Have you successfully located and enabled the UPnP or NAT-PMP settings in your router's web UI?
· I've turned UPnP/ NAT-PMP on and ARC won't connect
Select the Diagnostic Keyword or Text String
· Something else
Don't give up yet.
· I'm stuck. I'd like to create a post to ask Roon Community for help.
Describe the issue
Although several days ago I had Roon ARC running with the same router and servers, now it fails. I tried to switch UPNP OFF and ON several times and tried again but it always fails. I tried to make the alternative manual port mapping and failed again. Are you sure the last couple of days ROON ARC is generally running?
Describe your network setup
ISP: Cosmote in Athens-Greece. MODEL: Speedport Plus 2 My Roon server is a MAC Mini with MAC OS 12.7.6 The connection of devices is simple over Ethernet with no other network device intervening
What do you see in ARC itself? If you’ve recently migrated your server between machines or restored a Backup (or otherwise reinstalled RoonServer), you might need to resync ARC itself.
Cosmote has commonly implemented carrier-grade NAT that will interfere with port forwarding, but your WAN IP doesn’t appear to be behind that NAT layer from our diagnostic servers.
Are you able to share the full diagnostic snippet from Roon Settings → ARC?
I have changed nothing. ARC is usable in my wi-fi at home but not away from it at the moment. The full diagnostic message in Roon settings for arc is below
Looking at your diagnostic snippet, this is carrier-grade NAT on Cosmote’s side, correcting what we said in the last reply. Your router’s own external IP falls inside a range ISPs use specifically for carrier-grade NAT, and it doesn’t match the public IP our servers actually see for your connection. The diagnostic also explicitly flags “MultipleNatFound” with 2 routers detected and only 1 mapped, that’s your router (correctly handled via UPnP), the second is Cosmote’s own NAT equipment, which your router settings can’t reach. That’s why toggling UPnP and adding a manual port mapping hasn’t changed anything.
Rather than fighting your ISP over this, the easiest fix is Tailscale, a free VPN service we officially support specifically for cases like CGNAT and double-NAT. It creates a direct secure tunnel between your phone and your Mac Mini without needing any port forwarding at all. Setup guide for your setup: Tailscale on MacOS RoonServer. You’ll install it on both the Mac Mini and your phone, and ARC should connect straight through it.
If you’d still rather solve it at the network level, asking Cosmote for a public/static IPv4 address on your line is the alternative, but Tailscale is faster and doesn’t depend on them.
If finally I can do it with Surfshark, can somebody explain to me how I will connect Roon ARC using Surfshar?. It is not very clear to me what I have to do.
Surfshark won’t work for this, and it’s worth explaining why since “VPN” covers two very different things here. Surfshark tunnels your traffic out to the internet through their server, it doesn’t connect your own devices to each other. Tailscale is a private network specifically for your own devices: your phone and Mac Mini find and connect directly to each other through it, bypassing Cosmote’s CGNAT entirely, which is exactly your problem. Roon ARC is built to recognize and use a Tailscale connection; it has no equivalent support for a general-purpose VPN like Surfshark.
You’ll need to install Tailscale (it’s free) on both your Mac Mini and your phone and sign into the same Tailscale account on both. Setup guide for your Mac Mini: Tailscale on MacOS RoonServer. Once that’s done, ARC should connect through it automatically when you’re away from home.