IPv4 address exhaustion is the depletion of the global pool of unallocated 32-bit internet addresses (~4.3 billion unique values). This problem was triggered by the exponential growth of the internet, mobile devices, and IoT. The Internet Assigned Numbers Authority (IANA) officially exhausted its central free pool of IPv4 blocks on February 3, 2011, distributing its final chunks evenly to the five Regional Internet Registries (RIRs). [1, 2, 3, 4, 5]

Since then, the RIRs have transitioned from broad administrative distribution to strict rationing, waiting lists, and supporting the private transfer/leasing market. [1, 2, 3]

Current Status of the 5 RIRs

Every RIR has officially entered a stage of IPv4 depletion, meaning they can no longer hand out large blocks of IP addresses to support significant new network infrastructure. Instead, they enforce “soft-landing” policies, reserving tiny pools exclusively to help members transition to IPv6. [1, 2, 3]

Regional Internet Registry (RIR)Region CoveredDepletion / Hard Rationing MilestoneCurrent Allocation Policy Strategy
APNICAsia-Pacific2011Rations a maximum of a single /23 block (512 addresses) per member from its final pool.
LACNICLatin America & Caribbean2015 / 2020Allocates strictly small blocks exclusively via a waiting list for IPv6 transition.
ARINNorth America2015Free pool fully depleted. Issues addresses strictly via a waiting list of recovered space.
RIPE NCCEurope, Middle East, Central Asia2019Fully exhausted its main pool in November 2019. Maintains a waiting list for small single /24 allocations (256 addresses) from recovered space.
AFRINICAfricaPhase 1: 2017 / Phase 2 ongoingOperates under a strict Phase 2 soft-landing policy, rationing allocations between a /24 and a /22 block.

How the Industry Adapts

Because the protocol still works and remains critical for backward compatibility, organizations rely on alternative mechanisms to survive the squeeze: [1, 2, 3]

  1. The Transfer & Leasing Market: IPv4 has transformed from a free administrative resource into a highly valued commercial asset. Companies buy or lease space from secondary markets. As of mid-2026, buying costs hover around $23.50 per address in the market, while leasing averages roughly $0.35 per IP per month on platforms like IPXO. [1, 2]
  2. Carrier-Grade NAT (CGNAT): Service providers use Carrier-Grade NAT to allow thousands of private networks to share a single public IPv4 address, stretching their existing inventory as far as possible. [1, 2]
  3. IPv6 Transition: The absolute, long-term solution is migrating to IPv6, which uses 128-bit addresses to provide an virtually inexhaustible supply (3.4 × 10³⁸) of unique coordinates. However, adoption remains a gradual process due to high deployment costs, lack of backward compatibility, and the necessity of running complex dual-stack networks in the interim. [1, 2, 3]

How public lever masquerading saves millions of IPs

IP masquerading—historically rooted in Linux systems and commonly recognized today as a specialized dynamic type of Network Address Translation (NAT) or Port Address Translation (PAT)—acts as a critical economic and technical lever that saves millions of public IP addresses every day. [1, 2]

Without this dynamic translation lever operating silently at the edge of almost every local network, the global pool of 4.3 billion IPv4 addresses would have collapsed entirely decades ago, long before IPv6 infrastructure could be deployed.

How shared IPs protect User Privacy

While shared IP addresses—achieved through IP masquerading, NAT, and Carrier-Grade NAT (CGNAT)—were originally designed to combat IPv4 address exhaustion, they have unexpectedly become one of the most powerful everyday tools for protecting end-user privacy.

By turning a scarce technical resource into a shared public utility, network architecture inadvertently built a foundational layer of anonymity that shields everyday internet users from targeted tracking.

So is this linked to IPv4 exhaustion?
Ja, absoluut. Dit is rechtstreeks en onlosmakelijk verbonden met de uitputting van IPv4-adressen. Sterker nog: zonder de druk van de IPv4-schaarste zouden we tegenwoordig waarschijnlijk helemaal geen gedeelde IP-adressen gebruiken.

