How to Put Your ISP Modem in Bridge Mode
for a Better Home Office Network

- Bridge mode turns your ISP's modem-router combo (a "gateway") into a simple modem — passing full network control to your own router, which handles QoS, VPN, and Wi-Fi far better than any ISP-supplied device.
- The problem bridge mode solves is called Double NAT — when two devices on your network both try to manage traffic simultaneously, causing VPN drops, broken QoS, increased latency, and call instability.
- Bridge mode is the essential setup step for remote workers who bought a quality router (ASUS, TP-Link, Netgear) but still have an ISP gateway in the chain — without it, the new router's QoS and VPN features are severely limited.
- Bridge mode does not increase your internet plan speed. It improves real-world performance by eliminating double NAT — latency spikes, connection drops, and problems specifically with video calls and VPNs.
- The process takes 15–20 minutes, requires no tools, and is reversible — you can undo it at any time by logging back into the ISP gateway.
- AT&T does not use traditional bridge mode — it uses a feature called IP Passthrough, which accomplishes the same result. Exact steps for both are covered in this guide.
- Before starting: write down your Wi-Fi name and password, and know that you will lose internet for 1–3 minutes during the switch.
The Device Still Doing a Job It Shouldn't Be
You bought a quality Wi-Fi 6 router. You followed our QoS setup guide. You ran the speed test. But something still feels off — your VPN drops occasionally, your QoS settings do not seem to be doing much, and your work calls are less stable than they should be on a fast internet plan.
Table of Contents
ToggleThe problem is almost certainly sitting on your shelf right next to the new router — still plugged in, still doing routing work it was never supposed to do. It is your ISP's gateway.
Most ISPs provide a combination modem-router device — a single box that connects to the internet and manages your home network simultaneously. When you add your own router to this setup, both devices try to manage traffic at the same time. This creates a condition called Double NAT.
This guide walks through exactly how to do it for the three most common ISPs in the United States — Xfinity, AT&T, and Spectrum — plus a universal method that works across most other providers. If you're still building the rest of your workspace, start with our complete home office setup guide.
What Bridge Mode Actually Does
Think of it this way. Your ISP gateway is the building's front door — it connects your home to the outside world. Your personal router is the building manager — it decides how everyone inside uses the shared resources. Bridge mode fires the ISP gateway from the building manager role and hands that authority entirely to your personal router, which is far better qualified for the job.
After bridge mode is enabled:
- Your ISP gateway handles only the physical connection to the ISP — nothing else
- Your personal router handles all DHCP, NAT, firewall, QoS, and Wi-Fi
- Your QoS settings become fully effective
- Your VPN connects cleanly without Double NAT interference
- Your network has one single management point — your router's admin panel
What Is Double NAT, and Why Does It Hurt Remote Work?
NAT (Network Address Translation) is the process your router uses to give every device on your home network a private IP address while sharing a single public IP address from your ISP. It only works correctly when one device does it. When two devices both perform NAT in sequence, they create conflicts that surface as:
- VPN connection drops: traditional VPNs like IPsec and OpenVPN fail mid-session under Double NAT. Modern WireGuard-based VPNs are more resilient but still perform better with a clean single-NAT connection.
- VoIP and video call problems: business phone systems and video conferencing tools experience one-way audio, severe jitter, and call drops because voice packets can't route properly through two NAT layers.
- Broken QoS: when two routers each have their own QoS settings, they conflict — your carefully configured rules may be overridden by the ISP gateway's own traffic management.
- Failed port forwarding: any service requiring inbound connections — VPN servers, remote desktop, IP cameras — silently fails because the outer device doesn't know to forward traffic to the inner network.
Win+R, type cmd) or Terminal (Mac). Type tracert 8.8.8.8 (Windows) or traceroute 8.8.8.8 (Mac/Linux) and press Enter. Look at the first two hops. If hop 1 shows a private IP (192.168.x.x) and hop 2 also shows a private IP — you have Double NAT. If hop 2 is a public IP, you have single NAT and bridge mode isn't needed.Before You Start: What to Prepare
Bridge mode takes 15–20 minutes and is fully reversible. Complete these four preparation steps first.
- Write down your current Wi-Fi name and password. Bridge mode disables the gateway's own Wi-Fi — any connected devices will need to reconnect to your personal router's network afterward.
- Have your personal router connected and ready — physically connected to the ISP gateway via Ethernet cable, gateway LAN port to router WAN/Internet port.
- Know that you will lose internet briefly — usually one to three minutes while the gateway restarts. Schedule this during a break, not during a call.
- Note your ISP gateway's admin IP and login credentials — usually printed on a sticker on the device itself, typically
192.168.0.1or192.168.1.1.
Universal Bridge Mode Steps (Works on Most Routers)
If your ISP isn't Xfinity, AT&T, or Spectrum — or you want to confirm the general process before following brand-specific steps — use this method.
- Connect your computer directly to the ISP gateway using an Ethernet cable — not through your personal router.
- Open a web browser and navigate to the gateway address, usually
http://192.168.1.1orhttp://192.168.0.1. The login password is typically on a sticker on the device. - Once logged in, look for an Advanced Configuration, WAN Setup, or Firewall menu. Search for "Bridge Mode," "Bridging," or "Modem Only."
- Enable bridge mode. Some gateways ask you to confirm — accept the warning. The gateway will restart.
