# ISP router firmware privacy

**URL:** https://discuss.privacyguides.net/t/isp-router-firmware-privacy/13949
**Category:** Questions
**Created:** 2023-09-13T13:29:56Z
**Posts:** 59

## Post 1 by @Regime6045 — 2023-09-13T13:29:56Z

Regarding the router firmware page: [Router Firmware - Privacy Guides](https://www.privacyguides.org/en/router/)

What exactly is the problem with using the standard router given by your ISP? My router settings don’t contain anything relating to privacy. And obviously my ISP knows who I am and which IP addresses I connect to, no matter what router or firmware I use. So what’s really the benefit of using an alternative firmware?

---

## Post 2 by @anon39565454 — 2023-09-13T13:37:41Z

> **[Reddit - The heart of the internet](https://www.reddit.com/r/hardware/comments/tbthjj/psa_newer_tplink_routers_send_all_your_web/)**

---

## Post 3 by @ph00lt0 — 2023-09-13T14:03:40Z

As above pointed out many routers collect data and share this data to third parties often labelled as anti virus companies.

Besides that often providers have a backdoor account for better and for worse to the router you get from them giving them direct access to your home network.

---

## Post 4 by @anon39565454 — 2023-09-13T16:19:30Z

Don’t forget the insecurities. It’s not uncommon for cheap routers to run outdated linux 3.x or 4.x kernels with no updates. Hell, the official way to install openWRT on a xiaomi router is with a system exploit

---

## Post 5 by @anon76231192 — 2024-11-13T10:41:06Z

Basically my router that is provided by my ISP sucks and gives me much slower WiFi speeds than what I pay for. Ethernet works as fast as advertised just not WiFi.

I saw online people recommend putting that ISP router into modem mode and buying another third party router which has better range and is generally faster in theory.

Is that ok for privacy? I don’t know if that opens my house up to security flaws or other issues that may be risky?

Which router should I buy? Are they all more or less equal in terms of security? I am in Europe.

Sorry, that’s a lot of questions but I am a beginner and a bit clueless really.

---

## Post 6 by @anon48875053 — 2024-11-13T11:42:39Z

Why not just buy some access points?

---

## Post 7 by @anon73250778 — 2024-11-13T13:44:00Z

There are router-access point combos and for a typical home use case it, should be fine.

GL.inet and Fritz seem to be ok.

---

## Post 8 by @anon10852480 — 2024-11-13T13:55:41Z

check out the GL.iNet Flint 2 router

---

## Post 9 by @anon42475305 — 2024-11-13T14:55:55Z

You should ask your ISP if it’s possible to use your own router without their modem. This would be ideal, but it’s also probably fine to keep their modem if necessary.

* * *

As for which router/access point you should purchase, it’s really a question of budget and the area you are hoping to cover.

Personally, I’ve found Ubiquiti Unifi gear to be rock solid, and they have a lot to choose from depending on your requirements. They constantly release software updates with new features and security patches, which is far from guaranteed in consumer-grade routers, which often have very short support periods.

[This](https://eu.store.ui.com/eu/en/category/all-unifi-cloud-gateways/products/ux) is their cheapest all-in-one solution with built-in Wi-Fi for a very reasonable price. They have a lot to pick from, though, and as long as you disable remote access, they are very privacy-friendly working entirely locally.

---

## Post 10 by @anon76231192 — 2024-11-20T15:06:54Z

Thank you all for your advice here. It is really helpful! :slight_smile:

---

## Post 11 by @unclebob — 2023-07-26T10:22:23Z

Hi,

I want to split answers into two categories, each for its own setup:

1. When the user/client **has** the full ability to control/use his home router.
2. When the user/client **doesn’t** have the full ability to control/use his home router.

I want to know, what is/are the **worst case scenario/s** that the user/client can expect if ISP is fully compromised and what can user do about it.

Thanks

---

## Post 12 by @anon30510143 — 2023-07-26T10:28:09Z

Basically they can see anything that’s not encrypted. So you’ll want HTTPS/VPN/Tor. There’s not really much difference if you use the ISP router other than it can see your device name/MAC address (which a lot of devices now will just send a blank name and randomized MAC by default).