De directe link tussen IPv4-uitputting, masquerading en privacy werkt als volgt:

Hoe IPv6 dit privacyvoordeel weer kan veranderen

De link met IPv4-uitputting wordt nog duidelijker als we kijken naar de toekomst met IPv6:
Met IPv6 is er zóveel adresruimte dat IPv4-uitputting geen rol meer speelt. Elk apparaat op aarde kan weer een uniek, eigen openbaar IP-adres krijgen.

Hoewel dit technisch perfect is, verdwijnt hierdoor het automatische privacyvoordeel van de “digitale menigte”. Omdat netwerkbeheerders dit beseften, moesten er voor IPv6 speciaal nieuwe privacy-extensies (zoals IPv6 Privacy Extensions) worden ontworpen om de tracking-risico’s op te vangen die bij IPv4 gratis werden opgelost door de schaarste.

Showing IPv6 Privacy Extensions Status in Windows 11

123

Windows 11 – How to permanently disable temporary IPv6 address – Mi…

https://learn.microsoft.com/en-us/answers/questions/1195611/windows-11-how-to-permanently-disable-temporary-ip

IPv6 Privacy Extensions: What They Are and How to Enable

https://ipaddresslocation.net/articles/ipv6-privacy-extensions-what-they-are-and-how-to-enable

How to Enable and Disable Temporary IPv6 Addresses – PerfCode

https://en.perfcode.com/windows/issues/enable-disable-temporary-ipv6-address

You can check easily whether IPv6 privacy extensions (temporary addresses) are enabled on your Windows 11 device using built-in commands.

Method 1: Using PowerShell

  1. Click the Start menu, type PowerShell, and select Run as administrator.
  2. Enter Get-NetIPv6Protocol | Format-List to view current IPv6 protocol settings, including RandomizeIdentifiers and UseTemporaryAddresses.

Method 2: Using Command Prompt (netsh)

  1. Click the Start menu, type cmd, and select Run as administrator.
  2. Enter netsh interface ipv6 show privacy to display the current privacy extension status.

Method 3: Listing Current IPv6 Addresses

  1. Open PowerShell as administrator.
  2. Enter Get-NetIPAddress -AddressFamily IPv6 | Where-Object SuffixOrigin -eq ‘Random’ to list temporary IPv6 addresses currently assigned.

The Dual-Stack Era: Running Both Protocols to Survive

The transition from IPv4 to IPv6 could not happen overnight because the two protocols are completely incompatible—an IPv6-only device cannot communicate directly with an IPv4-only server. To prevent global internet disruption during this prolonged transition, networks entered the Dual-Stack era, a resource-intensive survival strategy where infrastructure must run both protocols simultaneously.

This overlapping era has turned into a decades-long bridging phase. Organizations are forced to bear the high maintenance costs of running dual infrastructures simply to stay reachable to all corners of the global market while waiting for the legacy IPv4 world to finally fade away.

Has Sorce NAT and NAT has anything to do with this transition? Source Network Address Translation

Ja, absoluut. Zowel NAT (Network Address Translation) in het algemeen als Source NAT (SNAT) in het bijzonder spelen een gigantische en cruciale rol in deze transitie. [1, 2]

Sterker nog: ze zijn getransformeerd van hulpmiddelen om IPv4-adressen te besparen naar de belangrijkste bruggen die ervoor zorgen dat het internet tijdens de overgang naar IPv6 niet in tweeën splitst. [1, 2]

Omdat IPv4 en IPv6 totaal verschillende talen spreken en niet rechtstreeks met elkaar kunnen communiceren, worden NAT en SNAT op de volgende manieren ingezet om de transitie te overleven: [1]

1. De rol van Source NAT (SNAT) bij IPv6-naar-IPv4 (NAT64)

Veel moderne netwerken (zoals grote mobiele 4G/5G-netwerken of datacenters) willen intern IPv6-only draaien om van het IPv4-beheer af te zijn. Maar als een IPv6-only smartphone een website wil bezoeken die alleen nog een oud IPv4-adres heeft, kan dat niet rechtstreeks. [1, 2, 3]

