
Network Address Translation, or NAT, changes address information as traffic crosses a network boundary. In the most familiar setup, a home or office router lets devices with private IPv4 addresses share one public IPv4 address.
NAT explains why a laptop can show 192.168.1.25 in its network settings while a website sees a completely different public address. The translation is useful, but it is not encryption, a VPN, a proxy service, or a complete security policy.
Quick Answer
NAT, or Network Address Translation, rewrites IP address information as packets pass through a router or gateway. Home networks commonly combine NAT with Port Address Translation so many private devices can share one public IPv4 address. The gateway keeps a translation table so replies return to the correct device. NAT does not encrypt traffic or guarantee anonymity.
Key Takeaways
- NAT translates addresses between network realms. The common home-router case translates private IPv4 traffic to a public IPv4 address.
- PAT lets many devices share one public address. It distinguishes concurrent flows with transport protocols and port numbers.
- A NAT table is temporary connection state. It links an internal address and port to an external mapping so return traffic reaches the right host.
- Private, shared, and public address space are different. 100.64.0.0/10 is carrier Shared Address Space, not one of the RFC 1918 private ranges.
- Port forwarding creates an inbound mapping. It must be paired with the correct firewall rule and cannot normally cross an upstream NAT that the subscriber does not control.
- Double NAT and CGNAT often cause inbound-connectivity problems. Browsing may work normally while hosting, gaming, peer-to-peer applications, or remote access fails.
- NAT is not a proxy, VPN, firewall, or anonymity system. These technologies can coexist, but each performs a different job.
Methodology: We reviewed the existing Proxidize article, the IETF descriptions of traditional NAT, private IPv4 addressing, IPv6 local-network protection, Shared Address Space, Port Control Protocol, and carrier-grade NAT requirements, plus current IANA address registries and Proxidize networking guides on September 29, 2026. The packet examples below use reserved documentation addresses; they are explanatory, not a live network test.
What Is NAT?
Network Address Translation is a function that maps an IP address in one network realm to an address in another. The gateway rewrites relevant packet headers and keeps enough state or configuration to reverse the translation for returning traffic.
RFC 3022 describes two traditional forms:
- Basic NAT maps IP addresses.
- Network Address Port Translation, or NAPT, maps addresses and transport identifiers such as TCP or UDP ports.
Most consumer routers use the second form. It is commonly called NAT, PAT, NAPT, NAT overload, or masquerading depending on the vendor and operating system.
The three devices retain separate private addresses on the local network. Internet destinations normally see connections from the router's public address. Port mappings and protocol state let the router distinguish their return traffic.
This is the typical IPv4 use case, not the only possible translation design. NAT can map between two IPv4 realms, translate destinations for inbound services, or participate in IPv4/IPv6 transition systems. This guide focuses on the NAT44 behavior most people encounter at home, in small offices, and behind internet providers.
How Does NAT Work?
Consider a laptop opening an HTTPS connection. The following values are examples only; 192.0.2.0/24 and 198.51.100.0/24 are reserved for documentation.
The connection follows this sequence:
- The laptop sends a TCP packet from 192.168.1.25:51514 to 192.0.2.80:443.
- The router receives the packet on its internal interface.
- The router creates or reuses a NAT mapping.
- It replaces the private source address with 198.51.100.20 and, in this example, replaces source port 51514 with 62001.
- It updates the affected checksums and sends the packet toward the website.
- The website replies to 198.51.100.20:62001.
- The router finds the mapping, restores destination 192.168.1.25:51514, and forwards the packet to the laptop.
The translation can be summarized as follows:
| Packet stage | Source | Destination | Translation performed |
|---|---|---|---|
| Outbound, before NAT | `192.168.1.25:51514` | `192.0.2.80:443` | None yet |
| Outbound, after NAT/PAT | `198.51.100.20:62001` | `192.0.2.80:443` | Source address and port translated |
| Reply, before reverse translation | `192.0.2.80:443` | `198.51.100.20:62001` | Router receives public-side reply |
| Reply, after reverse translation | `192.0.2.80:443` | `192.168.1.25:51514` | Destination restored to internal host |
The remote server does not send a reply directly to 192.168.1.25; that private address is not globally reachable. It replies to the public address and mapped port exposed by the NAT device.
What Is a NAT Table?
