Why does carrier-grade NAT number the links to subscribers' routers from 100.64.0.0/10 rather than RFC 1918 space, and what changes for subscribers?
answer
- two layers of translation
- inside and outside must not overlap
- Shared Address Space, RFC 6598
- port plus timestamp for attribution
basics
~20 sRFC 1918 space may already be used inside the subscriber's home, so the provider uses RFC 6598 Shared Address Space, 100.64.0.0/10. Subscribers then share public addresses, lose unsolicited inbound reachability, face per-subscriber port limits and need port-level logs for attribution.
solid answer
~50 sWith carrier-grade NAT (CGN) the subscriber's home router still translates, but its outside interface no longer gets a public address. Numbering that link from RFC 1918 space risks the same block appearing on both sides of a home router the provider does not manage, so RFC 6598 reserved `100.64.0.0/10` as Shared Address Space: never routed across provider boundaries and kept out of external DNS zones. For subscribers, the public address is now shared. Unsolicited inbound connections fail unless the CGN creates a mapping, which is why RFC 6888 requires a protocol for explicit control, preferably PCP. A CGN must keep all of a subscriber's sessions on one public address by default and must support per-subscriber port limits. Abuse reports and blocklists keyed on an IPv4 address now hit many subscribers, so identifying one needs the source port and an accurate timestamp.
go deeper
Recall that 100.64.0.0/10 is Shared Address Space for carrier-grade NAT, distinct from the RFC 1918 private ranges, and that it means two layers of translation.
Explain why RFC 1918 space can collide on a subscriber-owned router and therefore why a separate block was reserved, plus the rules that keep it off the public internet and out of DNS.
Spell out what subscribers lose behind a CGN, from inbound reachability and port budgets to shared reputation, and how attribution works with source ports and accurate timestamps.
Weigh CGN as a stopgap against its costs to subscribers and to the provider's logging and support, and against investing in IPv6 to shrink the traffic that needs translation at all.
## Two layers of translation A **carrier-grade NAT** (CGN) is a NAPT run by the service provider, shared by many subscribers. The subscriber's own router (the customer premises equipment, CPE) usually keeps translating its home network as before, so traffic now crosses **two** translators: 1. home device (private address) to CPE, translated to the CPE's outside address; 2. CPE outside address to CGN, translated to one of the provider's public addresses. The question is what to number the link between CPE and CGN with. ## The options RFC 6598 weighed | Option | Problem | |---|---| | Globally unique addresses | the whole point is that the provider does not have enough | | Someone else's public space ("squat space") | RFC 6598 says providers MUST NOT; leaks hurt the real holders, and the provider loses reachability to them | | RFC 1918 private space | safe only if the provider knows the CPE copes with the same block on both sides, or that the block is not used inside the home; with subscriber-owned routers it cannot know | | **Shared Address Space** | a dedicated block that no home network should be using | RFC 6598 therefore reserved **`100.64.0.0/10`**, that is `100.64.0.0` to `100.127.255.255`, 4,194,304 addresses, as Shared Address Space. A /10 was described as the smallest block that lets a provider deploy CGNs regionally without nesting them. It is listed in the special-purpose address registry (RFC 6890). ## Rules for Shared Address Space - Packets with these source or destination addresses **MUST NOT be forwarded across service provider boundaries**, and providers MUST filter them on ingress links (hosted CGN services being the stated exception). - They MUST NOT appear in DNS zone files, or in external-facing zones in a split DNS setup. - Reverse DNS queries for them MUST NOT be forwarded to the global DNS. - Using the block for anything other than CGN risks collisions later, when such a network itself ends up behind a CGN. RFC 6598 also notes a risk: applications that check whether their router's outside address is private, to decide whether inbound connections can work, may not recognize `100.64.0.0/10` and wrongly conclude the address is reachable. ## What changes for the subscriber **Shared public address.** Many subscribers leave through the same public IPv4 address. RFC 6888 REQ-2 requires a CGN's default IP address pooling behaviour to be **"Paired"**: every session of one subscriber, whatever the protocol, uses the same external address, so applications that open several connections see one consistent address. **No unsolicited inbound by default.** Forwarding a port on the home router only gets traffic as far as the CGN, which has no mapping for it. RFC 6888 REQ-9 says a CGN MUST implement a protocol that gives subscribers explicit control over mappings, and that it SHOULD be the Port Control Protocol (PCP, RFC 6887). **A port budget.** RFC 6888 REQ-4 says a CGN MUST support limiting the number of external ports per subscriber, to stop one subscriber starving others. A heavy user can exhaust their own allowance while the CGN has ports to spare. REQ-7 recommends endpoint-independent filtering, and REQ-1 requires the CGN to meet the UDP, TCP and ICMP behavioral requirements of RFC 4787, RFC 5382 and RFC 5508. **Collateral reputation.** RFC 6269 describes services that rate-limit or block by source IPv4 address; when one address carries many subscribers, one abuser's penalty lands on all of them. ## Attribution needs a port and a clock An abuse report of the form "this address did something at this time" no longer identifies anyone. RFC 6269 section 12 describes two ways out: - **Servers log the source port** of incoming connections, and the request to the provider carries address, port and timestamp. Accurate time is essential, because small clock skew between server and CGN can point at the wrong subscriber. - Otherwise the provider would have to log destination addresses, which is weaker: many subscribers reach the same popular server at once. RFC 6888 section 4 lists what a CGN would log per mapping (protocol, subscriber identifier, external address, external port, timestamp) and REQ-12 says it SHOULD NOT log destinations unless required to. Logging every mapping is expensive, which is why port allocation schemes that log once per block of ports exist.
- A subscriber behind a carrier-grade NAT forwards a port on the home router, yet nobody outside can connect. Why, and what are the options?The forward only moves traffic from the CPE's outside address inward; the CGN in front of it has no mapping for unsolicited packets on its public address. The options are a mapping requested through the CGN's control protocol (RFC 6888 requires one, preferably PCP), a dedicated public IPv4 address from the provider, or reaching the service over IPv6.
- Why must a carrier-grade NAT default to paired address pooling?Applications that open several connections, or that tie a session to the client's address, break if the connections leave from different public addresses. RFC 6888 REQ-2 therefore makes Paired the default for every session of a subscriber, across TCP, UDP and ICMP alike, while letting an administrator relax it for protocols known to cope.
saying these in an interview costs you the question
- 100.64.0.0/10 is simply a fourth RFC 1918 private range.
- A carrier-grade NAT uses 100.64.0.0/10 addresses on its internet-facing side.
- Forwarding a port on the home router is enough to accept inbound connections behind a CGN.
- An abuse report naming the public IPv4 address and a time identifies the subscriber.
- Providers may route Shared Address Space to each other like ordinary public space.