Network Address Translation is commonly used in IPv4 home networks so many private devices can share a smaller number of public addresses. The router tracks connections and translates between local and external address/port combinations.

NAT is not the same as a firewall

Consumer routers often provide NAT and stateful firewalling together, so the two are casually treated as one feature. Conceptually they are different: NAT rewrites addressing, while a firewall applies traffic policy.

What is double NAT?

Double NAT happens when one NAT router sits behind another. A common example is an ISP gateway routing 192.168.1.x while a personal router behind it routes 192.168.0.x.

Why it can matter

Normal web browsing often works fine. Problems are more likely with inbound port forwarding, peer-to-peer applications, some games/consoles, VPNs, and remote-access services because two translation layers must be considered.

Common fixes

If you want your own router to be the main router, see whether the ISP gateway supports bridge/passthrough mode. If you only need better Wi-Fi or extra Ethernet ports, putting the second device in access-point mode may be simpler. Do not change modes without knowing which device will provide DHCP and firewalling afterward.

NAT is translation; firewall is policy

They often coexist but are not the same. IPv4 NAT rewrites address/port mappings; firewall rules decide what traffic is allowed.

Detect double NAT

If the personal router WAN receives a private IPv4 and clients sit behind another private subnet, an upstream router is likely. This can complicate inbound services, gaming and some VPNs.

Fix based on your goal

Use ISP bridge/passthrough if the personal router should own routing, or access-point mode if the second box only needs to provide Wi-Fi/Ethernet. Avoid DMZ/forward-all hacks without understanding exposure.

How to use this concept on a real network

Map the concept to one packet path: client → local switch/Wi-Fi → default gateway → WAN/ISP → destination. Identify which device performs each function rather than memorizing definitions in isolation. Packet captures, route tables, DHCP leases and router status pages are useful when available.

Common source of confusion

Home routers combine several roles in one box, so people use “router,” “Wi-Fi,” “DNS,” “DHCP” and “internet” interchangeably. Separating the roles makes troubleshooting faster and helps you understand what changes when another router, mesh system or VPN is added.

Connect the concept to packet flow

Start with one client sending one request. The client has a link, an address and a routing table. It decides whether the destination is on-link or must go to a gateway. The local network transports the frame, the router applies routing/firewall/NAT policy as appropriate, and upstream networks carry it toward the destination. DNS can be needed before the first packet if the user supplied a hostname.

Observe instead of guessing

Useful evidence includes the client IP configuration, ARP/neighbor table, routing table, DHCP lease, DNS response, router WAN/LAN status, firewall logs and packet captures where appropriate. You rarely need every tool; choose the observation that tests the current hypothesis.

Home gateways combine roles

A single plastic box can be Ethernet switch, Wi-Fi access point, IPv4 router, IPv6 router, DHCP server, DNS forwarder, NAT device, firewall and VPN endpoint. Understanding which role is failing prevents category errors such as changing Wi-Fi channels to fix a DNS problem.

Topology changes behavior

Add a second router, mesh system, managed switch, VLAN, VPN or ISP gateway and the path changes. Double NAT, overlapping subnets and multiple DHCP servers are topology problems, not mysterious “bad internet.” Draw the path and mark which device owns each role.

Security is part of the model

Isolation and firewall rules can intentionally prevent reachability. A failed connection is not always a fault; it can be policy working correctly. Diagnose from an authorized network segment before disabling security controls.

Addressing evidence to collect

Write the client IP/prefix, default gateway, DHCP server, lease state and router LAN/WAN addresses. Compare networks mathematically instead of matching the first three octets by eye. Overlapping private ranges become especially important with VPNs, second routers and virtual networks.

Do not confuse local and public identity

Private addresses are reusable and scoped to the LAN. NAT/CGNAT can make several devices or even several customers share public addressing. Treat public-IP lookups as network metadata, not proof of an individual person or exact location.

Where the simplified explanation stops

Real networks can include policy routing, IPv6, multiple VLANs, several DNS resolvers, carrier NAT, dynamic routing, tunnels and stateful firewalls. The home-network model in this guide is deliberately practical, not a replacement for the protocol standard or vendor implementation documentation.

Terms that often get mixed together

Addressing, routing, name resolution, switching, wireless access and transport security are related but separate. When a troubleshooting step changes one layer, be explicit about which outcome should change. That discipline makes advanced topics easier later.

Use packet-level evidence when necessary

When basic status pages cannot explain a failure, a packet capture or detailed router log can show whether requests leave, replies return, DNS answers differ, or a firewall resets/drops traffic. Capture only traffic you are authorized to inspect.