IPv4 address. A connection error means the test did not obtain a result; it does not establish CGNAT.
Guide
Interpret the result carefully
- WAN is 100.64.0.0/10: consistent with carrier shared-address space, but still confirm its purpose with the ISP.
- WAN is 10/8, 172.16/12 or 192.168/16: there is private addressing upstream. This could be an ISP network, a building network or a second router you control (double NAT).
- WAN equals the visible public IPv4: consistent with a directly assigned public address for that path. It does not prove that inbound ports are open.
- WAN differs but is not in those ranges: check VPNs, additional routers, multi-WAN routing and whether both values were captured at the same time. The mismatch alone does not identify CGNAT.
Guide
Why port forwarding may not work
A forwarding rule on your own router only controls that router. If another NAT device upstream has no matching rule, unsolicited inbound IPv4 traffic cannot reach your service through it.
Ask your ISP about a public IPv4 option, or use an authenticated outbound tunnel or mesh VPN that supports your use case. Native IPv6 may provide a separate path when both ends support it, but router and host firewalls still govern access. Do not disable those firewalls as a diagnostic shortcut.
Guide
What CGNAT does not tell you
CGNAT is not a measurement of internet speed and does not by itself mean browsing is broken. A failed ping, blocked port or traceroute containing private addresses is not enough to prove CGNAT. Public address sharing also means an IP address should not be used as a unique subscriber identifier.
Examples
Examples
Illustrative upstream NAT
WAN 100.100.20.5 → public 192.0.2.40
The WAN value is in shared space; the public value is a documentation-only stand-in. Confirm the real network arrangement with the ISP.
Next steps
Related guides and tools
Questions
FAQ
Can ShowIP automatically confirm CGNAT?
No. ShowIP sees the address reaching its server, not your router's WAN configuration or the ISP's internal network. Comparing those values provides clues; the ISP can confirm.
Does a 192.168 address mean I have CGNAT?
A device's local 192.168 address is normal on many home networks. Even a private router WAN address can be double NAT rather than carrier-grade NAT.
Sources