Stage 2 → CGNAT

CGNAT Calculator for ISP Port Capacity

Understand why a CGNAT design can run out of ports even when public IP count looks adequate.

Free to use · Runs locally in your browser · Last reviewed 2026-09-26
Review before deployment: CGNAT capacity is limited by both public IPv4 addresses and transport ports. The result is an estimate and does not design logging, port preservation, or application exceptions.

Inputs

cgnat-capacity.txt
Change an input to recalculate.

How to use this result

Each public IPv4 has roughly 65,535 TCP/UDP port numbers, but practical capacity is lower because of reserved ports, mapping policy, logging, port blocks, and bursts. Compare required subscriber ports with the usable public-port budget, then test real application behavior.

CGNAT also changes operations: inbound port forwarding may be impossible, abuse reports need timestamp and source-port correlation, and users may need IPv6 or a public-IP option.

Related tools

Sources and safe-use notes

This page follows the RouterOS documentation and the networking standards linked below. RouterOS syntax, hardware limits, and packet direction depend on your exact release and topology. Export a backup, test one controlled case, and keep a rollback path before applying generated output.

MikroTik documentation · RouterOS manual · RFC 4632 — CIDR · RFC 6598 — shared address space · RFC 8200 — IPv6 · RFC 6598 — shared address space · MikroTik NAT documentation