Skip to content
bgplookup.io

August 17, 2026

CGNAT makes your IP lookup look wrong

cgnat ip lookup

A CGNAT IP lookup will show you a prefix, an origin ASN, and a city that belongs to a CMTS or an EPC, not a doorbell. Carrier-grade NAT puts hundreds or thousands of subscribers behind one public address. If you treat that address as a user, you will ban a neighborhood and miss the one modem that is actually loud.

I still run the IP lookup. I need the prefix and the origin. Then I look at category on geolocation — residential plus a giant access ASN is CGNAT until proven otherwise. The abuse contact finder is how you talk to the ISP. You will not get a name. You might get a filter if you send ports and timestamps.

What to put in a CGNAT IP lookup ticket

UTC start and end. Source port. Destination port. Protocol. A sample of URIs or signatures. “This IP attacked us” is how reports die in a queue. Shared space needs more entropy than a single address. If you have X-Forwarded-For from your own edge, that is the number that matters inside your network — not the CGNAT door.

Banning a CGNAT address is how you discover how many paying customers share a door with one idiot.

What the lookup will never show

The subscriber. The NAT mapping. The other five hundred households. WHOIS on the prefix is the ISP, not the laptop. RFC 6598 set aside 100.64.0.0/10 for this on purpose; if you see that range on your inside, you are looking at the private side of the same story.

Use the lookup to find the operator. Use the ports to give them a chance. Then decide whether your controls should key on something other than a public IPv4 that is doing too many jobs.

Leave a Reply

Your email address will not be published. Required fields are marked *

BGPLOOKUP.IO ACCOUNT

Sign in or create an account

Continue with an account you already use.

Your provider password is never shared with bgplookup.io.