What is a source port and when do I need it?¶
A source port is a temporary connection number used with an IP address. When several customers share one public IP address, the public-facing source port may help a provider distinguish one connection from another.
The simple model¶
An IP address is like the building address. The source port is more like the apartment or conversation using the entrance. It is not permanent and may be changed by translation.
Read the values together¶
A source record may contain:
- source IP: 198.51.100.84
- destination IP: 203.0.113.40
- source port: 51543
- destination port: 443
- protocol: TCP
The destination port describes the service. The source port describes the originating connection at that observation point.
Why it matters for shared addresses¶
Three customers can use one public address in the same second. The address and rounded time are shared; the port and protocol help separate the sessions.
Incomplete and complete records¶
An abbreviated record may show only an event ID, time and source IP. A fuller event may also contain milliseconds, source port and protocol.
If the first return omits the port, ask whether the originating service recorded or retained the fuller event. Do not guess.
Which source port?¶
For a CGNAT enquiry, the useful value is generally the public-facing translated source port observed by the external service. Do not confuse it with the destination port, an internal source port, an account number or a port from another event.
The timestamp, address, port and protocol must describe one connection event.
When no source port is available¶
Record the limitation and ask whether fuller logging exists. A provider may have another matching route, but that depends on its systems and retention.
See why a provider may be unable to identify one customer and the mobile or CGNAT request checklist.
The point to remember
In shared-address environments, a source port can be the difference between a network match and a match to one particular connection.