NAT Loopback in subnetwork
NAT Loopback in subnetwork
Hi,
I have a TPLink VDSL Modem (TD-W9960 v1 1.2.0 0.8.0 v009d.0 Build 201016 Rel.78709n) and TPLink Access Point (Archer c80 v1 1.5.7 Build 210308 Rel.60033n(4555)) on my network.
A LAN cable (192.168.1.2) reaches the AP working in router mode through its WAN port. They both have Wireless enabled, but I treat the AP as my secure home network.
Modem directs the traffic on all ports to AP with NAT-dmz forwarding. It also uses tplink ddns service to bind subdomain.tplinkdns.com to my public IP.
The AP has some NAT port forwarding settings for various services including http on port 80.
When I connect to the modem's wifi, I can access all ports via the ddns domain. (NAT loopback works even I am on the local network)
But when I connect to the AP's wifi, I cannot access anything on my local network neither using the subdomain nor my public IP.
NAT boost is not activated on neither devices as I read that it disables the NAT loopback.
Can you please help me to figure out how can I enable access to my local network servers via the domain.
Best
- Copy Link
- Subscribe
- Bookmark
- Report Inappropriate Content
Before you start I would suggest to backup the TD-W9960 and C80 configuration just in case.
You will need these credentials for configuring C80 PPPoE session:
Delete the old Internet connection in TD-W9960 (PPPoE):
Add new Internet connection of type Bridge (click Save at the end):
Settings in C80:
After configuring the PPPoE in C80 click CONNECT (if available) and you should be able to establish the PPPoE session from C80.
You'll have an internet connection with a single NAT in C80 and since Kevin already confirmed the NAT loopback (hairpinning) implemented in C80 FW this configuration should resolve your issue.
- Copy Link
- Report Inappropriate Content
- Copy Link
- Report Inappropriate Content
There are various reasons for that @terziyski. I would rather keep c80 as my router. Double NAT is not a serious problem, but we need to enable NAT Loopback (hairpinning) on it somehow.
- Copy Link
- Report Inappropriate Content
OK, but you should know that NAT loopback/hairpinning is a feature that is FW embedded.
If it's not implemented in the C80 current FW release (which can be confirmed by TP-Link), then you'll have to wait for a release with that feature added.
- Copy Link
- Report Inappropriate Content
C80 supports NAT Loopback (hairpinning) by default.
May I know who is your ISP? Is it possible to configure the W9960 into bridge mode, then configure the internet settings on the C80 to confirm if there is still an issue?
- Copy Link
- Report Inappropriate Content
Hi @Kevin_Z ,
Sounds interesting.
My ISP is TurkNet. I can manually configure the dsl settings, but how can I set the modem into bridge mode?
- Copy Link
- Report Inappropriate Content
Before you start I would suggest to backup the TD-W9960 and C80 configuration just in case.
You will need these credentials for configuring C80 PPPoE session:
Delete the old Internet connection in TD-W9960 (PPPoE):
Add new Internet connection of type Bridge (click Save at the end):
Settings in C80:
After configuring the PPPoE in C80 click CONNECT (if available) and you should be able to establish the PPPoE session from C80.
You'll have an internet connection with a single NAT in C80 and since Kevin already confirmed the NAT loopback (hairpinning) implemented in C80 FW this configuration should resolve your issue.
- Copy Link
- Report Inappropriate Content
Thanks @terziyski!
Used this option and NAT loopback on c80 works now.
Wish nested NAT loopback would work as well, as I am not able to use W9960's WiFi coverage on other end of the home now as it does not have Internet. Can I somehow make it repeat c80's signal while it still stays in the Bridge mode?
Another question: I cannot use 192.168.1.1 to access W9960's interface yet through the other Wifi from c80. Is there a way to make this possible?
- Copy Link
- Report Inappropriate Content
No, you can't use the W9960 wireless in bridged mode for internet access or WDS. That's why I suggested C80 in AP mode in the first place.
Accessing W9960's WebGUI should be possible. You can try by adding a static route in C80 to the LAN IP address of W9960 via C80 WAN interface:
assuming 192.168.1.1 is the W9960 LAN IP address, and 192.168.0.1 is the C80 LAN IP address.
If above doesn't work try to connect your PC by ethernet cable to W9960's LAN port (Set static IP address 192.168.1.3, mask 255.255.255.0, gw 192.168.1.1 on your PC LAN adapter/disconnect from wi-fi if any) - then browse 192.168.1.1 (W9960 login page).
- Copy Link
- Report Inappropriate Content
Good to know changing the W9960 to bridge mode works, while there is no internet anymore on the 9960. To address the issue and try to fix it, we would like to have a specialist look into this further via email. Please check your mailbox later, and let us know if the issue is resolved.
- Copy Link
- Report Inappropriate Content
Hi @terziyski !
Thanks for your help. Your assumptions regarding the IP addresses of both devices on their respective networks were true.
But adding new routing entry with that information results this error:
When I check with subnet 255.255.255.255, as below:
I get this error which I don't understand its meaning:
- Copy Link
- Report Inappropriate Content
Information
Helpful: 0
Views: 4914
Replies: 12
Voters 0
No one has voted for it yet.