AT&T Fiber BGW320 IP Passthrough Setup Guide

Updated 2026-10-09 • By Marcus Vance, CCNA (Senior Network Engineer)

To enable IP Passthrough on an AT&T Fiber BGW320-500 or BGW320-505 gateway, log into http://192.168.1.254 using the printed Device Access Code, navigate to Firewall > IP Passthrough, set Allocation Mode to Passthrough and Passthrough Mode to DHCPS-fixed, and select your third-party router's WAN MAC address. Because the BGW320 authenticates via 802.1X certificates, DHCPS-fixed passthrough hands your router the public WAN IPv4 address while preventing Double NAT.

Key Technical Takeaways
  • Connect to the blue 5GbE port: Plug your router's WAN port into Port 1 (the blue 5Gbps RJ45 port) on the rear of the Humax BGW320-500 or Nokia BGW320-505.
  • Change the BGW320 LAN subnet first: If your own router uses 192.168.1.1/24, change the BGW320 Home Network IPv4 address from 192.168.1.254 to 192.168.2.254 to prevent WAN/LAN subnet collisions.
  • Use DHCPS-fixed mode: Always select Allocation Mode: Passthrough and Passthrough Mode: DHCPS-fixed tied to your router's exact WAN MAC address.
  • Disable BGW320 firewall inspection and WiFi: Turn off all checkboxes under Firewall → Firewall Advanced and disable both 2.4 GHz and 5 GHz radios so the gateway acts purely as an ONT.

1. Resolving the 192.168.1.x Subnet Conflict and Logging In

Unlike standalone fiber ONTs, the AT&T BGW320 (manufactured by Humax as the BGW320-500 and Nokia as the BGW320-505) integrates the XGS-PON optical transceiver and 802.1X EAP-TLS authentication certificates inside the gateway chassis. You cannot remove the BGW320 without advanced SFP+ PON spoofing, so configuring IP Passthrough is the official method to assign your public AT&T IPv4 address directly to a Ubiquiti UniFi, ASUS, TP-Link, or Netgear router.

Before enabling passthrough, connect a laptop to one of the yellow Gigabit LAN ports on the BGW320 and browse to http://192.168.1.254. Click the Home Network → Subnets & DHCP tab and enter the 10-digit Device Access Code printed on the rear label of the BGW320. If your personal router uses 192.168.1.1 as its LAN gateway, change the BGW320's Device IPv4 Address to 192.168.2.254, set the DHCPv4 Start Address to 192.168.2.64, and set the DHCPv4 End Address to 192.168.2.253. Click Save and reconnect at http://192.168.2.254 so your router's WAN and LAN interfaces never share the same 192.168.1.0/24 subnet.

2. Configuring Firewall > IP Passthrough (DHCPS-Fixed)

Plug a Cat6 or Cat6a patch cord from the BGW320's Port 1 (Blue 5Gbps Multi-Gig port) directly into the WAN port of your third-party router, and power on your router so its MAC address registers in the BGW320 device table. Ensure no other switches, Apple TVs, or PCs remain plugged into the BGW320's yellow ports, as leaving devices on the gateway LAN breaks local discovery.

  • Navigate to Firewall → IP Passthrough in the top BGW320 navigation bar.
  • Set Allocation Mode from Default to Passthrough.
  • Leave Default Server Internal Address blank.
  • Set Passthrough Mode to DHCPS-fixed (do not use Dynamic or Manual).
  • Under Passthrough Fixed MAC Address, choose your router from the Choose from list dropdown, or select Manual Entry and type your router's exact WAN MAC address in xx:xx:xx:xx:xx:xx format.
  • Set Passthrough DHCP Lease to 1 day (or 99 days on newer firmware builds) and click Save, then confirm the gateway reboot if prompted.

3. Disabling BGW320 Packet Filters, NAT Helpers, and WiFi Radios

Even with IP Passthrough enabled, the BGW320 continues tracking connections in its internal NAT state table (which is capped at 8,192 sessions) and inspecting packets unless you explicitly disable its stateful firewall filters. Leaving these enabled reduces multi-gig throughput and causes dropped UDP sessions during gaming or WireGuard VPN transfers.

  • Go to Firewall → Status and confirm that Packet Filter and Firewall Advanced can be modified.
  • Click Firewall → Packet Filter and click the Disable Packet Filters button so all five default rules are turned off.
  • Click Firewall → Firewall Advanced and set every single option—Drop Incoming ICMP Echo Requests, Drop Incoming Unicast, Reflexive ACL, ESP ALG, and SIP ALG—to Off, then click Save.
  • Navigate to Home Network → Wi-Fi, click Advanced Options, and set both the 2.4 GHz Wi-Fi Operation and 5 GHz Wi-Fi Operation dropdowns to Off. Disabling the BGW320 radios eliminates co-channel interference with your primary router or mesh system.