A NAT table records active or configured mappings. Exact fields differ by implementation, but an entry can include:
| Field | Example | Purpose |
|---|---|---|
| Protocol | TCP | Keeps TCP, UDP, and other supported traffic distinct |
| Inside local address | `192.168.1.25:51514` | Identifies the internal flow |
| Public mapping | `198.51.100.20:62001` | Receives return traffic from the external network |
| Remote endpoint | `192.0.2.80:443` | May influence mapping or filtering behavior |
| State or timer | Established; device-specific timeout | Determines how long the mapping remains usable |
Dynamic entries are not permanent. A router may remove them when a TCP flow closes or after a protocol- and implementation-specific idle period. UDP has no TCP-style connection teardown, so a NAT usually relies more heavily on timers.
This state explains several practical behaviors:
- Unsolicited inbound traffic usually has no matching dynamic entry and is not delivered to an internal device.
- A long-idle application can lose its mapping and need to reconnect or send a keepalive.
- Rebooting the router clears dynamic state and interrupts active connections.
- Asymmetric routing can fail when the reply bypasses the NAT that created the mapping.
- A busy gateway can run out of mapping, port, memory, or processing capacity even when bandwidth remains available.
The NAT table should not be confused with a routing table. A routing table chooses the next network path; a NAT table records how address and port values are translated.
What Does NAT Change?
Traditional NAT changes selected network and transport-header information. It does not automatically change every property of a connection.
| NAT commonly changes | NAT does not inherently provide |
|---|---|
| Source or destination IP address | Payload encryption |
| TCP or UDP port under PAT/NAPT | User anonymity |
| Checksums affected by rewritten headers | A new geographic location |
| Return path through a stateful mapping | Malware protection |
| Public address seen by an external destination | Browser-cookie or account isolation |
| Reachability of an internal service when a mapping exists | A complete firewall policy |
HTTPS, SSH, and VPN protocols can encrypt traffic carried through NAT. Their encryption comes from those protocols, not from the address translation.
Public, Private, and Shared IP Addresses
The address on a local device and the address observed by a website often differ because they belong to separate address realms.
IANA lists three private-use IPv4 blocks, as originally defined by RFC 1918:
| Address block | Common use | Globally reachable? |
|---|---|---|
| `10.0.0.0/8` | Large private networks, cloud networks, enterprises, and some home networks | No |
| `172.16.0.0/12` | Private networks | No |
| `192.168.0.0/16` | Home and small-office networks | No |
Private addresses can be reused independently by many organizations. A router translates them when traffic needs to cross into a realm where those addresses are not valid.
Carrier networks also use 100.64.0.0/10. RFC 6598 reserves this as Shared Address Space for service-provider NAT deployments. It is not an RFC 1918 private range, even though it is also not globally reachable.
Do not assume every address outside the three private ranges is an ordinary public address. IANA maintains an IPv4 Special-Purpose Address Registry covering loopback, link-local, documentation, benchmarking, shared, and other special blocks.
For a deeper explanation of local and Internet-facing addresses, see public vs. private IP addresses.
Static NAT vs. Dynamic NAT vs. PAT
Static, dynamic, and port-based translation describe different mapping strategies.
| Type | Mapping model | Public-address requirement | Typical fit | Main limitation |
|---|---|---|---|---|
| Static NAT | One fixed address maps to another fixed address | Usually one public address per mapped internal address | Predictable inbound and outbound mapping | Does not conserve public addresses through sharing |
| Dynamic NAT | Internal addresses temporarily use addresses from a public pool | A pool of public addresses | Outbound access where one-to-one mappings can be allocated temporarily | New mappings fail when the pool is exhausted |
| PAT, NAPT, or NAT overload | Many internal flows share one or several public addresses using ports | One public address can support many simultaneous flows | Home routers, offices, and shared Internet access | Port and state limits; inbound reachability needs an explicit mapping |
Static NAT
Static NAT keeps a consistent mapping, such as one private server address to one public address. It can make address translation predictable, but it does not automatically permit traffic. Firewall policy remains separate.
Static NAT also does not mean the ISP has assigned a permanent public address. The external address must still be provided and routed by the upstream network.
Dynamic NAT
Dynamic NAT selects an available address from a configured pool. The same internal host may receive a different public mapping later. Unlike PAT, each active basic-NAT mapping typically consumes one address from the pool.
PAT or NAPT
Port Address Translation lets simultaneous connections share a public address. The combination of public IP, translated port, and protocol helps keep flows distinct. This is the behavior most people mean when they say their home router “does NAT.”
NAT vs. PAT: What Is the Difference?
