Guide

CGNAT on UK broadband: how to tell, and what to do about it

If you have set up a port forward correctly and it still shows as closed, the most likely reason on a newer UK full‑fibre or 4G/5G connection is carrier‑grade NAT. Here is how to confirm it and the realistic ways round it.

Updated · Checked against published provider information, August–September 2026 · 6 min read

Check takes
2 minutes
Tell‑tale sign
Router WAN IP in 100.64.0.0/10
Most common fix
Buy a public IPv4 add‑on
No‑cost options
IPv6, Tailscale, a tunnel

What CGNAT is, in one paragraph

There aren’t enough IPv4 addresses for every home to have its own, so many providers put customers behind a large shared NAT in their own network. Your router gets a private address, typically from 100.64.0.0/10, and hundreds of households leave the internet through the same public address. Outgoing traffic works normally. Incoming connections have nowhere to go, because the provider’s NAT has no idea which of its customers a new connection is meant for – and you can’t add a port forward to equipment you don’t control.

How to check in two minutes

  1. Sign in to your router and find the WAN, Internet or Broadband status page. On BT hubs this is at 192.168.1.254; on Sky and Virgin Media hubs at 192.168.0.1.
  2. Note the IPv4 address it shows for the internet connection (not the router’s own 192.168.x.1 address).
  3. Open ip.uk.app/cgnat-check and enter it. The page compares it with the address the internet actually sees.
Router showsMeaningCan you port forward?
Same address as ip.uk.appA public IPv4 addressYes
100.64.x.x – 100.127.x.xCGNAT at your providerNo, not over IPv4
192.168.x.x, 10.x.x.x, 172.16.x.x – 172.31.x.xUsually another router in front of yours – see double NAT. Occasionally CGNAT using other private rangesYes, once you fix the double NAT
A public address, but different from ip.uk.appTraffic leaves through something else: a VPN on your device, a proxy, or CGNAT with public‑looking rangesTest with the port checker to be sure

Tip

Run a quick test: forward a port to a device that is definitely listening, then try it with the open port checker. If it still says closed with the device’s own firewall off, and your router’s WAN address isn’t public, CGNAT is the answer.

Which UK providers use CGNAT?

Providers rarely put this on their sales pages, and policies change, so treat this as a starting point and always run the check above.

  • 4G and 5G home broadband (routers that take a SIM) is almost always behind CGNAT for IPv4. The same goes for tethering from a phone.
  • Satellite services such as Starlink use CGNAT for IPv4 on residential plans, while handing out public IPv6.
  • Full‑fibre altnets: several say openly that they use CGNAT on home plans and sell a public IPv4 address as an add‑on. At the time of writing that included brsk, toob, YouFibre and Community Fibre (for new and renewing customers since June 2026), with add‑ons from about £4 to £8 a month. Check the provider’s current help page, as prices and policies change.
  • The large national providers – BT, Sky, Virgin Media, TalkTalk and the brands that use their networks – have traditionally given home customers a public, dynamic IPv4 address. They don’t publish a guarantee, though, so check rather than assume.

Five ways to host at home behind CGNAT

1. Ask for a public IPv4 address

This is the cleanest fix, and often the cheapest in time. Search your provider’s help pages for “public IP”, “static IP” or “CGNAT opt‑out”, or ask support. Some providers will move you off CGNAT for free if you explain you need incoming connections for a home server or games console; others sell it as an add‑on. Once you have it, every guide on this site works as written.

2. Use IPv6

Many CGNAT providers give every customer a routed IPv6 range, and IPv6 has no NAT to get in the way. You allow the port through the router’s IPv6 firewall (sometimes called a pinhole) and publish an AAAA record for your name. The catch is the visitor’s side: most mobile networks support IPv6, but many office and café Wi‑Fi networks still don’t, and those visitors won’t be able to connect.

A uk.app dynamic DNS client can update the AAAA record – pass your server’s IPv6 address in myip=, because the update service is reached over IPv4 and would otherwise record that. Unlike IPv4, the address you publish is the server’s own, not the router’s.

3. A mesh VPN such as Tailscale

Tailscale, ZeroTier and similar services connect each device outwards to a coordination server, then build direct encrypted links between your devices wherever they can. No port forwarding and no public IP needed. It is ideal when only you and your household need access. It doesn’t help strangers or smart TVs reach a public URL.

4. A tunnel service

Cloudflare Tunnel and Tailscale Funnel run a small agent at home that connects out and receives web traffic for a public name. They work well for a web app behind CGNAT. Things to weigh up: your HTTPS traffic is decrypted on their servers, there can be limits on upload sizes and video streaming in their terms, and the name normally has to be managed in their account. For a Cloudflare Tunnel you need a domain whose DNS is hosted by Cloudflare.

5. Your own small VPS as a relay

Rent the cheapest virtual server you can find (a few pounds a month), run WireGuard between it and your home, and forward ports on the VPS through the tunnel. You keep full control, including over encryption, and can forward any protocol – game servers too. Point your uk.app name at the VPS’s fixed IP and you don’t even need dynamic DNS.

A common misunderstanding

Dynamic DNS doesn’t fix CGNAT. It will faithfully publish your shared public address, but connections to it still end at your provider’s NAT.

CGNAT or double NAT?

They look similar from the outside, but you can fix one of them yourself. Double NAT means two routers inside your home – typically the ISP hub plus your own router or mesh system. Put the hub in modem mode, or forward the port on both. CGNAT happens in your provider’s network. The double NAT guide explains how to tell them apart.

Once you have a public address

Set up a dynamic DNS name so you can reach home by name, then add HTTPS. With a uk.app name, create a DDNS token and point an updater at ddns.uk.app – the start guide has a ready‑made cron job, and the uk.app dynamic DNS page covers other clients. Then:

  1. Does the name point home? Look up home.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Why do providers use CGNAT?

The world ran out of new IPv4 addresses years ago. Newer providers either buy addresses on the open market, which is expensive, or share them between customers. CGNAT is the sharing mechanism.

Does CGNAT affect gaming?

It can. Online games that need incoming connections may report a strict or moderate NAT type, and hosting a game server at home over IPv4 won’t work. A public IPv4 add‑on fixes it.

Will UPnP open ports behind CGNAT?

No. UPnP only configures your own router. The provider’s NAT is out of its reach.

Is my IP address private if I am behind CGNAT?

Websites still see a public address, just one shared with other customers. It is not an anonymity feature; your provider can still tell which customer made a connection.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners