Carrier-grade NAT
Carrier-grade NAT is address translation performed inside an operator's own network, so that many subscribers share a single public address.
Addresses belonging to a mobile carrier and shared behind carrier-grade NAT. Why that sharing is the entire mechanism, what control you give up, and the two billing models.
A mobile proxy exits from an address belonging to a mobile network operator, shared at that moment with a crowd of real handsets. It is for mobile-only surfaces and for targets that have refused every cheaper category, and it is where you buy tolerance by giving up control.
Mobile operators have far fewer public addresses than subscribers, so they place many subscribers behind one public address using carrier-grade NAT. The handset gets no public address at all. It gets one from the space set aside for this purpose, 100.64.0.0/10, allocated in RFC 6598 because operators needed a block they could reuse internally without colliding with customers' private networks. The address the destination logs is the carrier's, on the public side of that translator, and a large, shifting group of real people are using it too.
Everything about the category falls out of that:
| Consequence of the shared address | What it means for you |
|---|---|
| Blocking the address blocks real subscribers | Filtering systems tolerate carrier ranges more |
| The operator cannot tell which subscriber caused a problem | Neither can the target, so behaviour attaches to the crowd |
| The crowd's traffic is mixed with yours | You inherit a reputation you did not create |
| The address is a translator's, not a device's | It can change for reasons outside your session |
The third row is the counterweight to the marketing. Tolerance is a property of the sharing, not of your traffic, and not something the provider supplies. A target that has decided to be strict with a carrier range applies that as readily as leniency.
In every other category the address is something you hold; here it is something you observe. RFC 6888 requires a carrier-grade NAT to default to paired address pooling — while a subscriber's mappings exist, its sessions leave from one external address — but it permits other behaviours, and says nothing about how long a mapping lasts or what happens when the device changes cell. Nothing promises you the same address on the next request.
So rotation stops being a parameter you set:
Verify the exit address at the start of every session and record it with every result. Code that assumes the address from ten minutes ago still holds fails in a way that reads as an application bug.
| Shared pool, per gigabyte | Dedicated port or SIM, per month | |
|---|---|---|
| What you rent | Access to many carrier exits | One modem and its data plan |
| Who else is on your address | Other customers and carrier subscribers | The carrier's subscribers only |
| Who triggers rotation | The provider's gateway | You, by API or timer — and the carrier |
| The constraint that bites | The meter, as on residential | The plan's fair-use policy behind the SIM |
| Suits | Many short requests, wide spread | Few, long-lived identities |
Both trace back to sourcing. The input is a real SIM on a real consumer data plan, so the provider's cost is either the carrier's metered data — passed on per gigabyte, metering everything bandwidth billing describes — or a fixed line and a modem, passed on as rent. The second looks unmetered and is not: fair-use terms sit behind it, and the operator can throttle a heavy job with no signal from the provider.
Right: endpoints that exist only for handsets; targets whose defences have beaten residential addresses on the same job; work where a shared carrier address is the plausible context.
Wrong, and commonly bought anyway:
# Is the exit really on a carrier network, and does it hold still?
for i in $(seq 1 30); do
curl -s --max-time 30 -x "http://USER:[email protected]:8000" https://echo.example/ip
sleep 60
done | tee exits.txt | sort -u
# Who announces each address you saw?
sort -u exits.txt | while read -r ip; do
whois -h whois.cymru.com " -v $ip" | tail -1
done
Read the holder field, not the invoice: you paid for a mobile network operator, and a hosting company there means you did not get one. See ASN for how that record drives classification. The run over time is the other half of the test, because how often the address really moves is what no product page states accurately.
No prices, no latency figures, no success rates and no pool sizes. Latency here is a radio measurement that changes with the cell and the hour, so a number from our vantage point would mislead. A success rate would describe which carrier crowd we shared an address with that day. Pool size is barely defined when the addresses belong to an operator, not the provider selling them.
Sample it yourself instead, over hours rather than minutes, against your own targets. Success rate lists what a rate must state to be comparable, and the tools show the address the far end really sees.
Carrier-grade NAT is address translation performed inside an operator's own network, so that many subscribers share a single public address.
A proxy exiting through a mobile carrier address, shared by many real handsets via carrier-grade NAT.