What's new

Double NAT, VPN Client, Firewall ...

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

netguru

Regular Contributor
Hi there,

i am running since years Merlin behind a Fritzbox Router perfectly.
Fritzbox has its own IP Range and DHCP and a static Route to Merlin.
On Merlin there a running a few clients, some are in VPN Client Mode, some not. To connect TO the VPN Clients i use the VPN IP and connects to them with open Ports on firewall. Works perfectly.

My Problem ist now, that i have a client on the ASUS Merlin machine, which ist NOT in VPN.
So i have to connect the client via normal ISP IP via the Fritzbox Router.

The problem ist, that the static route from fritzbox to asus does not work because of the NAT working on the asus merlin one ...
Ist there any disadvantage turning off NAT on the asus router? Losing firewall could be important? VPN provider uses firewall also ... So i have to open the ports on asus AND provider. Problem turning NAT off?

Thx a lot
 
Last edited:
Is there any reason you can’t bridge the fritzbox and make Asus main router without double NAT?
 
Yes, fritzbox deals also as telephone station and has several clients istself connected via cable ...
if turning off NAT is a problem, then it is no big problem, its only one client and i have then to test if it works when it is also a vpn client (connection then works, but streaming television is not so good)
 
How about connecting Asus Merlin router to Fritzbox using the LAN port? Fritz can be the DHCP server for the entire network. VPN clients will still work if you define a default route (0.0.0.0) on Merlin so all Internet traffic routes to the Fritz.

I have this kind of setup. My main router is Verizon @ 192.168.0.1 whereas my Merlin AC86u is on 192.168.0.2 connected via LAN port, in router mode. With some customizing, I have been able to get guest networks, VPN server (PPTP/OpenVPN/IPSEC ikev2) and some other things to work. Needless to say the firewall on the Merlin is off. I think this kind of setup has a lot less overhead than double-NAT. On the main router 192.168.0.1 you need static routes for any VPN IP ranges to 192.168.0.2.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top