Starlink Bypass Mode & Third-Party Router Setup Guide
To use your own router with Starlink, connect your router's WAN port to the Starlink Gen 3 RJ45 port (or the Gen 2 Ethernet Adapter), open the Starlink mobile app, navigate to Settings > Router > Bypass Mode, and slide the toggle to Enable. Adding a static host route for 192.168.100.1/32 out your router's WAN interface preserves local Starlink dish obstruction and latency telemetry.
- Hardware connection by generation: Gen 2 (Actuated) requires the external Starlink Ethernet Adapter; Gen 3 (Standard) has two built-in RJ45 ports under the rear weather plug; Starlink Mini has a built-in weatherproof RJ45 port.
- Expect CGNAT IPv4 (100.64.x.x): Standard residential and Roam Starlink plans assign a Carrier-Grade NAT IPv4 address from
100.64.0.0/10alongside a globally routable IPv6/56prefix. - Add static route 192.168.100.1: Route
192.168.100.1/32(Mask255.255.255.255) to gateway0.0.0.0(WAN interface) sohttp://dishy.starlink.comworks locally. - Factory reset exits Bypass Mode: To re-enable the Starlink router's built-in WiFi, power-cycle the router 6 times in a row (Gen 2) or press the recessed Reset pin under the RJ45 cover (Gen 3).
1. Physical Ethernet Cabling: Starlink Gen 2 vs. Gen 3 vs. Mini
Because the indoor Starlink router also acts as the high-wattage proprietary PoE injector for the outdoor phased-array Dishy terminal on Gen 2 and Gen 3 systems, you cannot simply throw the Starlink router in a closet—unless you install a dedicated third-party 48V–56V DC PoE conversion kit. Instead, you keep the Starlink unit inline for dish power and enable Bypass Mode to turn off its routing and WiFi radios:
- Starlink Gen 2 (Standard Actuated / Rectangular Dish): Has zero RJ45 ports on the router body. Power down the router, unplug the dish cable from the bottom, insert the official Starlink Ethernet Adapter inline, and run a Cat6 patch cable from the adapter to your third-party router's WAN port.
- Starlink Gen 3 (Standard Kickstand Dish with UTR-232 Router): Pull out the rubber weather plug on the back of the Gen 3 router to expose two built-in Gigabit RJ45 ports. Connect either port to your third-party router's WAN port.
- Starlink Mini: Has the WiFi router built directly into the dish housing alongside a rear weatherproof RJ45 port that outputs Ethernet directly to an indoor router WAN port.
2. Enabling Bypass Mode in the Starlink App
Once your third-party router's WAN port is physically cabled to the Starlink Ethernet port, connect your smartphone to the default Starlink WiFi network and open the Starlink App:
- Tap Settings on the main home screen.
- Select Router (or tap the router node in the network diagram).
- Toggle Bypass Mode to the right and confirm the prompt.
The Starlink router will immediately reboot, shut down its 2.4 GHz and 5 GHz WiFi radios, and transition into a pure Layer-2 bridge between the outdoor dish and the RJ45 port. Note that on the Gen 3 router, only one of the two rear Ethernet ports can hold the bridged WAN DHCP lease from the dish—never plug a second device (like a PC or switch) into the second Gen 3 RJ45 port while Bypass Mode is active, or the two devices will fight for the single WAN IP lease. On Gen 3, the front LED glows solid violet/purple to confirm Bypass Mode is active.
3. Adding Static Route 192.168.100.1 for Local Dishy Stats & Obstruction Maps
The outdoor Starlink dish hosts its gRPC telemetry server and web dashboard (http://dishy.starlink.com) at the fixed local IPv4 address 192.168.100.1. While Dishy sends DHCP Option 121 (Classless Static Route) during WAN negotiation, many consumer routers (including TP-Link, Netgear, and older UniFi gateways) ignore Option 121 when the WAN IP is in the 100.64.0.0/10 range, causing the Starlink App to report "Starlink Disconnected" unless it routes over the internet cloud.
