CGNAT on MikroTik: Stretch Your IPv4 for a Small WISP
Public IPv4 addresses are scarce and expensive, and a growing WISP can't buy one per subscriber. Carrier-grade NAT (CGNAT, also called NAT444 or LSN) is how you serve hundreds of customers behind a small block of public addresses. MikroTik's Cloud Core Routers are the workhorse for this at the small-to-mid scale, and this guide covers the config, the sizing, and the one piece operators forget: logging.
The routers below are in stock at Javelin Networks with fast US shipping.
What CGNAT is — and its trade-offs
With CGNAT, each subscriber gets a private address from the shared 100.64.0.0/10 range (RFC 6598, reserved exactly for this), and the router translates all of them to a pool of public IPs on the way out. Hundreds of customers can share a few dozen public addresses. The trade-off is that nothing on the internet can initiate a connection into a subscriber: inbound port-forwarding, hosting a server, some peer-to-peer apps, and a few online games or VPNs need extra handling. Most residential customers never notice; power users may ask for a dedicated public IP, which you can offer as an add-on by bypassing CGNAT for them.
What you need
CGNAT lives or dies on connection-tracking capacity and CPU, so size the router to your subscriber count:
- CCR2004-16G-2S+ — a strong starting point for a small WISP up to a few hundred subscribers.
- CCR2116-12G-4S+ — 16 cores and 16 GB RAM for a growing base with heavier traffic.
- CCR2216 — the flagship for high subscriber counts and multi-10G/100G uplinks.
Browse the whole CCR range or all routers & firewalls. Configure in WinBox; the RouterOS NAT documentation is the reference for every option below.
Basic CGNAT configuration
Assume subscribers are handed addresses from 100.64.0.0/10 and your public pool is a small block (here we show a single public IP; a pool is better — see sizing). The core is one source-NAT rule that translates the CGN range to your public address, applied only on the WAN out-interface:
/ip/firewall/nat add chain=srcnat src-address=100.64.0.0/10 \
out-interface=WAN action=masquerade comment="CGNAT"
For a pool of public IPs (recommended — it spreads subscribers and raises the usable port count), use action=src-nat with an address range instead of masquerade:
/ip/firewall/nat add chain=srcnat src-address=100.64.0.0/10 out-interface=WAN \
action=src-nat to-addresses=203.0.113.2-203.0.113.9 comment="CGNAT pool"
To offer a customer a real public IP (bypassing CGNAT), add an accept rule above the CGNAT rule for their address:
/ip/firewall/nat add chain=srcnat src-address=100.64.5.20 action=accept \
place-before=0 comment="Public-IP customer bypass"
Sizing: ports, connection tracking, and CPU
The real limit on CGNAT is not bandwidth — it is ports and tracked connections. Each public IP has roughly 64,000 TCP and 64,000 UDP ports; a busy subscriber can hold thousands of simultaneous connections. Two rules of thumb: give yourself enough public IPs that you are not packing more than ~100–250 subscribers per address, and make sure the router's connection-tracking table and RAM have headroom for your peak. The larger CCRs carry more RAM precisely for this.
Best for: A small WISP up to a few hundred subscribers
Best for: A growing base with heavier per-user traffic
Best for: High subscriber counts and 10/100G uplinks
Don't skip: logging for compliance
If you operate as an ISP, you are very likely required to keep records that map a public IP and port, at a given time, back to the subscriber behind it — so you can answer lawful requests. With CGNAT, that means logging NAT translations. Plan for this from day one: enable connection logging or an external flow/NetFlow collector, keep the records for your jurisdiction's required retention period, and store them securely. This is an operational and legal requirement, not an optional extra — confirm the specifics with your own counsel or regulator, as rules vary by country and region.
Frequently asked questions
What address range should subscribers use behind CGNAT?
Use 100.64.0.0/10, the shared address space reserved by RFC 6598 for exactly this purpose. Avoid reusing normal private ranges (like 192.168.x.x) that customers already use on their home routers, which would cause conflicts.
Will CGNAT break my customers' internet?
For normal browsing, streaming, and apps, no. What breaks is inbound connections: hosting a server, some port-forwarding, certain games and peer-to-peer apps. Offer a dedicated public IP as a paid add-on for the few customers who need it.
How many subscribers can one public IP handle?
It is limited by ports, not bandwidth. A common target is roughly 100–250 subscribers per public IP, adjusted for how heavy your users are. Monitor port and connection-table usage and add public IPs before you run tight.
Which CCR do I need?
Start with a CCR2004 for a small base, step up to a CCR2116 as traffic and subscriber count grow, and move to a CCR2216 for large deployments with 10/100G uplinks. RAM and connection-tracking headroom matter more than raw throughput for CGNAT.
Do I legally have to log CGNAT translations?
In most jurisdictions an ISP must be able to attribute a public IP and port at a point in time to a subscriber, which requires logging NAT translations. Retention periods and specifics vary — confirm your obligations with counsel or your regulator and build logging in from the start.
Scaling your network? Browse the CCR range and we will help you size the right router.
Products in this article