On this page
- What CGNAT is and why networks use it
- How to tell if you are behind CGNAT
- Option 1: a public IP SIM
- Option 2: a private APN
- Option 3: a VPN from the router
- Option 4: remote access platforms
- Which option suits which job
- What about IPv6?
- Fixed IP and failover
- Security with a public IP
- Double NAT and why it matters
- Dynamic DNS on mobile
- Common symptoms and their causes
- Asking the right questions of a SIM provider
- Summary
- Questions people ask
Short answer. Most mobile SIMs give a 5G router a private IP address behind carrier-grade NAT (CGNAT), so nothing on the internet can connect into the router. That is why port forwarding fails on most 5G connections. To reach equipment behind a 5G router you need one of four things: a SIM with a public IP address, ideally static; a private APN; a VPN that the router connects out to; or a remote access service. Each has trade-offs in cost, security and complexity.
If you have ever set up port forwarding on a 5G router, checked it three times, and still could not reach the camera or PLC behind it, CGNAT was almost certainly the reason. It is the single most common source of confusion with mobile routers, and it is worth understanding properly because it shapes almost every remote access decision.
What CGNAT is and why networks use it
There are not enough IPv4 addresses for every mobile device to have its own public one. Mobile networks deal with this by giving devices private addresses and sharing a pool of public addresses between many customers, using network address translation in the operator’s core. That is carrier-grade NAT.
From the router’s point of view, it has an address such as 10.x.x.x or 100.64.x.x on its mobile interface. When it connects out to a website, the operator translates that to one of its shared public addresses. Replies come back through the same translation. But a connection started from the internet has nowhere to go, because the public address is shared and the operator has no idea which device it is meant for.
Why inbound connections fail behind CGNAT
- Remote userTries to connect to the site
- Shared public IPUsed by many mobile customers at once
- Operator CGNATNo mapping for an unsolicited inbound connection
- Connection droppedNever reaches your router
- Your 5G routerHas only a private address
How to tell if you are behind CGNAT
Look at the IP address on the router’s mobile WAN interface. Then check your public IP from a device behind the router using any what-is-my-IP website. If the two do not match, or the router’s address is in a private range such as 10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16 or 100.64.0.0/10, you are behind NAT and inbound connections will not work.
Option 1: a public IP SIM
Some SIM providers offer tariffs with a public IP address assigned directly to the router. This comes in two forms:
- Public dynamic IP. The router gets a public address, but it may change when the router reconnects. You can use dynamic DNS to keep track of it.
- Public static or fixed IP. The router always gets the same public address. This is what most people want for remote access, firewall whitelisting and hosted services.
With a public IP, port forwarding and inbound VPN connections work as they would on a fixed line. That is convenient, but it also means the router is directly exposed to the internet and will be scanned constantly. You must lock the firewall down: allow only the specific ports you need, restrict them to known source addresses where possible, and never expose management interfaces.
Option 2: a private APN
A private APN connects your SIMs directly to your own network through a dedicated link from the mobile operator or SIM provider. Each router gets a private IP address that you choose, and your central systems can reach every router directly. Nothing touches the public internet unless you allow it.
Private APNs are common in utilities, payment networks and large IoT deployments. They are secure and scalable, but they have setup costs, need a VPN or leased line from the provider to your data centre or cloud, and work best at a decent scale. For a handful of routers they are often overkill.
Option 3: a VPN from the router
The router connects outwards to a VPN server, which might be in your office, a data centre or the cloud. Because the connection is outbound, CGNAT does not block it. Once the tunnel is up, you reach the router and devices behind it through the VPN server.
This works with ordinary SIMs and is often the best balance of cost and security. WireGuard, OpenVPN and IPsec are all common. You do need a VPN server with a public address, and someone needs to manage it. See VPNs over 5G.
Some VPN services provide a static public IP at the server end, which gives you a fixed address that follows the router regardless of which SIM or network it is using. That is a neat way to deal with IP whitelisting on mobile connections.
Option 4: remote access platforms
Many router manufacturers and third parties offer cloud services that let you reach the router’s interface and devices behind it through a web portal, using a connection the router initiates outbound. Overlay networks such as ZeroTier and Tailscale work in a similar way and run on many routers.
These are quick to set up and work through CGNAT. The trade-offs are dependence on a third party service, possible per-device costs and the need to manage user access carefully.
