How to spot double NAT
Open the admin page of the router your devices actually connect to – your mesh app, or your own router – and look at its WAN or Internet IPv4 address.
- If it is a private address such as
192.168.1.64or192.168.0.23, the ISP hub in front of it is doing NAT too. That’s double NAT. - If it matches ip.uk.app, there is only one NAT and your problem is elsewhere.
- If it is in
100.64.0.0–100.127.255.255, that is CGNAT at your provider – a different problem.
Mesh systems are the usual cause. A Deco, Google/Nest Wifi, Eero or Orbi plugged into a BT Smart Hub or Virgin Media Hub runs in router mode by default, so every device sits behind two routers.
Fix 1: put the ISP hub in modem or bridge mode
This removes the hub’s NAT and firewall completely, so your own router receives the public IP address directly. It is the cleanest fix: one NAT, one place to set up port forwards, UPnP works as designed, and games stop reporting a strict NAT type.
- Virgin Media Hub 5 (cable): has a built‑in modem mode. After switching, your router plugs into the hub and the hub’s own page moves to
192.168.100.1. The full‑fibre Hub 5x doesn’t offer modem mode at the time of writing. See the Virgin Media guide. - BT: home Smart Hubs don’t have a simple modem mode. On full fibre (FTTP), the fibre box on the wall (the ONT) is a separate device, and many people replace the Smart Hub with their own router connected to it using PPPoE. On FTTC (copper to the cabinet), you need a separate VDSL modem or a router with one built in. See the BT guide.
- Sky: hubs don’t offer a modem mode. On full fibre you can connect your own router to the ONT, which needs the router to support Sky’s login method (DHCP option 61). See the Sky guide.
- Other providers: look for “modem mode”, “bridge mode” or “use your own router” in the provider’s help pages.
Watch out
In modem mode the ISP hub no longer protects your network, so make sure your own router’s firewall is on. If you have landline calls over the hub (BT Digital Voice, Sky Talk), check that they still work before relying on the new set‑up.
Fix 2: put your mesh or router in access‑point mode
If you can’t bypass the ISP hub, do the opposite: let the hub be the only router, and switch the mesh system into access point (sometimes called bridge) mode. Your devices then get addresses from the hub, there is one NAT, and you set port forwards on the hub.
You lose the mesh system’s own router features – its parental controls, its port forwarding, sometimes its app features – but many people never use them anyway. On a TP‑Link Deco this is under More → Advanced → Operation Mode in the app.
Fix 3: forward the port on both routers
If neither box can change mode, chain two forwards:
- On the inner router (the one your server connects to), forward the port to the server’s LAN address, for example TCP 443 →
192.168.68.20. - On the outer ISP hub, forward the same port to the inner router’s WAN address, for example TCP 443 →
192.168.1.64. - Give the inner router a fixed address on the hub’s network (a DHCP reservation), or the second forward will break the next time it gets a new address.
Some ISP hubs have a DMZ setting that sends every unrequested incoming connection to one device. Pointing the hub’s DMZ at your own router is a shortcut for “forward everything”, and is reasonable here because your router’s firewall still decides what gets through. Don’t point a DMZ at a server or PC.
Tip
Double NAT also breaks automatic port mapping (UPnP / NAT‑PMP) for apps such as Plex. After fixing it, turn off any manual forwards the app no longer needs.
What about IPv6?
IPv6 doesn’t use NAT, but a second router can still get in the way if it doesn’t receive a delegated IPv6 range from the hub. In that case devices behind it get no IPv6 at all. Modem mode fixes that too. If you rely on IPv6 for incoming connections, check that your server has a global IPv6 address (one starting with 2) and that you allowed the port through the IPv6 firewall on whichever box is the router.
Check the result
- Does the name point home? Look up
home.yourname.uk.appwith the DNS lookup and compare the A record with the address on ip.uk.app. After a change, the propagation checker shows which resolvers still have the old one. - Is the port open from the internet? Run the open port checker against port 443. “Open” means your router forwards it and something answers. “Closed” or “timed out” means the forward, the device’s own firewall or CGNAT is in the way.
- Is the certificate right? The SSL checker shows whether the certificate covers the exact name, who issued it and when it expires.
- Test from outside for real. Turn Wi‑Fi off on your phone and open the address over mobile data. Testing from inside your own network can give misleading results.