DIAGNOSTIC TOOLKIT
CGNAT Checker: Compare Your Public and Router IP
LumaProbe can see the public address used for this request but cannot sign in to your router. Enter the router’s WAN or Internet IPv4—not a device address such as 192.168.x.x—to make a controlled comparison.
How this check works
The server returns the public address associated with this HTTPS request. You supply the IPv4 shown as WAN, Internet or external address in the router status page. The browser validates the supplied dotted address locally, classifies standard private ranges and the RFC 6598 shared range, then compares it with the public IPv4.
The router is never contacted by LumaProbe and no router password is required. The entered WAN address is not sent to the API; classification takes place in the page. This deliberately modest design avoids asking for administration access merely to make an address comparison.
Prepare for a useful result
Find the router status page using its own documentation or provider application. Look for WAN IPv4, Internet IPv4 or external IPv4. Do not use a local device address such as 192.168.1.24, a Wi-Fi password, account number, serial number or router login credential.
Note whether a VPN, privacy relay, business tunnel, mobile hotspot or multi-WAN service is active. These can make the public address used by the browser differ from the route shown by the router. If safe, compare once without the optional tunnel.
What the result can tell you
A router WAN in 100.64.0.0 through 100.127.255.255 is within the shared address space reserved by RFC 6598 for carrier-grade NAT and is a strong indicator. A WAN address in 10/8, 172.16/12 or 192.168/16 shows private upstream addressing and may indicate a second local router or provider-side NAT.
When the router WAN is a public IPv4 and matches the request address, this comparison does not indicate CGNAT. When public addresses differ, upstream translation is possible but a VPN, failover path or stale router display can explain the mismatch. The result is therefore worded as evidence, not certainty.
Limits of this browser test
A web page cannot automatically read the router WAN address without unsafe administration access. The comparison also cannot see provider architecture, inbound firewall policy, port mapping, dynamic address changes or whether an application uses relay servers. IPv6 connectivity can provide direct addressing even where shared IPv4 is present.
Do not treat “CGNAT not indicated” as proof that a port is open or a service is safe to publish. Router and device firewalls, provider filtering and application configuration remain separate. Never expose a router administration page to the public internet merely to make remote access work.
What to do next
If CGNAT is indicated and you need inbound access for a game, camera or server, first check whether the application supports a secure relay or outbound tunnel. Ask the provider whether a public IPv4, static address or native IPv6 option is available and whether additional charges or security responsibilities apply.
If a private WAN suggests double NAT, identify whether a provider hub and a personal router are both translating addresses. Bridge, modem-only and access-point modes vary by provider and model; follow official documentation and retain a way to restore the existing configuration.
Read the complete LumaProbe test methodology and privacy notes →