Jellyfin behind CGNAT: remote access on Starlink and 5G home internet

Updated ยท 6 min read

You forwarded the port, the rule looks right, and Jellyfin still can't be reached from outside. On Starlink, 5G home internet and many other plans, the reason is carrier-grade NAT. This page shows how to confirm it and the four ways to reach Jellyfin behind CGNAT anyway.

What CGNAT does

There aren't enough IPv4 addresses for every home, so some providers put many customers behind one shared public address. Your router no longer gets a public address of its own; it gets another private one from the provider. Outgoing traffic works normally, which is why browsing and streaming Netflix feel fine.

Incoming visits are the problem. A phone on cellular trying to reach your server arrives at the provider's shared address, and the provider's equipment has no idea which of its customers it's for. Your router never sees the visit, so no rule you set on it can help. Port forwarding, UPnP and DMZ all stop at a door you don't control.

Check whether you're behind it

Two numbers tell you. It takes a couple of minutes.

  1. Find your router's internet address. Open the router's settings in a browser, sign in, and look on the status page for the WAN or Internet IPv4 address. Use the router, not your computer: your computer only shows its home address.
  2. Find the address the internet sees. On a device at home with any VPN turned off, search for "what is my IP" and note the IPv4 address shown.
  3. Compare them. If the router's address is between 100.64.0.0 and 100.127.255.255 (the range 100.64.0.0/10 that providers use for shared NAT), you're behind CGNAT. If the two addresses differ in any other way, something upstream is translating too.
  4. Rule out double NAT. If the router's address starts with 192.168, 10 or 172.16 to 172.31, your router may sit behind another router, such as the provider's modem. Putting that modem in bridge mode, or forwarding on it as well, can fix that case. True CGNAT can't be fixed at home.

Tip: Tailscale gives your devices addresses in the same 100.64.0.0/10 range. A 100.x address on your computer's Tailscale adapter isn't a sign of CGNAT. Only the router's WAN address counts.

Starlink's residential plans and many 5G and satellite services commonly use CGNAT for IPv4. Plans and equipment change, so trust the check over any list.

Ask for a public IPv4 address

The simplest fix, when it's offered. Some providers give a home its own public IPv4 address on request, sometimes free, sometimes as a paid add-on or a business plan. Ask support for a "public IP" or to be "taken off CGNAT". Once you have it, the usual setup works: a reverse proxy with HTTPS and port 443 forwarded, as in Jellyfin remote access, step by step.

Use IPv6

Many providers that share IPv4 give every home real public IPv6 addresses. With IPv6 there's no NAT: your server has its own address that the internet can reach, if your router's IPv6 firewall lets it.

  • Find the server's stable IPv6 address. Computers also create temporary IPv6 addresses for privacy that change often; don't use those.
  • Add an AAAA record for your domain pointing at that address. Use dynamic DNS that supports IPv6 if your prefix changes.
  • In the router, find the IPv6 firewall (sometimes called pinholes or IPv6 port opening) and allow incoming TCP 443 to the server's address only. Routers don't forward IPv6; they allow or block.
  • Run a reverse proxy with HTTPS on the server, as in the HTTPS guide. Let's Encrypt can check your name over IPv6.

The limit: anyone watching from a network without IPv6, such as some hotel or office Wi-Fi, can't reach you. Most cellular networks have IPv6. Some provider-supplied gateways also don't offer an IPv6 firewall setting at all. More on router pinholes in the IPv6 help topic.

Use Tailscale or another overlay VPN

Tailscale works through CGNAT because both ends connect outward. Install it on the Jellyfin server and on each device, sign in with the same account (step by step), and connect to the server's Tailscale address on port 8096. Nothing is opened at home. When a direct path can't be made, Tailscale passes traffic through its relays, which works but can be slower.

The trade-off is that every device needs the Tailscale app. That suits your own phone and laptop, less so a friend's smart TV.

Tunnel through a rented server

If you need a public address that works for anyone, rent a small cloud server (a VPS) with its own public IPv4. Your home server connects out to it, so CGNAT doesn't matter.

  • Set up a WireGuard tunnel between the VPS and your home server. Your home side starts the connection and keeps it alive.
  • Point your domain's A record at the VPS, and run a reverse proxy there that sends visits through the tunnel, for example reverse_proxy 10.0.0.2:8096 in a Caddyfile, where 10.0.0.2 is the home server's tunnel address.
  • In Jellyfin, add the VPS's tunnel address to Known proxies on the Networking page.

Every stream crosses the VPS twice, in and out, so check its monthly data allowance before inviting the family. Hosted tunnel services such as Cloudflare Tunnel avoid running your own VPS, but read the provider's terms first: Cloudflare's service-specific terms say video served through its CDN should use its paid services unless you're an Enterprise customer.

Questions

Can I port forward on Starlink?

Not over IPv4 on plans that use CGNAT, because the visit never reaches your router. You can open a port in the router's IPv6 firewall if your plan gives you IPv6, or use Tailscale.

What IP range means CGNAT?

A router WAN address between 100.64.0.0 and 100.127.255.255, the 100.64.0.0/10 range. An address that differs from the one "what is my IP" shows is another strong sign.

Will a VPN app on my server fix CGNAT?

A normal VPN subscription won't: the internet then sees the VPN's address instead, and it doesn't accept visits for you. Tailscale, a VPN that supports port forwarding, or your own tunnel to a VPS does work.

Is double NAT the same as CGNAT?

No. Double NAT is two routers in your own home, which you can fix with bridge mode or a second forward. CGNAT happens at your provider, outside your reach.

The one-click way: Reelhost

Reelhost spots carrier-grade NAT before it opens anything: it checks whether your router's internet address is a private one or starts with 100.64 to 100.127, and whether the internet sees your home at a different address. With a public IPv6 address, your yourname.watchhome.app setup carries on over IPv6 and shows the one router step for its IPv6 firewall. Without one, nothing is claimed or opened, and private watching with Tailscale works today. A Reelhost relay for these connections is planned, not available yet. Watching away from home needs Complete or Yearly.

The check-up is free and changes nothing. Every fix is previewed, backed up and reversible.