Double NATing - setup ASUS RT-AC68U behind Pace 5168N-010 modem

Oct 11, 2018
5
0
20
Want to disable the Pace 5168N-010 handling NAT and have ASUS RT-AC68U do it. Currently double NAT ing

On Pace 5168N-010 the changes required as far as I can see are
1) in Pace modem use ASUS default address of 192.168.1.1 as the "select computer addresss"
OR should it be 192.168.100.100 as specified as current address in Pace
OR should i go to LAN/LAN IP "Address Allocation" from private pool to private fixed
2) Select "All applications DMZ mode"


On ASUS RT-AC68U "WAN - Internet Connection" Tab
1) I belive only the "Basic Config section" if anything need be changed.
2) Only the "Wan connection type" from "Automatic IP" to "Static IP" is the only change I can see.
Now I am confused: Regardless of pool or fixed IP the ASUS only uses a single IP address for all traffic.
Do I need to even change away from Automatic IP or should I set Pace to Private Fixed and set the router to use that address.
 
Solution
I Found the solution below which does NOT quite work in my case but a variation did. When I select the "Choose" button I loose the ability to select ‘forward ALL traffic' (selection disappears with choose button click). But since my computer/router is identified already by its MAC no need to (i think) which allows me to then select "Allow all applications (DMZ mode)".

The simple testing that I did appears to work (usage and windows troubleshooter) just not sure what I can do to adequately test it. Any suggestions appreciated.

If I discover any problems with this configuration I will update this post.

=================================================================================
SOLUTION FROM WEB...
A quick perusal of Wiki on PACE 5168N says to use LAN SUBPORTS instead of bridge mode, but try both see what happens. You have succeeded when you get a public IP on the LAN side.

If this is an ISP-supplied box, sometimes it's locked and won't let u change things.
 
Oct 11, 2018
5
0
20


 
Oct 11, 2018
5
0
20
I Found the solution below which does NOT quite work in my case but a variation did. When I select the "Choose" button I loose the ability to select ‘forward ALL traffic' (selection disappears with choose button click). But since my computer/router is identified already by its MAC no need to (i think) which allows me to then select "Allow all applications (DMZ mode)".

The simple testing that I did appears to work (usage and windows troubleshooter) just not sure what I can do to adequately test it. Any suggestions appreciated.

If I discover any problems with this configuration I will update this post.

=================================================================================
SOLUTION FROM WEB
=================================================================================
----------------------------------------------------

Detfree23

Tutor

Dec 29, 2016 1:32 PM

Re: Is Pace 5268ac capable of bridge or IP passthrough mode?

The answer is YES! I just did it (with ATT support). All steps are done through Ethernet.



Step one: Connect the ATT router..(say ethernet port 1), connected to your WAN Ethernet port on your personal Router.

Step two: Connect an Ethernet cable from your computer to the LAN connection to your router.

Step three: Find the "DHCP IP address" from your WAN interport on your personal router (will likely be 192.168.1.x or the typically the DHCP Gateway Address)- Make note that the ATT Pace 5268AC's default is 192.168.1.254).

Step three .a: Log in, or while logged into your personal router, set the WAN Connection type to Automatic IP or what ever setting the router has that will automatically acquire an IP from the PACE 5268AC modem.

Step four: Go to the PACE FIREWALL page - "Applications/Pinholes and DMZ, and look for section "1". In that area there will be a Cell window where you can type in the known WAN address of your personal router (192.168.1.x).

Step five: Put that IP address in the window and click the button to the right called CHOOSE.

Step six: Scroll down to Options "2" area and at the bottom there is a radio button to ‘forward ALL traffic to your (it says computer, but we know it's your router)’. Enable that button and click on the save button.

Step seven: If you look at the STATUS tab on the ATT FIREWALL Status tab now, you'll see ALL/ALL inbound traffic to be directed to your ROUTER.

Step eight: Turn off your router now.

Step nine: Reboot the ATT PACE 5268AC router and wait until you see the "Service" light come on blinking actively. This will take oh....2 minutes? Once the Service light is on....turn your personal router on

Step ten: After your personal router boots, log into it and you should see the WAN interface with the PUBLIC IP on it.



Note: all ports will be forwarded and open. Make sure your router has only ports open that you want open.
Message 13 of 25
 
Solution
Oct 11, 2018
5
0
20
Had a glitch. Rebooted Modem no problem. ROUTER: Little unsure of order here (after/before re-boot) but started get hangs in setup screens. Then lost connectivity to internet.

In ROUTER "Wan\ Special Requirement from ISP\Host name" I entered a host name.

In MODEM Lan page Now reflects the host name as
Device Interface MAC Address SSID IP Address
XXxxxxx Port 2 14:74:11:52:d9:12 n/a xxx.xx.13.176

Reset up firewall DMZ as before and everything appears to function normaly

ROUTER: Network Map/ Internet Status IP address changed
was: WAN IP: 192.168.100.100
now: WAN IP: xxx.xx.13.176