---
title: "What is CGNAT and why it blocks your server | StreetHosting"
description: "Understand CGNAT, the 100.64.0.0/10 range, how to tell whether your ISP uses it, and how a VPS or a WireGuard tunnel gets your open ports back."
url: "https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat"
type: "page"
language: "en-US"
---

Infrastructure · 11 min · Intermediate

Published on Sep 28, 2026 · Updated on Sep 28, 2026

# CGNAT: why port forwarding doesn't work on your internet connection

With CGNAT, your ISP shares a single public IP among several customers and no connection from the outside ever reaches your home. Here is how to confirm whether that is your case and which workarounds actually work for hosting a server.

By [Equipe StreetHosting](https://streethosting.com.br/en/autores#equipe-streethosting) · StreetHosting infrastructure and support team

[Network, DNS and domains](https://streethosting.com.br/en/guides/topics/networking)

Summarize with:

[](https://chat.openai.com/?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "ChatGPT") [](https://claude.ai/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Claude") [](https://www.google.com/search?udm=50&aep=11&q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Google AI Mode") [](https://x.com/i/grok?text=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Grok") [](https://www.perplexity.ai/search/new?q=Summarize%20the%20key%20points%20of%20this%20StreetHosting%20guide%3A%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat.%20Highlight%20the%20step-by-step%20instructions%2C%20the%20prerequisites%20and%20the%20most%20common%20mistakes. "Perplexity")

Share:

[](https://x.com/intent/tweet?text=What%20is%20CGNAT%20and%20why%20it%20blocks%20your%20server&url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat "Share on X") [](https://www.facebook.com/sharer/sharer.php?u=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat "Share on Facebook") [](https://www.linkedin.com/sharing/share-offsite/?url=https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat "Share on LinkedIn") [](https://wa.me/?text=What%20is%20CGNAT%20and%20why%20it%20blocks%20your%20server%20https%3A%2F%2Fstreethosting.com.br%2Fen%2Fguides%2Finfrastructure%2Fwhat-is-cgnat "Share on WhatsApp")

For agents: Copy as Markdown [.md](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat.md)

In this guide 7 sections

* [What CGNAT is](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#o-que-e-cgnat)
* [How to tell if you are behind CGNAT](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#como-detectar)
* [Why port forwarding does not help](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#port-forwarding)
* [IPv6 as a partial workaround](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#ipv6)
* [A VPS as your public endpoint](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#vps-ponto-publico)
* [Which workaround to choose](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#qual-saida)
* [Which VPS to use](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#onde-rodar)

Quick answer

**CGNAT**(Carrier Grade NAT) is when your ISP puts several customers behind the same public IP. Your connection browses normally, but nobody on the outside can start a connection to your home, so opening a port on your router does nothing. You confirm CGNAT when the router's WAN IP falls in the 100.64.0.0/10 range or differs from your public IP. The real options are asking your ISP for a public IP, using IPv6, or putting a VPS with a public IP in front.

## What CGNAT is[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#o-que-e-cgnat)

IPv4 ran out a long time ago. There are just over 4 billion addresses, and ISPs can no longer hand a public IP to every new customer. The workaround most of them adopted is carrier-grade NAT: a central piece of equipment at the ISP translates the traffic of hundreds or thousands of customers into a small pool of public IPs, the same way your router does with the devices in your home.

In practice there are two NATs in a row. The first is your router's, which translates the local network addresses (192.168.0.x, for example) into the WAN IP. The second is the ISP's, which translates that WAN IP into a shared public IP. For the address between the two NATs, RFC 6598 reserved the 100.64.0.0/10 range, which runs from 100.64.0.0 to 100.127.255.255. It is not routed on the internet and exists only for this purpose.

If all you do is browse, stream video and play games as a client, CGNAT goes unnoticed. Every connection leaving your home is translated on the way out and the reply comes back along the same path. The problem shows up when the direction flips and someone outside needs to reach you: friends joining your Minecraft server, remote access to a camera or NAS, a P2P game that asks for open NAT, a file server or a website hosted at home.

CGNAT is very common on mobile internet, 4G and 5G, and it also shows up on a good share of residential fiber connections. It is not a fault in your setup: it is a decision the ISP made to save addresses.

## How to tell if you are behind CGNAT[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#como-detectar)

The test takes two minutes and needs no special tool. The idea is to compare the address your router received from the ISP with the address the internet sees.

1. Open your router's admin page, usually at `192.168.0.1` or `192.168.1.1`, and look for the connection status. Write down the field called WAN IP, Internet IP or external IPv4 address.
2. Find your public IP on an IP lookup site or, in a terminal, with `curl -4 ifconfig.me`.
3. Compare the two. If they match, you have a public IP and CGNAT is not your problem. If they differ, there is one more NAT between your router and the internet.
4. Confirm it through the route. On Windows, run `tracert -d 1.1.1.1`; on Linux, `traceroute -n 1.1.1.1`. If the second or third hop falls in the 100.64.x.x to 100.127.x.x range, it is CGNAT.

