Starlink runs behind CGNAT. That means that, straight out of the box, you cannot view your cameras, your recorder or your card terminal from outside. Here is why it happens, why opening ports does not fix it, and how we solve it.
Further reading: Starlink installers in Alicante · Starlink plans · Business backhaul · AI-powered CCTV
It is the most frequent call we get about Starlink, and it almost always comes weeks after the installation: "I had cameras and could see them on my phone; since I got Starlink, I can't." It is not a fault with the dish or the installation. It is how Starlink's network works by design, and it is worth knowing before you buy the equipment.
A "normal" internet connection assigns you a public IP address: a unique identifier on the internet that can be reached from outside. It is what allows your phone, from another city, to find the recorder sitting in your industrial unit.
Starlink does not do that. It uses CGNAT (Carrier-Grade NAT): instead of giving you your own public IP, it hands you a private address and shares a single public IP between many customers at once. For browsing, streaming video or sending email it works perfectly, because in all of those cases you are the one initiating the connection outwards.
The problem appears in the opposite direction. When something tries to come in — your phone looking for the camera — it arrives at an IP shared by dozens of customers and there is no way of knowing that traffic was meant for you. The connection is discarded before it ever reaches your router. It is not a block that can be switched off: it is a structural limitation of the addressing.
📡 Why Starlink does it this way
It is not an arbitrary decision, nor a way of charging more. Very few free IPv4 addresses remain worldwide, and any fast-growing operator turns to CGNAT in order to serve more customers than its block of addresses would otherwise allow. Many mobile operators do exactly the same.
These are the specific cases we come across on installations around the province. If any of them sounds familiar, CGNAT is the cause:
Before reaching us, most customers have already tried one of these routes. None of them works with CGNAT, and it is worth understanding why so as not to waste time or money:
Opening ports on the router
Port forwarding distributes traffic that has already arrived at your router. With CGNAT it never arrives: it is discarded earlier, on the operator's network. You can configure it flawlessly and it will make no difference.
DDNS / No-IP / DynDNS
A DDNS solves the problem of a public IP changing. It does not solve the problem of not having a public IP at all. It will correctly point to a shared address that you still cannot get into.
Switching plan
Moving from Residential to Business does not in itself give you a fixed public IP. It changes the service terms and network priority, not the addressing.
There is also the idea of using the camera manufacturer's cloud remote-access services (P2P). They do work in many cases, but they depend on the manufacturer's servers, tend to degrade video quality, do not let you integrate the system with anything else, and stop working the day the manufacturer decides to shut the service down or charge for it. That is not a foundation on which to build a business's security.
The real solution is to stop fighting CGNAT and go around it. With MikroWizard, our own platform, we set up a dedicated VPN tunnel between your installation and one of our servers, which does have public addresses of its own.
The practical result is that you get a genuine fixed public IP, a permanent one, pointing at your network. From outside you connect to that address exactly as you would with a business fibre line: your cameras, your recorder and your equipment are back where you expected to find them. Nothing depends on Starlink's CGNAT any more.
Works with any plan
Business, Residential, Roam or Maritime. The only requirement is that the dish has an internet connection; the platform handles the rest.
The IP does not change
It is fixed and yours for as long as the service is active. You can record it in your camera system, in a maintenance contract or on an access whitelist.
Also over 4G, 5G or fibre behind CGNAT
The problem is not unique to Starlink. If your mobile or fibre connection is also behind CGNAT, the approach is the same.
It can be added later
We do not have to have installed the dish ourselves. If you already have Starlink up and running, it is added without touching the existing installation.
It is also the basis on which we provide 24/7 monitoring: with the tunnel established we can watch the link continuously and, normally, detect an outage before you notice it.
Because Starlink runs behind CGNAT and does not give you a public IP of your own: it shares one address between many customers. When your phone tries to come in from outside, the connection reaches that shared address and is discarded before it gets to your router, because there is no way to determine which customer it was meant for. Going out to the internet works normally; what stops working is connections coming in to you.
In the Spanish market there is currently no standard purchasing option that delivers a fixed public IP on the usual plans. That is why the practical route is the dedicated tunnel: it does not depend on Starlink changing its addressing policy.
No. Port forwarding decides which device on your internal network receives traffic that has already reached your router. With CGNAT that traffic never arrives, because it is discarded earlier on the operator's network. You can leave the configuration immaculate and still be unable to connect.
No. A DDNS solves the problem of a public IP changing over time, by keeping a hostname permanently up to date. It does not solve the problem of having no public IP at all: it will still point to a shared address that cannot be reached.
Not on its own. Changing plan affects the service terms and your priority on the network, not the fact of being behind CGNAT. It is a fairly widespread misunderstanding, and worth clearing up before paying a higher fee expecting it to solve this.
Yes. The fixed public IP is added on top of an existing installation without touching the dish mounting or the cabling. The original installation does not have to have been carried out by us.
Yes. CGNAT is not unique to Starlink: many mobile operators and some fibre providers use it. The technical picture is the same, and so is the solution.
Tell us what you have installed and what you need to see from outside. We will tell you whether a fixed public IP solves your case and what it involves, with no obligation.
Discuss my case →You may also be interested in: Starlink in Orihuela Costa