What information is needed for a mobile or CGNAT request?¶
Mobile networks and carrier-grade NAT can place many customers behind one public address. The matching fields therefore matter as much as the address itself.
The short version¶
Preserve the complete same-event tuple: public IP, precise time and offset, public source port, protocol, and any destination or event identifiers actually recorded.
A worked comparison¶
Incomplete: time=20:41:16Z source_ip=198.51.100.84
Useful: time=20:41:16.482Z source_ip=198.51.100.84
source_port=51543 protocol=TCP event_id=FRM-482771
The additional port and protocol may distinguish one translation from many simultaneous users. They are useful only if they came from the same original event and represent the public-facing values.
Before sending the request¶
Check that the timestamp is precise and unambiguous; the port is the translated public source port; the protocol is stated; and no private or destination value has been substituted. Ask the provider what its system needs if a field is missing.
What a response establishes¶
The result may identify a mobile-data session, SIM, subscriber account or service record. It does not automatically identify the handset or person.
Same event means same event
A technically complete tuple assembled from different log entries can still point to the wrong session.