The WAN address says a lot about your situation. Use the table to interpret what your router showed.

| WAN IP on the router          | What it means                                     | Next step                                     |
| ----------------------------- | ------------------------------------------------- | --------------------------------------------- |
| 100.64.0.0 to 100.127.255.255 | ISP CGNAT (RFC 6598)                              | Ask for a public IP, use IPv6 or a VPS        |
| 10.x.x.x                      | Private range: ISP NAT or another router in front | Check whether the ISP modem is in router mode |
| 172.16.x.x to 172.31.x.x      | Private range, same reading as the row above      | Check the modem and ask the ISP               |
| 192.168.x.x                   | Almost always two routers chained inside the home | Put the ISP modem in bridge mode              |
| Same as the public IP         | Connection with a public IP, no CGNAT             | Review port forwarding and firewall           |

A WAN IP in the 192.168 range is usually double NAT inside your own home, not CGNAT: the ISP's ONT or modem is routing and your router sits behind it. You can fix that yourself by putting the ISP's equipment in bridge mode or opening the port on both devices. A traceroute helps tell one case from the other, as shown in the guide on [using traceroute to diagnose the route](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute).

## Why port forwarding does not help[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#port-forwarding)

Port forwarding is a rule on your router that says: whatever arrives on port 25565 of my WAN IP goes to the computer at 192.168.0.50. The catch is that, under CGNAT, your friend's connection never reaches your WAN IP. It reaches the shared public IP, which belongs to the ISP's equipment.

That equipment only knows which customer to send a packet to when the packet is a reply to something the customer sent earlier. A new connection coming from outside, with no prior mapping, has no owner. The ISP drops the packet and your router never even learns that someone tried. That is why the symptoms are always the same:

* **Friends get a timeout:** the game keeps trying to connect until it gives up, because the packet vanishes along the way. In Minecraft, it is the classic connection timed out.
* **Port check sites say closed:**even with the right rule on the router and the computer's firewall open.
* **UPnP changes nothing:** it only configures your router, and your router was never the problem.
* **Dynamic DNS does not help:** it points a name at an IP that changes, but the CGNAT public IP is not yours and is shared with other customers.
* **Everything outbound works:** browsing, online games as a client and video calls carry on as normal, which confuses a lot of people during diagnosis.

The first attempt is worth a phone call: some ISPs take your connection out of CGNAT on request, others only offer a public IP on a business plan or as a paid add-on. Ask specifically for a public IPv4 address, not just a static IP, because they are different things.

## IPv6 as a partial workaround[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#ipv6)

Many ISPs deliver IPv6 alongside CGNAT IPv4. There is no address shortage in IPv6, so every device in your home gets a global address and there is no NAT in the path. In theory, anyone with IPv6 reaches your server directly. The fundamentals are in [how IPv6 works in hosting](https://streethosting.com.br/en/guides/infrastructure/how-ipv6-works).

In practice, the workaround is partial for three reasons:

* **Whoever connects also needs IPv6:** the friend who only has IPv4 still cannot reach you. Corporate networks, some mobile networks and many older routers still run on IPv4 only.
* **The router blocks inbound by default:** most home routers have an IPv6 firewall that drops new connections coming from outside. You need to create a rule allowing the port to the address of the device running the server.
* **The prefix can change:**on many connections the IPv6 block handed out by the ISP changes when the router reboots, and your domain's AAAA record starts pointing to the wrong place.

For a small group where everyone has IPv6, it works. For a server open to the public, you cannot rely on it alone: some of your players simply will not be able to get in, and they will not know how to explain why.

## A VPS as your public endpoint[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#vps-ponto-publico)

A VPS has a public IPv4, stays on around the clock in a datacenter and accepts connections on any port you open in the firewall. It solves CGNAT in two ways, depending on where the server needs to run.

### Running the server directly on the VPS[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#servidor-na-vps)

This is the cleanest way out. You install the game server, the website or the API on the VPS itself and users connect to its IP. Your home internet leaves the equation entirely: CGNAT, limited upload, a power outage or the computer being switched off at night no longer matter. Players connect straight to the datacenter, without passing through your connection.

For Minecraft, the step by step is in [hosting Paper on a VPS with root access](https://streethosting.com.br/en/guides/vps/host-paper-minecraft-server-on-vps). If you would rather not manage Linux, a managed Minecraft server solves the same problem with a ready-made control panel.

