# CGNAT and why mobile IPs are hard to block
Source: https://proxuno.com/blog/cgnat-and-mobile-ip-reputation
Updated: 2021-11-23

> Mobile carriers share each public IPv4 address between many subscribers through carrier-grade NAT. Here is how that works, what it means for IP reputation, and where its limits are.

When customers ask why a mobile proxy gets through where a datacentre or even a residential IP is challenged, the answer is almost always **carrier-grade NAT**. This article explains what CGNAT is, how European carriers deploy it, and what it does — and does not — do for IP reputation.

## The IPv4 shortage, briefly

There are about 4.3 billion IPv4 addresses, and RIPE NCC, the registry for Europe, handed out its last free blocks in 2019. A large mobile operator has tens of millions of active SIM cards — phones, tablets, routers, connected cars, meters. It cannot give each of them a public IPv4 address.

The solution is the same one your home router uses, scaled up: **network address translation**. Your phone receives a private address, and a NAT gateway in the carrier's core network translates its connections to one of a limited set of public addresses.

## How CGNAT works

At home, NAT maps the devices in one flat to one public address. A carrier-grade NAT does the same for a whole region:

1. When your phone attaches to the network, the packet gateway (the PGW in 4G, the UPF in 5G) assigns it an address from a private or shared range. RFC 6598 reserved `100.64.0.0/10` for exactly this purpose, though some carriers use RFC 1918 space.
2. When the phone opens a connection, the CGNAT device picks a public IPv4 address from its pool and a source port, and records the mapping.
3. Return traffic is translated back using that mapping.

Many carriers use **port block allocation**: each subscriber gets a block of, say, 512 or 1,024 source ports on one public address, and logs only the block assignment. That keeps logging volumes manageable for lawful-intercept obligations — and it means one public IP is shared by dozens to thousands of subscribers at the same moment.

You can see this from inside a mobile proxy. The address on the modem's interface is typically in `100.64.0.0/10` or `10.0.0.0/8`, while the address websites see is something entirely different.

## Why this makes mobile IPs resilient

Websites protect themselves with **IP reputation**: they count requests, failures and abuse reports per address or per range, and they block or challenge addresses that look bad. That works well when one address equals one actor. Behind CGNAT it does not.

- **Collateral damage.** Blocking a mobile IP blocks every real subscriber behind it, including paying customers. Large platforms learned this the hard way and generally treat mobile ranges with caution: rate limits are higher, outright bans rarer.
- **Noisy baselines.** A single CGNAT address legitimately produces large numbers of requests from different devices, browsers and accounts. Volume alone is a weak signal.
- **Constant churn.** Phones move between cells, attach and detach many times a day, and get reassigned to other public addresses. Reputation attached to one address decays quickly.

The result is that mobile ranges sit at the top of most IP-quality scores. They are identified correctly as "mobile", and that classification is itself a signal of a probably-human visitor.

## What CGNAT does not do

It would be convenient if a mobile IP made any traffic invisible. It does not, and it is worth being precise about the limits.

### Websites look at more than the IP

Modern bot detection weighs the IP as one input among many: TLS fingerprint, HTTP/2 settings, header order, JavaScript-collected browser properties, mouse and timing behaviour, cookie history, account age. A script sending identical requests every 200 ms is detectable from any address. A mobile IP lowers the starting suspicion; your client still has to look like a real one.

### Sessions are tracked by cookies, not addresses

If you log in to an account, the platform links your activity through the session cookie. Rotating the IP during a session does not create a new identity — it creates a logged-in user whose address jumps around, which some platforms treat as a risk signal of its own.

### Some ranges are shared with you

Because many subscribers share each address, your traffic is mixed with theirs. If a target has temporarily throttled an address because of another user's behaviour, you inherit it until you rotate. This is rare in practice, and the fix is simple: rotate.

## Rotation on a CGNAT network

When we rotate a mobile proxy, the modem detaches from the network and attaches again. The packet gateway assigns a new internal address, and the next outgoing connection is mapped to a public address from the CGNAT pool — usually a different one.

"Usually" matters. Carrier pools are finite, and in quiet hours on a small cell you can occasionally receive the same public address again. Our rotation process checks the public address after reconnecting and retries when it has not changed, so a rotation that reports success has actually produced a new IP.

How large is the pool you rotate within? That varies by carrier and region and changes over time. In our French fleet, we observe several hundred distinct public addresses per carrier per week on a single modem, spread across a handful of /16 and /18 ranges. That diversity is what makes rotation useful.

## IPv6 changes the picture, slowly

Most European carriers now give phones an IPv6 address too, without NAT. For IPv6-capable targets, each device has its own globally unique prefix, which removes the "crowd" effect. In practice most proxy traffic still uses IPv4, because many targets and client tools prefer it. Our gateways connect to targets over IPv4 by default for this reason.

## Practical takeaways

- Treat the mobile IP as a **good starting reputation**, not a disguise. Fix the client fingerprint and request pacing as well.
- **Rotate between tasks, not in the middle of one.** Keep the same IP for the lifetime of a login session; rotate when you start a new identity or when you hit a throttle.
- **Spread fleets across carriers.** Each carrier has its own CGNAT pool and its own reputation profile with each target.
- **Watch the rotation history.** If you see the same addresses repeating, increase the time between rotations so the modem attaches to a less busy part of the pool.

The [IP rotation documentation](/docs/ip-rotation) covers the manual, API and link-based rotation methods, and the cooldown between two rotations.
