Carrier-grade NAT
Carrier-grade NAT is address translation performed inside an operator's own network, so that many subscribers share a single public address.
Carrier-grade NAT is address translation performed inside an operator’s own network, so that many subscribers share a single public address. It exists because operators ran out of IPv4 addresses to give each customer one, and it is now normal on mobile networks and common on fixed broadband.
#How the address is shared
The subscriber’s device receives a private or shared address. The operator’s translator rewrites the source address and source port on the way out, and reverses the rewrite on the way back. The destination sees the operator’s public address and has no way to distinguish one subscriber behind it from another.
RFC 6598 reserves 100.64.0.0/10 as Shared Address Space for exactly this purpose. Seeing an address from that block on your own interface is a strong hint that your operator is translating.
#What it changes for proxies
This is the mechanism behind the reputation of mobile proxies. Blocking the visible address hits every subscriber sharing it, so targets are more reluctant to do it and more likely to apply softer measures instead. That reluctance is the asset, not the address itself.
The same sharing works against you when a target counts requests per address. You are competing for a per-address allowance with strangers, so a limit can be reached without you having caused it. See rate limiting.
#Consequences that surprise people
- Inbound connections do not work without an explicit mechanism, so a device behind a translator cannot simply listen on a port.
- Address-based geolocation degrades, because the translator may be far from the subscriber.
- Abuse attribution needs the source port and a timestamp, not just the address. RFC 6888 sets out what operators are expected to log.
#Commonly confused with
A home router also performs translation, but for one household and under the subscriber’s control. Carrier-grade NAT sits a layer above that, is operated by the ISP, and cannot be configured by the customer. A connection can traverse both, one after the other.