Router troubleshooting · Updated 7 October 2026
Why is my router's WAN IP different from my public IP?
Your router can have an address on its internet-facing interface while a website sees an address further upstream. Another router, your provider's carrier-grade NAT, a VPN or a different IP version can explain the difference. First make sure you are comparing the right two addresses.
Find the WAN address, not the router login address
Open your router's administration interface using its manufacturer's instructions. Look in the Internet, WAN or connection-status section for its WAN IPv4 address. The exact screen depends on the model. An address such as 192.168.1.1 used to open the administration page is usually the LAN gateway address, which is not the WAN address you need for this check.
- Use the same connection. Check from a device connected to that router, rather than from your phone's mobile data.
- Note any VPN or proxy. A website sees the route used by your browser. If you choose to disconnect one for this check, do so only when appropriate for your privacy needs.
- Compare the same IP version. Match the WAN IPv4 with a fresh IPv4 result. If our checker shows IPv6, this tool has not independently measured your public IPv4. Use a dedicated IPv4 check or ask your provider.
- Read the addresses together. A mismatch is a clue about routing or translation, not an automatic diagnosis of CGNAT.
What does the WAN IPv4 range tell you?
| WAN address range | Meaning | Next check |
|---|---|---|
10.0.0.0–10.255.255.255172.16.0.0–172.31.255.255192.168.0.0–192.168.255.255 | Private IPv4 space. Another device or provider can translate traffic to a public address upstream. | Look for a second router, then ask your provider about their network. |
100.64.0.0–100.127.255.255 | Shared address space reserved for uses including provider CGNAT. | Ask your provider whether your connection uses CGNAT and whether a public address is available. |
A WAN address outside these ranges is not automatically usable from the internet; other reserved ranges and provider policies exist. Even a globally routable address can sit behind a firewall. These range checks are clues, not a reachability test.
Double NAT and carrier-grade NAT
Double NAT at home can happen when your own router connects through a second router that also translates addresses. The inner router's WAN address may be a private address supplied by the outer one. Check the actual equipment and configuration before changing router modes.
Carrier-grade NAT (CGNAT) adds address translation in your provider's network. Multiple customers can share an internet-facing IPv4 address. You generally cannot configure that upstream translation from your home router. The shared 100.64.0.0/10 block is distinct from the private ranges used on many home networks.
A worked example of upstream translation
This illustrative connection has a private LAN address, a shared-carrier WAN address and a public-facing documentation address:
LAN IPv4192.168.1.20
WAN IPv4100.64.12.34
Website sees203.0.113.42
The last address is reserved for documentation, not a real result. The example explains why the two addresses can differ; it does not show your connection or verify your provider's setup.
Why port forwarding may still not work
A rule on your router controls only the translation or firewall you can configure there. It does not create a matching rule on another router or your provider's CGNAT system. If you need inbound access for a service, ask your provider about a public IPv4 option and its restrictions. Your service's official remote-access method may be another option.
A dynamic DNS name can track some address changes, but cannot remove upstream NAT. IPv6 has different addressing and routing behaviour; whether inbound access works still depends on support at both ends and firewall rules. Do not broadly disable a firewall to solve an address mismatch.
What to tell your provider
Use their trusted support channel to describe the task that fails, the WAN address range, the IP version and when you checked. Ask whether your service uses CGNAT, whether you have a public address, and whether inbound connections are supported. Avoid posting complete addresses or router-status screenshots publicly.
If the mismatch appeared only after connecting a VPN, start with the VPN comparison guide. If the address changes over time, read why public IPs change. A wrong map location is a separate issue covered in our geolocation guide.
Further reading
The private ranges are defined in RFC 1918 and shared-carrier space in RFC 6598. Our public and private IP guide explains which address to use for support.