Guides

Why does sharing one public IP between subscribers make tracing hard?

Sharing does not simply blur the picture. It moves all the precision into a number that gets recycled, and puts a stopwatch on how long that number means anything.

One address carries a fixed budget of port numbers, and every subscriber behind it takes a slice. The larger the crowd, the smaller each slice, the faster ports are handed back and reissued, and the narrower the window in which a port number belongs to one customer. Precision does not vanish. It becomes a matter of seconds.

Why is one address given to many subscribers in the first place?

Because there are not enough of them, and there have not been for a long time. The pools that regional registries once handed out on request emptied, and what remains circulates through a transfer market rather than an allocation queue.

That turned addresses from something an operator was given into something an operator buys, holds and accounts for. A growing network either finds more of them or puts more customers behind the ones it has, and the second option needs no purchase, no waiting list and no approval.

So sharing spread quietly, one growth spurt at a time, and the record keeping consequences arrived years later in the form of questions nobody could answer. Very few networks decided to make tracing difficult. They decided to keep connecting customers, and this came with it.

How many customers actually fit behind one address?

Whatever the port budget allows, which is a decision rather than a constant. An address offers roughly sixty four thousand usable source ports once the low numbered ranges are set aside, and the ratio falls out of how many of those each subscriber may hold at once.

usable source ports on one address ~64,500 port allowance per subscriber 512 customers that fit 126 same address, allowance raised to 2,048 customers that fit 31

The allowance is not a formality. Best practice for large scale translation requires the equipment to support a configurable per subscriber limit, precisely so that one customer cannot consume the shared pool and squeeze everybody else off it.

What makes the arithmetic uncomfortable is modern browsing. A single content heavy page opens dozens of connections across several destinations, a television app holds more open in the background, and a household with a few devices sits comfortably in the hundreds during an evening. Set the allowance too low and customers report that things load slowly for no visible reason. Set it high and the address serves a handful of homes.

What else runs out before the ports do?

Room on the device. Every open mapping occupies space in the router's own session table, so equipment can run short of somewhere to hold connections well before the address runs short of ports.

Which of the two you meet first depends on what the traffic is doing rather than on the specification sheet. A network full of households holding many small connections presses on the session table. One carrying a few heavy transfers barely touches it while consuming the same bandwidth.

Finding out during an evening peak is the expensive way to learn which applies to you. The cheap way is to watch both figures, the count of open mappings and the share of ports in use, and see which one climbs faster as the evening builds.

What does sharing take away from the record itself?

It removes the address from the answer. Where an address belongs to one line, the address is the answer and everything else is detail. Where it is shared, the address describes a group and nothing more, and every question of identity moves onto the port and the moment.

This is why anything on the receiving end that records only an address becomes useless to you. It is not that the information is thin. It is that it points at a crowd, and no amount of careful searching on your side turns a crowd into a person.

The reverse holds as well. Records on your side that keep the address and drop the port have the same defect, and they usually look complete while having it, which is worse than looking obviously incomplete.

Why does a port number stop being unique so quickly?

Because ports are borrowed rather than owned. A connection takes one, holds it while it lasts, and hands it back when it closes, at which point it goes to whoever asks next.

Established practice puts a delay on that reissue, with a common figure being a wait of at least a hundred and twenty seconds before a released port goes out again. The delay exists to stop stray packets from an old connection landing on a new one, not to help anybody trace anything, and two minutes is generous by that standard and very short by the standard of a question asked months afterwards.

The consequence is a clock on the answer. A port number paired with a date is not an identifier. A port number paired with a moment accurate to the second is, and only until that port comes round again.

Two things follow from that, and both are cheap to arrange in advance. Time sources have to agree across every device that writes these records, and any moment you are given has to be converted before it is searched rather than assumed to be local.

What changes as the ratio climbs?

Every constraint tightens together, so networks tend to cross from comfortable to difficult without noticing the boundary.

How the sharing ratio changes what a trace demands
Customers per addressPort allowance eachHow often a port recyclesWhat the trace then needs
A handful Thousands Rarely, ports sit idle The address and roughly the right hour
Tens One or two thousand Through the evening peak The port, and a time good to the minute
Around a hundred A few hundred Continuously at peak The port, and a time good to the second
Several hundred A hundred or fewer Faster than customers reconnect The port, the second, and agreement between clocks

The table also explains a support pattern that looks unrelated. Complaints about video calls dropping, pages half loading, or a game refusing to connect cluster at peak on the addresses carrying the most customers, because that is where the allowance runs out first.

The last row is where operators find that requests they used to answer confidently now come back with two candidates. Nothing broke. The ratio moved, the recycling sped up, and the same records stopped being decisive.

Customers feel it before the record keeping does. Applications that hold many connections open start behaving oddly at peak, and the support calls that follow are rarely connected by anybody to a decision about address space.

There is a customer facing cost to a high ratio as well, and it lands unevenly. When one address gathers a complaint, whether that is a rate limit, a challenge page or an outright block at the far end, it lands on every household sharing it rather than on the one that earned it. The people who ring you about it are not the people who caused it.

Can you share addresses and still keep tracing simple?

Yes, by giving up flexibility instead of accuracy. Deterministic allocation hands each subscriber a fixed block of ports on a fixed address, so a port number maps back to a customer by calculation rather than by lookup.

The gain is substantial. There is far less to write down, because the mapping is a rule rather than an event, and an answer can be produced from the rule even for a period where the detailed records have already gone. The cost is unused ports, since a subscriber holding a block of five hundred rarely needs all of them at once, and the block sizing becomes a decision you have to live with.

Neither route removes the need to hold something. Deterministic blocks still have to be recorded somewhere as an assignment, because a rule nobody wrote down is not evidence, and the assignment changes whenever a customer is added, moved or removed.

The other route is to stop sharing where you can. Traffic that runs over IPv6 needs no translation and therefore no reconstruction, so every service that moves across quietly removes itself from this problem. Most networks will run both for years, which means the arithmetic above still has to be got right for the part that stays.

Whichever route is taken, the decision belongs with whoever understands the ratio, not with whoever is next asked to answer a request about a connection from four months ago.

How many subscribers can sit behind one public IPv4 address?

It depends entirely on the port budget each subscriber is allowed. An address carries roughly sixty four thousand usable source ports, so a limit of five hundred ports each fits around a hundred and twenty subscribers, and a limit of two thousand fits about thirty.

Why does a port number stop identifying one subscriber?

Because ports are returned to the pool and issued again. Best practice suggests waiting at least a hundred and twenty seconds before reusing one, so the same number can belong to two different customers within the same few minutes.

Does a higher sharing ratio make tracing harder?

Yes, and not gradually. More customers per address means a smaller port budget each, faster recycling, and a shorter interval in which a port belongs to one customer, so the accuracy demanded of the timestamp rises with the ratio.

Is there a way to share addresses and keep tracing simple?

Deterministic allocation gives each subscriber a fixed block of ports on an address, so the mapping can be worked out rather than looked up. It costs unused ports in exchange for far less to record and a far simpler answer.

What is your ratio costing you?

Tell us how many public addresses you run and how many customers sit behind them, and we will show you what that leaves you with.

Request a quote