---

## Post 13 by @unclebob — 2023-07-26T10:32:35Z

> [@anon30510143](#):
>
> Basically they can see anything that’s not encrypted. So you’ll want HTTPS/VPN/Tor.

What about DNS?

> [@anon30510143](#):
>
> There’s not really much difference if you use the ISP router

Router can act as an in between layer between user/client’s device/s and the network.

---

## Post 14 by @anon30510143 — 2023-07-26T10:34:43Z

Yeah you can use encrypted DNS as well. It really doesn’t matter, you can see the router as outside infrastructure if you want. The encryption happens on your device so they still can’t really see anything. Same situation when you connect to public wifi, you don’t really need to worry about it.

---

## Post 15 by @unclebob — 2023-07-26T10:41:53Z

> [@anon30510143](#):
>
> Yeah you can use encrypted DNS as well.

I’m not a privacy/security expert, I want to know all the ways ISP/external network can use in order to achieve a breach.

> [@anon30510143](#):
>
> The encryption happens on your device so they still can’t really see anything.

They can become a MITM, as CloudFlare(just an exmaple), right? So the SSL isn’t very practical by its own here.

> [@anon30510143](#):
>
> Same situation when you connect to public wifi, you don’t really need to worry about it.

But I’m connecting with a wire, doesn’t it make any difference?

---

## Post 16 by @anon30510143 — 2023-07-26T10:49:47Z

> They can become a MITM, as CloudFlare(just an exmaple), right? So the SSL isn’t very practical by its own here.

No they can’t MITM you.

> But I’m connecting with a wire, doesn’t it make any difference?

No doesn’t matter either way. Really all you need to worry about is if you’re using encryption.

---

## Post 17 by @unclebob — 2023-07-26T10:52:46Z

OK, thanks a lot for helping me to sort things out.

---

## Post 18 by @anonymous293 — 2025-05-11T02:08:01Z

If I use their stock router can they see the LAN traffic across machines? Like shares on a NAS?

---

## Post 19 by @jonah — 2025-05-11T02:16:12Z

> [@anonymous293](#):
>
> If I use their stock router

Yes, that’s why you don’t.

---

## Post 20 by @anon63378630 — 2025-05-11T03:28:05Z

hm, there was actually a pretty good CCC or DEFCON? talk about this like a decade ago, I can’t seem to find it, anyone remember it?

edit: here is a related one: [Beyond your cable modem - media.ccc.de](https://media.ccc.de/v/32c3-7133-beyond_your_cable_modem)

---

## Post 21 by @jonah — 2025-05-11T03:31:24Z

I would guess it’d be something to do with TR-069

---

## Post 22 by @Stiffly2505 — 2025-05-11T05:18:04Z

Technically? Yeah, it passes through a device where they control software.

Realistically? They don’t give a shit.

Is it still a privacy problem? Yes, ISP modems are frequently hacked, potentially by someone who does give a shit.

---

## Post 23 by @Machkiel — 2025-05-12T07:11:38Z

A few years ago, on an ISP provided modem/router combo device I found a port forward (WAN to LAN) that I know I did not add. I had added a couple of port forwards of my own, fully documented that, and their rogue port forward was obvious. I do not know if the ISP did that or if it was a random bad actor. My personal router/firewall behind the ISP provided modem router combo device neutralized whatever they were attempting, but it provided a lesson in how insecure using someone else’s equipment really is. Never trust the ISP provided hardware.

---

## Post 24 by @jonah — 2025-05-12T13:31:06Z

> [@Stiffly2505](#):
>
> Realistically? They don’t give a shit.

You will have to check your local laws before assuming this is true. In most cases with ISP-provided routers they _do_ log at least all your local MAC addresses at minimum, and if they do that then there are also laws in many places requiring they _retain_ that information for law enforcement investigations.

---

## Post 25 by @anon21060844 — 2025-05-12T13:51:09Z

I’m seeing lots of good discussions concerning routers (ISP Provided vs Privacy firmware like DD-WRT, etc.) but what about ISP Modems? Are there practices or changes we should be implementing on the ISP modems? My initial assumption is that we have little to no configurable options on that modem, except to be sure and randomize my Routers MAC address.

---

## Post 26 by @Stiffly2505 — 2025-05-12T14:01:07Z

You should avoid using it for anything other than a modem.