Hier komt een transitiemechanisme genaamd NAT64 in actie, dat zwaar leunt op Source NAT: [1, 2]

Dankzij SNAT kunnen miljoenen nieuwe IPv6-apparaten naadloos communiceren met de erfenis van het oude IPv4-internet, zonder dat die apparaten zelf een IPv4-adres nodig hebben. [1, 2]

2. NAT als alternatief voor Dual-Stack (Adresbesparing)

Zoals in de vorige sectie is beschreven: het draaien van een Dual-Stack netwerk (waar elk apparaat verplicht een IPv4- én een IPv6-adres heeft) loodzwaar en duur. Er zijn simpelweg niet genoeg IPv4-adressen om elk nieuw IPv6-apparaat ook een IPv4-identiteit te geven. [1, 2]

Hierdoor vormt Carrier-Grade NAT (CGNAT) (een grootschalige vorm van Source NAT bij de internetprovider) de reddingsboei: [1, 2]

Samengevat

NAT en Source NAT zijn verschoven van een tijdelijke pleister voor IPv4-schaarste naar de essentiële vertaalmachines

The Two Scales of Source NAT: Local vs. Carrier-Grade

Source Network Address Translation (SNAT) is the foundational mechanic that allows multiple devices to hide behind a single IP address. However, as the IPv4 pool reached critical depletion, network engineers had to deploy SNAT at two entirely different scales to keep the internet functioning.

  1. Local SNAT (The Home Scale): This is the traditional NAT running on your consumer router. Your router takes all internal nodes (laptops, phones, smart TVs) with private IPs (e.g., 192.168.1.x) and uses SNAT to rewrite their source headers to match the single public IP address provided by your Internet Service Provider (ISP).
  2. Carrier-Grade NAT / Massive SNAT (The Provider Scale): As public IPv4 addresses became too scarce and expensive for ISPs to give one to every single household, providers stopped handing out unique public IPs to homes. Instead, they deployed Carrier-Grade NAT (CGNAT)—essentially a massive, high-throughput SNAT infrastructure at the core of their own network that multiplexes thousands of entire households behind a single public IP address.

The Two-Stage Process (Double NAT)

Because both scales of SNAT must coexist to survive the current IPv4 landscape, traffic originating from a local node often has to pass through a Two-Stage Process before it ever reaches the public internet. This creates a multi-layered translation environment:

[ Local Node ] (Private IP: 192.168.1.10)
│
▼
┌────────────────────────────────────────┐
│ STAGE 1: Local SNAT (Home Router) │
│ Translates 192.168.1.10 to 100.64.0.15 │
└────────────────────────────────────────┘
│
▼
[ ISP Network ] (CGNAT Private IP Pool: 100.64.0.0/10)
│
▼
┌────────────────────────────────────────┐
│ STAGE 2: Massive SNAT (ISP Core) │
│ Translates 100.64.0.15 to 203.0.113.5 │
└────────────────────────────────────────┘
│
▼
[ Public Internet ] (Global Destination)

While this two-stage process successfully saves millions of IPv4 addresses globally, it adds processing overhead and breaks traditional inbound port forwarding, making it difficult for local nodes to host servers without specialized transition tools.

CGNAT stands for Carrier-Grade Network Address Translation. It is a method used by internet service providers (ISPs) to let multiple customers share a single public IPv4 address. [1, 2]

Why ISPs Use CGNAT

How CGNAT Works

Limitations of CGNAT

But how does this break inbound port forwarding?

To understand why Carrier-Grade NAT (CGNAT) breaks port forwarding, it helps to look at how traditional port forwarding works versus how CGNAT changes the rules.

In short: Port forwarding requires control over the public IP address, but under CGNAT, your ISP controls it, not you.

Here is the step-by-step breakdown of why it breaks:

1. The Double-NAT Problem (Two Barriers)

In a standard home network, you have one layer of Network Address Translation (NAT) managed by your home router:

When you set up port forwarding, you tell your router: “If traffic comes to my Public IP on Port 80, send it directly to my private computer at 192.168.1.5.”