NAT is the broader concept of translating network addresses. PAT is a many-to-one technique that also translates transport ports.
Strictly speaking, the common home-router setup is NAPT. In everyday product interfaces, documentation, and support conversations, it is usually shortened to NAT. When troubleshooting, ask whether the device translates only addresses or also ports rather than relying on the label alone.
SNAT, DNAT, and Port Forwarding
Source and destination NAT describe which side of the packet is rewritten.
- Source NAT, or SNAT, changes the source address. Outbound private-to-public translation is the familiar example.
- Destination NAT, or DNAT, changes the destination address. Publishing an internal service through an external address is a common example.
- Port forwarding creates a mapping from an external address, protocol, and port to an internal address and port. It is commonly implemented with destination translation plus an appropriate firewall rule.
A port-forwarding rule might look like this:
Someone connecting to public port 8443 is forwarded to the internal service on port 443. These are documentation addresses, not a functioning endpoint.
Before exposing a service, confirm all of the following:
- The service is listening on the expected internal address and port.
- The internal device has a stable address, usually through a DHCP reservation or deliberate static configuration.
- The forwarding rule uses the correct TCP or UDP protocol.
- Router and host firewalls permit only the required traffic.
- The router has a usable public address rather than an uncontrolled upstream NAT.
- The application is patched, authenticated, and designed for Internet exposure.
- The test is performed from outside the local network unless hairpin NAT support has been confirmed.
Port Control Protocol is one standards-based way for a host to request mappings from a participating NAT or firewall. Consumer equipment may instead expose manual rules or other automatic mapping systems. Automatic convenience should not replace review of which service is being exposed.
What Is Double NAT?
Double NAT occurs when traffic crosses two IPv4 translation layers before reaching the Internet.
Common causes include:
- connecting a personal router behind an ISP modem/router that is still routing;
- placing a second Wi-Fi router behind the first;
- running a nested lab or virtual network;
- receiving a non-public WAN address from the ISP;
- using an upstream network that performs NAT before the subscriber's router.
Ordinary outbound browsing often works. Problems appear with inbound connections, port forwarding, peer-to-peer applications, some VPN protocols, voice or video sessions, remote access, and gaming.
Possible fixes depend on who controls the two devices:
- put the ISP gateway into bridge or passthrough mode where supported;
- use the second device as an access point instead of another router;
- forward through both layers, although this increases complexity;
- request a public address from the ISP;
- use an authorized outbound tunnel or relay when direct inbound addressing is unavailable.
Do not enable bridge mode without understanding which device will provide firewalling, authentication, Wi-Fi, and DHCP afterward.
What Is CGNAT?
Carrier-Grade NAT is translation performed inside an Internet service provider's network. It allows multiple subscribers to share a smaller supply of public IPv4 addresses.
| Characteristic | Home or office NAT | Double NAT | CGNAT |
|---|---|---|---|
| Who operates the relevant layers? | The local network operator | Usually the subscriber and another local or upstream operator | The ISP or mobile carrier operates the shared outer layer |
| Common inside/WAN address | Router receives a public address | Outer router receives the public address; inner router receives private space | Subscriber may receive `100.64.0.0/10`, private space, or another provider-specific non-public address |
| Can the subscriber configure the outer mapping? | Usually yes | Sometimes | Usually not through the home router |
| Ordinary outbound traffic | Normally works | Normally works | Normally works |
| Direct inbound IPv4 and port forwarding | Possible with correct rules | Requires control of both layers | Usually unavailable without provider support or a different service |
RFC 6888 documents common requirements for carrier-grade NATs. It also addresses explicit subscriber control of mappings, but real provider support and product terms vary. Do not assume a home-router port-forwarding rule can configure the carrier's gateway.
CGNAT is common in mobile and fixed networks, but implementation varies. It is inaccurate to say every mobile subscriber is always behind the same NAT arrangement or that a public address changes on one universal schedule.
The complete CGNAT guide covers the 100.64.0.0/10 range, verification, gaming, hosting, VPNs, IPv6, and available workarounds in more detail.
How to Check Whether You Are Behind NAT, Double NAT, or CGNAT
Compare three different addresses instead of relying on one checker.
1. Find the Device's Local Address
Open the active network connection's details on the computer, phone, or console. An address in 10.0.0.0/8, 172.16.0.0/12, or 192.168.0.0/16 confirms that the device is using private IPv4 locally. That is normal and does not reveal how many upstream translation layers exist.
