5 ms·
CGNAT means you don't have an internet routable IP, so you have no way of hosting something anyone can access without some external proxy, such as cloudflare or
by mcfedr 3y ago
CGNAT means you don't have an internet routable IP, so you have no way of hosting something anyone can access without some external proxy, such as cloudflare or tailscale
- timcobb 3y agoOh so it’s just like home NAT, and they won’t let me port for ward
- foresto 3y agoIt's more complicated than that. https://tailscale.com/blog/how-nat-traversal-works#concerning-cgnats https://tailscale.com/blog/how-nat-traversal-works#concernin...
- RealityVoid 3y agoIf I'm reading this right, just the fact you have a static IP does not mean you're not behind a CGNAT. It could be static at the carrier level only, right? How could I reliably tell if I'm behind a CGNAT or not? If I poll one of those "what is my IP" websites, and the IP my router has assigned from the wan matches the what is my IP then I'm fine, I'm not behind one, right? And if you can access the services using a dydns kind of thing, then you're safe, you're not behind a CGNAT as well. Only catch where you could be wrong is if you try to access from the same CGNAT network (is this how you call it?) But since the dydns is probably swing your wide internet IP that should still not work?
- tomxor 3y ago> How could I reliably tell if I'm behind a CGNAT or not? If I poll one of those "what is my IP" websites, and the IP my router has assigned from the wan matches the what is my IP then I'm fine, I'm not behind one, right? My layman understanding is that the WAN IP on your router will match the "what is my ip" website, but the problem is that it will also match many other people's routers. Basically imagine your home router and NAT has been moved into the ISP and is serving thousands of end users as well as you... you can't just configure the ISP's CGNAT to forward port 80 to you alone. I'm not sure if there is a definitive way to know if you are behind CGNAT, however its definitely the case on all mobile networks.
- deleted 3y ago[deleted]
- hunter2_ 3y ago> the WAN IP on your router will match the "what is my ip" website, but the problem is that it will also match many other people's routers That's interesting. So the ISP is directing packets at the various customer routers using some other identifier than the WAN IP the router sees? MAC address or something?
- dwattttt 3y agoI don't specifically know, but typical NAT can use stateful flow information, i.e. "a UDP packet originated from inside the NAT to external IP/port X, packets from that external IP/port should be routed to the originating NAT/customer" (see https://en.m.wikipedia.org/wiki/UDP_hole_punching https://en.m.wikipedia.org/wiki/UDP_hole_punching)
- LilBytes 3y agoSome ISPs use MAC address filtering. HFC (Hybrid Fiber Coaxial) and FttN (Fiber to the Node) are such examples. The rest of them if you don't have a static IP or an internet routable address, use NAT (Network Address Translation) and in some even more exotic environments they use Port Address Translating (PAT), but it's been many years since I've seen PAT in any way at commercial, residential or enterprise setups in ISP space. But PAT is quite common in the reverse and forward proxy space.
- Grimburger 3y ago> If I poll one of those "what is my IP" websites You'll get your public IP, it won't signal whether you are behind CGNAT or not. Check your WAN, if it's in a private range then you're behind CGNAT, likely going to be 10.0.0.0/8 for most ISP's but all the other private ranges count too. Otherwise it will show a public address that matches your "whats my IP" website.
- wrboyce 3y agoCGNAT should be using 100.64.0.0/10 per RFC 6598.
- cookiengineer 3y agoIt's a little different because all the ipv4 tunneling protocols were invented either for or to counter that. NAT64 is usually done at the ISP's gateway and the public IPv4 (at least) is shared with thousands of other customers. (With such internet connections you are always classified as a bot/spam with captcha services that don't understand IPv6 btw) As a customer, you cannot influence the IPs and neither the ports that get routed through, so you have to connect to a server that you host somewhere else, just for the purpose of tunneling the traffic. So the server at home is actually a client that reconnects to the reverse proxy as there's no other way to have the open connection. I saw a big chance for WebRTC data channels to fix exactly that, but I've given up because Google and Mozilla both put a lot of restrictions in the protocol to make it unfeasible for this use case. And this kinda applies for most cable internet providers in Europe because RIPE ran out of IPs a long time ago. On one hand we got Daimler blocking a whole /8 subnet, and on the other hand we have ISPs that have less than 16 IPv4s. Doesn't make sense to me how this is handled tbh. [1] https://en.wikipedia.org/wiki/NAT64 https://en.wikipedia.org/wiki/NAT64
- lostmsu 3y agoCan you describe the WebRTC restrictions you mentioned?
- deleted 3y ago[deleted]