### WireGuard tunnel from the VPS to your home[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#tunel-wireguard)

Sometimes the server has to stay at home: hardware you already own, a big local disk, a personal lab. In that case the VPS becomes just the front door. The trick is that CGNAT blocks inbound connections, but not outbound ones. The home machine opens a WireGuard tunnel to the VPS, the tunnel stays open with periodic keepalive messages, and the VPS relays the traffic arriving on the public port through it.

Install WireGuard on both ends with `sudo apt install wireguard` and generate a key pair on each with `wg genkey | tee privada.key | wg pubkey > publica.key`. The guide on [WireGuard VPN on a VPS](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps) covers the basics. On the VPS, the `/etc/wireguard/wg0.conf` file looks like this, with the example forwarding Minecraft's TCP port 25565:

`[Interface] Address = 10.8.0.1/24 ListenPort = 51820 PrivateKey = CHAVE_PRIVADA_DA_VPS PostUp = iptables -t nat -A PREROUTING -i eth0 -p tcp --dport 25565 -j DNAT --to-destination 10.8.0.2:25565; iptables -t nat -A POSTROUTING -o wg0 -j MASQUERADE PostDown = iptables -t nat -D PREROUTING -i eth0 -p tcp --dport 25565 -j DNAT --to-destination 10.8.0.2:25565; iptables -t nat -D POSTROUTING -o wg0 -j MASQUERADE [Peer] PublicKey = CHAVE_PUBLICA_DE_CASA AllowedIPs = 10.8.0.2/32`

On the home machine, the file points to the VPS IP and keeps the tunnel alive every 25 seconds, which stops CGNAT from forgetting the mapping:

`[Interface] Address = 10.8.0.2/24 PrivateKey = CHAVE_PRIVADA_DE_CASA [Peer] PublicKey = CHAVE_PUBLICA_DA_VPS Endpoint = IP_DA_VPS:51820 AllowedIPs = 10.8.0.1/32 PersistentKeepalive = 25`

What is left is enabling forwarding on the VPS and bringing up both ends. Replace `eth0` with the name of the public interface, which shows up in `ip -br a`:

`# on the VPS echo "net.ipv4.ip_forward=1" | sudo tee /etc/sysctl.d/99-encaminhamento.conf sudo sysctl --system sudo ufw allow 51820/udp sudo ufw route allow in on eth0 out on wg0 to 10.8.0.2 port 25565 proto tcp sudo systemctl enable --now wg-quick@wg0 # at home sudo systemctl enable --now wg-quick@wg0 sudo wg show`

When `wg show` displays a recent latest handshake, players can already connect at `IP_DA_VPS:25565`. For UDP games, repeat the DNAT and `ufw route` rules with `-p udp` and `proto udp`. If you are unsure which protocol your game uses, see [TCP or UDP for servers](https://streethosting.com.br/en/guides/infrastructure/tcp-vs-udp).

The tunnel has costs you need to accept. Every packet travels player, VPS, your home and back, so the final latency adds the leg to the VPS and the stretch between the VPS and your home. Your internet's upload remains the bandwidth ceiling. And, with the MASQUERADE in the example, the home server sees every connection coming from 10.8.0.1, which breaks IP bans and per-source connection counting.

## Which workaround to choose[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#qual-saida)

There is no single answer. The table compares the options by what matters to someone who wants to receive connections from outside.

| Workaround                  | Who can connect                                | Latency                                 | Effort                                             |
| --------------------------- | ---------------------------------------------- | --------------------------------------- | -------------------------------------------------- |
| Ask the ISP for a public IP | Everyone, over IPv4                            | Same as your connection                 | One phone call, sometimes with an extra charge     |
| ISP IPv6                    | Only people who also have IPv6                 | Same as your connection                 | An IPv6 firewall rule on the router                |
| Third-party HTTP tunnel     | Everyone, but only for websites and web panels | Goes through the service&apos;s network | Low, no ports to open                              |
| WireGuard tunnel to a VPS   | Everyone, any TCP or UDP port                  | Adds the VPS-to-home leg                | Medium, needs Linux on both ends                   |
| Server directly on the VPS  | Everyone, any TCP or UDP port                  | Only player to datacenter               | Medium, but takes home internet out of the picture |

For websites and panels, an HTTP tunnel may be enough, and how it works is in [Cloudflare Tunnel on a VPS](https://streethosting.com.br/en/guides/vps/cloudflare-tunnel-vps). For game servers, voice or any protocol that is not HTTP, the reliable path is having a public IP in front, whether it comes from the ISP or from a VPS.

## Which VPS to use[](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#onde-rodar)

The [StreetHosting VPS](https://streethosting.com.br/en/vps) plans are hosted in São Paulo, with a public IPv4, root access, KVM virtualization, a 1 Gbps uplink and Anti-DDoS included. That covers both scenarios in this guide.