Which option suits which job
| Need | Good options |
|---|---|
| Occasional engineer access to a few sites | Router remote access platform, or a VPN |
| CCTV viewing from a phone app | Manufacturer P2P app, or VPN |
| SCADA polling from a control room | Private APN, or site-to-site VPN |
| Supplier needs to whitelist your IP | Static public IP SIM, or VPN with static exit IP |
| Hosting a service at the site | Static public IP SIM with a tight firewall |
| Hundreds of IoT devices | Private APN |
| Failover that keeps the same public IP | VPN with static exit IP |
What about IPv6?
IPv6 has enough addresses for every device to have a public one, which in theory removes the need for CGNAT. Some UK mobile networks provide IPv6 to devices that request it. In practice, IPv6 support varies across tariffs, routers and the equipment behind them, and inbound connections may still be filtered by the operator. It is worth enabling and testing, but do not rely on it for remote access unless you have confirmed it works end to end with your SIM and equipment.
Fixed IP and failover
A static IP is tied to a SIM. If the router fails over to a second SIM, or a fixed line, the address changes. If your remote access depends on the fixed address, it will break during failover. A VPN with a static exit address avoids that problem, because the router simply rebuilds the tunnel over whichever connection is working.
Security with a public IP
- Disable remote access to the router’s web interface and SSH from the WAN
- Allow only the ports you need, and restrict them by source IP
- Prefer a VPN terminated on the router over individual port forwards
- Keep the router firmware updated
- Monitor logs for unexpected connection attempts
- Use strong, unique credentials and certificates where possible
Double NAT and why it matters
CGNAT is not the only translation that can get in the way. If a 5G router sits behind another router, or an outdoor 5G unit feeds an indoor router without passthrough, traffic can be translated twice inside your own site before it even reaches the operator. That is double NAT.
Double NAT makes port forwarding and some VPNs more complicated, because forwards have to be configured on both devices. Where possible, set the first device to bridge or IP passthrough mode, so the second router receives the mobile address directly. That leaves only the operator’s CGNAT to think about, or none at all with a public IP SIM.
Dynamic DNS on mobile
With a public dynamic IP SIM, the address can change whenever the router reconnects. Dynamic DNS keeps a hostname pointing at the current address. Most business routers have a built-in dynamic DNS client supporting several providers. It works well, with two caveats: there is a short delay after an address change before DNS updates everywhere, and dynamic DNS does nothing at all behind CGNAT, because the address it would publish is not reachable. Check you genuinely have a public address first.
Common symptoms and their causes
Port forwarding configured but nothing connects. CGNAT. Check the WAN address.
Remote access worked, then stopped after a reboot. Public dynamic IP changed. Use dynamic DNS or a static IP.
Remote access works on one SIM but not the other. One SIM has a public IP and the other does not.
VPN connects but devices behind the router are unreachable. Routing or firewall rules on the router, not CGNAT.
Asking the right questions of a SIM provider
Before buying SIMs for a project that needs remote access, ask the provider directly: does the tariff give a public IP or a private one; if public, is it static or dynamic; are any inbound ports blocked by the network; is IPv6 available; which APN is used; and does the public IP apply on every network if it is a multi-network SIM. The answers vary more than you might expect, and getting them in writing avoids a lot of head scratching later.
Summary
CGNAT is normal on mobile networks and is not a fault. Decide what you need to reach and how, then choose the approach that fits: a public static IP for simplicity, a private APN for scale and security, a VPN for flexibility, or a remote access platform for convenience. Make that decision before buying SIMs, because changing later means touching every site.
For help choosing the right remote access approach for your sites, email sales@5grouter.co.uk.
Questions people ask
Why does port forwarding not work on my 5G router?
Most mobile SIMs put the router behind carrier-grade NAT with a private address, so inbound connections from the internet are dropped by the operator before reaching your router.
What is CGNAT?
Carrier-grade NAT is how mobile networks share a limited pool of public IPv4 addresses between many customers. Devices get private addresses and outbound traffic is translated, but unsolicited inbound connections cannot be routed.
How do I get a static IP on a 5G router?
Use a SIM and tariff that provides a public static IP, or a VPN service that gives the router a fixed public exit address. The VPN option keeps the same address even after failover.
Is a public IP on a 5G router safe?
It can be, if the firewall is locked down, management interfaces are not exposed and remote access goes through a VPN. Forwarding ports directly to cameras or PLCs is risky.
What is a private APN?
A private APN connects your SIMs directly to your own network, giving each router a private address you control and keeping traffic off the public internet. It suits utilities and larger estates.
Planning a deployment, or stuck with one that is not behaving? Email sales@5grouter.co.uk with the site, the equipment and what you need it to do.