Port forwarding not working, or can't reach your home server, CCTV or NAS from outside? Your ISP may be sharing one public IP address across many customers (CGNAT). Compare your router's WAN IP with your public IP to find out.
Turn off any VPN or proxy first, or this comparison will be wrong. You can edit this if detection fails.
Your router has two addresses: one on your home network (like 192.168.1.x) and one facing the
internet - the WAN IP. If your ISP gives you a real public address, the WAN IP matches the public IP that
websites see. If it doesn't match, or the WAN IP sits in 100.64.0.0/10 (the range reserved for
carrier-grade NAT) or in a private range, another device at your ISP is translating your traffic, so nobody on
the internet can connect in to you directly.
Known limitations: this tool compares two addresses you provide; it can't see inside your ISP's network. Some ISPs use public-looking addresses for their NAT, which shows up as "probably behind NAT" rather than a certain answer. Results are wrong if a VPN or proxy is active. And having a public IP doesn't guarantee ports are open - your router's firewall and your ISP's own filtering still apply. Use our Open Port Checker to test a specific port.
Read more: CGNAT on Indian ISPs: why port forwarding fails and what to do.