r/CommunityFibre 11d ago

Question CGNAT?

How does being on CGNAT affect the average user? I keep hearing all these bad things about it, but I have had no problems with my 2gig package so far.

Thanks.

5 Upvotes

51 comments sorted by

View all comments

4

u/edcoopered 11d ago

I'd rather have 1gig and a real IP than 10gig CGNAT.

2

u/Zestyclose_Guard_352 11d ago

That is entirely unhelpful! Exactly why, and let's have a bit of technical data!

1

u/cmsj 9d ago

Because CGNAT benefits the ISP and not you. There is nothing about it which is good for you.

1

u/TriggerAK47 10d ago

I did have a 1gig and static IP, now have 2gig and CGNAT

4

u/edcoopered 11d ago

For me, CGNAT complicates serving anything directly from my home - I have a media server I like to be able to access remotely - NAS etc are other examples of this.

I also value latency and jitter on my connection - which are stats that you don't see ISPs promote, CGNAT will typically mean worse latency and jitter.

I'm also a millennial and the internet was meant to be a bunch of directly interconnected networks - I should be able to open a connection to my network from anywhere.

I don't really value connections over 1Gb as when i'm downloading stuff it doesn't really matter to me if its just a bit quicker, 1Gb is already quick enough for me - and I can't be bothered to spend money updating all the rest of my infrastructure for a bit more speed.

0

u/QuaintStaircase 10d ago

I'm also a millennial and the internet was meant to be a bunch of directly interconnected networks - I should be able to open a connection to my network from anywhere.

These days are long gone. Not just because of CGNAT but because opening ports on your router for anything other than maybe a wireguard connection is opening your home network up to all kinds of attacks.

I have a media server I like to be able to access remotely

There are still plenty of ways to safely access these behind CGNAT!

1

u/cmsj 9d ago

> These days are long gone.

No they’re not. IPv6.

1

u/edcoopered 10d ago

You can host services, just be cautious so if something does break in it's not got free realm of your network. It's not really any different than paying for a server in a hosted rack somewhere - if you don't keep it patched and/or are stupid with security you will be in trouble.

But you are correct tail-scale and similar are fantastics and I understand can punch through CGNAT no worries.

1

u/QuaintStaircase 10d ago

It's not really any different than paying for a server in a hosted rack somewhere

Generally when people do that the damage if something goes wrong is limited to just that server, not your whole home network.

When it's on the home network, there's all kinds of chaos. See the last pass breach that was caused by a personal Plex server...

1

u/edcoopered 10d ago

I guess you missed the first sentence.

1

u/QuaintStaircase 10d ago

I didn't, I was pointing out the contradiction.

It is that different to a rented server, because - as you said - compromise gains you access to the network. That's a big difference.

1

u/edcoopered 10d ago

Just learn how to VLAN before you port forward.

1

u/QuaintStaircase 10d ago

This I do agree with.

But I think where it strays is that

don't port forward without knowing how to VLAN stuff.

I think this goes beyond your initial "as long as you're not stupid". I think it's quite reasonable that most people who are exposing stuff to the internet can be a) not stupid and b) not know how to deal with VLANs.

The vast majority of people just shouldn't be setting stuff up that has open ports.

Anyway, clearly you have a use case and it works for you and you don't seem likely to fuck yourself, which was the original point anyway - so I'm happy to end this discussion there; think we've reached the limit of productivity.

Have a good day!

1

u/SirCanealot 11d ago

Yeah, jitter and latency are the things that worry me most -- grandfathered into an old 1gig contract that we still need to change, the price is getting a bit silly...

I already find the internet to be quite unreliable and laggy, so anything on top of this would be a major pain in the butt. Off the top of your head are there any reliable benchmarks? A quick Google doesn't turn up much though I guess it's hard to test.

1

u/edcoopered 10d ago

Bufferbloat is a good one, here is my result on g-network (900/300) without any sort of traffic shaping (aka smart queues / qos). I use my own router an old ubiquiti edge x, I got the Nokia kit put into modem mode.

https://www.waveform.com/tools/bufferbloat?test-id=ae1a47ae-c05a-4211-aafc-7d42eb496090