Get One Month of Starlink FreeSPECIAL OFFER: GET A FREE MONTH OF STARLINK >
Connected network ports on a home router

Starlink Double NAT: How to Diagnose It and Pick the Right Fix

Troubleshooting & Fixes

Back to Troubleshooting & Fixes
Independent guide: Starlink Tips is not part of Starlink. Hardware, software, plan features and network behavior can change, so check the instructions for your exact kit and router before changing settings.

Claim Your Free Month

Order through my referral link and activate your service. Your second month of Starlink service will be free. Current terms are shown at checkout.

What double NAT means

Network address translation (NAT) lets a router share one internet connection with several devices on a private home network. Double NAT means two routers are both performing that job.

A common Starlink layout looks like this:

Starlink dish -> Starlink router -> third-party router -> phones, computers and smart-home devices

The Starlink router creates one private network, then the second router creates another private network inside it. Normal web browsing may still work, but the extra boundary can interfere with online games, VPNs, device discovery, remote access and applications that expect a direct path.

Double NAT is not automatically a fault. It can be deliberate when you need two separately managed networks. The problem is usually that a second router was added without deciding which device should manage the home network.

Symptoms that suggest double NAT

Look for a pattern rather than relying on one warning from an app:

  • A console reports a strict or moderate NAT type after you add a second router.
  • Devices on one side of the setup cannot discover printers, cameras, media servers or smart-home equipment on the other side.
  • A VPN connects unreliably, or inbound connections work only when one router is removed.
  • Port forwarding works on the second router but not from the internet.
  • A router's WAN or Internet address is a private address assigned by another router.
  • The Starlink connection looks healthy in the Starlink app, but the network behind your own router has the problem.

A slow connection by itself does not prove double NAT. Wi-Fi interference, obstructions, congestion, a busy household or a device problem can produce similar symptoms.

First, draw your actual network

Before changing settings, write down the physical path:

  1. Identify the Starlink kit and whether Ethernet is built into the router or power supply, or requires an adapter.
  2. Find every device that has a WAN, Internet, Router or Gateway role.
  3. Mark whether each extra device is configured as a router, access point, bridge, mesh node or switch.
  4. Note which device provides the Wi-Fi network your phone and other devices actually use.

The important question is not how many boxes you own. It is how many boxes are routing traffic between your devices and Starlink.

Check the second router's WAN address

Connect to the administration page or app for the third-party router and find its WAN, Internet or external IPv4 address.

If that address is in a private range such as 192.168.x.x, 10.x.x.x or 172.16.x.x through 172.31.x.x, the router is probably receiving an address from another router upstream. That is strong evidence of local double NAT when the upstream device is the Starlink router.

Some routers label the address as WAN IP, Internet IP, IPv4 address or DHCP lease. Do not confuse it with the LAN address that your own router gives to your laptop or phone.

If the WAN address is in 100.64.0.0 through 100.127.255.255, that is commonly associated with carrier-grade NAT. It may indicate an additional translation layer at the provider rather than a second router in your home.

Use the result as a clue, not a guarantee. Router menus and Starlink kit behavior vary.

The three sensible ways to fix it

Option 1: Keep the Starlink router as the main router

Choose this when you want the simplest Starlink-managed setup and do not need advanced routing features on the second device.

  1. Change the third-party router to Access Point, Bridge, AP mode or the equivalent setting.
  2. Follow that router manufacturer's instructions for the correct cable and port. Some access-point modes use the LAN port rather than the WAN port.
  3. Leave DHCP and routing enabled on the Starlink router unless the access-point instructions say otherwise.
  4. Give the access point a different management address if the manufacturer requires one.
  5. Reconnect your devices to the access point and confirm that they receive addresses from the Starlink-managed network.

This removes the second routing layer while keeping the Starlink router responsible for addresses, firewalling and the primary network.

Not every router uses the same labels. Do not guess between router mode and access-point mode; use the model's current documentation.

Option 2: Let your own router manage the home network

Choose this when you need your own router's firewall, VPN, quality-of-service, parental-control or more advanced network features.