Under CGNAT, a second layer is added by the ISP:

2. Traffic Gets “Lost” at the ISP Level

When an outside device tries to connect to your home server, it sends traffic to the shared Public IP address on a specific port.

Because you do not own that Public IP exclusively, your home router never sees that incoming traffic. The traffic hits the ISP’s CGNAT router first. The ISP’s router looks at the incoming packet, realizes it didn’t request this data from the inside, doesn’t know which of the 500 shared households it belongs to, and instantly drops the connection.

You can configure port forwarding rules on your home router all day, but they are useless because the traffic is blocked before it ever reaches your house.


Direct Comparison: Normal Internet vs. CGNAT

FeatureStandard Internet (No CGNAT)CGNAT Internet
Your Router’s WAN IPPublic & UniquePrivate (Shared with others)
Who controls the Public IP?You (via your router)Your ISP
Inbound Port ForwardingWorks (Direct path available)Broken (Blocked at the ISP level)

How to Bypass This Limitation

If you need to host a game server, access a home security camera, or use Plex, you can bypass CGNAT using these methods:

Dual-stack oplossing van onze meesterlijke providers

De term “dual-flex” (vaak aangeduid als Dual-Stack of transitietechnieken zoals DS-Lite / Dual-Stack Lite) is de perfecte aanvulling op dit overzicht. Dit is de methode waarbij een provider beide protocollen (IPv4 en IPv6) tegelijkertijd aanbiedt om de overgang naar het moderne internet soepel te laten verlopen. [1, 2, 3, 4]

Hier is de uitgebreide en bijgewerkte tabel waarin deze flexibele dual-oplossing is meegenomen:

Directe vergelijking: Normaal internet vs. CGNAT vs. Dual-Stack (Oplossing)

Kenmerk / ProbleemNormaal internet (Geen CGNAT)CGNAT-internetDual-Stack / DS-Lite (De Dual-Flex Oplossing)
WAN IP-adres van je routerPubliek & uniekPrivé / Gedeeld (vaak in de 100.64.x.x reeks)Beide: Je krijgt een uniek publiek IPv6-adres én een gedeeld IPv4-adres.
Wie beheert het publieke IP?Jijzelf (via je eigen router)Je internetprovider (ISP)Jij beheert het IPv6-gedeelte; de ISP beheert de gedeelde IPv4.
Inkomende poortdoorsturingWerkt direct (open, rechtstreeks pad)Gebroken (verkeer strandt bij de provider)Gedeeltelijk: Werkt perfect via IPv6, maar blijft gebroken voor ouderwetse IPv4-verbindingen.
Gedrag bij IPv4Eén uniek IPv4-adres per huishouden; poorten zijn vrij open te zetten.Grootste probleem: Honderden huishoudens delen hetzelfde IPv4-adres. Poortdoorsturing is onmogelijk.Gecapsuleerd: IPv4-verkeer wordt via een ’tunnel’ door het IPv6-netwerk van de provider geleid (DS-Lite).
Gedrag bij IPv6Elk apparaat krijgt een uniek, openbaar IPv6-adres. Geen NAT nodig.Verschilt per provider. Als het ontbreekt, zit je volledig vast aan de IPv4-beperkingen.Volledig native: Al het moderne internetverkeer loopt via een directe, snelle IPv6-verbinding zonder tussenkomst van NAT.

Waarom dit een “flexibele” oplossing is…?

Met een Dual-Stack (of DS-Lite) netwerk hoeft de provider niet in één keer heel het internet te dwingen om over te stappen. Je computer kiest automatisch de beste route: [1, 2]

  1. Bezoek je een moderne website (zoals Google of Netflix)? Dan gaat dit rechtstreeks en razendsnel via IPv6.
  2. Bezoek je een oudere server die alleen IPv4 begrijpt? Dan schakelt je router flexibel over naar de CGNAT-route om die site alsnog te bereiken. [1, 2, 3]

Voordelen met hosten van gaming servers of streaming (twitch) gaming gerelateerd

Het hosten van je eigen gaming servers of het streamen naar platforms zoals Twitch werkt heel verschillend onder een traditionele verbinding, CGNAT of een Dual-Flex (Dual-Stack) oplossing.

