How do NAT and CGNAT affect IP addresses?¶
An IP address describes a connection from a particular point in a network route. Network Address Translation (NAT) changes the addressing presented as traffic crosses a network boundary. A home router commonly uses it so several devices with private addresses can communicate through one public IPv4 address.
Carrier-Grade NAT (CGNAT) applies the same broad idea inside an internet or mobile provider's network. It can make several customers appear to an online service under the same public IPv4 address, even at the same time.
The short version
NAT means the IP address recorded by an online service may identify a translated connection point, not the original device. With CGNAT, it may not identify one customer without an accurate time and a source port.
How do NAT and CGNAT affect IP addresses?
This version retains the approved technical script, exact fictional connection values and Hazel placeholder narration while testing the corrected shared visual system. Its creative treatment remains unreviewed.
Open or download the corrected benchmark MP4 if inline playback does not work. Open the preserved original pilot.
Follow one connection through both translation layers¶
Dave's laptop uses 192.168.1.24 on his home Wi-Fi and opens a webpage. His router translates that private connection onto the provider-facing address 100.64.12.8. The provider's CGNAT system then presents the connection to the website as 198.51.100.84 with public source port 51543.
An address and port considered together form a connection tuple. The protocol records how the connection was carried — for example, TCP or UDP. The tuple changes at each observation point below, so the same connection can appear under different values in different records.
192.168.1.24:53012The router translates this to 100.64.12.8:62001.198.51.100.84:51543The provider allocates this public address and port for the connection.198.51.100.84:51543The final public source tuple visible to the service.The values are fictional, but the distinction is real. The website does not normally receive the laptop's private address or the provider-facing shared address.
| Record holder | What its record may connect |
|---|---|
| Website | Account or request event to the public IP, public source port, protocol and time |
| CGNAT provider | Public tuple and time to a provider-side customer/session mapping |
| Home router or managed network | Provider-facing connection to a private device address, where suitable records exist |
| Device | Application activity to a local interface, process or connection artefact |
This is why an investigation may need to join records across layers rather than treat the website's public IP as the device address.
NAT on a home or workplace network¶
A device inside a local network may use a private IPv4 address such as 192.168.1.20. Private addresses are not normally routed across the public internet.
When the device connects to an online service, a router can translate the connection so that it appears on the internet using the router's public address.
The device and the online service therefore see different sides of the same communication:
- the device may know its private address;
- the router maintains a temporary translation between inside and outside traffic; and
- the online service normally records the public source address visible to it.
Why port numbers matter¶
NAT commonly distinguishes simultaneous connections using port numbers as well as IP addresses.
For example, several devices may connect to the same website through one public address. The translating system can allocate different public source ports so it knows which returning traffic belongs to which internal connection.
A translation can therefore involve a combination such as:
private IP + private port → public IP + public port
The exact behaviour varies between systems, but the important point is that the public IP address may be only part of the identifying tuple.
Address, port, protocol and time must all describe the same event before they can be used as one matching set.
What changes with CGNAT¶
With ordinary local NAT, several devices within one home or organisation may share a public address.
With CGNAT, the provider may place another translation layer between the customer and the public internet. Several separate customers can then appear to use the same public IPv4 address, sometimes at the same time.
Provider systems may use address space reserved for this shared function, including 100.64.0.0/10, between the customer-facing connection and the provider's public internet edge.
The address seen by an online service may therefore identify the provider's shared translation infrastructure rather than one subscriber connection. The 100.64.0.0/10 range is evidence of provider shared-address space when it appears at the relevant observation point; it is not itself the public address seen by the website.
Time and the translation record¶
NAT mappings are not necessarily permanent. They can be created when a connection begins, reused and removed after activity stops.
To distinguish a CGNAT connection, a provider may need:
- the complete public IP address;
- an accurate date and time;
- the applicable time zone;
- the public source port; and
- sometimes the destination details or protocol.
Which fields are necessary depends on how that provider operated and logged the translation. An IP address without the accompanying context may be insufficient even when the record is otherwise genuine.
A simplified provider mapping for Dave's connection might read:
start=2026-09-06T14:22:31.482Z
protocol=TCP
public_source=198.51.100.84:51543
subscriber_side=100.64.12.8:62001
session_ref=CGN-7F3A91
The website event and provider mapping can be compared using the public source IP, public source port, protocol and precise time from the same event. If those fields align, the provider may be able to identify the relevant customer connection or session. The exact field names and matching method vary by provider.
The website event was presented through a particular provider translation associated with the returned customer connection or session at the relevant time.
Which device used that connection, who operated it, whether another device used a hotspot or local network, and who was responsible for the website activity.
If the service did not preserve the source port or sufficient timestamp precision, follow the focused guidance on why a provider may be unable to select one customer.
NAT does not make traffic anonymous by itself¶
NAT changes addressing. It does not encrypt traffic or automatically prevent a network operator from keeping translation records.
Nor does a successful translation result identify the person who generated the traffic. It may identify a customer connection, router or internal device association at a relevant time. Personal attribution still depends on the wider evidence.
IPv6 and translation¶
IPv6 provides a much larger address space, so the pressure to share one public IPv4 address between many customers is reduced. The CGNAT mechanism described here is an IPv4 mechanism. Devices can still use temporary IPv6 addresses and networks can use other transition arrangements, so an IPv6 address must still be interpreted in its recorded context.
The point to remember¶
NAT can make several devices share one public address. CGNAT can make several customers share it. The address must be interpreted with its time, port and recording context.
Explore related guidance
Go deeper
- What is an IP address?
- What is an IP packet?
- What is a port?
- What is the difference between a static and dynamic IP address?
Offender viewpoint
Investigator First - back to the investigation