How to Check for CGNAT (100.64.0.0/10) & Port Forward Fixes

Updated 2026-10-09 • By Devon Brooks, CISSP (Network Security & VPN Specialist)

To check if your ISP uses Carrier-Grade NAT (CGNAT), log into your router's WAN status page and verify whether your IPv4 address falls inside the RFC 6598 shared block (100.64.0.0/10 to 100.127.255.255) or differs from your public IP at ifconfig.me. Because CGNAT blocks inbound IPv4 port forwarding, you must bypass it using native IPv6 firewall pinholes, Tailscale mesh VPNs, Cloudflare Tunnels, or a static IP.

Key Technical Takeaways
  • RFC 6598 Shared Address Space: Any router WAN IPv4 between 100.64.0.0 and 100.127.255.255 confirms your ISP is placing you behind Carrier-Grade NAT.
  • 2-Step CLI Verification: Compare your router's WAN IP against curl -4 ifconfig.me and run tracert -d 1.1.1.1 to spot a 100.x.x.x second hop.
  • Zero-Cost Mesh Workaround: Install Tailscale or ZeroTier on your NAS or home server to traverse CGNAT via UDP hole-punching (STUN/DERP) without opening router ports.
  • Public Web Hosting Fix: Use Cloudflare Tunnel (cloudflared) or request a leased public IPv4 address ($5–$15/mo on Metronet, regional fiber, or Starlink Priority).

What Is CGNAT (RFC 6598) and Why Does Port Forwarding Fail?

Carrier-Grade NAT (CGNAT), standardized under IETF RFC 6598, allows Internet Service Providers to conserve exhausted IPv4 addresses by sharing a single public IPv4 address across 32 to 256 residential subscribers. Instead of assigning your home router a globally routable WAN IP, the ISP's core router assigns your CPE an internal address from the 100.64.0.0/10 block (spanning 100.64.0.0 through 100.127.255.255).

This creates a permanent ISP-level Double NAT architecture. When you configure a port forwarding rule on your home router (for example, TCP 32400 for Plex or UDP 51820 for a WireGuard server), your router opens its local firewall, but unsolicited inbound packets from the internet hit the ISP's CGNAT gateway first. Because the carrier gateway does not have a matching state table entry or static port mapping for your subscriber line, it silently drops the inbound SYN or UDP packet before it ever reaches your home.

2-Step Diagnostic Test: Confirm CGNAT on Your Connection

Do not guess whether a firewall rule or CGNAT is blocking your server. Run this two-step verification from any desktop computer connected to your local network:

  • Step 1 — Compare Router WAN IP vs Public IP: Open your router's administration portal (such as 192.168.1.1) and record the WAN IPv4 Address. Next, open a terminal and run curl -4 ifconfig.me. If your router WAN IP starts with 100.64.x.x–100.127.x.x (or 10.x.x.x / 172.16.x.x) while ifconfig.me reports a completely different public IP, you are behind CGNAT.
  • Step 2 — Inspect Your First ISP Hop via Traceroute: Run tracert -d 1.1.1.1 on Windows or traceroute -n 1.1.1.1 on macOS/Linux. Hop 1 is your local router (e.g., 192.168.1.1). If Hop 2 returns an address in the 100.64.0.0/10 range, your traffic is passing through an ISP CGNAT concentrator.

Which US ISPs Use CGNAT in 2026?

Traditional incumbent cable and fiber providers that acquired massive legacy IPv4 allocations in the 1990s—including Comcast Xfinity, AT&T Fiber, Verizon Fios, Cox, and Charter Spectrum—still assign dynamic public IPv4 addresses to standard residential lines. If port forwarding fails on those providers, the culprit is almost always an unbridged ISP gateway causing local Double NAT rather than carrier CGNAT.

Conversely, rapidly expanding regional fiber builders and wireless carriers rely heavily on CGNAT. T-Mobile 5G Home Internet, Verizon 5G Home, and AT&T Internet Air enforce strict CGNAT on all consumer plans. Starlink places Standard residential dishes behind CGNAT (`100.64.x.x`), though upgrading to a Starlink Priority (40GB+) plan unlocks a toggleable Public IPv4 option in the account dashboard. Regional FTTH providers such as Metronet, Ezee Fiber, GoNetSpeed, Tachus, and Pavlov Media also default to CGNAT but typically lease a static or dynamic public IPv4 for $5 to $15 per month.

