Game Hosting

Monsoon Special: save up to 35% on Minecraft & game server plans Up to 35% off games

Claim offer
What is CGNAT, and Why Can't I Port Forward on My Own Router?
Aug 26, 2026 10 views

What is CGNAT, and Why Can't I Port Forward on My Own Router?

You've opened the port, checked it twice, and it still doesn't work. Here's why — and it usually isn't your router's fault.

What is CGNAT, and Why Can't I Port Forward on My Own Router?

"I forwarded the port, I can see it in my router, and it still doesn't work" is one of the most common networking complaints there is — and in a lot of cases, the router was never the problem.

What CGNAT actually is

Carrier-Grade NAT (CGNAT) is how many ISPs — especially mobile carriers and newer fiber/broadband providers — share a single public IPv4 address across hundreds or thousands of customers. IPv4 addresses are scarce and expensive, so instead of giving every customer their own, the ISP gives you a private address and does the translation at their own equipment, far upstream of your router.

Why this breaks port forwarding

Port forwarding on your router only controls traffic between your router and your own local network. It has no effect on, and no visibility into, whatever the ISP's equipment does further upstream. If your connection is behind CGNAT, your router's public-facing IP isn't actually public at all — it's just another private address on the ISP's own internal network. Forwarding a port on it doesn't make you reachable from the internet, because the internet never had a direct path to that address in the first place.

How to tell if you're behind CGNAT

Compare the IP address shown on your router's status page to what a site like whatismyip.com reports from a device on your network. If they're different, something between you and the internet is translating your address — and if your router's address starts with 100.64. through 100.127., that's CGNAT's officially reserved range, a dead giveaway.

What actually fixes it

Nothing on your end can undo CGNAT — it's configured at the ISP's infrastructure, not yours. The fix is to get your traffic a real public IP somewhere else and tunnel it back to you. A Port Forwarding plan does exactly that: traffic hits a real public IP we provide, then forwards to your server over an encrypted connection, bypassing the CGNAT problem entirely because your ISP's translation never has to be reachable from the internet at all.

Could I just ask my ISP for a public IP?

Some ISPs offer a static or public IP as a paid add-on — worth asking about if you want one permanently and your ISP actually supports it. Many mobile and budget broadband plans simply don't offer this option at any price, which is exactly the gap a tunnel is built for.

See also: How to Host a Minecraft Server at Home Without a Public IP.

Did you find this blog helpful?

found this blog helpful.