What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Disabling NAT (as "secondary" router)

CalB

Occasional Visitor
I have 2 Asus routers, both running Merlin wrt:
- an RT-AX86U - the ISP facing router, 192.168.a.0/24 local plan
-an older RT-AC87U (wan IP on 192.168.a.0/24 lan, and it's local plan is 192.168.b.0/24).
I am trying to use the older router as a normal router,... as in route between different networks.
The main router does have a route pointing back to 192.168.b.0/24, yet, as soon as I disable NAT, everything but ping stops working. I can ping Google and stuff without any issues, which is weird.

This is a capture of a random stream, but all of them are like this (192.168.20.3 is 192.168.b.0/24). There is obviously some traffic going back and forth, so the routing should be fine. From a MAC perspective all lookig good as well
Capture from the laptop behind the 2nd router
1741727872846.png


capture from the ISP facing router, same stream

1741727956366.png


Ping looks very weird as well (capture is from the ISP-facing router. For some reason tcpdump on the router does not capture the destination MAC, which makes it kinda hard to check if both repeating packets go toward the same interface.
1741728627980.png


Can anyone help me out and point to the obvious thing I'm overlooking?
 
I can't think why this wouldn't work. I had the same setup a few years ago with my RT-AX86U and RT-AC68U and it "just works".

I presume your RT-AC87U is minimally configured, e.g. no AiProtection, No QoS, no VPN, standard WAN DHCP, etc.? How about the main router, AiProtection on that?
 
I can't think why this wouldn't work. I had the same setup a few years ago with my RT-AX86U and RT-AC68U and it "just works".

I presume your RT-AC87U is minimally configured, e.g. no AiProtection, No QoS, no VPN, standard WAN DHCP, etc.? How about the main router, AiProtection on that?
Correct, no AI protection, no QoS on either of them, no skynet. VPN & Firewall only on the ISP-facing one
I do have DHCP on both, but I don't see how that would impact things, each has its own lan (I did try with static IP as well)
As for the WAN, nothing fancy on this one
1741732716031.png

That's my Adguard DNS, but I tried without (and pointing the main router to Google for DNS as well) and nothing. Besides what I can tell from the packet captures, the client sitting behind the 2nd router gets the DNS resolved.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top