Check Your NAT Type Instantly
Free online tool to detect your NAT type for gaming (PS5, Xbox, PC) and understand your network connectivity
NAT Type Comparison
| NAT Type | Gaming | VoIP | P2P | PS5 | Xbox | Switch |
|---|---|---|---|---|---|---|
| Open Internet | Excellent | Excellent | Excellent | Type 1 | Open | Type A |
| Full Cone NAT | Excellent | Excellent | Excellent | Type 1 | Open | Type A |
| Restricted Cone NAT | Good | Good | Moderate | Type 2 | Moderate | Type A |
| Port-Restricted Cone NAT | Moderate | Moderate | Poor | Type 2 | Moderate | Type B |
| Symmetric NAT | Poor | Poor | Blocked | Type 3 | Strict | Type C–D |
| Blocked | Poor | Poor | Blocked | Type 3 / Failed | Strict / Unavailable | Type F |
Platform Guides
Learn how to check and improve NAT type on your device
Why Choose Us
Built for gamers and everyday users who want clear, reliable network diagnostics with no setup or sign-up.
Accurate Detection
We combine public IP-and-port mapping with real UDP connection checks to understand how your network handles peer connections.
How we detect your NAT type
Discover your public mapping
STUN reveals the public IPv4 address and UDP port assigned to your browser’s connection.
Check UDP connectivity
Your browser exchanges WebRTC connection information with our test server. ICE checks try to establish a real UDP path.
Report the observed behavior
Our server returns a NAT category from the mapping and connection checks. The result describes this tested path.
Built on IETF protocols
Public addresses, mapped ports, NAT type, and IPv6 connectivity are separate observations. Here is how to read each result.
This is the public IPv4 address reported during the test. A router or ISP may translate a private address before traffic reaches the internet, so several devices or subscribers can share a public address.
An address alone does not confirm CGNAT or Double NAT. A VPN can also change the public address seen by the test.
When a port is available, the number after the colon in the IPv4 result is a UDP port observed for this browser test. For example, 203.0.113.10:62000 shows an address and the reported port 62000.
It is not a game port, a port-forwarding rule, or proof that a service is reachable at that address. Mappings can change between tests or destinations, especially with Symmetric NAT.
This describes the IPv4 UDP behavior observed on the tested path. NAT 1 is Full Cone, NAT 2 is Restricted Cone, NAT 3 is Port-Restricted Cone, and NAT 4 is Symmetric. Open Internet is a separate result for a path where no NAT was observed.
These are NAT Checker’s labels for the RFC 3489 categories. PlayStation, Xbox and other platforms use their own labels and tests. NAT type does not measure download speed or guarantee that every game can connect to every peer. Select “How we classify NAT” to see the decision logic.
This is a global IPv6 address exposed by your browser during the IPv6 check. Local-only addresses are excluded. IPv6 discovery runs separately from the IPv4 NAT check.
An address alone does not prove external connectivity. “IPv6 not detected” means this test found no global IPv6 address; it does not establish that your ISP or device cannot support IPv6.
“External connectivity confirmed” means our IPv6 test service reported a successful WebRTC/UDP connection on this test path. Finding an IPv6 address is not enough to produce this result.
“External connectivity not confirmed” means that path did not succeed. Firewall rules, a VPN, browser restrictions or network conditions may affect the check. Normal IPv6 browsing can still work because it uses different connections and protocols. A timeout or service error means the check did not complete.
Blocked is a result returned by the NAT test server when this UDP test path cannot be established. It does not identify which device or setting caused the failure.
Timeout means no final classification arrived within the test window. An error or service-unavailable message means the test could not complete. These outcomes are not confirmed NAT 1-4 classifications. Retry, then check browser restrictions, VPNs and firewall settings before assuming a router or ISP fault.
Our classification follows the mapping and filtering logic in RFC 3489, Sections 5 and 10.1. NAT 1-4 are our numbers for its four named NAT categories.
RFC 3489 distinguishes NATs by comparing public IP-and-port mappings and checking which reply sources can reach the same local UDP socket. Changing a reply’s source and changing a request’s destination test different behaviors.
- Test I: send a normal STUN Binding Request. The reply reports MAPPED-ADDRESS, the public IP and UDP port observed by the server. Compare both with the local socket’s address and port to determine whether translation occurred.
- Test II: ask for a reply from a different server IP address and port. Receiving it shows that an external sender the client has not contacted can reach the mapping.
- Alternate-destination Test I: send a normal request from the same local socket to the alternate server endpoint identified by CHANGED-ADDRESS. Compare the new public IP and port with the first mapping to detect destination-dependent mapping.
- Test III: ask for a reply from the original server IP address but a different port. This separates an IP-only incoming filter from a filter that requires both the IP address and port to match.
These are the RFC’s classification checks. Our browser test gathers the public mapping with STUN and uses server-assisted WebRTC connectivity checks to return the corresponding behavior category.
