CloudProxy

CGNAT Checker

Port forwarding not working, or can't reach your home server, CCTV or NAS from outside? Your ISP may be sharing one public IP address across many customers (CGNAT). Compare your router's WAN IP with your public IP to find out.

Turn off any VPN or proxy first, or this comparison will be wrong. You can edit this if detection fails.

Log in to your router (often 192.168.1.1 or 192.168.0.1 - check the label on the router), open the Status / Internet / WAN page, and copy the "WAN IP" or "Internet IP" address.

How this works

Your router has two addresses: one on your home network (like 192.168.1.x) and one facing the internet - the WAN IP. If your ISP gives you a real public address, the WAN IP matches the public IP that websites see. If it doesn't match, or the WAN IP sits in 100.64.0.0/10 (the range reserved for carrier-grade NAT) or in a private range, another device at your ISP is translating your traffic, so nobody on the internet can connect in to you directly.

Known limitations: this tool compares two addresses you provide; it can't see inside your ISP's network. Some ISPs use public-looking addresses for their NAT, which shows up as "probably behind NAT" rather than a certain answer. Results are wrong if a VPN or proxy is active. And having a public IP doesn't guarantee ports are open - your router's firewall and your ISP's own filtering still apply. Use our Open Port Checker to test a specific port.

Read more: CGNAT on Indian ISPs: why port forwarding fails and what to do.