4. Renewing Your Router WAN Lease and Configuring IPv6 (/64)

Once all BGW320 settings are saved, reboot your third-party router (or click Release / Renew WAN DHCP inside its web GUI). Check your router's WAN status page: the WAN IPv4 address must now match the public AT&T Broadband IPv4 address (typically starting with 99.x.x.x, 76.x.x.x, or 107.x.x.x) rather than a private 192.168.x.x address. If your router still shows a private WAN IP, verify that its WAN MAC address matches the DHCPS-fixed entry on the BGW320.

For native IPv6 connectivity on AT&T Fiber, note that the BGW320 receives a /60 block from AT&T and delegates up to eight individual /64 prefixes via DHCPv6 Prefix Delegation (PD). Inside the BGW320 under Home Network → IPv6, leave IPv6, DHCPv6, and DHCPv6 Prefix Delegation set to On. On your own router (UniFi, ASUS, OPNsense, or TP-Link), configure WAN IPv6 as DHCPv6 / Native with a requested Prefix Delegation Size of 64 (or 60 if requesting multiple VLANs).

AT&T BGW320 IP Passthrough Configuration Reference

BGW320 Menu PathParameter NameRecommended SettingTechnical Purpose
Home Network > Subnets & DHCPDevice IPv4 Address192.168.2.254 (Mask 255.255.255.0)Prevents conflict if router LAN uses 192.168.1.1
Firewall > IP PassthroughAllocation ModePassthroughBypasses private NAT IP assignment for the target MAC
Firewall > IP PassthroughPassthrough ModeDHCPS-fixedBinds public WAN IPv4 lease to your router's WAN MAC
Firewall > Packet FilterPacket FiltersDisabledStops BGW320 CPU from inspecting inbound/outbound frames
Firewall > Firewall AdvancedReflexive ACL / SIP ALG / ICMPAll OffAllows inbound VPNs, ping tests, and clean VoIP traversal
Home Network > Wi-Fi > Advanced2.4 GHz & 5 GHz Wi-Fi OperationOffStops RF interference with your third-party WiFi router

AT&T BGW320 Passthrough Verification Checklist

  1. BGW320 Device IPv4 Address changed to 192.168.2.254 if your personal router uses 192.168.1.1/24.
  2. Third-party router WAN connected to BGW320 Port 1 (blue 5Gbps port) with all yellow ports left empty.
  3. Firewall > IP Passthrough set to Passthrough + DHCPS-fixed with your router's exact WAN MAC address.
  4. All checkboxes under Firewall > Packet Filter and Firewall > Firewall Advanced turned Off.
  5. Both 2.4 GHz and 5 GHz radios disabled under Home Network > Wi-Fi > Advanced Options.
  6. Third-party router WAN DHCP renewed and confirmed showing a public AT&T IPv4 address.

Frequently Asked Questions

Why does my router still get a 192.168.1.x or 192.168.2.x WAN IP after enabling IP Passthrough?

This happens for one of two reasons: either your router requested a DHCP lease before you clicked Save on the DHCPS-fixed page, or your router's WAN MAC address does not match the MAC selected in the BGW320 dropdown. Verify the exact WAN MAC address on your router (which often differs from its LAN MAC by one hex digit) and reboot your router to force a new DHCP Discover handshake.

Does AT&T BGW320 IP Passthrough reduce my 1 Gbps, 2 Gbps, or 5 Gbps fiber speeds?

No. When connected to the blue 5Gbps RJ45 port (Port 1) with Packet Filters and Firewall Advanced turned off, hardware offloading on the BGW320-500 and BGW320-505 passes full multi-gigabit line rate (up to 4.7 Gbps real TCP throughput on 5 Gig plans) with sub-2ms latency.

Can I still access the BGW320 admin page at 192.168.1.254 from behind my own router?

Yes. As long as your router's LAN subnet is different from the BGW320's subnet (for example, your LAN is 192.168.1.0/24 and the BGW320 is 192.168.2.254), your router automatically forwards requests for http://192.168.2.254 out its WAN port to the BGW320 web interface.

Why did AT&T's hidden back-end wireless SSID stay active after I turned off WiFi?

The BGW320 broadcasts a hidden 5 GHz backhaul network reserved for AT&T Smart Home Manager extenders and wireless IPTV boxes. Turning off both the 2.4 GHz and 5 GHz radios under Home Network > Wi-Fi > Advanced Options disables the main user radios; if a low-power hidden BSSID persists after a firmware update, ensure Guest Wi-Fi is also set to Off.

Reviewed by Marcus Vance, CCNA (Senior Network Engineer)

Part of the Packetsaver Network Engineering Team. All configurations and firmware safety instructions follow vendor-verified RFC and IEEE standards. Read our testing methodology →