Ideally you should enable PPPoE passthrough (or ask your ISP to enable it) and then just use a proper (possibly OpenWRT) router behind it with your PPPoE credentials.

If it’s lacking such a feature, then the next best thing is bridge mode.

---

## Post 27 by @overdrawn98901 — 2025-05-12T14:07:55Z

> [@anon21060844](#):
>
> except to be sure and randomize my Routers MAC address

On this point, I recommend reading my post on what randomizing the routers MAC address will and won’t do. Its a relatively low-effort but low-yield outcome.

> [@Router MAC address privacy](https://discuss.privacyguides.net/t/router-mac-address-and-privacy/24805/2):
>
> This is a better question for the OpenWRT forum imo. Did a 5 second internet search and found results with the almost exact same question: [Add random MAC generation after each reboot - #5 by elbertmai - Feature Requests - OpenWrt Forum](https://forum.openwrt.org/t/add-random-mac-generation-after-each-reboot/193265/5) I will copy the most descriptive reply here. TLDR; If and only if you keep the router online and are physically moving around with the router at the same time, then maybe the MAC randomization may benefit you. Otherwise, I’d argue it has negligible benefits if …

> [@anon21060844](#):
>
> Are there practices or changes we should be implementing on the ISP modems?

You can also buy your own Modem, but this gets trickier with fiber. Even so, the ISP needs to configure your modem to work with their setup.

> [@Stiffly2505](#):
>
> Ideally you should enable PPPoE passthrough (or ask your ISP to enable it) and then just use a proper (possibly OpenWRT) router behind it with your PPPoE credentials.
> 
> If it’s lacking such a feature, then the next best thing is bridge mode.

PPPoE seems to be common for DSL from what I briefly read. For cable or fiber, don’t think this is an option. And I’m not sure why you’d recommend bridged mode - this is for specific topologies, not just every use case.

---

## Post 28 by @Stiffly2505 — 2025-05-12T14:11:44Z

> [@overdrawn98901](#):
>
> For cable or fiber, don’t think this is an option.

I’m on gigabit fiber with PPPoE, with passthrough to my OpenWRT router right now.

> [@overdrawn98901](#):
>
> And I’m not sure why you’d recommend bridged mode - this is for specific topologies, not just every use case.

Because you’d want to entrust NATing, LAN traffic, and firewalling to your trusted proper router, instead of the ISP’s. And double NAT is stupid.

---

## Post 29 by @anon63378630 — 2025-05-12T14:15:02Z

> [@overdrawn98901](#):
>
> gets trickier with fiber

some starter links for ont bypasses:

- [GitHub - rssor/fs\_xgspon\_mod](https://github.com/rssor/fs_xgspon_mod)
- [GitHub - djGrrr/8311-was-110-firmware-builder](https://github.com/djGrrr/8311-was-110-firmware-builder)

---

## Post 30 by @anon21060844 — 2025-05-12T14:43:09Z

Thank you for the reply and this information on “Router MAC address randomization”. I am doing my best to understand the value of which devices can “see” my routers specific MAC address. The best I can determine on that part is that to be of any value, a person must reboot a Randomized MAC address regularly, but even then (per this write-up), it doesn’t actually help with privacy from the ISP? (I thought one specific privacy recommendation was to always use a Randomized MAC address on the Router).

As for the Modem configuration, I think I am understanding that we should log into the Modem and configure PPPoE passthrough. This Modem configuration will increase Privacy because it bypasses the ISP’s ability to “see” what we are doing?  
(as always, I have to ask stupid questions to get my brain to actually comprehend..)

---

## Post 31 by @Stiffly2505 — 2025-05-12T14:50:25Z

> [@anon21060844](#):
>
> As for the Modem configuration, I think I am understanding that we should log into the Modem and configure PPPoE passthrough. This Modem configuration will increase Privacy because it bypasses the ISP’s ability to “see” what we are doing?  
> (as always, I have to ask stupid questions to get my brain to actually comprehend..)

The ISP will always see your outgoing traffic, you’re sending it to them. If you want to avoid that, you want a VPN. (And maybe configure it on your router to tunnel everything.)

What moving PPPoE to your trusted router can help with is that it removes any insight or access the ISP modem has or could have to your internal traffic, connected devices, etc. It turns the device into a box that just turns ethernet into fiber / dsl (this is a bit of an oversimplification). It no longer does (much) networking.

