Double NAT / VPN / DDNS / ASUS router possible solution, will this work?

funkytwig

Distinguished
Dec 13, 2006
185
5
18,685
Has been fighting with this problem for days (including hours of reading forum posts/goggling).

My main problem is I have a Technicolor TG582n behind a ASUS AC56U. I am trying to get VPN working so was trying to use the ASUS DDNS. This gave the double NAT problem. Using the TG582n (or another ADSL modem) in bridge mode is a problem as UK ISPs use PPPoA, not PPPOE.

It strikes me the problem with double NAT is the DDNS, not the VPN (is this correct). It came to me that if I use the DDNS on the TG582n (connecting it to the AC56U vis the 'internet' RJ45) the problem goes away, is this correct?

My thinking is that between the remote computer and the VPN there must be NAT in several places so NAT is not the problem. The problem is that if the AC56U tried to run DDNS behind the TG582n it has no way of knowing the public IP.

I was thinking of putting the AC56U in the TG582ns DMZ. Maybe I also need some prot forwarding/triggering?

Be good if people can help as this problem is starting to take over my life;). I dont mind getting a replacement for the TG582n but please bear in mind I am in the UK and my ISP only supports PPPoA.

Regards,
Ben
 
DDNS that runs on the router is pretty stupid. It must run on the device that has the actual IP address which in your case would be the first device. It would be nice if you could run it like the pc based ddns that just goes out every once and while and checks if the real ip has changed but it doesn't work that way.

It depends how you are running vpn. You can technically not run router behind router if you like. You would just have to put static routes in your PC telling to go to the VPN routers IP rather than the real gateway. I tend to do that when I want some traffic to go via vpn and other to not. I am not sure you can run that vpn config on all routers I have used dd-wrt for so long I forget what factory ones can do.

 

funkytwig

Distinguished
Dec 13, 2006
185
5
18,685
OK, so if I run DDNS and DHCP on the first device (the ADSL modem/router) and turn off DHCP on the second device (The wireless router). Are you saying have DHCP behind the wireless router (in its LAN), so we have phone line->ADSL Modem->Wireless router->DHCP server? We dont have a PC on all the time in the LAN but do have a Raspberry Pi 2B. We only have a few machines so could set that up as a DHCP server.

Why is having DHCP on the first device (ADSL Modem/router) stupid? Is this not the way most people do it on small networks (i.e. under 10 devices)?

"You can technically not run router behind router if you like", think this is a typo, does not make seance to me?

The VPN server is built into the AC56U. I know what a static route is (I think) in theory but ever used them. Be good if you could give a bit more detail as to the setup, I'me new to this type of networking. Talking in dd-wrt is fine as I will probably be running Merlin (which I believe is a dd-wrt derivative).

Thanks a lot for your help.

Ben
 
You are still making this overly complex and when you run ddns on a router you have little choice. The main device must run as a router not just a modem. You only want a single router and plug all your devices into that one. You can use another device as a dhcp server if you like. It can be a "router" but it work the same as if you were using a server. The end users devices are still connected to the modem/router. The DHCP router/server is pluged in just like a PC. You can do VPN the same way if you want, it is more complex to setup vpn with just a single interface but it can be done.
 

funkytwig

Distinguished
Dec 13, 2006
185
5
18,685
We just got the AC56U so are kind of stuck with it. I know it would be better to get a DSL-AC68U but it is expensive (were no initially even going to upgrade the router). Maybe there is a cheaper option, advice for a mid range ADSL AC router would be good. I was really hoping i could get the AC56U working with a separate ADSL modem;(. Its kind of embarrassing, Ive only just started doing IT for the charity.
 

funkytwig

Distinguished
Dec 13, 2006
185
5
18,685
The other option is to use the AC56U just for its wireless (tun off everything apart from wireless) and get a combined VPN tunnel ADSL router with DDNS (does not have to have wireless) but not sure what to get. Ive really messed up and it would probably have to come out of my pocket.