* **WireGuard tunnel only:**WireGuard uses little CPU and memory, and the entry plan is already more than enough. The Xeon VPS starts at R$ 26.00 per month with 2 vCPU, 2 GB of RAM and 20 GB NVMe. The tunnel's real bandwidth will be capped by your home upload, not by the VPS.
* **Game server directly on the VPS:** games depend on high per-core clock speed, and the Ryzen 9 9950X line with DDR5 is the one to pick. It starts at R$ 40.00 with 1 vCPU and 2 GB, and a Minecraft server with plugins for a group of friends usually starts at 4 vCPU and 8 GB, which costs R$ 118.00 per month.
* **Website, API or several services:** the Xeon line delivers more vCPU for your money, with 4 vCPU and 6 GB for R$ 60.00 and 6 vCPU and 8 GB for R$ 77.00.

The VPS is activated within 60 seconds after payment, which can be made by Pix, boleto or card, and plan upgrades are done from the control panel, charging only the prorated difference. For game servers, see the tiers on the [Ryzen VPS page](https://streethosting.com.br/en/vps/ryzen).

In this guide

* [What CGNAT is](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#o-que-e-cgnat)
* [How to tell if you are behind CGNAT](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#como-detectar)
* [Why port forwarding does not help](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#port-forwarding)
* [IPv6 as a partial workaround](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#ipv6)
* [A VPS as your public endpoint](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#vps-ponto-publico)
* [Which workaround to choose](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#qual-saida)
* [Which VPS to use](https://streethosting.com.br/en/guides/infrastructure/what-is-cgnat#onde-rodar)

## Frequently asked questions

How do I know if my internet connection has CGNAT?

Open your router's admin page and write down the WAN IP, then compare it with the public IP shown by an IP lookup site. If the WAN IP falls between 100.64.0.0 and 100.127.255.255, you are behind CGNAT. If the two match, your connection has a public IP and the port problem lies somewhere else.

Can I open a port while behind CGNAT?

Not from your router. The port forwarding you configure at home never reaches the ISP's NAT equipment, which is what actually receives the connection from outside. The real options are asking your ISP for a public IP, using IPv6 when the people connecting also have it, or putting a public endpoint in front, such as a VPS.

Is a dynamic IP the same thing as CGNAT?

No. A dynamic IP is a public IP that changes from time to time, and a dynamic DNS service solves that by pointing a name at the new address. Under CGNAT the address is not even yours: it is shared with other customers, so no dynamic DNS can make an outside connection reach you.

Does IPv6 solve the CGNAT problem?

Partly. With IPv6 every device in your home gets a global address and can accept connections, as long as the router's firewall allows the port. The limit is that only people who also have IPv6 can reach the server, and plenty of people still connect over IPv4 only.

Does a VPS solve CGNAT for a Minecraft server?

Yes, in two ways. The simplest is running the server directly on the VPS, which has a public IP and receives players without depending on your home internet. If the server has to stay at home, the VPS becomes the entry point and relays the traffic through a WireGuard tunnel that your home machine opens from the inside out.

Next step

See VPS plans

Root VPS in Brazil with NVMe and Anti-DDoS.

[See VPS plans](https://streethosting.com.br/en/vps)

[See Xeon VPS Xeon VPS for steady workloads, automation and long-running projects.](https://streethosting.com.br/en/vps/xeon) [See Ryzen VPS Ryzen 9 9950X VPS in São Paulo with root access, NVMe and gamer Anti-DDoS.](https://streethosting.com.br/en/vps/ryzen)

## Related guides

[VPS Advanced How to set up a WireGuard VPN on your VPS for private access Instead of exposing panels and databases to the internet, put everything behind a VPN. WireGuard is lightweight, fast and simple to configure, and it gives you secure private access to your VPS services. 3 min Read guide](https://streethosting.com.br/en/guides/vps/wireguard-vpn-vps) [Infrastructure Intermediate How IPv6 works for hosting and servers: a practical guide IPv4 is exhausted. IPv6 fixes that with a practically unlimited address space. Here is how IPv6 works in practice, how it affects servers and applications, and how to configure it on your VPS. 4 min Read guide](https://streethosting.com.br/en/guides/infrastructure/how-ipv6-works) [Infrastructure Intermediate How to use traceroute to find routing problems Traceroute lists every router between you and the server and how long each one takes to answer. Read the right way, it shows whether the delay starts at your home, at your ISP, between networks or at the destination. 8 min Read guide](https://streethosting.com.br/en/guides/infrastructure/how-to-use-traceroute)

[← Back to the Guide Center](https://streethosting.com.br/en/guides)
