Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Some links on this page are affiliate links: if you buy through them we may earn a commission, at no extra cost to you.

Double NAT means two devices on the path to the internet are both translating IPv4 traffic—most often an ISP gateway and a second home router. It usually does not slow ordinary browsing or Wi-Fi by itself, but it can complicate gaming, port forwarding, remote access, VPN servers, and communication between devices on separate networks. If everything works, you may not need to change anything.

What is NAT, and what makes it “double”?

Network address translation (NAT) lets devices with private IPv4 addresses share an internet connection. A router typically rewrites the source address—and often the port—of outgoing traffic so it can travel through a public IPv4 address. For incoming connections, a router can use a port-forwarding rule, also called destination NAT, to direct selected traffic to a device inside the home. NAT is not the same thing as Wi-Fi: it is a routing function. See Ubiquiti’s NAT overview.

Double NAT occurs when two routers perform NAT in sequence. For example:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Internet
  ↓
ISP gateway (router/NAT)
  ↓
Personal router or mesh primary (router/NAT)
  ↓
Your devices

The inner router gives your devices addresses on its own network, then sends their traffic to the ISP gateway. The gateway translates that traffic again before sending it onward. Two boxes do not necessarily mean Double NAT: a modem, optical network terminal (ONT), Ethernet switch, mesh satellite, or access point may not be routing or performing NAT. What matters is whether two devices are acting as routers.

#1 Best Overall
Sale
TP-Link ER605, Wired Gigabit VPN Router
  • 【Five Gigabit Ports】1 Gigabit WAN Port plus 2 Gigabit WAN/LAN Ports plus 2 Gigabit LAN Port. Up to 3 WAN ports optimize bandwidth usage through one device.
  • 【One USB WAN Port】Mobile broadband via 4G/3G modem is supported for WAN backup by connecting to the USB port. For complete list of compatible 4G/3G modems, please visit TP-Link website.
  • 【Abundant Security Features】Advanced firewall policies, DoS defense, IP/MAC/URL filtering, speed test and more security functions protect your network and data.
  • 【Highly Secure VPN】Supports up to 20× LAN-to-LAN IPsec, 16× OpenVPN, 16× L2TP, and 16× PPTP VPN connections.
  • Security - SPI Firewall, VPN Pass through, FTP/H.323/PPTP/SIP/IPsec ALG, DoS Defence, Ping of Death and Local Management. Standards and Protocols IEEE 802.3, 802.3u, 802.3ab, IEEE 802.3x, IEEE 802.1q

Double NAT commonly appears after adding a mesh system or personal router behind an ISP-provided gateway. It can also occur with cellular or fixed-wireless gateways, apartment or campus networks, or a managed firewall behind an ISP router.

Does Double NAT slow your internet?

Not necessarily. Double NAT is primarily a reachability and network-configuration issue, not an automatic Wi-Fi speed or latency penalty. Google says most people will not notice an effect on performance, while noting possible problems with gaming, port forwarding, IP assignments, and UPnP (Google Nest Help).

A slow connection or high ping may instead come from weak Wi-Fi, interference, ISP congestion, bufferbloat, an overloaded router, or a distant game server. Double NAT can make troubleshooting harder, but its warning alone does not prove it caused lag.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

What can Double NAT affect?

  • Online games: Some games or platforms may report Moderate or Strict NAT, have trouble with matchmaking or joining friends, or experience voice-chat and peer-to-peer connection problems. Double NAT is one possible cause, not a guarantee that a game will fail; requirements differ by game and platform. Bungie, for example, lists Double NAT among connection issues to investigate in its hardware troubleshooting guidance.
  • Port forwarding and hosting: A rule on the inner router may not be enough because the outer router can still block or translate the inbound connection. This matters for services such as a game server, NAS, camera system, or self-hosted application. A router without an inbound-reachable public address cannot receive ordinary internet port-forwarding traffic; see Ubiquiti’s port-forwarding guidance.
  • UPnP: UPnP lets compatible applications request port mappings automatically. With two NAT devices, a request may configure only the inner router, leaving the outer one unchanged. UPnP is not a universal fix and has security implications because it allows devices or applications to request openings automatically. Learn more from Ubiquiti’s UPnP explanation.
  • Remote access and VPN servers: Incoming connections to a home VPN server, remote desktop, or camera system may need to pass both routers. Port forwarding also exposes a service to unsolicited internet traffic; forward only what you need and keep the destination device updated. Ubiquiti notes that forwarded traffic is not encrypted by default in its remote-access guidance.
  • Local discovery: If the routers create separate private networks, devices on one side may not discover devices on the other. Printers, file shares, smart-home devices, and casting or AirPlay-style discovery can be affected. Google describes this kind of issue in its Double NAT help page.

