Use safely: Follow these steps only for a router or network you own or are authorised to manage. Never send Router Portal a router password, Wi-Fi key, MAC address, serial number or private screenshot.
Evidence and scopeSOURCE-BACKED · CHECK DATE
Sources3 official references
ScopeModel/OS/network dependent
CredentialsNever universal
ReviewRecheck after UI changes
Quick answer: Double NAT occurs when a personal router is routed behind another gateway instead of using a documented bridge, passthrough or access-point design.
What this page covers
Identify the WAN address on the downstream router and the upstream topology before changing mode.
Step-by-step workflow
- Record the downstream router WAN and LAN ranges privately.
- Check whether its WAN address is private or otherwise upstream-managed.
- Find the upstream gateway model and supported topology.
- Choose bridge/IP passthrough/AP mode only from current documentation.
Decision table
| Check | What it tells you | Safe next action |
|---|---|---|
| Downstream WAN is private | Another routing layer is present | Map the upstream gateway |
| Port forwarding fails | Rules may need a second layer or another design | Prefer VPN/relay where suitable |
| Voice/TV breaks after bridge | Provider features may depend on gateway routing | Restore or consult the provider |
Limits and verification
Double NAT is not automatically unsafe or broken. The correct architecture depends on ISP features, IPv6, support and the service being used.
Official sources
- IETF RFC 7857 — Updates to NAT terminology (NAT terminology)
- CISA — Securing Home Network Devices (home-network safety guidance)
- Xfinity — Enable bridge mode (provider-specific bridge behavior)
Related Router Portal guides
Router login troubleshooting · Router security guide
Editorial note: This pilot page is written for one distinct question. Firmware, operating-system menus, ISP policies and regional radio rules can change, so confirm the source and exact device before applying a setting.