Tech Behind ThingsHow the ordinary machinery actually works

Networks

Why you cannot reach your own devices from outside your house

Address exhaustion pushed most homes behind shared translation, and the consequences show up in gaming, cameras and remote access.

A clean and modern minimalist design of a white round electronic device with a blue light ring on a reflective glass surface.
Photograph by Jens Mahnke via Pexels
Editorial note. Independent reporting and analysis. Nothing here is sponsored or paid for. How we work.

There is a short answer about network address translation and a useful one, and they are not the same. What follows is the useful one.

The short version

  • A home usually has one public address shared by every device.
  • Carrier-grade translation shares one address between many homes.
  • Incoming connections have nowhere to go unless something forwards them.

One address, many devices

The original addressing scheme provides about four billion addresses, which was exhausted as connected devices multiplied. Network address translation lets a household use private addresses internally and share a single public one outward.

The router rewrites the source address and port on the way out and reverses the rewrite for replies, keeping a table of active conversations. This works well for connections you start and badly for connections somebody else starts.

Inbound connections have no destination

A packet arriving at your public address with no matching entry in the translation table has no way to know which internal device it belongs to. The router discards it, which is the reason hosting anything at home requires explicit port forwarding. This is also, incidentally, a substantial security benefit that people rely on without knowing it.

At the protocol level, a firewall does the same job deliberately; translation does it as a side effect.

Carrier-grade translation removes the option

Many providers now place customers behind a second layer of translation, sharing one public address among many households. The public address is therefore not yours, and port forwarding on your own router accomplishes nothing. The symptom is that remote access, some gaming modes and self-hosted services all fail with no obvious cause.

In practice, providers usually offer a public address on request or on a business package, sometimes for a fee.

Peer-to-peer software works around it

Techniques collectively known as hole punching use a third-party server to coordinate two devices into sending outbound packets simultaneously, which opens matching table entries in both routers. This works with many translation implementations and fails with the stricter ones, which is what console network type indicators are reporting. When it fails, traffic is relayed through a server, which adds latency and cost that somebody must pay for.

Video calling, gaming and remote desktop tools all contain this machinery whether or not it is visible.

The newer addressing scheme removes the problem

The larger address space gives every device a globally unique address, so no translation is needed. A firewall is then doing the security work explicitly rather than as an accident of address sharing, which is a clearer design. Adoption is substantial and very uneven by country and by provider, so both schemes will coexist for a long time.

In the datasheet, devices generally prefer the newer scheme when both are available and fall back silently when not.

Getting remote access without a public address

Overlay networks that connect your devices through a coordination service work regardless of translation and are the pragmatic modern answer. A small server elsewhere with a public address can act as a relay for your home network. Dynamic name services solve a different problem, keeping a name pointing at a changing address, and do not help if the address is not yours.

In practice, exposing services directly to the internet requires deliberate attention to authentication and updates, which is why the relay approaches have largely won.

The takeaway

You are sharing an address. That is why nothing can find you unless you arrange it.

Once you know what it is trading away, the design stops looking arbitrary.

Questions readers ask

How do I tell if I am behind carrier-grade translation?

Compare the address your router reports on its outside interface with the address a public what-is-my-address service reports. If they differ, another layer of translation sits between you and the internet.

Is address translation a firewall?

Not by intent, but the effect is similar for inbound traffic. It is not a substitute for a firewall, which enforces policy deliberately rather than as a consequence of address sharing.

Networksnatipv6addressingremote access
Mikkel Aas
Editor, Tech Behind Things

Mikkel edits Tech Behind Things and has taken apart more devices than he has successfully reassembled.

Also by Mikkel Aas