- Test I receives a reply, and the mapped public IP or port differs from the local socket endpoint, so NAT is present.
- Test II receives a reply from a different server IP and port, even though the client has not sent traffic to that reply source.
- In RFC 3489’s decision tree, this is Full Cone NAT, which we label NAT 1.
Once a UDP mapping exists, other external senders can reach that mapping without prior contact. This generally makes direct peer connections easier; it does not mean every port is open.
- NAT is present, but Test II gets no reply from the changed IP and port.
- A new Test I to the alternate destination returns the same mapped public IP and port as the first request. The mapping does not change with that destination.
- Test III receives a reply from the original server IP at a different port. Prior contact with that IP is sufficient; prior contact with the reply’s exact port is not required.
This is Restricted Cone NAT, our NAT 2. Incoming UDP traffic is allowed from external IP addresses the client has already contacted.
- NAT is present, and Test II gets no reply from the changed IP and port.
- Test I to the alternate destination returns the same mapped public IP and port, ruling out destination-dependent mapping in this comparison.
- Test III also gets no reply when only the server’s source port changes. In the RFC model, incoming traffic must match an IP address and port the client has already contacted.
This is Port-Restricted Cone NAT, our NAT 3. The mapping stays the same in the comparison, but the incoming filter is stricter than NAT 2.
- NAT is present, and Test II gets no reply from the changed IP and port.
- Repeat Test I from the same local UDP socket to the alternate server endpoint.
- If the mapped public IP or port differs from the first mapping, the RFC decision tree identifies Symmetric NAT, our NAT 4.
For example, one destination might see 203.0.113.10:62000 and another 203.0.113.10:62001. A port change is enough; the public IP does not also have to change. An endpoint learned from one server may therefore be unsuitable for another peer, and some applications may need a relay.
If Test I gets no response, RFC 3489’s discovery flow reports UDP Blocked. In a browser test, a failed or incomplete UDP path can also be affected by browser settings, VPNs, firewalls, service availability or packet loss; it does not by itself locate the cause.
If Test I succeeds and the mapped IP and port both equal the local socket endpoint, no NAT is observed. Test II succeeding then identifies Open Internet. If Test II fails on that no-NAT path, the RFC calls it a Symmetric UDP Firewall. That is a filtering condition without address translation, not Symmetric NAT, and must not be confused with NAT 4.
Our result labels do not expose a separate Symmetric UDP Firewall category. An incomplete test or service error is also separate from a confirmed NAT category.
STUN discovers public mappings, ICE checks connectivity, and RFC 3489 supplies the NAT classification model.
STUN, documented in RFC 8489, lets the browser learn a public address and UDP port observed outside the local network. ICE, documented in RFC 8445, uses connectivity checks to establish a path between endpoints.
RFC 3489 defines the Full Cone, Restricted Cone, Port-Restricted Cone and Symmetric categories, along with the mapping-and-reply tests that separate them. We use that classification logic with our browser and test servers; IPv6 address discovery and external connectivity are separate checks.
The result describes this browser’s tested UDP path. VPNs, firewalls and browser restrictions can affect it, and a real network can combine mapping and filtering behaviors that historical NAT labels do not fully describe.
The test does not confirm CGNAT or Double NAT, verify every application port, or guarantee a console’s NAT label or every peer connection. A public IPv6 address is not proof of external UDP connectivity.
RFC 3489 also notes that repeating a discovery with the same local socket can reuse earlier NAT bindings and distort the result. A fresh discovery uses a new local endpoint or waits for old bindings to expire; results describe the network at the time of that check.
Fast Results
NAT 1-4 typically finish in 2-10 seconds. Blocked paths take about 20 seconds.
See detection times
Results appear as each check completes. Typical IPv4 detection times depend on the NAT behavior:
- Full Cone (NAT 1)
- ~2 s
- Restricted (NAT 2)
- ~5 s
- Port-Restricted (NAT 3)
- ~8 s
- Symmetric (NAT 4)
- ~10 s
- Blocked / UDP timeout
- ~20 s
Blocked paths use the full 20-second window to allow connection attempts to finish. Times are approximate; network conditions and the separate IPv6 check can affect total duration.
IPv4/IPv6 Dual-Stack
Separate IPv4 NAT and IPv6 checks, with real external UDP connectivity verification.
How both checks work
IPv4 and IPv6 run as separate checks, so you can see how each network path behaves.
- IPv4 NAT behavior
- Reports your NAT classification and public IPv4 address using STUN and server-assisted connection tests.
- Public IPv6 discovery
- Looks for a global IPv6 address exposed by your browser. Local-only addresses are excluded.
- External IPv6 connectivity
- Our IPv6 server attempts a real WebRTC/UDP connection. An address alone is not treated as proof of connectivity.
“External connectivity not confirmed” means this test path was not established. IPv6 browsing may still work; firewall rules or browser restrictions can affect the result.
