What CGNAT is, in one paragraph
There aren’t enough IPv4 addresses for every home to have its own, so many providers put customers behind a large shared NAT in their own network. Your router gets a private address, typically from 100.64.0.0/10, and hundreds of households leave the internet through the same public address. Outgoing traffic works normally. Incoming connections have nowhere to go, because the provider’s NAT has no idea which of its customers a new connection is meant for – and you can’t add a port forward to equipment you don’t control.
How to check in two minutes
- Sign in to your router and find the WAN, Internet or Broadband status page. On BT hubs this is at
192.168.1.254; on Sky and Virgin Media hubs at192.168.0.1. - Note the IPv4 address it shows for the internet connection (not the router’s own
192.168.x.1address). - Open ip.uk.app/cgnat-check and enter it. The page compares it with the address the internet actually sees.
| Router shows | Meaning | Can you port forward? |
|---|---|---|
| Same address as ip.uk.app | A public IPv4 address | Yes |
100.64.x.x – 100.127.x.x | CGNAT at your provider | No, not over IPv4 |
192.168.x.x, 10.x.x.x, 172.16.x.x – 172.31.x.x | Usually another router in front of yours – see double NAT. Occasionally CGNAT using other private ranges | Yes, once you fix the double NAT |
| A public address, but different from ip.uk.app | Traffic leaves through something else: a VPN on your device, a proxy, or CGNAT with public‑looking ranges | Test with the port checker to be sure |
Tip
Run a quick test: forward a port to a device that is definitely listening, then try it with the open port checker. If it still says closed with the device’s own firewall off, and your router’s WAN address isn’t public, CGNAT is the answer.
Which UK providers use CGNAT?
Providers rarely put this on their sales pages, and policies change, so treat this as a starting point and always run the check above.
- 4G and 5G home broadband (routers that take a SIM) is almost always behind CGNAT for IPv4. The same goes for tethering from a phone.
- Satellite services such as Starlink use CGNAT for IPv4 on residential plans, while handing out public IPv6.
- Full‑fibre altnets: several say openly that they use CGNAT on home plans and sell a public IPv4 address as an add‑on. At the time of writing that included brsk, toob, YouFibre and Community Fibre (for new and renewing customers since June 2026), with add‑ons from about £4 to £8 a month. Check the provider’s current help page, as prices and policies change.
- The large national providers – BT, Sky, Virgin Media, TalkTalk and the brands that use their networks – have traditionally given home customers a public, dynamic IPv4 address. They don’t publish a guarantee, though, so check rather than assume.
Five ways to host at home behind CGNAT
1. Ask for a public IPv4 address
This is the cleanest fix, and often the cheapest in time. Search your provider’s help pages for “public IP”, “static IP” or “CGNAT opt‑out”, or ask support. Some providers will move you off CGNAT for free if you explain you need incoming connections for a home server or games console; others sell it as an add‑on. Once you have it, every guide on this site works as written.
2. Use IPv6
Many CGNAT providers give every customer a routed IPv6 range, and IPv6 has no NAT to get in the way. You allow the port through the router’s IPv6 firewall (sometimes called a pinhole) and publish an AAAA record for your name. The catch is the visitor’s side: most mobile networks support IPv6, but many office and café Wi‑Fi networks still don’t, and those visitors won’t be able to connect.
A uk.app dynamic DNS client can update the AAAA record – pass your server’s IPv6 address in myip=, because the update service is reached over IPv4 and would otherwise record that. Unlike IPv4, the address you publish is the server’s own, not the router’s.
3. A mesh VPN such as Tailscale
Tailscale, ZeroTier and similar services connect each device outwards to a coordination server, then build direct encrypted links between your devices wherever they can. No port forwarding and no public IP needed. It is ideal when only you and your household need access. It doesn’t help strangers or smart TVs reach a public URL.
4. A tunnel service
Cloudflare Tunnel and Tailscale Funnel run a small agent at home that connects out and receives web traffic for a public name. They work well for a web app behind CGNAT. Things to weigh up: your HTTPS traffic is decrypted on their servers, there can be limits on upload sizes and video streaming in their terms, and the name normally has to be managed in their account. For a Cloudflare Tunnel you need a domain whose DNS is hosted by Cloudflare.
5. Your own small VPS as a relay
Rent the cheapest virtual server you can find (a few pounds a month), run WireGuard between it and your home, and forward ports on the VPS through the tunnel. You keep full control, including over encryption, and can forward any protocol – game servers too. Point your uk.app name at the VPS’s fixed IP and you don’t even need dynamic DNS.
A common misunderstanding
Dynamic DNS doesn’t fix CGNAT. It will faithfully publish your shared public address, but connections to it still end at your provider’s NAT.
CGNAT or double NAT?
They look similar from the outside, but you can fix one of them yourself. Double NAT means two routers inside your home – typically the ISP hub plus your own router or mesh system. Put the hub in modem mode, or forward the port on both. CGNAT happens in your provider’s network. The double NAT guide explains how to tell them apart.
Once you have a public address
Set up a dynamic DNS name so you can reach home by name, then add HTTPS. With a uk.app name, create a DDNS token and point an updater at ddns.uk.app – the start guide has a ready‑made cron job, and the uk.app dynamic DNS page covers other clients. Then:
- Does the name point home? Look up
home.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.