Skip to content

Double NAT: two routers, two front desks

Plug your own router into your ISP's box and you've built double NAT. Why that breaks hosting, how to spot it, and the setting that fixes it.

5 min read

Nobody sets out to build double NAT. You just want better Wi-Fi.

So you buy a decent router or a mesh kit and plug it into the box your ISP gave you. Everything works. Netflix works. Discord works. Except that box from the ISP was already a router, and now you have two of them, one behind the other, each with its own mailroom and its own logbook.

Our own house runs exactly this: the ISP's gateway, and behind it the router we actually use. It's one of the most common home setups there is, and nothing ever tells you you've got it.

Two front desks

If NAT is a front desk that drops visitors nobody asked for, double NAT is two front desks in a row. Your friend has to get past the first one before the second one even sees them.

And here's the trap. You log in to your router, the one you bought, the one with the nice app. You set up a port forward. Totally correct. Totally useless, because the first front desk, the ISP's box, never heard about it.

Double NAT: the ISP's box and your own router in a row A friend's connection reaches the ISP's gateway, which holds the public address. The port forward was set up on the home router behind it, so the gateway has no rule and drops the traffic before the home router sees it. Your friendjoins 203.0.113.7:8211Front desk 1: your ISP's boxpublic 203.0.113.7no rule for 8211Front desk 2: your routerWAN 192.168.1.143rule: 8211 → 192.168.88.30Game server192.168.88.3012

Two routers, two front desks. Your forward is on the second one.

  1. 1Your friend reaches your public address. That address lives on the ISP's box, the first front desk.
  2. 2The forward is on your own router, the second front desk. The first one has no rule for this port, so it drops the connection before your router ever sees it.

How to spot it

  1. Look at your own router's WAN address. If it's private, like 192.168.1.143, 10.0.0.2 or anything from 172.16 to 172.31, something is in front of it.
  2. Now log in to the ISP's box (often 192.168.1.254 or 192.168.0.1) and check its status page. If it shows the same address as "what is my IP", that's double NAT, and you can fix it.
  3. If the ISP box shows an address from 100.64 to 100.127 instead, you've got double NAT and CGNAT on top. Fix the double NAT anyway, then deal with the CGNAT.

Consoles often hint at it too. If your Xbox says "Strict" or your PlayStation says "Type 3", double NAT is a common reason.

How to fix it

In rough order of how clean the result is:

  • Bridge mode on the ISP's box. It stops being a router and becomes just a modem, and your own router gets the public address. One front desk. Forward ports there and you're done.
  • IP passthrough. Some ISP gateways (AT&T's, for one) can't do a full bridge mode but can pass the public address through to one device behind them. Point it at your router and you get the same result.
  • Put your own router in access point mode. The ISP's box stays the only router, and yours just does Wi-Fi. Fixes it, but you lose whatever made you buy the nicer router.
  • Forward on both. On the ISP's box, forward the port to your router's WAN address. On your router, forward it to the server. Works fine, but it's two places to keep in sync, and the next person to touch either box will not know.

Mesh systems deserve a special mention, because they cause this constantly. Most of them start out in router mode. If the ISP's box is staying a router, switch the mesh to its bridge or access point mode instead.

Or skip all of this

Void Sluice gets players into a server behind any of these walls without you touching the router. Your server dials out, we hand you an address, your friends connect.

Keep reading