1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.
Dismiss Notice

Welcome To SNBForums

SNBForums is a community for anyone who wants to learn about or discuss the latest in wireless routers, network storage and the ins and outs of building and maintaining a small network.

If you'd like to post a question, simply register and have at it!

While you're at it, please check out SmallNetBuilder for product reviews and our famous Router Charts, Ranker and plenty more!

Double NAT, VPN Client, Firewall ...

Discussion in 'Asuswrt-Merlin' started by netguru, Feb 12, 2019.

  1. netguru

    netguru Regular Contributor

    Joined:
    Dec 24, 2015
    Messages:
    60
    Hi there,

    i am running since years Merlin behind a Fritzbox Router perfectly.
    Fritzbox has its own IP Range and DHCP and a static Route to Merlin.
    On Merlin there a running a few clients, some are in VPN Client Mode, some not. To connect TO the VPN Clients i use the VPN IP and connects to them with open Ports on firewall. Works perfectly.

    My Problem ist now, that i have a client on the ASUS Merlin machine, which ist NOT in VPN.
    So i have to connect the client via normal ISP IP via the Fritzbox Router.

    The problem ist, that the static route from fritzbox to asus does not work because of the NAT working on the asus merlin one ...
    Ist there any disadvantage turning off NAT on the asus router? Losing firewall could be important? VPN provider uses firewall also ... So i have to open the ports on asus AND provider. Problem turning NAT off?

    Thx a lot
     
    Last edited: Feb 12, 2019
  2. Zonkd

    Zonkd Senior Member

    Joined:
    Oct 19, 2014
    Messages:
    472
    Is there any reason you can’t bridge the fritzbox and make Asus main router without double NAT?
     
  3. netguru

    netguru Regular Contributor

    Joined:
    Dec 24, 2015
    Messages:
    60
    Yes, fritzbox deals also as telephone station and has several clients istself connected via cable ...
    if turning off NAT is a problem, then it is no big problem, its only one client and i have then to test if it works when it is also a vpn client (connection then works, but streaming television is not so good)
     
  4. guho

    guho Occasional Visitor

    Joined:
    Apr 26, 2012
    Messages:
    44
    How about connecting Asus Merlin router to Fritzbox using the LAN port? Fritz can be the DHCP server for the entire network. VPN clients will still work if you define a default route (0.0.0.0) on Merlin so all Internet traffic routes to the Fritz.

    I have this kind of setup. My main router is Verizon @ 192.168.0.1 whereas my Merlin AC86u is on 192.168.0.2 connected via LAN port, in router mode. With some customizing, I have been able to get guest networks, VPN server (PPTP/OpenVPN/IPSEC ikev2) and some other things to work. Needless to say the firewall on the Merlin is off. I think this kind of setup has a lot less overhead than double-NAT. On the main router 192.168.0.1 you need static routes for any VPN IP ranges to 192.168.0.2.