Centralized Deterministic CGNAT¶
Ricardo Dominguez - 08/03/2023
All you need to know on Centralized Deterministic NAT configuration, scale and performance on MX routers.
Introduction¶
Internet Assigned Numbers Authority (IANA) allocated the last 5 IPv4 addresses blocks on February 3, 2011.
RIPE NCC run out of IPv4 addresses, it allocated the final /22 IPv4 address on November 25, 2019.
IPv6 adoption started more than 10 years ago and till June 2023, only 40% of the Internet traffic is over IPv6.

Worldwide IPv6 usage, it varies country by country, Uruguay, USA, Mexico and Brazil lead IPv6 adoption in America; France, Germany and Finland in Europe; India, Malaysia and Japan in Asia; while Africa has few IPv6 endorsement.

In July 2022, about 33% of websites were just IPv6.

IPv4 still dominates and will continue dominating Internet traffic for a while, CGNAT is widely needed due to public IPv4 address exhaustion and the number of connected devices has overcome the IPv4 address space.
IPv4 NAT Alternatives¶
There're many IPv4 NAT alternatives widely used, either, basic NAT, static source NAT, destination NAT and Dynamic NAT.
NAT44 mainly involves three NAT alternatives: Dynamic NAT, Port Block Allocation (PBA) and Deterministic NAT.
| Dynamic NAT | NAT w/ BPA | Deterministic NAT | |
|---|---|---|---|
| Logging | High | Low | Null |
| Security | High | Medium | Medium |
| Ratio Subscribers / IP Public | High | Low | Low |
Dynamic NAT¶
Dynamic NAT allows mapping private IPv4 address (M) to public IPv4 address (N) from a pool, typically this M:N relation means many private IPv4 addresses to few public IPv4 addresses using port translation. Public IPv4 addresses are assigned dynamically.
This kind of NAT involves high volume of logging, a log is created for a source private IP/Port to source public IP/Port translation, it requires a high storage capacity in logging servers. The security for this NAT is high as the public IP/Port can fall in any of the 64,512 port available per public IP. The subscribers/IP public ratio is excellent as it can use the total of the 64,512 port per public IP, meaning less public IP addresses waste.
NAT w/PBA¶
NAT w/PBA is a Dynamic NAT alternative, which assigns a block of ports per private IPv4 addresses. Using PBA reduces drastically the number of log entries, a port block is assigned to the first source private IP/Port to source public IP/Port translation, the rest of the same source private IPs will use same port block, only a log entry will be created for this port block, if the same source private IP needs more ports, another block can be assigned and new log entry will be generated for this new block.
When having PBA, the subscribers/IP public ratio can lead to some public IP addresses waste, In order to minimize this waste, it's important to assign smaller port blocks per private IP and if needed, then add more blocks to same private IP.
Deterministic NAT¶
Deterministic NAT works similar to PBA in terms of allocating a block of ports per private IP but instead of generating a log entry to logging server, the entry is registered locally in Juniper MX router, the relation between source private IP/Port to corresponding public IP/Port block is setup when creating Deterministic NAT configuration and log server is no longer needed. A similar block of ports design as in the case of PBA is recommended to reduce wasting public IP addresses.
CGNAT Configuration Blocks¶
CGNAT configuration is quite simple if we follow/understand each of its configuration parts, I call building blocks to these parts, the CGNAT processing relies on Juniper MX SPC3 services card.

Service Set¶
It's the main CGNAT building block, it groups the inside and outside multiservice interfaces along the NAT rule, this is where the translation takes place. The packets toward the inside multiservice interface are translated based on the NAT rule defined under this service-set.
Having a next-hop style service represents an inside multiservice interface (private network addressing) and the outside multiservice interface (public network addressing).
Following is typical service-set configuration:
¶
Firewall¶
A firewall rule is needed for the service-set, this firewall rule can accept everything as shown below or can do firewalling based on specific requirements.
¶
Multiservice Interface¶
The multiservice interface has 2 legs, one to the private network (inside) and one to public network (outside), the inside multiservice interface is in charge to send traffic to the Juniper MX SPC3 service card, so traffic can be translated. These interfaces are numbered according to the slot which SPC3 is inserted, PIC0 represents SPC3 NPU0 and PIC1 represents SPC3 NPU1, the port number is always 0.
A typical multiservice interface configuration is shown:
¶
CGNAT Routing Instance¶
The inside multiservice interface is assigned to a routing-instance, either a VRF or VR, these are used to send traffic to the corresponding mutiservice interface in next-hop CGNAT solution. A VR configuration displayed below:
¶
NAT Rule¶
The NAT identifies the source private addressing and based on the source addressing along the ALGs does the source NAT, it calls a pool in the source NAT action.
A NAT rule is defined under a NAT rule-set, the NAT rule-set can have multiple NAT rules. A NAT Rule configuration:
¶
Address Book¶
An address books contains address ranges, private source addressing is defined under these ranges. An address book configuration is below:
¶
CGNAT ALGs¶
Application Layer Gateways allows applications to work within NAT, Junos includes a rich ALGs for NAT such as FTP, DNS, H323, ICMP, SIP, RSTP, PPTP, SNMP, TFTP, etc. Most applications have evolved to function in an IPv4 NAT, working in the application layer.
An example of ALGs configuration:
¶
NAT Pool¶
The NAT pool contains the public IPv4 address to which private addressing will be translated, the ports range available per public IPv4 address, if PBA or Deterministic NAT are used, it then also includes the port block-size and the IPv4 private addressing.
A Pool with deterministic CGNAT is shown:
CGNAT Deterministic NAT44¶
One of the Service Providers concerns when deploying a centralized CGNAT solution, it's the fact to modify or alter routing in order to send private IPv4 traffic to a centralized CGNAT solution. An alternative to this concern is the usage of a CGNAT VRF through the MPLS network, in which different BNG / PEs private IPv4 traffic is send dynamically through a CGNAT VRF to centralized CGNAT PE.
A topology with this scenario is show below, this topology will be used for CGNAT scalability testing.
A BNG or PE receives private IPv4 traffic across different access interfaces which are assigned to CGNAT VRF, MX480 in our testing topology is acting as such PE. This PE in its CGNAT VRF receives a default route to points traffic to same VRF in CGNAT PE. Through this default route traffic will be routed from Remote PEs to CGNAT PE through MPLS network.
PTX10K1-36MR is acting a peering node emulating Internet peering and public IP addressing, to have a more realistic scenario, a 15K OSPF and 15K LDP routes are being injected to PTX10K1-36MR and such routes are sent to both CGNAT PE and remote PE. 2M IPv4 routes are also injected to duplicate the size of the Internet IPv4 table and 500K IPv6 routes are tripling the IPv6 Internet table.