EDIT:

There’s a great recent DEFCON talk about hacking ISP modems: [https://www.youtube.com/watch?v=MmpkfM8I33Q](https://www.youtube.com/watch?v=MmpkfM8I33Q)

Generally you just want to give the least amount of access to the ISP’s devices to both your network and your traffic, so reducing its role in everything is always the best step you can take. Really, just assume the thing is just outright malicious, since they’re all notably insecure. That can be

1. Replacing it entirely (See [https://discuss.privacyguides.net/t/isp-modem-question/27514/5](https://discuss.privacyguides.net/t/isp-modem-question/27514/5) )
2. Moving PPPoE to your router
3. Moving off NATing and firewalling at least.

The earlier point you can do the better, but it depends on your connection type, your ISP’s policies, and your ISP modem.

---

## Post 32 by @anon21060844 — 2025-05-12T17:49:36Z

I logged into the ISP DSL Modem (C4000LG) and the best I can tell, the closest option to “PPPoE Passthrough” is labeled as “Transparent Bridging” (it is at the bottom of this links page).  
Is this correct?

> **[WAN settings](https://www.centurylink.com/home/help/internet/modems-and-routers/advanced-setup/wan-settings.html)**
>
> If instructed by a technician, you can change the protocol and addressing type on your modem, including PPPoE, IPoE or transparent bridging.

---

## Post 33 by @Machkiel — 2025-05-12T19:04:06Z

The pfSense / PF documentation is murky on this, but it is my understanding that one or both of them provide a feature called Static Port. Regardless of the vague naming, I think Static Port sets the WAN / outgoing traffic MAC address of all traffic to the MAC address of the router/firewall’s WAN MAC address. Instead of LAN MAC addresses being shown in Internet traffic, everything outside appears to be the router/firewall’s WAN MAC. Supposedly, Static Port handles all the MAC address translation similar to how NAT handles the IP address translation.

Please correct me if I am off base on this. Again, the product docs could use some work. If I understand all this correctly, Static Port would keep LAN MAC addresses out of ISP logs.

---

## Post 34 by @Anonymous126 — 2023-12-17T12:14:29Z

Hello,

I have a WiFi router provided by my ISP that runs on closed-source firmware. My question is, does using a VPN service (specifically Mullvad) ensure that my internet activity remains private and secure from my ISP? Thank you.

---

## Post 35 by @anon89321548 — 2023-12-17T13:24:06Z

If the connection starts downstream closer to your PC, probably. Your connection eventually routes through your ISP regardless.

Maybe I haven’t been exposed to much in this space around routers but my issue with these devices is usually the lack of features in the firmware or some other limitation.

---

## Post 36 by @Anonymous126 — 2023-12-17T14:15:20Z

Thanks for the reply. :slight_smile:

---

## Post 37 by @anon73250778 — 2023-12-17T16:41:39Z

Welcome to the forum!

Usually the ISP provided routers are extremely cheap and cannot competently connect and route multiple devices. They may even cheap out on the LAN ports and give you a non-full duplex port. Yes it can do gigabit transfers but only in one direction and cannot upload and download simulaneously at 1 gigabit. Or worse yet, give you 4 LAN ports with a shared connection and all 4 ports can only do a total of a gigabit speed at any one time. This is enough for non-power users but probably not enough for tech savvy people like us.

Get a router you own and control (like a Protecli) then connect it to the ISP via a VPN that tunnels all your traffic.

You can also connect directly to ISP provided router and use the VPN on top of the OS but if you are using iOS and MacOS, they dont like that you are using a VPN and will undermine it and connect directly to its Apple servers. I personally do not like that and would not want to wrestle with the computer that I own. It should repect my preference so I force it to a VPN tunnel outside its OS that it cannot control.

You can use other OS but you risk exposing your WiFi/LAN ports MAC Address. This is less of an issue if you are using a privacy oriented device (like GrapheneOS) that can randomize MAC on a per connection (or even per session setting).

---

## Post 38 by @Anonymous126 — 2023-12-17T17:17:24Z

Thank you for your response and welcome to the forum! :blush:

Unfortunately, I’m currently stuck with a MacBook for now, and it’ll likely take a few years before I can afford to buy a new PC.