4 Proven Ways to Bypass CGNAT Without Changing ISPs

If your ISP cannot or will not assign a public IPv4 address, choose one of four architectural workarounds based on your workload:

  • 1. Tailscale or ZeroTier Overlay VPN: Ideal for private remote access to NAS boxes, Home Assistant, RDP, and SSH. Tailscale uses STUN (UDP port 41641) and NAT-PMP/UPnP hole-punching to establish direct peer-to-peer WireGuard tunnels straight through CGNAT gateways.
  • 2. Cloudflare Tunnel (cloudflared): Ideal for hosting public HTTPS web apps (Overseerr, Nextcloud, Immich) without exposing an IP. A lightweight daemon inside your LAN initiates an outbound-only HTTP/2 or QUIC connection to Cloudflare's edge.
  • 3. Native IPv6 Firewall Pinholes: Most CGNAT ISPs (including Starlink, T-Mobile 5G on supported gateways, and regional fiber) delegate a globally routable /56 or /64 IPv6 prefix. Create an inbound IPv6 Allow rule in your router firewall targeting your server's global 2001: or 2600: address.
  • 4. VPS WireGuard Reverse Proxy: Rent a $4/month cloud VPS with a dedicated public IPv4, link your home router via outbound WireGuard, and use iptables PREROUTING DNAT to forward ports down the tunnel.

US ISP CGNAT Status & Public IPv4 Options (2026)

ISP / CarrierDefault IPv4 ModeNative IPv6 PrefixPublic IPv4 Workaround / Cost
AT&T Fiber / Verizon FiosPublic Dynamic IPv4Yes (/60 or /56 PD)Enable IP Passthrough / Bridge Mode (Free)
Comcast Xfinity / SpectrumPublic Dynamic IPv4Yes (/60 or /64 PD)Use standalone DOCSIS 3.1 modem or Bridge Mode (Free)
Starlink (Standard Plan)CGNAT (100.64.0.0/10)Yes (/56 PD)Upgrade to Priority 40GB Plan & toggle Public IP ($40+/mo diff)
T-Mobile 5G Home InternetStrict CGNAT (464XLAT)Yes (/64 Passthrough)Tailscale/Cloudflare Tunnel, or Business Plan static IP
Metronet / GoNetSpeed FiberCGNAT (100.64.0.0/10)Varies by marketCall support to add Static Public IPv4 ($10–$15/mo)
Ezee Fiber / Tachus / ZiplyCGNAT or Public DynamicYes (/56 PD)Request Public Dynamic or Static IP lease ($0–$10/mo)

CGNAT Detection & Bypass Action Checklist

  1. Log into your router's WAN status page and check if the IPv4 address starts with 100.64.x.x through 100.127.x.x.
  2. Run curl -4 ifconfig.me in a terminal and compare the output to your router's reported WAN IPv4 address.
  3. Run tracert -d 1.1.1.1 (Windows) or traceroute -n 1.1.1.1 (macOS/Linux) to verify whether Hop 2 is a local ISP gateway or a 100.x.x.x CGNAT node.
  4. Check if your ISP delegates a global IPv6 prefix (2000::/3) so you can reach servers directly via IPv6 DNS (AAAA records) and IPv6 firewall pinholes.
  5. Deploy Tailscale with a Subnet Router (--advertise-routes=192.168.1.0/24) for zero-configuration private access to your entire LAN.
  6. Contact your fiber ISP's technical support to ask whether a dynamic public IPv4 or static IPv4 add-on is available before building complex VPS tunnels.

Frequently Asked Questions

Is 100.64.x.x a private local IP or an ISP CGNAT address?

Addresses from 100.64.0.0 to 100.127.255.255 belong to the RFC 6598 Shared Address Space reserved specifically for Carrier-Grade NAT between an ISP's core network and subscriber routers. While Tailscale also uses 100.x.x.x addresses for virtual VPN interfaces, seeing 100.64.0.0/10 on your router's physical WAN port confirms ISP CGNAT.

Does CGNAT cause Strict NAT or Type 3 NAT on PlayStation, Xbox, and Nintendo Switch?

Yes. Because CGNAT prevents inbound UDP peer-to-peer connections and disables UPnP at the carrier edge, consoles often report NAT Type 3 (PlayStation), Strict NAT (Xbox), or NAT Type D (Switch). Matchmaking on dedicated cloud servers works normally, but peer-hosted multiplayer lobbies will fail without a VPN or public IP.

Can DMZ or UPnP on my home router bypass ISP CGNAT?

No. Enabling UPnP or placing a console in your home router's DMZ only opens your local router firewall; it cannot instruct the ISP's upstream 100.64.0.0/10 CGNAT gateway to forward ports to your home.

How does Plex Remote Access work behind CGNAT?

By default, Plex falls back to Plex Relay detrás of CGNAT, which caps video streams to 1 Mbps (or 2 Mbps with Plex Pass). To get full-bitrate direct streaming behind CGNAT, either enable IPv6 server support in Plex Settings > Network with an IPv6 firewall pinhole, or connect your clients and server over Tailscale.

Reviewed by Devon Brooks, CISSP (Network Security & VPN Specialist)

Part of the Packetsaver Network Engineering Team. All configurations and firmware safety instructions follow vendor-verified RFC and IEEE standards. Read our testing methodology →