What's new

NAT disable on a 4G-AC53U LTE modem

  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Firewall and NAT are two different things. The firewall can be disabled in the Firewall tab :rolleyes:, but it not advisable to do so. NAT cannot be turned off when the WAN Interface is Mobile Broadband (it would make no sense to have that option).
 
Firewall and NAT are two different things. The firewall can be disabled in the Firewall tab :rolleyes:, but it not advisable to do so. NAT cannot be turned off when the WAN Interface is Mobile Broadband (it would make no sense to have that option).
Thank you Colin. I know that the general meaning of the words differ but as far as I remember small home modems and gateways, when they came with "firewall" functionality back in the days it was mostly a NAT functionality, or am I wrong? The thing is that it will sit a Ubiquiti UniFi Security Gateway just after the ASUS with all the firewall functionality etc so I was hoping to be able to configure the ASUS basically as an 4G Internet gateway and avoid "double-NAT" problems. I want to be able to run Site-to-Site VPN with Auto IPsec VTI which cannot be done thru NAT.

So the question remains, does the disabling of firewall remove NAT in this case?
 
Thank you Colin. I know that the general meaning of the words differ but as far as I remember small home modems and gateways, when they came with "firewall" functionality back in the days it was mostly a NAT functionality, or am I wrong?
You are correct in that the "firewall" and NAT are both performed by the kernel's netfilter code.

The thing is that it will sit a Ubiquiti UniFi Security Gateway just after the ASUS with all the firewall functionality etc so I was hoping to be able to configure the ASUS basically as an 4G Internet gateway and avoid "double-NAT" problems. I want to be able to run Site-to-Site VPN with Auto IPsec VTI which cannot be done thru NAT.

So the question remains, does the disabling of firewall remove NAT in this case?
I don't believe that's the case. I don't have that device but it looks to be mostly the same as their non-LTE routers. On those devices disabling the firewall doesn't effect the NAT operation.

Maybe use port forwarding to the Ubiquiti? The router has NAT passthrough for IPSec but I don't think that's applicable with your setup.
EDIT: Or put the Ubiquiti in the Asus' DMZ, although you'd still have NAT.


The manual doesn't indicate that it can be configured in a "modem-only" mode which is what you're asking for. If that were an option I'd expect to see it under Administration > Operation Mode.
 
Last edited:
Or put the Ubiquiti in the Asus' DMZ, although you'd still have NAT.
Here is the screen for creating a virtual DMZ. I am not sure what they meen by "Some applications require special handler against NAT. These special handlers are disabled in default."
 

Attachments

  • dmz.PNG
    dmz.PNG
    124.7 KB · Views: 481
They're probably referring to things like FTP which require special helpers to work through NAT.
 

Latest threads

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Top