How to Tell If You're Behind CGNAT

·Updated September 26, 2026·6 min read·FindMyIP Team

This guide is a practical check, not a definition. You will compare two numbers — your router’s WAN address and the public IP the internet sees — then interpret the result, including messy cases like double NAT. For what CGNAT is and why ISPs use it, read What Is CGNAT? Shared Public IP Explained, then come back here to verify your own line.


What you are checking for

CGNAT (carrier-grade NAT) means your ISP puts many customers behind one shared public IPv4. Everyday browsing still works. What often fails is inbound access: port forwards, some game hosts, and “call me from outside” setups.

You will not get a reliable “CGNAT: yes” badge from a random website. You can gather evidence at home in a few minutes, then ask the ISP to confirm when the answer matters.


Before you start

  1. Use the home network you care about (not café Wi‑Fi, not cellular).
  2. Turn any VPN off — it changes the public address sites see.
  3. Have router admin access ready (often 192.168.1.1 or 192.168.0.1).
  4. Note whether you use one router or a modem plus a second router. Two NAT devices at home confuse the comparison.

Step 1 — Read the public IP the internet sees

Open the FindMyIP homepage on that home network. Write down the IPv4 shown. That is the address remote servers record for this visit.

This number alone does not prove or disprove CGNAT. On a CGNAT plan it often looks like a normal public address — because it is the ISP’s shared exit, not a unique line to your house.

Optional: paste the address into ISP Lookup to see which provider owns that exit. Useful for support tickets. Still not proof of CGNAT by itself.


Step 2 — Read the router WAN IP

Log into the router. Open the WAN / Internet / Status page. Copy the WAN IPv4 exactly (labels like “Internet IP,” “WAN IP,” or “External IP”).

That is the address on the ISP-facing side of your home router — not a 192.168… LAN address on your laptop.


Step 3 — Compare the two numbers

Source What it is
Router WAN Address your gateway thinks it has toward the ISP
What Is My IP Address the open internet sees

Strong clue — Shared Address Space on WAN. If WAN is in 100.64.0.0–100.127.255.255 (100.64.0.0/10, RFC 6598), treat CGNAT as likely. That range is reserved for carrier-grade NAT. It is not a globally routable public endpoint, and it is not classic home private space (10., 172.16–31., 192.168.).

Strong clue — mismatch with a non-public WAN. If WAN ≠ the FindMyIP address, and WAN is Shared Address Space or RFC1918 private, you are probably behind at least one extra NAT. On many plans that layer is CGNAT.

Weaker or unclear. WAN matches FindMyIP and looks like a normal public IPv4 → often not CGNAT for IPv4 (or you already have a unique public assignment). WAN is private-looking but you run a second router → fix double NAT first (next step).


Step 4 — Rule out double NAT at home

A WAN/public mismatch is not automatic proof of ISP CGNAT. Your own gear can create a second NAT: ISP modem/router in router mode, plus your Wi‑Fi router also NATing behind it. Symptoms overlap: failed port forwards, “strict” NAT in games.

Quick fix and recheck: put the ISP device in bridge / modem-only mode if allowed, or put your second router in access-point mode so only one device NATs. Then re-check WAN vs What Is My IP.

If the mismatch disappears, the problem was home gear. If WAN stays in 100.64.0.0/10 on a clean single-router setup, the clue points at the ISP.


Step 5 — Ask the ISP when the answer matters

Home checks are evidence, not a verdict. Ask support:

  • “Am I on CGNAT / shared public IPv4?”
  • “Can I get a unique public IPv4 on this plan?”
  • “Is global IPv6 enabled end-to-end?”

Bring your notes: WAN address, public IP from FindMyIP, and that you already ruled out a second home router. ISP Lookup helps you and the agent talk about the same exit IP.


What this check proves (and what it does not)

Supports: CGNAT is likely when WAN is in 100.64.0.0/10 on a single-router setup; you are behind extra NAT when WAN ≠ public IP and WAN is not a unique public address; outbound browsing working while inbound IPv4 fails is consistent with CGNAT (and with other firewall/NAT issues).

Does not prove: that a normal-looking public IP on FindMyIP is yours alone; that CGNAT is the only reason a port forward failed; that your public IP will stay the same tomorrow — many plans are dynamic even without CGNAT (does your IP address change).

Treat the checklist as triage. Use ISP confirmation when money or uptime depends on the answer.


What to do next if you are behind CGNAT

Keep this brief. Depth lives in the CGNAT overview.

  • Ask the ISP for a unique public IPv4 add-on if you need inbound IPv4.
  • Prefer IPv6 when the ISP gives a global prefix and the service supports it.
  • Use vendor relays / cloud for cameras and NAS instead of raw port forwards.
  • Use a tunnel or VPS only when you truly need an inbound endpoint you control.
  • Do not expect a consumer VPN alone to open inbound ports on a CGNAT path — it changes the exit sites see; it does not make your home IPv4 reachable.

If you only browse and stream, you may not need to change anything. CGNAT is a problem when the internet must call you.


Decision tree

  1. VPN off on home Wi‑Fi? Continue. Else fix the path and restart.
  2. Note public IP on /.
  3. Note router WAN IP.
  4. WAN in 100.64.0.0/10? → CGNAT likely → ask ISP if inbound matters.
  5. WAN ≠ public IP, WAN private-looking, two routers? → remove double NAT → recheck.
  6. Still mismatched with non-public WAN on one router? → likely ISP extra NAT / CGNAT → ask ISP.
  7. WAN equals public IP and looks public? → CGNAT less likely for IPv4 → look elsewhere if inbound still fails.

Summary

To tell if you are behind CGNAT, compare router WAN to the public IP on What Is My IP, watch for 100.64.0.0/10, rule out double NAT, and ask the ISP when inbound access is the real goal. ISP Lookup names the provider on the public exit; it does not replace that WAN comparison. For definitions and what usually breaks, use the CGNAT shared-public-IP explainer — this page is the check you run at home.

How we research and correct articles

Your privacy choices

Optional analytics helps us understand site usage. It stays off unless you accept. All tools work without it. Privacy policy