CGNAT calculator

Work out how many subscribers share each public IPv4 address behind carrier-grade NAT, and how many addresses your subscriber base needs. It runs in your browser: nothing you type is sent anywhere.

A CIDR block or a number of addresses

Commonly 1,024 or 2,048

Ports below 1024 are left out

How many sit behind the NAT

Used in the rules below

Ports per public IP
64,512
Subscribers per public IP
31
Public IPs in the pool
8
Subscribers the pool supports
248
Public IPs needed
7
Is the pool enough?
Yes, 1 address to spare

Every address in the pool is counted, network and broadcast included: a NAT pool uses them all. 1,024 ports per address are left over, too few for another block.

MikroTik rules

/ip firewall nat
add chain=srcnat action=src-nat src-address=100.64.0.1 protocol=tcp to-addresses=203.0.113.0 to-ports=1024-3071
add chain=srcnat action=src-nat src-address=100.64.0.1 protocol=udp to-addresses=203.0.113.0 to-ports=1024-3071
add chain=srcnat action=src-nat src-address=100.64.0.1 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.2 protocol=tcp to-addresses=203.0.113.0 to-ports=3072-5119
add chain=srcnat action=src-nat src-address=100.64.0.2 protocol=udp to-addresses=203.0.113.0 to-ports=3072-5119
add chain=srcnat action=src-nat src-address=100.64.0.2 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.3 protocol=tcp to-addresses=203.0.113.0 to-ports=5120-7167
add chain=srcnat action=src-nat src-address=100.64.0.3 protocol=udp to-addresses=203.0.113.0 to-ports=5120-7167
add chain=srcnat action=src-nat src-address=100.64.0.3 to-addresses=203.0.113.0
add chain=srcnat action=src-nat src-address=100.64.0.4 protocol=tcp to-addresses=203.0.113.0 to-ports=7168-9215
add chain=srcnat action=src-nat src-address=100.64.0.4 protocol=udp to-addresses=203.0.113.0 to-ports=7168-9215
add chain=srcnat action=src-nat src-address=100.64.0.4 to-addresses=203.0.113.0

4 of 200 subscribers shown, three rules each: 600 in all. Paste them above your masquerade rule, and on a large pool put them behind jump chains so each packet is matched against a few rules, not every one.

What each figure means

How the ports on one public address are shared out, and what the rules do with them.

Port block

The ports each subscriber may hold open on its public address at once. 1,024 suits most homes; 2,048 gives heavy users and game consoles more headroom. A smaller block fits more subscribers on each address.

Usable port range

The ports the router may translate to. Ports below 1024 are left out by default, which leaves 64,512 per address. A block that does not fit the range is refused rather than rounded.

Every address in the pool counts

A /29 holds eight addresses, and a NAT pool translates to all eight: no network or broadcast address is set aside, as it would be on a LAN.

Deterministic CGNAT

Each subscriber is pinned to one public address and one port block, so who used a port can be read from the rules, without logging every connection.

Shared address space

Subscribers behind CGNAT take addresses from 100.64.0.0/10 (RFC 6598), set aside so they never clash with a customer's own private network.

Bill the subscribers behind that NAT.

Centipid assigns addresses, provisions MikroTik and collects the payment that keeps them online.