  1. Confirm that your Starlink kit supports a wired connection to third-party equipment. Depending on the kit, you may need a Starlink Ethernet Adapter or may connect through Ethernet on the power supply.
  2. Connect the Starlink Ethernet path to the WAN port of your own router.
  3. Enable Bypass Mode on the Starlink router when your kit and setup support it.
  4. Configure your own router's WAN interface to obtain an address automatically through DHCP unless its manufacturer or Starlink instructs otherwise.
  5. Configure Wi-Fi, DHCP, firewall rules and device reservations on your own router.
  6. Reconnect your devices to the new router network and test before removing the old configuration.

Starlink's current third-party-router guidance says the exact cable path and bypass requirement depend on the kit. When bypass mode is active, Starlink says the built-in router Wi-Fi is disabled, so your own router must provide the working Wi-Fi network.

Keep a copy of your old router settings before switching. Do not factory-reset the Starlink router as a first troubleshooting step.

Option 3: Keep two routed networks on purpose

There are legitimate reasons to keep two routers, such as separating a work network from a personal network or placing an untrusted device group behind its own firewall. In that case, double NAT is a design trade-off rather than an accidental fault.

Document which router owns each network, avoid overlapping private address ranges, and expect that:

  • Port forwarding may need a rule on both routers.
  • Devices on the two networks may not discover each other automatically.
  • UPnP and console NAT detection may be unreliable.
  • Troubleshooting becomes harder because each router has its own DHCP, firewall and logs.
  • Some VPN and remote-access tools may need extra configuration.

For a normal home network, an access point or a single main router is usually easier to operate.

Double NAT is not the same as CGNAT

This distinction matters:

  • Double NAT: two routing layers exist in your home, often because the Starlink router and a second router are both in router mode.
  • CGNAT: the provider translates traffic upstream before it reaches the wider internet. You may still be behind CGNAT even after you correctly use bypass mode or a single router.
  • IPv6: IPv6 addressing and firewall behavior are separate from the IPv4 NAT check. Do not disable a firewall just to make an address appear reachable.

If your third-party router has a single WAN connection and its address is still in a provider-shared range after you remove the local second router, bypass mode may have fixed double NAT without creating a public IPv4 address. That is expected. Use a private mesh VPN or an authenticated outbound tunnel for remote access when appropriate; do not expose a router, camera or NAS administration page directly to the internet.

Test after the change

Use a short, repeatable test instead of changing several settings at once:

  1. Check that the Starlink app reports the system online.
  2. Check that the main router or access point has the expected WAN or management address.
  3. Confirm that a phone and laptop receive addresses from the intended DHCP server.
  4. Open a few ordinary websites.
  5. Test one local task, such as printing or reaching a home media device.
  6. Retest the original symptom from the affected device.
  7. If the issue involved remote access, test from a genuinely separate connection with Wi-Fi disabled.
  8. Record the working topology before making another change.

If the problem remains after there is only one local router, stop changing NAT settings. Check Wi-Fi signal, cable seating, device firewall rules, obstructions, congestion and the application's own service status.

Safety checklist

  • Export or photograph router settings before changing modes.
  • Do not disable the firewall to solve a NAT warning.
  • Do not publish router, camera, NAS or smart-home administration pages without a clear security design.
  • Use unique administrator and Wi-Fi passwords.
  • Keep router and device software current.
  • Change one setting at a time and keep a note of the previous value.
  • If a configuration leaves you offline, return to the last known working topology before trying a new design.

Bottom line

When Starlink works but a second router causes strict NAT, broken device discovery or unreliable VPN behavior, first confirm whether both devices are routing. Then choose one clear owner for the home network: keep the Starlink router and use the other device as an access point, or use your own router as the main router with a supported Starlink bypass setup.

If the extra layer is provider-side CGNAT, changing your local router mode will not create a public IPv4 address. Diagnose the layer first, then choose the smallest change that solves the actual problem.

For current kit-specific wiring and bypass details, see Starlink's guide to using a third-party router and Starlink's bypass mode explanation.

Related Starlink guides

Answers for your next step