2. Find the Router's WAN or Internet IPv4 Address
Sign in to the router or gateway you administer and locate its WAN, Internet, or uplink IPv4 address. Do not publish a full production address in screenshots or support forums.
3. Check the Public IP From the Same Route
Open the Proxidize IP Checker or another trusted public-IP service from the application being tested. Disable an application proxy or VPN only when it is safe and appropriate to test the ordinary ISP path; otherwise, the checker may correctly show that intermediary's exit instead.
4. Compare the Results
| Router WAN result | Public checker result | Likely interpretation | What to confirm next |
|---|---|---|---|
| Same globally reachable IPv4 | Same address | One local NAT layer is likely | Confirm firewall and port-forwarding rules if inbound access is needed |
| RFC 1918 private address | Different public address | Another NAT exists upstream | Check for a second router or ISP gateway |
| Address inside `100.64.0.0/10` | Different public address | CGNAT is likely | Ask the ISP whether it uses CGNAT and whether a public address is available |
| Different addresses, but WAN appears public | Could be upstream NAT, a proxy/VPN, multiple WANs, or stale status | Result is inconclusive | Recheck the route and ask the network operator or ISP |
The WAN comparison is evidence, not universal proof. Router interfaces can display stale data; VPNs, proxies, failover links, IPv6, or provider-specific designs can change the observed path. The ISP is the authoritative source for whether the subscription uses CGNAT.
What Do Open, Moderate, and Strict NAT Types Mean?
Gaming platforms and applications sometimes label connectivity as Open, Moderate, Strict, Type 1, Type 2, Type 3, or another product-specific category. These are reachability summaries, not Internet-standard NAT architectures.
The labels can reflect:
- whether unsolicited inbound traffic can reach the application;
- whether a stable port mapping can be created;
- how the NAT maps and filters traffic for different remote endpoints;
- whether UPnP, PCP, manual forwarding, or a relay is available;
- whether another NAT or CGNAT exists upstream;
- the application's own test method and servers.
An “Open” result does not necessarily mean NAT is disabled or that every inbound port is exposed. A “Strict” result does not diagnose the exact cause. Use the platform's current support instructions and change only the mappings needed by the application.
If gaming or voice chat fails:
- Confirm the console or computer has a stable local address.
- Check for a second router and compare the router WAN address with the public IP.
- Update router firmware and review firewall rules.
- Use the application's documented ports or supported automatic mapping method.
- Avoid placing a device in a fully exposed DMZ merely to improve a label unless the security consequences are understood.
- Ask the ISP about CGNAT or public-address options when the outer layer cannot be controlled.
Latency and NAT type are separate. A strict reachability result can disrupt peer connectivity without being the cause of general network latency.
Is NAT a Firewall?
No. NAT translates addresses; a firewall permits or denies traffic according to security policy. Home gateways frequently implement both, which is why the functions are easy to confuse.
RFC 4864 explicitly notes that IPv4 NAT was not developed as a security mechanism. The common protection effect comes from stateful behavior: unsolicited inbound traffic lacks an existing mapping and is not delivered. A stateful firewall can provide that filtering without translating addresses.
The difference becomes obvious with static mappings and port forwarding. NAT can translate an inbound connection to an internal host, while a firewall independently decides whether that connection is allowed.
Use explicit firewall policy, secure host configuration, updates, and application authentication. Do not treat private addresses or NAT alone as complete protection.
NAT vs. Proxy vs. VPN
NAT, forward proxies, and VPNs can all cause a destination to observe an address different from a device's local address. Their mechanisms and control scopes are different.
| Technology | Primary job | Typical configuration point | Connection behavior | Encryption provided by the technology? |
|---|---|---|---|---|
| NAT/PAT | Translate addresses and ports between network realms | Router, gateway, firewall, carrier, VM network, or cloud network | Usually transparent to the application | No |
| Forward proxy | Relay configured application connections through a proxy endpoint | Browser, HTTP client, operating-system proxy setting, or enforced gateway | Proxy accepts a client connection and connects onward | Depends on proxy protocol and transport; not inherent to the word proxy |
| VPN | Route selected network traffic through a tunnel to a VPN endpoint or private network | Operating system, router, or VPN application | Creates a tunnel and adds a routed network path | Normally yes, through the VPN protocol |
A home router's NAT usually changes the source address of all matching outbound traffic without the browser selecting it. A forward proxy is explicitly configured or enforced and can offer provider-controlled locations, sessions, and exit pools. A VPN establishes an encrypted tunnel and can cover traffic according to its routes.
