Guide

Double NAT: port forwarding with an ISP hub and your own router

If you have added a mesh system or your own router behind the hub your provider sent, you probably have two layers of NAT. A port forward on either one alone won’t work. There are three ways to fix it, in order of preference.

Updated · Checked against BT, Sky, Virgin Media and TP-Link documentation, September 2026 · 5 min read

Symptom
Forward looks right, port still closed
Tell‑tale sign
Your router’s WAN IP is 192.168.x.x
Best fix
Modem or bridge mode on the ISP hub
Quick fix
Forward the port on both routers

How to spot double NAT

Open the admin page of the router your devices actually connect to – your mesh app, or your own router – and look at its WAN or Internet IPv4 address.

  • If it is a private address such as 192.168.1.64 or 192.168.0.23, the ISP hub in front of it is doing NAT too. That’s double NAT.
  • If it matches ip.uk.app, there is only one NAT and your problem is elsewhere.
  • If it is in 100.64.0.0–100.127.255.255, that is CGNAT at your provider – a different problem.

Mesh systems are the usual cause. A Deco, Google/Nest Wifi, Eero or Orbi plugged into a BT Smart Hub or Virgin Media Hub runs in router mode by default, so every device sits behind two routers.

Fix 1: put the ISP hub in modem or bridge mode

This removes the hub’s NAT and firewall completely, so your own router receives the public IP address directly. It is the cleanest fix: one NAT, one place to set up port forwards, UPnP works as designed, and games stop reporting a strict NAT type.

  • Virgin Media Hub 5 (cable): has a built‑in modem mode. After switching, your router plugs into the hub and the hub’s own page moves to 192.168.100.1. The full‑fibre Hub 5x doesn’t offer modem mode at the time of writing. See the Virgin Media guide.
  • BT: home Smart Hubs don’t have a simple modem mode. On full fibre (FTTP), the fibre box on the wall (the ONT) is a separate device, and many people replace the Smart Hub with their own router connected to it using PPPoE. On FTTC (copper to the cabinet), you need a separate VDSL modem or a router with one built in. See the BT guide.
  • Sky: hubs don’t offer a modem mode. On full fibre you can connect your own router to the ONT, which needs the router to support Sky’s login method (DHCP option 61). See the Sky guide.
  • Other providers: look for “modem mode”, “bridge mode” or “use your own router” in the provider’s help pages.

Watch out

In modem mode the ISP hub no longer protects your network, so make sure your own router’s firewall is on. If you have landline calls over the hub (BT Digital Voice, Sky Talk), check that they still work before relying on the new set‑up.

Fix 2: put your mesh or router in access‑point mode

If you can’t bypass the ISP hub, do the opposite: let the hub be the only router, and switch the mesh system into access point (sometimes called bridge) mode. Your devices then get addresses from the hub, there is one NAT, and you set port forwards on the hub.

You lose the mesh system’s own router features – its parental controls, its port forwarding, sometimes its app features – but many people never use them anyway. On a TP‑Link Deco this is under More → Advanced → Operation Mode in the app.

Fix 3: forward the port on both routers

If neither box can change mode, chain two forwards:

  1. On the inner router (the one your server connects to), forward the port to the server’s LAN address, for example TCP 443 → 192.168.68.20.
  2. On the outer ISP hub, forward the same port to the inner router’s WAN address, for example TCP 443 → 192.168.1.64.
  3. Give the inner router a fixed address on the hub’s network (a DHCP reservation), or the second forward will break the next time it gets a new address.

Some ISP hubs have a DMZ setting that sends every unrequested incoming connection to one device. Pointing the hub’s DMZ at your own router is a shortcut for “forward everything”, and is reasonable here because your router’s firewall still decides what gets through. Don’t point a DMZ at a server or PC.

Tip

Double NAT also breaks automatic port mapping (UPnP / NAT‑PMP) for apps such as Plex. After fixing it, turn off any manual forwards the app no longer needs.

What about IPv6?

IPv6 doesn’t use NAT, but a second router can still get in the way if it doesn’t receive a delegated IPv6 range from the hub. In that case devices behind it get no IPv6 at all. Modem mode fixes that too. If you rely on IPv6 for incoming connections, check that your server has a global IPv6 address (one starting with 2) and that you allowed the port through the IPv6 firewall on whichever box is the router.

Check the result

  1. Does the name point home? Look up home.yourname.uk.app with the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one.
  2. Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
  3. Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
  4. Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.

A name for your next idea

Give your website, home server or next project a memorable address: yourname.uk.app. Choose your name and check availability before registering.

Find your name

Questions people ask

Is double NAT bad for normal browsing?

Not noticeably. It mainly matters for incoming connections: servers, some games, and video calls that prefer direct connections.

Can I just use UPnP on both routers?

UPnP on the inner router only opens its own NAT. The outer hub never hears about it, so the port stays closed from the internet.

Does modem mode change my public IP address?

It may, because a different device now requests the address from your provider. Dynamic DNS takes care of that.

Sources and further reading

We check each guide against the vendor’s own documentation and support forums. If something has changed on your firmware, tell us.

Partners