Starlink Bypass Mode & Third-Party Router Setup Guide

Updated 2026-10-09 • By Marcus Vance, CCNA (Senior Network Engineer)

To use your own router with Starlink, connect your router's WAN port to the Starlink Gen 3 RJ45 port (or the Gen 2 Ethernet Adapter), open the Starlink mobile app, navigate to Settings > Router > Bypass Mode, and slide the toggle to Enable. Adding a static host route for 192.168.100.1/32 out your router's WAN interface preserves local Starlink dish obstruction and latency telemetry.

Key Technical Takeaways
  • Hardware connection by generation: Gen 2 (Actuated) requires the external Starlink Ethernet Adapter; Gen 3 (Standard) has two built-in RJ45 ports under the rear weather plug; Starlink Mini has a built-in weatherproof RJ45 port.
  • Expect CGNAT IPv4 (100.64.x.x): Standard residential and Roam Starlink plans assign a Carrier-Grade NAT IPv4 address from 100.64.0.0/10 alongside a globally routable IPv6 /56 prefix.
  • Add static route 192.168.100.1: Route 192.168.100.1/32 (Mask 255.255.255.255) to gateway 0.0.0.0 (WAN interface) so http://dishy.starlink.com works locally.
  • Factory reset exits Bypass Mode: To re-enable the Starlink router's built-in WiFi, power-cycle the router 6 times in a row (Gen 2) or press the recessed Reset pin under the RJ45 cover (Gen 3).

1. Physical Ethernet Cabling: Starlink Gen 2 vs. Gen 3 vs. Mini

Because the indoor Starlink router also acts as the high-wattage proprietary PoE injector for the outdoor phased-array Dishy terminal on Gen 2 and Gen 3 systems, you cannot simply throw the Starlink router in a closet—unless you install a dedicated third-party 48V–56V DC PoE conversion kit. Instead, you keep the Starlink unit inline for dish power and enable Bypass Mode to turn off its routing and WiFi radios:

  • Starlink Gen 2 (Standard Actuated / Rectangular Dish): Has zero RJ45 ports on the router body. Power down the router, unplug the dish cable from the bottom, insert the official Starlink Ethernet Adapter inline, and run a Cat6 patch cable from the adapter to your third-party router's WAN port.
  • Starlink Gen 3 (Standard Kickstand Dish with UTR-232 Router): Pull out the rubber weather plug on the back of the Gen 3 router to expose two built-in Gigabit RJ45 ports. Connect either port to your third-party router's WAN port.
  • Starlink Mini: Has the WiFi router built directly into the dish housing alongside a rear weatherproof RJ45 port that outputs Ethernet directly to an indoor router WAN port.

2. Enabling Bypass Mode in the Starlink App

Once your third-party router's WAN port is physically cabled to the Starlink Ethernet port, connect your smartphone to the default Starlink WiFi network and open the Starlink App:

  1. Tap Settings on the main home screen.
  2. Select Router (or tap the router node in the network diagram).
  3. Toggle Bypass Mode to the right and confirm the prompt.

The Starlink router will immediately reboot, shut down its 2.4 GHz and 5 GHz WiFi radios, and transition into a pure Layer-2 bridge between the outdoor dish and the RJ45 port. Note that on the Gen 3 router, only one of the two rear Ethernet ports can hold the bridged WAN DHCP lease from the dish—never plug a second device (like a PC or switch) into the second Gen 3 RJ45 port while Bypass Mode is active, or the two devices will fight for the single WAN IP lease. On Gen 3, the front LED glows solid violet/purple to confirm Bypass Mode is active.

3. Adding Static Route 192.168.100.1 for Local Dishy Stats & Obstruction Maps

The outdoor Starlink dish hosts its gRPC telemetry server and web dashboard (http://dishy.starlink.com) at the fixed local IPv4 address 192.168.100.1. While Dishy sends DHCP Option 121 (Classless Static Route) during WAN negotiation, many consumer routers (including TP-Link, Netgear, and older UniFi gateways) ignore Option 121 when the WAN IP is in the 100.64.0.0/10 range, causing the Starlink App to report "Starlink Disconnected" unless it routes over the internet cloud.