The tools can be combined. A device can sit behind home NAT, connect through a VPN, and then use an application proxy. More layers are not automatically safer or better; they add routing, DNS, performance, and troubleshooting dependencies.
See VPN vs. proxy for the fuller traffic-coverage and encryption comparison.
Does NAT Hide Your IP Address?
NAT replaces a private source address with a public mapping for traffic that crosses the gateway. The destination normally sees the public NAT address rather than 192.168.x.x or another internal address.
That is address translation, not anonymity. A destination can still associate activity with:
- the shared public IP;
- an account or login;
- cookies and local storage;
- request and browser characteristics;
- application identifiers;
- timing and behavior;
- information voluntarily submitted to the service.
Several people or devices sharing one public address also does not make their activity indistinguishable. NAT changes the network-layer route, while applications operate with much more context.
What Does NAT Mode Mean for a Virtual Machine?
In a virtual-machine NAT mode, the guest receives an address on a virtual private network and reaches external networks through translation performed by the virtualization platform or host-side networking service.
The VM can therefore show a different private address while websites still see the same public ISP address as the host. Changing a VM from NAT to bridged mode changes how it joins the local network; it does not automatically provide another public address or country.
The virtual-machine networking guide explains NAT, bridged, and host-only modes and shows why a proxy configured inside one guest application has a different scope from the VM's network adapter.
Does IPv6 Need NAT?
IPv6 was designed with a much larger address space, so private-to-public translation is not normally required for address conservation. Devices can receive globally unique IPv6 addresses while a stateful firewall controls unsolicited inbound access.
This does not mean every IPv6 device should be reachable from everywhere. Routing and firewall policy still matter. Privacy addresses can also reduce long-term address stability without translating the address at a gateway.
Translation still exists in IPv6 environments for specific purposes. NAT64, for example, helps IPv6 clients communicate with IPv4 services. That is a protocol-transition function, not evidence that ordinary NAT44 is required for native IPv6 security.
NAT and firewalls should remain separate concepts: address translation is not what makes an IPv6 network safe.
Benefits and Limitations of NAT
NAT solved practical IPv4 deployment problems, but its tradeoffs should be stated precisely.
| Benefit | Operational value | Limitation or cost |
|---|---|---|
| IPv4 address sharing | Many private hosts can use one or a few public addresses | Adds state and complicates direct inbound connectivity |
| Internal address reuse | Separate networks can reuse RFC 1918 space | Overlapping ranges complicate VPNs, mergers, and routed interconnection |
| Renumbering boundary | Internal addressing can remain stable after some provider changes | The NAT gateway becomes a stateful dependency |
| Topology hiding | External peers do not see ordinary private addressing | This is not encryption, identity protection, or a firewall policy |
| Centralized mapping | Administrators can publish selected internal services | Port-forwarding rules create exposure and management work |
Applications that embed IP addresses or ports in their payloads can require NAT-aware designs, application-level gateways, or traversal protocols. Peer-to-peer systems commonly use techniques such as STUN, ICE, or relays because not every NAT permits the same mappings.
NAT can also complicate attribution. One public IP may represent many devices or subscribers, so an address alone does not identify one user. Operators that need auditability must retain appropriately protected and time-synchronized mapping records under applicable privacy and retention rules.
Common NAT Problems and How to Troubleshoot Them
| Symptom | Likely cause | What to check | Appropriate next step |
|---|---|---|---|
| Device has a private IP but websites show another IP | Normal NAT/PAT behavior | Local address, router WAN address, and public checker | No fix is needed if outbound access works |
| Port forwarding does not work | Wrong host, protocol, firewall, stale address, double NAT, or CGNAT | Listener, internal address, TCP/UDP selection, firewall, WAN/public comparison | Correct the failed layer; do not expose every port |
| Service works inside the LAN but not externally | No inbound mapping, firewall rejection, upstream NAT, or hairpin-test confusion | Test from a genuinely external network | Add only the required mapping and security rule |
| Game reports Strict or Type 3 NAT | Platform cannot establish its preferred reachability | Double NAT, CGNAT, application ports, automatic mapping, firewall | Follow platform guidance or request a public address |
| Voice, video, or peer connection is intermittent | Mapping timeout, endpoint-dependent behavior, ALG issue, or relay failure | Application logs, router settings, reconnect behavior | Update equipment and use the application's supported traversal method |
| VPN connection fails behind NAT | Protocol or configuration does not traverse the current NAT path | VPN logs, ports, protocol support, double NAT | Use a supported VPN mode or contact the administrator |
| Connections fail only under heavy load | Translation state, port, CPU, or memory pressure | Router connection count and resource telemetry | Reduce unnecessary concurrency or use appropriately sized equipment |
| Router WAN IP differs from public checker | Upstream NAT, CGNAT, proxy/VPN, failover, or stale status | Address ranges and active route | Remove diagnostic intermediaries where appropriate and ask the ISP |
| Connection breaks after router reboot | Dynamic NAT state was cleared | Application reconnect behavior | Reconnect; use an explicit stable mapping only when required |
Avoid changing several layers at once. Record the device IP, router WAN address, public IP, timestamp, protocol, ports, and exact failure before changing the configuration. That makes it possible to distinguish NAT from DNS, firewall, application, or provider problems.
