CGNAT Check

Troubleshooting

Why port forwarding fails

Port forwarding problems are not always caused by the router rule itself. The real issue is often another NAT layer, the wrong WAN IP, or a service that is not reachable from the outside.

CGNAT or another upstream NAT layer

If your router WAN IP is private, shared, or reserved, inbound traffic may stop before it reaches your own router.

Double NAT inside the home

An ISP gateway plus your own router can create two NAT layers locally, even if the ISP gives the gateway a public IPv4 address.

Local firewall or device settings

Even with a good port forward, the target device still has to listen on the port and allow incoming traffic.

Testing from inside the same network

Many routers do not support loopback testing, so an open port can look closed from your own Wi-Fi.

Troubleshooting order

Work from the service outward

Start with the endpoint you control, then move through the LAN, router, and ISP path. This order prevents an upstream theory from hiding a simple local issue and avoids changing several settings before you know which layer failed.

  1. 1

    Confirm the application or service is running

    A router rule forwards traffic to a device, but only a running service can answer it. Start the real application before testing and confirm it has finished loading.

  2. 2

    Check the listening port and protocol

    Verify the configured port in the application itself. TCP and UDP are separate protocols, and some services need one while others need both.

  3. 3

    Verify the forwarding target

    The router rule must point to the LAN IP of the device running the service. Check the address on that device instead of relying on an old setup note.

  4. 4

    Make sure the LAN address has not changed

    DHCP can assign a different local address after a restart or lease change. Use a router-side reservation where appropriate so the rule keeps targeting the same device.

  5. 5

    Review the operating-system firewall

    Allow the intended application or port on the correct network profile. Avoid disabling the whole firewall, which creates risk and does not reveal which rule was wrong.

  6. 6

    Look for more than one router

    An ISP gateway in router mode plus a personal router creates two local NAT layers. The inner router may need a different mode, the outer gateway may need bridge mode, or both devices may require configuration.

  7. 7

    Compare the router WAN IP with the public IPv4

    A matching public pair suggests the standard IPv4 path reaches that router. A private WAN or mismatched public value means another upstream layer needs investigation.

  8. 8

    Check for 100.64.0.0/10 on the WAN side

    A WAN value from 100.64.0.0 through 100.127.255.255 is strong evidence of provider shared-address space. Your own forwarding rule cannot control that upstream NAT layer.

  9. 9

    Ask whether the ISP filters the required traffic

    Even with a public address, an ISP plan or network policy may filter selected ports or inbound traffic. Ask about the exact protocol and service rather than assuming all traffic is blocked.

  10. 10

    Confirm the application uses direct inbound connections

    Some games, remote-access tools, and cloud-managed devices use relays, outbound sessions, matchmaking, or vendor services instead of a simple public listening port. Follow the application documentation.

Read the WAN comparison carefully

First locate the separately labelled WAN or Internet IPv4 using the WAN-IP guide. Then run the best-effort CGNAT comparison. Do not enter the computer's LAN address or Default Gateway as a substitute.

A private WAN proves another NAT layer exists but does not prove CGNAT. Use the CGNAT-versus-double-NAT guide to distinguish an ISP shared-address signal from a second local router.

Make the external test valid

A port test needs a running service and the correct protocol. Test from outside the home LAN where possible because same-network tests can fail on routers without NAT loopback support. A timeout remains ambiguous: filtering, an inactive service, an incorrect rule, double NAT, and CGNAT can all produce silence.

Follow the complete port-forwarding test checklist before treating a closed or inconclusive result as an ISP problem.

Free option first

Ask your ISP about a public IPv4

Once the local router path is clean, ask whether the connection uses CGNAT or shared IPv4 and whether the ISP can provide a public IPv4 before paying for a workaround.

Browse ISP guides
Paid optionAffiliate link

PureVPN

Need port forwarding behind CGNAT?

If your ISP cannot provide a public IPv4 and you specifically need inbound port forwarding, PureVPN offers an optional paid port-forwarding feature that may help for some use cases.

It does not universally remove CGNAT. Check supported locations, protocols, and ports before buying.

Check PureVPN port forwarding

CGNAT Check may earn a commission at no additional cost to you. Check the provider's current port, protocol, plan, and location support before buying.

Compare all solutions