Skip to content

NAT Loopback / Hairpin NAT

Cannot connect to WireGuard VPN using external DNS name (vpn.microsoftlab.ch) from inside the network.

ISP router does not support NAT loopback (hairpin NAT).

When inside network, connect to internal IP instead of external DNS.

Configure internal DNS to resolve vpn.microsoftlab.ch to internal IP.

Some ISP routers have NAT loopback setting - check router configuration.

On ISP router:

External Port: 51820
Protocol: UDP
Internal IP: 192.168.1.100 (UniFi Gateway WAN)
Internal Port: 51820