To guarantee instant local access to http://192.168.100.1 for real-time ping graphs, snow melt controls, and obstruction maps even when the satellite link is down, add a manual static route on your third-party router:
- Network / Destination IP:
192.168.100.1 - Subnet Mask / Prefix Length:
255.255.255.255(/32host route) - Gateway IP / Next Hop:
0.0.0.0(or selectInterface: WANon UniFi, OPNsense, pfSense, and ASUS routers) - Metric / Administrative Distance:
1
4. Understanding Starlink CGNAT (100.64.0.0/10), Short Leases, and IPv6 /56
When your third-party router connects to Starlink in Bypass Mode, inspect its WAN IPv4 address carefully:
- Boot-up 192.168.100.100 Lease: While Dishy searches for satellites during the first 60 seconds after a power outage, it hands your router a temporary
192.168.100.100/24lease with a 5-second TTL. Once satellite lock is achieved, Dishy replaces this with your real WAN IP (5-minute lease time). - CGNAT vs. Public IPv4: Standard Residential and Roam plans assign a shared Carrier-Grade NAT address in RFC 6598 space (
100.64.0.0/10, i.e.,100.64.x.xto100.127.x.x). Because of CGNAT, traditional IPv4 port forwarding does not work unless you upgrade to a Starlink Priority (Business) plan and toggle Public IP in the Starlink web portal, or deploy Tailscale / Cloudflare Tunnel. - Native IPv6 (/56): Starlink delegates a globally routable IPv6
/56prefix via DHCPv6-PD on every terminal. Enable DHCPv6 with Prefix Delegation Size56on your router WAN to give every LAN device a public IPv6 address.
Starlink Hardware Generations & Bypass Mode Specifications
| Starlink Hardware | Ethernet Port Access | Bypass Mode Indicator | How to Factory Reset (Exit Bypass) |
|---|---|---|---|
| Gen 2 (Standard Actuated) | Requires external Starlink Ethernet Adapter | Bottom white power LED stays on; WiFi off | Unplug and plug AC power cord 6 times in a row |
| Gen 3 (Standard Kickstand) | 2x Built-in 1GbE ports under rear rubber plug | Front status LED glows solid Violet / Purple | Press recessed Reset button under rear plug for 3s |
| Starlink Mini | 1x Built-in weatherproof RJ45 port on rear of dish | Internal WiFi off; RJ45 outputs bridged WAN | Hold rear reset icon on the Mini dish for 3s |
| High Performance / Flat HP | Included Power Supply connects directly to RJ45 cable | No Starlink router required (Direct to WAN) | N/A (Dish outputs Ethernet directly from PSU) |
| Gen 1 (Round Dish) | Unplug white router; plug Dishy PoE brick white port to WAN | Starlink router physically removed | Reconnect original Gen 1 router to white PoE port |
Starlink Bypass Mode & Third-Party Router Checklist
- Connected third-party router WAN to Gen 3 port, Mini RJ45 port, or Gen 2 Ethernet Adapter.
- Enabled Settings > Router > Bypass Mode in the Starlink App (confirmed violet LED on Gen 3).
- Verified no secondary devices are plugged into the second RJ45 port on the Gen 3 router.
- Configured router WAN IPv4 as Automatic DHCP and confirmed receipt of a 100.64.x.x (CGNAT) or Public IP.
- Added a /32 static route for 192.168.100.1 (Mask 255.255.255.255) pointing to the WAN interface.
- Enabled WAN IPv6 DHCPv6 Prefix Delegation with a /56 prefix size for native end-to-end IPv6.
Frequently Asked Questions
Can I use both Ethernet ports on the Starlink Gen 3 router when Bypass Mode is enabled?
No. In Bypass Mode, the Starlink Gen 3 router disables its internal DHCP server and NAT engine, meaning the outdoor dish can only assign a single WAN IP lease. Plug only your third-party router's WAN port into the Gen 3 router, and connect all other wired devices to the LAN ports on your third-party router.
Why does my router lose internet after a power outage until I unplug and replug the Starlink WAN cable?
When power returns, your router boots faster than the Starlink dish can acquire satellite lock, so Dishy assigns a temporary 192.168.100.100 lease. Some routers fail to renew when Dishy switches to the 100.64.x.x CGNAT lease; enable 'Continuous WAN Ping / Link Monitoring' to 1.1.1.1 or 8.8.8.8 on your router so it automatically renews DHCP if upstream ping fails.
How do I port forward to my NAS or security cameras on Starlink CGNAT?
Because standard Starlink plans use CGNAT (100.64.0.0/10), inbound IPv4 ports are blocked at the Starlink ground station. You can bypass CGNAT for free without port forwarding by running a Tailscale Subnet Router on your LAN, or by upgrading to a Starlink Priority 40GB+ plan and switching your IP policy to Public IP in your account dashboard.
How do I turn Bypass Mode off on a Starlink Gen 2 or Gen 3 router?
To exit Bypass Mode, you must factory-reset the Starlink router. On a Gen 3 router, press the recessed button beneath the rear rubber port cover with a paperclip for 3 seconds until the front LED flashes rapidly; on a Gen 2 router, unplug and replug the AC power cord 6 times in a row at 2-second intervals.