Always Free
Free since our launch on July 21, 2025. We have never charged for a NAT test.
What’s included
- No account or sign-up required.
- Runs in your browser, with no software to install.
- NAT classification and IPv6 results are included, with no paid upgrade to view them.
Global Coverage
Reaching visitors across the Americas, Europe, and Asia.
- United States
- Brazil
- Germany
- United Kingdom
- Indonesia
- India
Languages & traffic source
Our homepages reach visitors across the Americas, Europe, and Asia, including:
Available in 24 languages, on desktop and mobile browsers that support WebRTC.
Countries listed by homepage Google Search clicks, June 30-September 29, 2026. Includes all language versions.
Privacy & DataYour recent test history is saved in this browser. You can clear it whenever you want.
- History you control
- Your last three results, including IP addresses and timestamps, are saved in this browser. Use “Clear” in History to remove them.
- Data needed for the test
- Our test servers and STUN providers receive network addresses to run connectivity checks. This is how the test discovers your public mapping.
- Service logs and advertising
- Our Privacy Policy sets a seven-day retention period for standard server request logs. The site uses Google AdSense and may use analytics.
Understanding NAT Types and Their Impact on Online Connectivity
Network Address Translation (NAT) is a fundamental part of how most modern networks connect to the internet. It allows multiple devices on a local network to share a single public IP address, conserving IPv4 resources and adding a layer of isolation between internal devices and external networks.
While NAT works transparently for everyday browsing, it plays a much more visible role when applications require direct or semi-direct connections between users. This is especially true for online gaming, voice chat, video calls, and peer-to-peer (P2P) services.
Understanding your NAT type helps explain why some connections work smoothly while others fail or fall back to slower relay paths.
Why NAT Behavior Matters More Than Internet Speed
Connection problems are often blamed on low bandwidth or a weak signal. In reality, a fast internet connection alone does not guarantee reliable real-time connectivity.
NAT controls how inbound traffic is handled and whether external devices can reach your system after an outbound connection is established. If your network restricts incoming responses too aggressively, applications that rely on peer-to-peer communication may struggle to establish or maintain direct connections.
Two users with similar internet speeds can therefore have very different experiences in online games or voice chat—often because of NAT behavior rather than raw bandwidth.
Common NAT Types and What They Mean in Practice
Different networks implement NAT in different ways. These behaviors are commonly grouped into several categories:
This configuration allows external hosts to reach your device once an outbound connection has been made. It provides the fewest restrictions and typically delivers the best experience for gaming and real-time communication.
Incoming connections are limited to external IP addresses that the device has previously contacted. Most applications still function, but some matchmaking or connection attempts may take longer.
Similar to Restricted Cone NAT, but incoming traffic must match both the external IP address and port. This creates more compatibility issues for some P2P applications.
A different external mapping may be used for each destination, while inbound traffic is heavily restricted. This is the most limiting configuration and often prevents direct peer-to-peer connections entirely.
How NAT Type Affects Gaming and Real-Time Applications
Online multiplayer games, voice chat systems, and conferencing tools often attempt to establish direct connections between players or participants to reduce latency and improve quality.
When restrictive NAT prevents a direct connection, traffic may be routed through a relay server. Communication can continue, but the relay may introduce:
In competitive or fast-paced environments, these effects can significantly impact the user experience.
NAT Challenges in Home and ISP Networks
Several common network setups can influence NAT behavior:
When two routers perform NAT, connection rules become more restrictive and harder to manage.
Without automatic port management, applications may not receive the inbound access they expect.
Some internet service providers place customers behind shared NAT infrastructure, limiting inbound connectivity regardless of local router settings.
Aggressive filtering can unintentionally block legitimate inbound traffic or responses.
Identifying your NAT type is the first step in determining whether these factors are affecting your network. Read the CGNAT check guide
Why Detecting NAT Type Is Useful
Knowing your NAT type provides clarity. It helps answer questions such as:
Designed for Clarity, Not Complexity
NAT Checker measures observable network behavior instead of inferring results from router settings. It provides clear, practical results without downloads, an account, or device permissions.
The test uses little data and reports results quickly, so you can check connectivity without disrupting normal use.
A Practical Tool for Everyday Users
Whether you are troubleshooting a game, diagnosing voice chat, or simply learning how your network behaves, your NAT type provides useful context. NAT Checker makes that behavior easier to interpret so you can make better decisions about router settings, hardware, and internet service.
Global Statistics
Frequently Asked Questions
Use a browser that supports WebRTC.
- Connect to the Wi-Fi or wired network you want to test. To check your home connection, disconnect any VPN first. Open natchecker.com on your computer or phone.
- Select “Check My NAT” at the top of the page and keep the page open. Allow up to 20 seconds for the IPv4 test.
- Read the result. Open “What your result means” in the section above for the field explanations.
- After changing your router, VPN, or network, select “Test Again” and compare the new result.