Use safely: Follow these steps only for a router or network you own or are authorised to manage. Never send Router Portal a router password, Wi-Fi key, MAC address, serial number or private screenshot.
Evidence and scopeSOURCE-BACKED · CHECK DATE
Sources2 official references
ScopeModel/OS/network dependent
CredentialsNever universal
ReviewRecheck after UI changes
Quick answer: Carrier-grade NAT can place a private/shared address between your router and the public Internet, preventing ordinary inbound forwarding from reaching your LAN.
What this page covers
Compare router WAN status with the public address shown by a trusted service, without publishing either value.
Step-by-step workflow
- Read the router WAN address and connection type privately.
- Check whether the provider or router identifies CGNAT/shared addressing.
- Test local service access separately from Internet access.
- Prefer provider-supported public IPv4, IPv6 firewall policy or VPN/relay options.
Decision table
| Check | What it tells you | Safe next action |
|---|---|---|
| WAN and public address differ | An upstream translation layer may exist | Ask the provider about the service |
| Local service works | The application and LAN may be fine | Do not open extra ports blindly |
| IPv6 is available | Inbound model may differ | Use an explicit IPv6 firewall policy |
Limits and verification
Do not expose a service merely to test it. Public IPv4 availability and IPv6 behavior are provider-specific.
Official sources
- IETF RFC 7857 — Updates to NAT terminology (NAT terminology)
- CISA — Securing Home Network Devices (home-network safety guidance)
Related Router Portal guides
Router security guide · Router login troubleshooting
Editorial note: This pilot page is written for one distinct question. Firmware, operating-system menus, ISP policies and regional radio rules can change, so confirm the source and exact device before applying a setting.