To guarantee instant local access to http://192.168.100.1 for real-time ping graphs, snow melt controls, and obstruction maps even when the satellite link is down, add a manual static route on your third-party router:

  • Network / Destination IP: 192.168.100.1
  • Subnet Mask / Prefix Length: 255.255.255.255 (/32 host route)
  • Gateway IP / Next Hop: 0.0.0.0 (or select Interface: WAN on UniFi, OPNsense, pfSense, and ASUS routers)
  • Metric / Administrative Distance: 1

4. Understanding Starlink CGNAT (100.64.0.0/10), Short Leases, and IPv6 /56

When your third-party router connects to Starlink in Bypass Mode, inspect its WAN IPv4 address carefully:

  • Boot-up 192.168.100.100 Lease: While Dishy searches for satellites during the first 60 seconds after a power outage, it hands your router a temporary 192.168.100.100/24 lease with a 5-second TTL. Once satellite lock is achieved, Dishy replaces this with your real WAN IP (5-minute lease time).
  • CGNAT vs. Public IPv4: Standard Residential and Roam plans assign a shared Carrier-Grade NAT address in RFC 6598 space (100.64.0.0/10, i.e., 100.64.x.x to 100.127.x.x). Because of CGNAT, traditional IPv4 port forwarding does not work unless you upgrade to a Starlink Priority (Business) plan and toggle Public IP in the Starlink web portal, or deploy Tailscale / Cloudflare Tunnel.
  • Native IPv6 (/56): Starlink delegates a globally routable IPv6 /56 prefix via DHCPv6-PD on every terminal. Enable DHCPv6 with Prefix Delegation Size 56 on your router WAN to give every LAN device a public IPv6 address.

Starlink Hardware Generations & Bypass Mode Specifications

Starlink HardwareEthernet Port AccessBypass Mode IndicatorHow to Factory Reset (Exit Bypass)
Gen 2 (Standard Actuated)Requires external Starlink Ethernet AdapterBottom white power LED stays on; WiFi offUnplug and plug AC power cord 6 times in a row
Gen 3 (Standard Kickstand)2x Built-in 1GbE ports under rear rubber plugFront status LED glows solid Violet / PurplePress recessed Reset button under rear plug for 3s
Starlink Mini1x Built-in weatherproof RJ45 port on rear of dishInternal WiFi off; RJ45 outputs bridged WANHold rear reset icon on the Mini dish for 3s
High Performance / Flat HPIncluded Power Supply connects directly to RJ45 cableNo Starlink router required (Direct to WAN)N/A (Dish outputs Ethernet directly from PSU)
Gen 1 (Round Dish)Unplug white router; plug Dishy PoE brick white port to WANStarlink router physically removedReconnect original Gen 1 router to white PoE port

Starlink Bypass Mode & Third-Party Router Checklist

  1. Connected third-party router WAN to Gen 3 port, Mini RJ45 port, or Gen 2 Ethernet Adapter.
  2. Enabled Settings > Router > Bypass Mode in the Starlink App (confirmed violet LED on Gen 3).
  3. Verified no secondary devices are plugged into the second RJ45 port on the Gen 3 router.
  4. Configured router WAN IPv4 as Automatic DHCP and confirmed receipt of a 100.64.x.x (CGNAT) or Public IP.
  5. Added a /32 static route for 192.168.100.1 (Mask 255.255.255.255) pointing to the WAN interface.
  6. Enabled WAN IPv6 DHCPv6 Prefix Delegation with a /56 prefix size for native end-to-end IPv6.

Frequently Asked Questions

Can I use both Ethernet ports on the Starlink Gen 3 router when Bypass Mode is enabled?

No. In Bypass Mode, the Starlink Gen 3 router disables its internal DHCP server and NAT engine, meaning the outdoor dish can only assign a single WAN IP lease. Plug only your third-party router's WAN port into the Gen 3 router, and connect all other wired devices to the LAN ports on your third-party router.

Why does my router lose internet after a power outage until I unplug and replug the Starlink WAN cable?

When power returns, your router boots faster than the Starlink dish can acquire satellite lock, so Dishy assigns a temporary 192.168.100.100 lease. Some routers fail to renew when Dishy switches to the 100.64.x.x CGNAT lease; enable 'Continuous WAN Ping / Link Monitoring' to 1.1.1.1 or 8.8.8.8 on your router so it automatically renews DHCP if upstream ping fails.

How do I port forward to my NAS or security cameras on Starlink CGNAT?

Because standard Starlink plans use CGNAT (100.64.0.0/10), inbound IPv4 ports are blocked at the Starlink ground station. You can bypass CGNAT for free without port forwarding by running a Tailscale Subnet Router on your LAN, or by upgrading to a Starlink Priority 40GB+ plan and switching your IP policy to Public IP in your account dashboard.

How do I turn Bypass Mode off on a Starlink Gen 2 or Gen 3 router?

To exit Bypass Mode, you must factory-reset the Starlink router. On a Gen 3 router, press the recessed button beneath the rear rubber port cover with a paperclip for 3 seconds until the front LED flashes rapidly; on a Gen 2 router, unplug and replug the AC power cord 6 times in a row at 2-second intervals.

Reviewed by Marcus Vance, CCNA (Senior Network Engineer)

Part of the Packetsaver Network Engineering Team. All configurations and firmware safety instructions follow vendor-verified RFC and IEEE standards. Read our testing methodology →