Choose between eero routing, double NAT, and bridge mode
Decide which router should own DHCP and NAT, then preserve one gateway eero and understand the features lost when eero is bridged.
Direct answer
The shortest reliable path.
For the fullest eero feature set, let eero replace the existing router or bridge the upstream modem/router. If the upstream router must remain active, eero can run behind it with double NAT or eero itself can be placed in bridge mode. Bridging eero disables its routing services and removes several advanced network features, while one gateway eero must remain wired in the path.
System view
Check the whole path.
- 01Internet service
- 02Modem or upstream router
- 03Gateway eero
- 04Other eero nodes
- 05Clients
Scope before steps.
eero networks installed behind an ISP modem/router or another router when deciding which device should perform routing, DHCP, and NAT.
ISP-specific television or voice requirements, PPPoE credentials, static public IP design, enterprise VLANs, or changing the ISP device without its documentation.
Procedure
Do this in order.
- 01
Choose the routing owner
Prefer one routing device: either bridge the upstream combo device so eero routes, or bridge eero so the upstream router routes.
- 02
Use double NAT when both routers must remain active
Connect the gateway eero behind the existing router and keep the two Wi-Fi networks on different SSIDs if both remain enabled.
- 03
Bridge eero only after reviewing feature loss
In the eero app, open Settings → Advanced networking → DHCP & NAT and change Automatic to Bridge after reviewing the unavailable features.
- 04
Verify topology and client addressing
After the network reboots, confirm all traffic still passes through one gateway eero and clients receive addresses from the intended router.
Diagnostic matrix
Read the result, not the guess.
| What you see | Check next | What it means |
|---|---|---|
| Port forwarding or inbound access fails under double NAT | Identify both NAT layers and decide whether one router can be bridged. | The inbound path crosses two routing boundaries. |
| eero advanced controls disappear after bridging | Compare the missing feature with eero’s bridge-mode limitations. | This may be an expected consequence of moving routing to the upstream device. |
| Clients join the wrong Wi-Fi network | Use distinct SSIDs during double NAT or disable the upstream Wi-Fi when appropriate. | Two active wireless networks are competing for client connections. |
Stop conditions
Know when not to keep changing things.
- Do not bridge an ISP gateway before recording services that may depend on it.
- Do not change the physical gateway-eero topology while diagnosing a routing-mode change.
- Contact the ISP when bridge mode or required credentials are controlled by its equipment or service plan.