Blog

How Carrier-Grade NAT Confuses Rate Limits

Rate limiting by address assumes an address corresponds roughly to a user. On large access networks that assumption fails completely, and the mechanism responsible is address translation performed by the operator.

Operators translate at scale

Address space ran short long ago, so providers assign private addresses to subscribers and translate them to a much smaller pool of public addresses at the network edge.

The ratio is severe. A single public address can front thousands of subscribers simultaneously on a mobile network, with the translation table distinguishing them by port number rather than by address.

From outside, all of that traffic is indistinguishable. The server sees one address making requests at the combined rate of everyone currently sharing it.

A rate limit becomes a neighbourhood limit

Setting a threshold that a single person could not plausibly exceed means setting it far below what a shared address legitimately produces during busy periods.

The result is that ordinary users are throttled because unrelated strangers on the same carrier were active at the same moment. Nothing about their own behaviour caused it.

The effect is also unevenly distributed. Users on networks with heavy translation absorb nearly all of the false positives, and those tend to be mobile and lower-cost providers.

Ports and timing do not rescue the key

Source ports do distinguish connections, but they are reassigned constantly and are not visible to application code behind a delivery network. They cannot serve as a stable key.

Translation table entries also expire quickly, so the same subscriber appears under different ports minute to minute. Any attempt to build continuity from them decays within a single session.

This is why address-plus-port keying is used for connection tracking and almost never for identity or quota enforcement.

Better keys exist above the network

Where users authenticate, the account is the correct quota key, because it corresponds to the thing being protected and cannot be diluted by shared infrastructure.

For unauthenticated traffic, a session token combined with device signals produces a key that survives address changes and does not group unrelated people together.

Address-based limits still have a role as a coarse outer bound against volumetric floods, but the threshold has to be set for a neighbourhood rather than a person.

The same problem affects reputation

Abuse from one subscriber attaches to the shared address and therefore to everyone behind it. A reputation penalty applied at that granularity is collective punishment by construction.

Systems that recognise translated ranges and weight their reputation records lower avoid most of this. Recognising which ranges those are is the part that requires ongoing data rather than a one-off configuration.