I was confused by your statement that ‘if you are using MacOS, they don’t like that you are using a VPN and will undermine it and connect directly to their Apple servers.’ Could you please clarify what you meant by this?

Furthermore, I have a few questions:

How can I tell if my MacBook is connecting directly to Apple servers and not Mullvad’s?

Is there anything I can do to prevent MacOS from connecting to Apple servers and instead route all internet traffic through Mullvad VPN only?

Lastly, I don’t understand how my IP address can be showing as from Singapore (Mullvad VPN location) but my traffic is through Apple’s servers. I don’t understand how this is possible. Can someone explain this to me? I’m a total beginner when it comes to this stuff, so feel free to explain it in detail.

---

## Post 39 by @anon63378630 — 2023-12-17T17:18:24Z

> [@Anonymous126](#):
>
> Unfortunately, I’m currently stuck with a MacBook for now, and it’ll likely take a few years before I can afford to buy a new PC.

You can just boot another OS, no need to replace a functioning computer.

---

## Post 40 by @Anonymous126 — 2023-12-17T17:55:56Z

Is there anything private and safe besides Asahi Linux? Unfortunately, it doesn’t work for me since my main screen is broken, and the MacBook Pro M1 2020 lacks HDMI output for an external display, which I confirmed on GitHub via the Asahi Linux documentation wiki."

[https://github.com/AsahiLinux/docs/wiki/M1-Series-Feature-Support#m1-devices](https://github.com/AsahiLinux/docs/wiki/M1-Series-Feature-Support#m1-devices)

---

## Post 41 by @anon73250778 — 2023-12-17T18:00:21Z

> [@Anonymous126](#):
>
> Could you please clarify what you meant by this?

Few years back (2020) this happened:

> **[Apple's own programs bypass firewalls and VPNs in Big Sur](https://www.macworld.com/article/675671/apples-own-programs-bypass-firewalls-and-vpns-in-big-sur.html)**
>
> Apple has made strange choice in macOS 11 that pose risks to both security and privacy - and protecting yourself is not easy

They’ve since then fixed this but at this point they’ve shown that when you are running iOS/MacOS your preferrence isnt really respected and they would still put themselves above you.

---

## Post 42 by @Anonymous126 — 2023-12-17T18:16:14Z

I wish I had known about all this earlier; I want out badly. I don’t even use any of Mac’s apps—19 out of 21 that I use often are open source, while the remaining two, Spotify and Obsidian, are closed source.

I could switch to Linux with minimal issues, but I feel stuck. I need a Linux machine or wish Asahi Linux starts working with external display for my Mac.

---

## Post 43 by @SteveR — 2023-12-17T18:33:24Z

If you really want out badly, is there any prospect of selling your Macbook and buying something like a refurbished business-class PC laptop secondhand to replace it and using Linux on that? I don’t use Apple stuff myself but I have the impression it does hold its value pretty well, and a business dealing in secondhand Apple stuff will probably not find it a huge job to replace the screen before reselling.

---

## Post 44 by @Anonymous126 — 2023-12-17T18:41:13Z

Thank you for replying.

On paper, that sounds great, but for me, it’s too much work. I already thought of this before posting my last comment and dismissed it. However, I still hope that Asahi might work well enough for me on my Mac."

---

## Post 45 by @anon90831229 — 2023-12-17T20:40:41Z

I recommend Asahi all day, it’s my main machine. But a broken screen of course, that could very well be an issue. DisplayLink is the only thing that comes to mind which could be a work-around. Just not sure if that works well enough to be able for you to go through system setup.

---

## Post 46 by @Anonymous126 — 2023-12-18T07:04:30Z

I’m familiar with installing software on Asahi, having done so previously. My method involves connecting a wireless mouse, navigating the installation using my Mac’s closed screen, and utilizing an external display.

Whenever keyboard input is required, I position the cursor over the relevant button or field, lift up my Mac’s screen, enter the necessary information, and then repeat this process until Asahi Linux is successfully installed.

However, upon completion of the installation, the system fails to display on my external screen, which is unsupported by Asahi for my MacBook Pro M1 13-inch 2020 model. Could you kindly provide instructions on implementing the DisplayLink work-around?