How to check for Double NAT—or CGNAT

A console warning is a useful clue, not a complete diagnosis. Check the actual network path and compare the router’s WAN address with the public address seen by an outside service.

Rank #2
Omada ER707-M2, Multi-Gigabit VPN Route
  • 【Flexible Port Configuration】1 2.5Gigabit WAN Port + 1 2.5Gigabit WAN/LAN Ports + 4 Gigabit WAN/LAN Port + 1 Gigabit SFP WAN/LAN Port + 1 USB 2.0 Port (Supports USB storage and LTE backup with LTE dongle) provide high-bandwidth aggregation connectivity.
  • 【High-Performace Network Capacity】Maximum number of concurrent sessions – 500,000. Maximum number of clients – 1000+.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【Highly Secure VPN】Supports up to 100× LAN-to-LAN IPsec, 66× OpenVPN, 60× L2TP, and 60× PPTP VPN connections.
  • 【5 Years Warranty】Backed by our 5-years warranty and free technical support from 6am to 6pm PST Monday to Fridays
  1. Trace the connection. Follow the cable from the wall, fiber ONT, or modem to the ISP gateway, then to your personal router or mesh primary. Identify which devices are in router mode and which are in access-point or bridge mode. Two Wi-Fi names alone do not establish that NAT is happening twice.
  2. Find the personal router’s WAN/Internet IPv4 address. In its app or administration page, look for Internet, WAN, or Status. Do not confuse this with your phone or computer’s local address.
  3. Compare it with the public IPv4 address reported by a reputable “what is my IP” service. If the router’s WAN address matches, it may have a public IPv4 address. If they differ, another NAT device or an ISP network is likely upstream. A private WAN address is strong evidence of an upstream private network, but not by itself proof that the cause is a second router in your home. Ubiquiti recommends this WAN-versus-public-address comparison in its public-access guide.

These IPv4 ranges are useful clues:

Address range What it indicates
10.0.0.0/8 Private IPv4 address space
172.16.0.0/12 Private IPv4 address space
192.168.0.0/16 Private IPv4 address space
100.64.0.0/10 Shared address space commonly used for carrier-grade NAT (CGNAT)

The first three ranges often indicate another private router or managed network upstream. The 100.64.0.0/10 range suggests CGNAT: an ISP shares public IPv4 addresses among customers. Ubiquiti lists these ranges as clues that a gateway may be behind Double NAT or CGNAT (source). You can use ipconfig on Windows, ip addr on Linux, or ifconfig on macOS to see your device’s local address and default gateway; those commands do not reveal the router’s public WAN address.

Double NAT and CGNAT are related, but different

Double NAT usually describes two customer-side routing devices translating traffic, such as an ISP gateway and your own router. CGNAT is NAT performed by the ISP upstream, often to share public IPv4 addresses among customers. They can coexist: your home may have two routers, and the ISP may also use CGNAT.

CGNAT is a likely explanation when your router’s WAN address is private or in 100.64.0.0/10, differs from the externally observed address, and remains non-public after you have eliminated extra home routers. Apartment, campus, cellular, and fixed-wireless networks can also place your router behind a managed upstream network. If you need inbound access, ask the ISP whether it can provide a public IPv4 address; buying another home router cannot remove ISP-controlled CGNAT.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Choose the fix that matches your network

Your situation Usually the best option Trade-off
You want your personal router to control the home network and the ISP gateway supports it Put the ISP gateway in bridge or a documented passthrough mode Phone, IPTV, Wi-Fi, or ISP-management features may depend on gateway router mode.
The ISP gateway cannot bridge, and you mainly want better Wi-Fi coverage Put your personal router or mesh system in AP mode The ISP gateway retains routing, NAT, DHCP, firewall, and usually port-forwarding control.
The ISP uses CGNAT and you need to accept incoming connections Ask for public IPv4, use supported IPv6, or use an outbound VPN/relay A public-IP option may be unavailable or cost extra; IPv6 support varies.
You deliberately need two isolated networks Keep both routers in router mode and configure the separation deliberately Inbound access and device discovery across the networks become harder.
Everything works and you only browse, stream, and use ordinary apps Leave the setup alone unless a real problem appears Advanced gaming, hosting, or remote-access needs may expose limitations later.

