Networking

Double NAT

A setup in which two routers each translate private addresses, often because one sits behind an internet provider router. It can complicate port forwarding, gaming and remote access.

How it works

Double NAT commonly occurs when a personal router is connected behind another routing device. Each maintains its own private network and address translation. Ordinary browsing may still work, but an incoming connection or some peer-to-peer applications must cross both translation boundaries instead of just one.

Important differences and limits

Double NAT is not the same as having two Wi-Fi access points. An access point that bridges traffic need not create another routed network. Provider-side carrier-grade NAT is another possible boundary outside your equipment; changing the home router cannot automatically remove it. Exposing a device through a DMZ is not a general security fix.

A useful practical check

Identify which device supplies addresses and which performs routing. If supported, choose one router and use the other device’s documented bridge or access-point mode. Preserve configuration and verify Wi-Fi, telephony and other provider functions before changing modes. If remote access remains blocked, ask the provider about its addressing arrangement.

An example in practice

A provider router feeding a second router’s WAN port commonly creates two local routed networks. Connecting an access point in its documented bridge arrangement can extend coverage without that extra translation. These are different designs even when both devices broadcast Wi-Fi with similar names.

Technical sources

← All glossary terms