---

## Post 47 by @anon90831229 — 2023-12-18T07:58:42Z

> [@Anonymous126](#):
>
> Whenever keyboard input is required, I position the cursor over the relevant button or field, lift up my Mac’s screen, enter the necessary information, and then repeat this process until Asahi Linux is successfully installed.

You are allowed to connect keyboards.

> However, upon completion of the installation, the system fails to display on my external screen, which is unsupported by Asahi for my MacBook Pro M1 13-inch 2020 model. Could you kindly provide instructions on implementing the DisplayLink work-around?

Yes, I’m not talking about the initial installation steps on macOS. I was saying that after booting into Asahi, then going through installation and setting everything up so that DisplayLink works, that would be the tricky part, as you don’t have any screen output. Generally DisplayLink is just a product from Synaptics that lets you connect special adapters to your computer and then you can get display output through USB, without needing special hardware support. Just need to install a proprietary driver, and you’re good to go. That’s why these adapters work even without HDMI support. But for you it would be probably almost impossible to install the driver etc.

Edit: If your laptop has an HDMI port (as in built-in HDMI, not just via adapter) then it might work [Asahi Linux: &quot;With the latest kernel update for Fedora Asahi, w…&quot; - Treehouse Mastodon](https://social.treehouse.systems/@AsahiLinux/111515422125309592)

---

## Post 48 by @Anonymous126 — 2023-12-18T21:09:29Z

Thanks for the info :slight_smile:

---

## Post 49 by @bitsondatadev — 2025-05-12T19:32:16Z

Happy to move this to its own question if it becomes an involved answer or seems too off topic.

Comcast/Xfinity is the only reliable ISP in my area, and so I decided to move to an offbrand modem as a potential minimal connection enabled along with Firewalla. I’m not sure if this actually does anything other than enable me not to use their router since there’s no modem only option. My hopes were that using an off branded modem would at least slow the capabilities that they would have with their own modems.

> **[Hitron CODA56 | Top Selling DOCSIS 3.1 Cable Modem](https://us.hitrontech.com/products/consumers/coda56/)**
>
> Increase Internet speeds up to 2.5 Gbps with the Hitron CODA56 DOCSIS 3.1 cable modem. Enjoy faster streaming, gaming. Eliminate modem rental fees. Order now!

I just did a basic up with the modem, and then everything else lives behind my FireWalla as the router where I do all my managing. All of the management and configs exist locally with a small amount of traffic that routes directly between me and FireWalla servers to provide dynamic DNS that keeps a consistent domain name for my external home services when xFinity changes the IP address. I then just route all my traffic through Proton VPN when communicating outside and anything anon obviously routes me to Tor which likely blends in better for Proton’s traffic patterns.

Is there any configuration I need to consider for this modem since it’s mostly just a medium to connect to the XFinity and I otherwise keep everything well blocked behind Firewalla/VPN?

---

## Post 50 by @Stiffly2505 — 2025-05-12T19:47:34Z

Never heard of Firewalla, I just use OpenWRT and a cheap as shit Xiaomi router, but if what you’re saying is correct and it just tunnels everything and isn’t misconfigured real bad, you should be golden. Regardless of whatever modem you use actually. Moving PPPoE to the router or switching to bridge mode just improves latency / bandwidth / reliability / overall sanity of the setup since you reduce the useless hops the traffic goes through, as in my experience ISP modems are pretty shit.

---

## Post 51 by @anon21060844 — 2025-05-12T21:19:34Z

My hope is to be understand the correct Privacy configuration/settings for the ISP modem on DSL.

Here is what I think I’ve learned so far:  
Modem: Configure it to be a simple passthrough (my modem only offers “Transparent Bridging” which I am assuming provides close to the same as PPPoE passthrough).

Router: This requires the Router to be configured with the PPPoE authentication username and password.

Question: Does the fact that the router now logs into the ISP/DSL account now expose the router to privacy issues, since it is now tied to the ISP user account where before it was “one step removed”?

