Hello,
I'm trying to get rid of double NAT in this scenario:
Internet (private address 10.x.x.x) <-> LTE modem in bridge mode / passthrough (currently WAP LTE KIT - passthrough on eth1) <-> hAP AC router <-> LAN
WAP LTE is in passthrough mode connected to eth1 port on hAP AC - I've got 10.x.x.x address and traceroute from router works fine - single NAT, the problem is when I'm trying to access the internet from LAN - I've got another NAT.
WAP LTE doesn't have any firewall rules, just provides internet on hAP AC WAN. On hAP AC I've got src-dst masquerade on eth1 (wan port) as out interface. Everything works fine but how to simplify this and reduce NAT?
Also, I want to connect hAP AC with HEX PoE to increase ports as I'm running out of them - trying to use SFP direct-attached cable - should I use VLAN there or anything else? HEX will be in bridge mode.
Any help or suggestions appreciated.