Option 1: Bridge the ISP gateway

Choose this when you want the personal router to be the home’s sole router and NAT gateway:

Rank #3
Sale
ASUS RT-BE58U WiFi 7 Router - Dual-WAN, 3.6 Gbps, Mesh + VPN Compatible
  • Beyond-fast WiFi 7 (802.11be) - WiFi 7 (802.11be) dual-band extendable router boosts speeds up to 3600 Mbps, with 4096-QAM increasing a single frequency band’s transmission speed by 1.2 times
  • Unleashing Multi-link operation (MLO) for Ultra-Smooth Connectivity - Link to multiple bands at the same time to ensure stable internet connections and efficient data transfers
  • Versatile WAN configuration options - Establish always-on internet through AI WAN detection and a convenient USB port ready for 4G LTE and 5G Mobile tethering.
  • Smart Home Master - Easily establish up to three SSIDs with Smart Home Master for easy IoT device setup and management, instant VPN connections, and convenient parental controls.
  • Commercial-Grade network security - Network security with commercial-grade AiProtection Pro powered by Trend Micro, plus a one-tap security scan and Safe Browsing.
Internet
  ↓
ISP gateway in bridge/modem-only mode
  ↓
Personal router in router mode
  ↓
Home devices

In bridge mode, the ISP gateway stops routing household traffic and passes the connection to the personal router. Google and TP-Link recommend bridging the upstream modem/router in the usual gateway-plus-personal-router arrangement (Google; TP-Link).

  1. Identify the ISP gateway and check the ISP’s documentation or support page for bridge mode, modem-only mode, NAT disabled, or an equivalent feature. Menu names and availability vary by provider, device, firmware, and connection type.
  2. Before changing settings, note any ISP-specific requirements and consider saving a configuration backup. Ask whether phone service, IPTV, provider Wi-Fi, or remote management depends on router mode.
  3. Enable the provider-documented bridge or passthrough option. Do not assume that a similarly named DMZ feature is identical to bridge mode.
  4. Connect the bridged gateway to the personal router’s WAN/Internet port. For the first test, disconnect other downstream routers and connect only the intended primary router.
  5. Restart the equipment in the order recommended by the ISP, then check the personal router’s WAN address and test the application that had a problem.

The personal router should now handle household NAT, DHCP, firewall rules, UPnP, and port forwarding. Some ISP equipment or services do not support this arrangement, and a gateway may require a provider-specific passthrough configuration rather than true bridge mode.

Option 2: Put the personal router or mesh system in AP mode

Choose AP mode when the ISP gateway needs to remain the router or cannot be bridged:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Internet
  ↓
ISP gateway in router mode
  ↓
Personal router/mesh in AP mode
  ↓
Home devices

AP mode removes the downstream device’s router/NAT role so it provides Wi-Fi and, depending on the model, Ethernet connectivity while the ISP gateway remains responsible for routing. ASUS describes AP mode as connecting a device to an existing router to extend wireless coverage; its wireless-router mode normally has NAT, firewall, and DHCP enabled (ASUS operation modes).

Rank #4
Sale
TP-Link ER7206, Multi-WAN Professional Wired Gigabit VPN Router
  • 【Flexible Port Configuration】1 Gigabit SFP WAN Port + 1 Gigabit WAN Port + 2 Gigabit WAN/LAN Ports plus1 Gigabit LAN Port. Up to four WAN ports optimize bandwidth usage through one device.
  • 【Increased Network Capacity】Maximum number of associated client devices – 150,000. Maximum number of clients – Up to 700.
  • 【Integrated into Omada SDN】Omada’s Software Defined Networking (SDN) platform integrates network devices including gateways, access points & switches with multiple control options offered – Omada Hardware controller, Omada Software Controller or Omada cloud-based controller(Contact TP-Link for Cloud-Based Controller Plan Details). Standalone mode also applies.
  • 【Cloud Access】Remote Cloud access and Omada app brings centralized cloud management of the whole network from different sites—all controlled from a single interface anywhere, anytime.
  • 【SDN Compatibility】For SDN usage, make sure your devices/controllers are either equipped with or can be upgraded to SDN version. SDN controllers work only with SDN Gateways, Access Points & Switches. Non-SDN controllers work only with non-SDN APs. For devices that are compatible with SDN firmware, please visit TP-Link website.
  1. Open the personal router’s app or administration page and look for Operation Mode, Network Mode, Access Point, or AP mode. Labels and feature availability differ by model.
  2. Select AP mode and follow the manufacturer’s instructions for the Ethernet connection to the ISP gateway.
  3. Leave DHCP and NAT to the ISP gateway. If you need port forwarding, UPnP, or firewall rules, configure them on that gateway instead.
  4. Reconnect devices and test internet access, local discovery, and any affected game or service.