MX960 is acting as CGNAT PE, it includes 2 x MPC10E for access and uplink connections, it also has 400G interfaces for uplink connections, to perform CGNAT functions, it has 7 x SPC3 LC. See below:
A Deterministic CGNAT was chosen in order to minimize syslog entries to an eternal logging system. MX980 is running Junos 21.2R3 version.
The following diagram shows MX960 CGNAT process.

MX960 has MPLS interfaces through which private IPv4 traffic is received, this traffic is assigned to CGNAT VRF (same VRF in remote PEs), this VRF advertises a default route to remote PEs, so these PE can send traffic via MPLS network to the CGNAT PE. An input CGNAT VRF forwarding-options FW Filter sends IPv4 private traffic to different VRs based on the source IPv4 subnet, each VR corresponds to a SPC3 NPU.
Traffic arrives to internal VRs and it's sent to inside multiservice interface via a static route, this multiservice interface is bound to SPC3 NPU, so traffic can be NATed, a NAT rule performs Deterministic NAT.
Once traffic has been NATed, a static route with public address is programmed in routing table pointed to outside multiservice interface, this route is created with a static protocol preference of 1. A policy-statement is used to announce public address through BGP.
When traffic comes from Internet, it's matched with such static route and pointed to outside multiservice interface, this interface pertains to a SPC3 NPU and traffic is translated from public addressing to corresponding private addressing and sent to inside multiservice interface's VR. Another VR static route sends traffic from each VR to CGNAT VRF, so this traffic can be sent to its remote PE via MPLS network.
Sessions Scalability¶
A 24 million sessions are processes per each SPC3 NPU, for a total of 336 million sessions in MX960.
The show services sessions count command shows the total number of current sessions being handled by the MX.
To check the creation of the pre-NAT, post NAT, and non-NAT'd sessions within the specified service set:
To verify the service set summary information for all services interfaces
CPS Scalability¶
A SPC3 NPU is able to create 350K sessions per second. The below commands show SPC3 NPU created sessions per second plus some commands to show NAT deterministic port used per source specific source prefixes.
¶
Throughput Scalability¶
TCP and UDP was sent for each SPC3 NPU, achieving 43Gbps traffic per NPU for 86Gbps per SPC3.
Conclusion¶
Juniper MX960 SPC3 can be deployed as a centralized CGNAT solution, allowing a complete and diverse NAT types and supporting up to 52M of sessions and 90Gbps throughput per SPC3. A MX960 can support till 7 x SPC3 and 400GigE interfaces
Useful links¶
- Google IPv6 Adoption Statistics: https://www.google.com/intl/en/ipv6/statistics.html#tab=ipv6-adoption
- Google per Country IPv6 Adoption: https://www.google.com/intl/en/ipv6/statistics.html#tab=per-country-ipv6-adoption
- World IPv6 Measurements: https://www.worldipv6launch.org/measurements/
- Adaptive Services Interfaces User Guide for Routing Devices: https://www.juniper.net/documentation/us/en/software/junos/interfaces-adaptive-services/interfaces-adaptive-services.pdf
- Next Gen Services Interfaces User Guide for Routing Devices: https://www.juniper.net/documentation/us/en/software/junos/interfaces-next-gen-services/interfaces-next-gen-services.pdf
Glossary¶
- ALG: Application Layer Gateway
- BNG: Broadband Network Gateway
- CGNAT: Carrier Grade NAT
- CPS: Calls per Second
- FW: Firewall
- IANA: Internet Assigned Numbers Authority
- IPv4: Internet Protocol version 4
- IPv6: Internet Protocol version 6
- MPLS: Multiprotocol Label Switching
- NAPT: Network Address Port Translation
- NAT: Network Address Translation
- NAT44: Translates an IPv4 to another IPv4
- PBA: Port Block Allocation
- PE: Provider Edge
- RIPE NCC: Réseaux IP Européens Network Coordination Centre
- VR: Virtual Router
- VRF: Virtual Routing and Forwarding
Acknowledgments¶
Thanks to Nicolas Fevrier for the opportunity and guidance to write this tech post. Thanks to Dirk van den Borne for encouraging me to create a tech post. Thanks also to Octavio Leonel, Mark Denny and Paul Lachapelle for the review and suggestions.