Line of sight ISP, steady 20Mps, wired ethernet setup, Eero 6 router, unmanaged switch, Roon server in an attached Nucleus, endpoint is Roon ready (Linn Klimax) ... followed instructions for manual port forwarding. Any help appreciated.
MultipleNatFound can be caused by one or both of two situations:
You have two routers in your local network.
Your ISP uses CG-NAT to provide your router with its WAN side ip address.
Since you state that you have only one router, it looks like your ISP uses CG-NAT.
There is actually another indication that this is the case:
This line indicates that the public ip address seen by the Roon cloud servers is 173.aaa.bbb.bbb (where the aaa.bbb.ccc is obfuscation) but that the ip address assigned to the WAN side of your router is 100.66.1.10. Thus there is definitely an NAT layer between your router and the Roon cloud server. Also the 100.66.1.10 ip address lies within a pool of ipv4 addresses (100.64.0.0 to 100.127.255.255) that are reserved for CG-NAT provisioned services.
Since your ISP is using CG-NAT, you will not be able to get ARC working using port forwarding. You thus have two options:
You can contact your ISP and ask them if they can provide you with an ip address that supports port forwarding - often a static ip address - but the ISP, if it can provide it, will likely charge an additional monthly fee for this. Once a suitable ip address is provided, you will be able to setup port forwarding using either uPnP/natPMP or a manual port forwarding rule as described in the Roon help centre article on Port Forwarding.
You can use Tailscale to provide your Roon ARC devices with local network access even when away from home and thus avoid the need for port forwarding altogether. Note: This does not ‘fix’ the multiple Nat issue. It just works around it. As such, the above ‘Not Ready’ status and diagnostic text will continue to be shown but can be ignored as it is not relevant to Tailscale setups.
The Roon description of the use of Tailscale can be found at:
This page provides links for installing Tailscale for different types of Roon Server. There is, however, a potential issue:
You don’t explicitely specify which Nucleus device you are using. If you use a Nucleus One or a Nucleus Titan, then you can find Tailscale setup instructions at:
However, if you use one of the older devices, a Nucleus or Nucleus Plus, then Tailscale is not supported on the device itself and thus the installation instructions above do not apply. In this case, there is still a way to use Tailscale but it is more complicated and it involves a second device - a computer of some kind - possibly a Raspberry Pi or similar extreme low power device - to run Tailscale as a subnet router. Instructions for doing this can be found at:
Warning: What follows is not an officially supported solution and it thus falls into Tinkering and may, in some circumstances, leave you without access to official support
Finally, some people have reported success in reconfiguring their Nucleus and Nucleus Plus devices to use UEFI boot (by changing BIOS settings - attached USB keyboard and HDMI monitor or TV required) and then reinstalling RoonOS using the ROCK installer. I believe the Nucleus related RoonOS customization can then be applied afterwards to restore the correct behavior for a fanless device (ROCK assumes NUC devices which have a fan). When this is done, the Nucleus will update to RoonOS build 271 which includes Tailscale support in the same way as it is on the Nucleus One and Nucleus Titan devices. As supplied, Nucleus and Nucleus Plus devices use BIOS boot which limits them to RoonOS build 259 or earlier which does not include Tailscale support. Of course, this process will involve completely reformatting the system SSD in your Nucleus and so you must have a good database backup before you start and you will have to restore your database from that backup once your Nucleus is up and running with RoonOS build 271.
Thank you. Unfortunately Tailscale is not supported on my Nucleus (rev B?, apologies for not specifying, as I had determined Tailscale was not available), so I’ll touch base with my ISP about the workaround you identify. (Rather than “tinker”).
I applaud your knowledge, and appreciate your taking the time to explain my situation so thoroughly and thoughtfully.
As @Wade_Oram ‘s comprehensive reply mentioned, it looks like you have CGNAT enabled by your ISP, and the way around this is to get a static IP, or use Tailscale. Note that you don’t have to use Tailscale on the Nucleus itself, but you can go the subnet routers’ direction and have it on a PC on the same network. In any case, let us know if you have any questions, and we’ll be happy to assist!
Who is your internet provider? The offerings around CG-NAT usually depend on the age of their infrastructure in your geographic region. We might be able to provide specific language for requesting a dedicated IPv4 or tips from other users with the same provider.