AP mode may disable or relocate router features such as port forwarding, VPN server, Dynamic DNS, traffic controls, parental controls, or guest-network isolation. Google also warns that putting a primary Google Wi-Fi device into bridge mode has limitations and may not suit every multi-device mesh setup; check the Google Nest configuration guidance before changing a mesh system’s mode.

Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

What if neither mode is available?

Some gateways offer IP passthrough, exposed host, or a DMZ-host setting. These are provider- and device-specific workarounds, not automatically the same as bridge mode. They may simplify inbound traffic to the downstream router, but the upstream device may still route or perform NAT. A DMZ setting can also send more unsolicited inbound traffic to the personal router, so keep its firewall enabled, maintain its firmware, and do not treat DMZ as a default security fix.

If both routers must remain in router mode and you control both, manual forwarding can work for a specific service:

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  1. Give the inner router a stable address on the outer router’s network, preferably using a DHCP reservation.
  2. Forward the required port and protocol (TCP, UDP, or both, as specified by the service) on the outer router to the inner router.
  3. Forward the same traffic on the inner router to the destination device, whose local address should also be stable.
  4. Test from outside your home network. Testing your public address from inside may fail on routers without NAT loopback, also called hairpin NAT.

This is a fallback, not a general cure. It will not create inbound access through CGNAT, an inaccessible upstream gateway, or a firewall that still blocks traffic. The exact ports depend on the application and can change; use current guidance from its publisher rather than copying a generic gaming port list. Port forwarding exposes the chosen service, so avoid opening unnecessary ports and keep that device secure.

Best Value
NETGEAR 10G/Multi-Gigabit Dual WAN Cloud Managed Pro Router (PR60X)
  • High performance hardware with one 10G/Multi-Gig configurable LAN/WAN port, one 2.5G WAN port, three 2.5G LAN ports and one 10G SFP+ port for long-distance backhaul
  • Dual WAN Ports with failover and load balancing for reliable, seamless connectivity. Optimize network performance and security with up to 32 VLANs
  • Secure remote network access via IPSec Site-to-Site and Client-to-Site VPN, Open VPN and WireGuard, with up to 100 client device connections and 30 VPN tunnels
  • Integrates with NETGEAR Pro WiFi Access Points and select Smart switches as part of NETGEAR’s Enterprise Network Solution, designed for easy SME management
  • NETGEAR Insight for remote network management anytime, from anywhere. Includes 1-year subscription

When the warning remains after changing router modes

If you enabled bridge mode but still see Double NAT, or your router still has a private WAN address, check the topology again before changing more settings:

  1. Make sure bridge mode was enabled on the upstream ISP gateway, not the personal router.
  2. Disconnect other routers or mesh systems temporarily so only the intended primary router remains downstream.
  3. Restart the gateway/ONT and personal router according to the ISP’s instructions.
  4. Compare the personal router’s WAN address with the externally observed public address again.
  5. If the WAN address remains private or in 100.64.0.0/10, ask the ISP whether CGNAT or another managed upstream network is involved.
  6. Confirm that the console or affected device is actually connected to the intended network; restart it if it may be showing a cached status.

IPv4 and IPv6 can also follow different paths. IPv6 can provide a route that does not rely on IPv4 address-sharing NAT, but it is not a guaranteed fix for a console’s NAT warning: the ISP, router, firewall, device, and application all need compatible IPv6 support.

Remote access when you are behind CGNAT

If you need to reach a home service from outside but cannot obtain an inbound-reachable public IPv4 address, ask the ISP about public or static IPv4. Other possibilities include supported IPv6, an outbound VPN connection, or a relay/mesh VPN service that does not require you to open an inbound port. An outbound connection can work through CGNAT because your home device initiates it. That is different from running an inbound VPN server at home, which generally needs an inbound path.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

A consumer privacy VPN usually routes your internet traffic through the VPN provider; it does not automatically make a NAS or home server reachable from the internet. Check the specific remote-access product’s requirements, security model, and any subscription or third-party dependency before relying on it.

When leaving Double NAT in place is reasonable

You do not have to remove Double NAT just because an app reports it. Keeping two routed networks can be intentional for a lab, an isolated IoT network, a business firewall, or an ISP service that requires its gateway to stay in router mode. If your devices work and you do not need inbound hosting or cross-network discovery, changing a stable setup may create more trouble than it solves.

If Double NAT is gone but gaming still lags, investigate the actual symptom separately: Wi-Fi signal and interference, congestion, bufferbloat, game-server distance, equipment load, and service outages can all matter. Removing a NAT layer does not guarantee lower latency or an Open NAT label.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.