Hier is het overzicht van de voordelen, nadelen en specifieke impact op jouw gaming- en streamingervaring per netwerktype:

Directe impact op Gaming Servers & Streaming

NetwerktypeHosten van Gaming Servers (bv. Minecraft, Rust, Ark)Streamen naar Twitch / YouTube (Uplink)
Normaal Internet (Eigen Publiek IPv4)Optimaal: Vrienden kunnen direct verbinding maken via je IP-adres. Poortdoorsturing (port forwarding) werkt feilloos.Uitstekend: Stabiele, directe route naar de streaming-servers (ingest servers) met minimale kans op framedrops.
CGNAT-Internet (Gedeeld IPv4)Niet mogelijk (zonder omweg): Vrienden kunnen jouw server niet bereiken omdat inkomend verkeer door de ISP wordt geblokkeerd.Matig/Instabiel: Je deelt je IP met honderden anderen. Als iemand anders op jouw IP zwaar downloadt of misbruik maakt, kan je stream haperen of word je geblokkeerd.
Dual-Flex / Dual-Stack (IPv6 + Gedeeld IPv4)Toekomstbestendig: Werkt perfect als je vrienden ook IPv6 hebben. Voor vrienden met alleen IPv4 moet je alsnog een VPN-tunnel of workaround gebruiken.Uitstekend: De stream naar Twitch verloopt soepel en stabiel via de dedicated IPv6-route, volledig gescheiden van het drukke IPv4-verkeer.

De Voordelen per activiteit (Waarom Dual-Flex/Normaal internet wint)

1. Bij het hosten van Gaming Servers 🕹️

Als je server draait op een netwerk met een eigen publiek IP (Normaal) of via IPv6 (Dual-Flex), profiteer je van:

2. Bij Live Streaming (Twitch / YouTube) 🎬

Streamen is uitgaand verkeer (upload), wat technisch wel werkt achter CGNAT, maar een Normale of Dual-Flex verbinding biedt grote voordelen:

Maar hebben alle computers na 2010 standaard ipv4 ondersteuning?

Ja, vrijwel 100% van alle computers, laptops en smartphones die na 2010 zijn gemaakt, ondersteunen standaard IPv4. Sterker nog, ze ondersteunen zelfs allemaal standaard IPv6.

IPv4 is de oer-technologie van het internet (ontstaan in de jaren ’80). Het zit zo diep ingebakken in elk besturingssysteem dat er na 2010 consumentencomputers is ontwikkeld die geen IPv4 begrijpt.

Wat na 2010 wél is veranderd, is hoe computers met deze twee protocollen omgaan.

Dit werkt via een systeem genaamd Happy Eyeballs:

Hoe jouw computer flexibel kiest

Sinds 2011/2012 gebruiken alle grote besturingssystemen (zoals Windows 10/11, macOS, Android en iOS) een techniek die officieel Happy Eyeballs (RFC 6555/8305) heet. Dit werkt als volgt:

  1. De Dubbele Test: Wanneer jij een website opent (bijvoorbeeld Twitch), stuurt jouw computer tegelijkertijd een kleine test naar het IPv4-adres én het IPv6-adres van die site (bijv. Twitch).
  2. De Snelste Wint: Welke verbinding het snelst antwoordt (meestal IPv6, omdat dit niet door de CGNAT-vertraging hoeft), wordt gebruikt voor jouw verbinding.
  3. Onzichtbare Back-up: Mocht IPv6 om een of andere reden falen, dan schakelt de computer binnen een fractie van een seconde (ongeveer 300 milliseconden) geruisloos over naar IPv4. De gebruiker merkt hier helemaal niets van.

Waar zit dan de bottleneck?

Het probleem ligt dus nooit aan de computer van jou of je vrienden.

De beperking zit puur in het netwerk tussen de computers:

De transitie naar IPv6: Een balans tussen netwerkinfrastructuur en de smartphone-revolutie

Hoewel consumentenapparatuur en besturingssystemen rond 2010 al standaard gereed waren voor IPv6, stonden internetproviders (ISP’s) voor een complexe afweging.

