What is CGNAT, and why does it break things?
Carrier-grade NAT is a technique ISPs use to share a single public IP address between many customers — a response to IPv4 address exhaustion, and a cause of a specific and confusing set of problems.
The underlying problem. IPv4 has about 4.3 billion addresses, and they ran out. Regional registries have been allocating from scarce reserves for years. IPv6 solves it permanently but adoption has been gradual, so ISPs needed an interim measure.
What CGNAT does. Instead of giving each customer a public address, the ISP assigns a private address from its own range and performs a second layer of address translation in its network. Dozens or hundreds of customers appear to the outside world as one public IP address, distinguished by port numbers.
This is the same principle your home router already uses for devices in your house — CGNAT simply does it again, one level up.
What it breaks:
Inbound connections. Nothing outside can initiate a connection to you, because your address is not routable. This breaks port forwarding entirely, and with it self-hosted servers, security camera access from outside, remote desktop, and home automation reachable from away.
Peer-to-peer and gaming. Some multiplayer titles and voice systems struggle, reporting a strict NAT type. Games generally work but hosting or direct connection may not.
Dynamic DNS becomes useless, since the address is not yours.
Shared reputation. If another customer behind the same address is abusive, the address can be rate-limited or blocked — which is why you may suddenly face repeated CAPTCHAs or a block on a site you have never misused.
Geolocation becomes less accurate.
How to tell if you are behind it. Compare the WAN address shown in your router with the address a "what is my IP" site reports. If they differ, you are behind CGNAT. A WAN address in ranges such as 100.64.0.0/10 is a strong indicator.
What to do: many ISPs will move you off CGNAT or provide a static IP on request, sometimes for a fee. IPv6, where offered, gives genuinely routable addresses and sidesteps the problem.