<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[Double NAT issue on Google Wifi - Why?]]></title><description><![CDATA[<p dir="auto">My Google Wifi (GWF) works much better when connected to the modem directly (as a primary router) than connected behind the pfsense. So I contacted Google support, they told me that it's a issue often reported when using a double NAT... Ok, let's bridge the GWF then...  Nope! otherwise the mesh doesn't work (it's a feature).<br />
The question is WHY? of course the Google tech couldn't say.<br />
I see a lot of TCP:FA, TCP:PA and TCP:RA from the Wifi to Internet for some reason, I guess whatever cause that is what makes the GWF sucks in double NAT.<br />
The setup is:<br />
internet &lt;-&gt; modem &lt;-&gt; pfsense &lt;-&gt; DMZ 192.168.1.0/24 &lt;-&gt; GF &lt;-&gt; LAN 192.168.2.0/24<br />
The PFSense has 192.168.1.1 on the DMZ, and GF has 192.168.1.2<br />
The GF has 192.168.2.1 on the LAN, the clients from 2.10 to 2.254<br />
The PfSense has a static route 192.168.2.0/24 to 192.168.1.2 (it works without but who knows)</p>
<p dir="auto">So Why?</p>
<p dir="auto">eg FW logs: [DMZ is label LAN... I know :(  ]<br />
Jun 2 19:04:01	LAN	  192.168.1.2:43192 172.217.9.195:443	        TCP:PA<br />
Jun 2 19:04:01	LAN	  192.168.2.234:46972 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:04:00	LAN	  192.168.2.234:46972 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:04:00	LAN	  192.168.2.234:46976 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:03:59	LAN	  192.168.2.234:46970 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:03:03	LAN	  192.168.2.234:46976 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:03:03	LAN	  192.168.2.234:46972 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:03:01	LAN	  192.168.2.234:46970 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:02:07	LAN	  192.168.2.234:46972 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:02:07	LAN	  192.168.2.234:46976 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:02:07	LAN	  192.168.1.2:46970 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:02:02	LAN	  192.168.1.2:46970 172.217.164.138:443	TCP:FA<br />
Jun 2 19:02:02	LAN	  192.168.1.2:46970 172.217.164.138:443	TCP:FA<br />
Jun 2 19:02:02	LAN	  192.168.1.2:46970 172.217.164.138:443	TCP:PA<br />
Jun 2 19:02:02	LAN	  192.168.2.234:46972 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:02:02	LAN	  192.168.2.234:46976 172.217.164.138:443	TCP:FPA<br />
Jun 2 19:01:30	LAN	  192.168.2.125:34099 172.217.7.202:443	TCP:R<br />
Jun 2 19:01:29	LAN	  192.168.2.125:34098 172.217.7.202:443	TCP:R</p>
]]></description><link>https://forum.netgate.com/topic/154142/double-nat-issue-on-google-wifi-why</link><generator>RSS for Node</generator><lastBuildDate>Sun, 12 Apr 2026 12:35:01 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/154142.rss" rel="self" type="application/rss+xml"/><pubDate>Tue, 02 Jun 2020 23:07:44 GMT</pubDate><ttl>60</ttl></channel></rss>