In plaats van een directe, volledige migratie naar IPv6, hebben veel providers de afgelopen 15 jaar gekozen voor transitietechnologieën zoals IP Masquerading (NAT/CGNAT) en Dual-Flex (Dual-Stack Lite). Deze strategie was noodzakelijk om de onvoorziene, explosieve groei van het internet op te vangen.

De historische realiteit laat hierin een duidelijke verdeling zien:

1. De impact van de smartphone-revolutie
Toen de introductie van de smartphone (aangejaagd door onder andere de iPhone van Apple in 2007) zorgde voor een exponentiële stijging van het aantal internetverbindingen, was deze massale vraag naar IP-adressen destijds niet vooraf te voorspellen.

Het direct ombouwen van de volledige netwerkinfrastructuur (wijkcentrales, softwaresystemen en consumentenmodems) naar IPv6 was financieel en logistiek een gigantische operatie.

Omdat de gemiddelde eindgebruiker primair een werkende verbinding eiste, boden technologieën zoals CGNAT een stabiele en kostenefficiënte methode om het tekort aan IPv4-adressen direct op te vangen zonder de internettoegang te onderbreken.

2. Mobiele netwerken en de noodzaak van CGNAT
Rond 2010 hadden mobiele netwerken door de smartphone-hausse direct miljoenen extra IP-adressen nodig. Mobiele providers (zoals KPN, Vodafone en Odido) introduceerden daarom op grote schaal IP Masquerading / CGNAT op hun 3G- en 4G-netwerken.

Hierdoor deelden duizenden mobiele gebruikers gelijktijdig hetzelfde publieke IPv4-adres. Pas rond 2019/2020 begon de grootschalige uitrol van native IPv6 binnen mobiele netwerken, toen de hardware en standaarden daar volledig op waren ingeregeld.

3. Vaste internetproviders en de Dual-Flex (DS-Lite) oplossing
Vaste kabel- en glasvezelproviders raakten pas in een later stadium door hun IPv4-voorraad heen. Om deze transitie soepel te laten verlopen, werd er gekozen voor de Dual-Flex (DS-Lite) methode om netwerken gefaseerd te moderniseren:

De huidige status van de infrastructuur
De migratie naar IPv6 is een van de grootste infrastructurele projecten in de geschiedenis van de telecommunicatie en is vandaag de dag nog steeds in gang.

In Nederland is de status afhankelijk van de gekozen netwerkstrategie per provider:

Het resultaat is een hybride technologielandschap: hoewel de hardware aan de kant van de eindgebruiker al 15 jaar klaar is voor de toekomst, bepaalt de specifieke netwerkinfrastructuur van de provider in de wijk welke protocollen en mogelijkheden (zoals poortdoorsturing) daadwerkelijk beschikbaar zijn.

Why IP Masquerading Feels Confusing

The reason this topic often feels confusing is that network engineers use entirely different names for the exact same mathematical and protocol operations, simply depending on who owns the router and the scale at which it is deployed:

The Reality at the Hardware Level

Strip away the marketing buzzwords and vendor documentation, and the reality is simple: the CPU inside your €50 home router and the massive, liquid-cooled routing blades inside a multi-million-dollar ISP data center are doing the exact same thing to every single packet.

At the silicon level, the process never changes. The hardware is continuously:

  1. Ripping open the Layer 3 packet header as it arrives at the gateway.
  2. Changing the source IP address from an internal private identity to an external public identity.
  3. Updating the transport port number to keep track of the specific conversation thread.
  4. Rewriting the checksum so the packet remains valid and doesn’t get dropped by the next hop on the internet.

Whether it is called masquerading, SNAT, or CGNAT, it is the same mathematical survival tactic running at different scales to keep the exhausted IPv4 internet alive.


Geef een reactie

Ontdek meer van Maikel van Esdonk

Abonneer je nu om meer te lezen en toegang te krijgen tot het volledige archief.

Lees verder