Where NAT Fits With Proxidize
NAT explains the underlying route, while a managed proxy gives an application deliberate control over the exit network, location, and session behavior.
For example, a mobile carrier may use CGNAT internally. That carrier behavior is not the same as a proxy provider's rotating or sticky session policy. Carrier reassignment and NAT mappings happen in the access network; the Proxidize access point is the application-facing proxy configuration.
Proxidize Mobile Proxies provide real US mobile-network routes with supported city and carrier targeting. Proxidize Residential Proxies provide residential routes across 195+ countries with country, city, and ISP targeting. Both product families expose standard proxy connection details and supported rotating or sticky behavior.
For a configured request, the route can include several distinct address layers:
The destination normally sees the proxy exit, not the application's private address or ordinary direct public route. Traffic that is not configured to use the proxy continues according to the device's other routes.
Use the Proxidize IP Checker inside the configured browser or application to confirm which public address that request exposes. A successful check proves the route used by that request; it does not establish that every application on the device is proxied.
What Should You Remember About NAT?
NAT maps addresses between network realms. In the familiar home-router design, PAT lets many private IPv4 devices share one public address, while a translation table directs return traffic to the correct internal flow.
That simple model explains public-versus-private address differences, but practical troubleshooting requires checking every layer. Port forwarding needs an inbound mapping and firewall permission. Double NAT adds another gateway. CGNAT adds a provider-controlled layer that a home-router rule usually cannot change.
Most importantly, translation is not encryption, anonymity, or a security policy. Treat NAT, firewalls, proxies, and VPNs as separate tools, then verify the exact route the application is using.
Frequently asked questions
NAT stands for Network Address Translation. It maps address information as traffic crosses between network realms, commonly between a private IPv4 network and the public Internet.
A NAT gateway rewrites selected packet addresses and, with PAT, ports. It stores a mapping so replies sent to the public address and translated port can be restored and delivered to the correct internal device.
NAT is the broader address-translation concept. PAT, also called NAPT or NAT overload, additionally uses transport ports so many internal flows can share one public IP address.
NAT changes the source address exposed beyond the translation boundary, but it does not decide how the ISP assigns the router's public address. A dynamic public address changes according to provider policy, reconnects, leases, or network events rather than one universal NAT schedule.
No. NAT translates addresses and ports; a firewall enforces allow-and-deny policy. Consumer routers often provide both functions, and dynamic NAT state commonly prevents unsolicited inbound delivery, but translation itself is not a complete security control.
Double NAT means traffic crosses two address-translation layers. It commonly occurs when a personal router sits behind another router or ISP gateway. Outbound access may work while port forwarding, gaming, peer-to-peer, or remote access becomes harder.
A rule on the home router normally cannot control the carrier's outer NAT mapping. The ISP may offer a public IPv4 address, IPv6, PCP, or another supported option. Otherwise, an authorized outbound tunnel or relay may be required.
NAT hides ordinary private addresses from Internet destinations and exposes a public mapping instead. It does not guarantee anonymity because websites can use accounts, cookies, browser signals, behavior, and the shared public address.
IPv6 does not normally need private-to-public NAT for address conservation. Globally unique addresses can be protected with routing and stateful firewall policy. Translation may still be used for specific transition functions such as NAT64.
NAT transparently translates addresses at a network boundary. A forward proxy relays application connections configured to use it. A VPN creates an encrypted tunnel and routed path to a VPN endpoint or private network. They can operate together but are not interchangeable.