---
title: "Carrier-grade NAT"
url: https://proxy.wiki/glossary/carrier-grade-nat/
type: Glossary Term
author: "proxy.wiki editorial"
published: 2026-09-06
updated: 2026-09-06
site: proxy.wiki
topics: ["Proxy fundamentals"]
license: CC BY 4.0 — quote freely with attribution to https://proxy.wiki/
---

# Carrier-grade NAT

> Carrier-grade NAT is address translation performed inside an operator's own network, so that many subscribers share a single public address.

**Carrier-grade NAT is address translation performed inside an operator’s own network, so that many subscribers share a single public address.** It exists because operators ran out of IPv4 addresses to give each customer one, and it is now normal on mobile networks and common on fixed broadband.

## How the address is shared

The subscriber’s device receives a private or shared address. The operator’s translator rewrites the source address and source [port](/glossary/port/) on the way out, and reverses the rewrite on the way back. The destination sees the operator’s public address and has no way to distinguish one subscriber behind it from another.

RFC 6598 reserves `100.64.0.0/10` as Shared Address Space for exactly this purpose. Seeing an address from that block on your own interface is a strong hint that your operator is translating.

## What it changes for proxies

This is the mechanism behind the reputation of [mobile proxies](/glossary/mobile-proxy/). Blocking the visible address hits every subscriber sharing it, so targets are more reluctant to do it and more likely to apply softer measures instead. That reluctance is the asset, not the address itself.

The same sharing works against you when a target counts requests per address. You are competing for a per-address allowance with strangers, so a limit can be reached without you having caused it. See [rate limiting](/glossary/rate-limiting/).

## Consequences that surprise people

- **Inbound connections do not work** without an explicit mechanism, so a device behind a translator cannot simply listen on a port.

- **Address-based geolocation degrades**, because the translator may be far from the subscriber.

- **Abuse attribution needs the source port and a timestamp**, not just the address. RFC 6888 sets out what operators are expected to log.

## Commonly confused with

A home router also performs translation, but for one household and under the subscriber’s control. Carrier-grade NAT sits a layer above that, is operated by the ISP, and cannot be configured by the customer. A connection can traverse both, one after the other.

## Frequently asked questions

### How can I tell whether my connection is behind carrier-grade NAT?

Compare the address on your own interface with the address a remote service reports. If your interface holds a private address or one from 100.64.0.0/10 while the remote address differs, translation is happening. Being unable to accept an inbound connection on any port is corroborating evidence.

### Why are mobile proxies harder to block than datacentre ones?

Because the visible address is shared by many real subscribers through carrier-grade NAT. Blocking it removes legitimate customers along with you, so targets weigh the cost differently. The protection comes from the collateral damage a block would cause, not from any property of the proxy software.

### Does carrier-grade NAT hide me from the operator?

No. The operator performs the translation and can map the public address and source port back to a subscriber at a given time. RFC 6888 describes the logging expected of such deployments. Sharing an address conceals you from the destination, not from the network doing the sharing.

## Sources

1. [RFC 6598: IANA-reserved Shared Address Space, 100.64.0.0/10](https://www.rfc-editor.org/rfc/rfc6598.html)
2. [RFC 6888: common requirements for carrier-grade NATs](https://www.rfc-editor.org/rfc/rfc6888.html)