---

## Post 52 by @bitsondatadev — 2025-05-13T00:49:46Z

> [@Stiffly2505](#):
>
> it just tunnels everything and isn’t misconfigured real bad, you should be golden. Regardless of whatever modem you use actually. Moving PPPoE to the router or switching to bridge mode just improves latency / bandwidth / reliability / overall sanity of the setup

Yeah Firewalla doesn’t tunnel by default but it is very easy to set up and more importantly maintain. The hardware is small SoC hardware with semi-managed (in that you are provided sensible defaults and dead simple knobs to adjust settings) open stack. Its not great if you are wanting to teach yourself stuff or get into a very detailed opinionated setup. Their target consumer is knowledgable enough prosumers that don’t have time or interest.

I’ve really enjoyed the control it has moved back to my court with less time sinks and sweating the security setup.

Thanks for the vote of confidence I’ll avoid hijacking this thread much more and just ask anyone who has any suggestions on modem configs or concerns let me know or I’ll just leave it be and give my router all the power.

---

## Post 53 by @0x1 — 2025-05-13T10:08:35Z

Is there any benefit to add a new router with openwrt after ISP’s modem/router? It’s a cable router with no option to replace it and it’s locked so no bridge mode or DNS change is possible.

I guess double NAT is inevitable.

---

## Post 54 by @Stiffly2505 — 2025-05-13T11:09:52Z

That sounds pretty terrible. Anyway, it’d still mask your devices’ MACs, route internal traffic, firewall off the modem from the rest of your devices, and let you use custom DNS or set up tunneling everything. Bridging, PPPoE passthrough or full replacement all just improve performance, bandwidth, latency, security. Ultimately the traffic that’s just passing through the modem is always visible on the other end of the cable.

---

## Post 55 by @jonah — 2025-05-13T13:13:33Z

> [@Stiffly2505](#):
>
> Anyway, it’d still mask your devices’ MACs, route internal traffic, firewall off the modem from the rest of your devices

:+1: As annoying as Double NAT is, if it is your _only_ option it still is the best way to go to secure your network.

Worst case scenario, you can connect game consoles to the ISP router and everything else to your own router. Those devices usually handle the double NAT situation the worst, and probably don’t need access to the devices on your trusted internal network in the first place. Everything else you can kind of resolve with double port forwarding.

---

## Post 56 by @jonah — 2025-05-14T20:35:52Z

I feel like the original question on this thread was never really answered.

**If you have your own separate router** that (is the only thing which) connects to the modem, then the answer to this question…

> [@anon21060844](#):
>
> Are there practices or changes we should be implementing on the ISP modems?

…is **no**. The edge of your network is controlled by your router/firewall that all of your devices connect to. The modem is the edge of the ISP’s network, and their responsibility. If applicable, simply typing in PPPoE credentials or otherwise configuring your router with ISP-provided config info is fine, but installing ISP-provided software/firmware would be dangerous.

---

## Post 57 by @anon83428815 — 2025-05-14T22:00:56Z

To add to this for people like myself and @bitsondatadev where Comcast/Xfinity is the only game in town, Xfinity charges an extra $30/month if you want unlimited data and use your own modem. This makes it much tougher to try and stick with your own equipment and have an affordable internet bill.

It seems things have gone a complete 180 from when you could get a discount for using your own equipment.

Its unclear to me how much a privacy concern an Xfinity modem/router combo in bridge mode is but, obviously not ideal.

---

## Post 58 by @bitsondatadev — 2025-05-14T23:45:52Z

Yup, they charge me $20/mo so my impression is they are proffiting on something when you use their modem. A less skeptical take could be that it offsets some maintenance costs if they have to troubleshoot different modems and routers. I think the former us more likely so to me I consider it a “privacy tax” and in some strange way makes me feel validated for doing it despite the absurdity.

I really hope there’s political shifts that open up the internet globally that isn’t so dependent on centralized infra.

I’m definitely excited to get local meshes going here in my town as an emergency system. If local meshes become the norm then there can be tactics people build to start connecting them across townships and cities.

Plenty of big cities do this which is possible due to the proximity of tall buildings. Just need to get local governments involves in community building of mesh networks in suburbs and rural areas [https://www.nycmesh.net/](https://www.nycmesh.net/)

---

## Post 59 by @anon63378630 — 2025-05-15T00:45:36Z

> [@anon83428815](#):
>
> is the only game in town

for those in the USA you should double check on [https://broadbandmap.fcc.gov/home](https://broadbandmap.fcc.gov/home) because some places do have non/under advertised municipal offerings
