<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0"><channel><title><![CDATA[UPnP double NAT working but not multiwan failover]]></title><description><![CDATA[<p dir="auto">Inspired by my success in having all games getting Open NAT, using 22.05, I decided to go on to test towards WAN2 (failover) which is on a consumer LTE router.</p>
<p dir="auto">This router does not support bridging so I am stuck with double NAT, or rather a DMZ setup. BUT, the only way was to go back to port forward of 3074 like before.</p>
<p dir="auto">After a bit of googling I found something about minupnp not working with Private IP on the external interface...<br />
Unexpectedly, my TP-Link archer actually allows me to set any IP on the internal interface, not just private IP ranges.</p>
<p dir="auto">So, I simply picked a random IP address that I knew belonged to the ISP I'm using, and... <strong>now it works!!</strong><br />
So this might be a tip for anyone sitting with an ISP router or on a FWA connection that doesn't support bridging. At least test it to see if the router allows it... I just realized that I never did any testing where I had turned off blocking of private and loopback addresses...</p>
<p dir="auto">The thing that still doesn't work however, is my scenario with failover...</p>
<p dir="auto">For regular port forwards I can set up two NAT rules for each port that I have forwarded, one for WAN and another for WAN2. In other settings I can simply use my Gateway Group which I created, like for DynamicDNS.</p>
<p dir="auto">The UPnP settings however does not give me the option of using a Gateway Group, and I obviously can't have two different settings for WAN and WAN2. Which means that in case of a failover scenario, UPnP will not work... <img src="https://forum.netgate.com/assets/plugins/nodebb-plugin-emoji/emoji/android/1f622.png?v=d0a5ddc94ac" class="not-responsive emoji emoji-android emoji--cry" style="height:23px;width:auto;vertical-align:middle" title=":cry:" alt="😢" /></p>
]]></description><link>https://forum.netgate.com/topic/177262/upnp-double-nat-working-but-not-multiwan-failover</link><generator>RSS for Node</generator><lastBuildDate>Thu, 05 Mar 2026 14:59:56 GMT</lastBuildDate><atom:link href="https://forum.netgate.com/topic/177262.rss" rel="self" type="application/rss+xml"/><pubDate>Sat, 21 Jan 2023 15:07:36 GMT</pubDate><ttl>60</ttl><item><title><![CDATA[Reply to UPnP double NAT working but not multiwan failover on Mon, 23 Jan 2023 19:14:41 GMT]]></title><description><![CDATA[<p dir="auto">Although UPnP works when using something other than a private IP on WAN2, it does break the Dynamic DNS update.<br />
Normally pfSense will use http://checkip.dyndns.org to get the IP address IF it detects a Private IP on the monitored port. If not, it will assume it is the correct IP which means the DDNS will be incorrect.</p>
<p dir="auto">As there doesn't seem to be a way to force it to use that checkup service so I guess it's back to using port forwards for MW3 on the WAN2 port ...</p>
]]></description><link>https://forum.netgate.com/post/1081957</link><guid isPermaLink="true">https://forum.netgate.com/post/1081957</guid><dc:creator><![CDATA[Gblenn]]></dc:creator><pubDate>Mon, 23 Jan 2023 19:14:41 GMT</pubDate></item></channel></rss>