- After the gateway restarts (allow 2–3 minutes), ensure the Ethernet cable from the gateway runs to the WAN/Internet port on your personal router. Restart your personal router.
- After your router restarts, run a speed test and a traceroute to confirm single NAT — hop 1 should be your router's IP, hop 2 should be a public IP.

Bridge Mode by ISP
Xfinity's bridge mode disables the gateway's routing, Wi-Fi, and NAT functions entirely. Important: enabling it disables xFi Advanced Security, xFi Pods, and parental controls tied to the gateway — your personal router handles all security from this point forward.
- Connect your computer to the Xfinity gateway via Ethernet.
- Open a browser and go to
10.0.0.1(not 192.168.1.1). - Log in — default username "admin," default password "password," or your custom credentials.
- Navigate to Gateway → At a Glance.
- Find "Bridge Mode." Click "Enable Bridge Mode."
- Confirm the warning by clicking "OK" or "Enable."
- Connect an Ethernet cable from a gateway LAN port to your router's WAN/Internet port. Only your personal router should be connected via Ethernet while in bridge mode.
- Wait 3–5 minutes for the gateway to fully restart, then restart your router. Confirm connectivity and run a traceroute — hop 2 should now show a public IP.
Troubleshooting: if you get no connectivity, check the cable connects gateway LAN to router WAN — not LAN to LAN. Confirm your router's WAN is set to obtain an IP automatically via DHCP, then reboot the gateway and wait for all lights to stabilize before rebooting the router.
AT&T fiber gateways don't offer traditional bridge mode. Instead, IP Passthrough accomplishes the same result: the public IP address is passed directly to your router, and the gateway stops performing NAT for your traffic.
- Connect your computer to the AT&T gateway via Ethernet.
- Open a browser and navigate to
192.168.1.254. - Log in using the "Device Access Code" printed on a sticker on the gateway.
- Navigate to Firewall → IP Passthrough.
- Set Allocation Mode to "Passthrough."
- Set Passthrough Mode to "DHCPS-fixed."
- In "Passthrough Fixed MAC Address," select your router's MAC address from the dropdown — your router must already be connected for it to appear.
- Click Save. After 1–2 minutes, your router will receive the public IP directly.
If Spectrum provided a modem only, you don't need bridge mode — plug your router into the modem's LAN port and you're done. Bridge mode is only relevant if Spectrum supplied a gateway (modem + router combined).
- Connect your computer to the Spectrum gateway via Ethernet.
- Open a browser and navigate to
192.168.0.1. - Log in — default username "admin," password "admin" or printed on the device sticker.
- Navigate to Advanced → Options or WAN Setup (label varies by model).
- Look for "Bridge Mode," "Router Mode," or "IP Passthrough." Toggle it to Bridge Mode or Disabled routing.
- Save and allow the gateway to restart. Connect your router's WAN port to the gateway's LAN port and restart the router.
If you don't see the option: some older Arris models don't expose bridge mode at all. Call Spectrum (1-833-267-6094) and request they enable it remotely, or ask about switching to "modem only" mode. Spectrum also allows customers to use their own approved modem.
After Bridge Mode: What to Check and Configure
Once bridge mode is active, run through this checklist to confirm everything is working correctly.
- Confirm single NAT with a traceroute. Hop 1 should be your router's IP, hop 2 a public IP. If hop 2 is still private, check that the gateway is fully bridged and your router's WAN port is connected to the gateway's LAN port, not its WAN port.
- Run a speed test and compare. Most remote workers see a modest latency improvement — 2–8ms lower ping — and more consistent results during peak household usage hours.
- Re-verify your QoS settings. With sole authority now, log into your router's admin panel and confirm your QoS rules are still in place — work laptop as highest priority, video conferencing as top category.
- Reconnect all Wi-Fi devices to your router. Smart home devices, TVs, streaming sticks, and game consoles previously on the gateway's Wi-Fi need to switch networks.
- Test your VPN. Connect and run a speed test and latency check — sessions that were dropping mid-call under Double NAT should now hold steady.
When Bridge Mode Is Not the Right Answer
Bridge mode is the correct solution for most home office Double NAT problems — but after reviewing 40+ home office network setups, we identified three specific situations where it isn't the right approach, and attempting it causes more problems than it solves.
Confirm CGNAT by checking whether your public IP (at whatismyip.com) matches your router's WAN IP. If they differ, you're behind CGNAT. Want the technical background? Read this overview of carrier-grade NAT.
Bridge Mode vs. Access Point Mode: Which Do You Need?
Remote workers sometimes confuse the two — they sound similar but solve opposite problems.
| Mode | What It Does | When to Use It |
|---|---|---|
| Bridge mode | Disables routing on the ISP gateway — your personal router takes over as the network manager | You have an ISP gateway + personal router, and want the personal router fully in charge |
| AP mode | Disables routing on your personal router — the ISP gateway stays as the network manager | Your ISP gateway works well and you just want to extend Wi-Fi coverage using a second device |
For remote workers with a quality personal router (ASUS, TP-Link, Netgear) and an ISP gateway — bridge mode is almost always the right choice. AP mode is for adding coverage, not improving network control.
Pro Tips for a Smooth Setup
- Label which port on the gateway your router is connected to. If you ever unplug and replug cables during troubleshooting, you'll know exactly where everything belongs.
- Keep the gateway's admin page bookmarked. You'll rarely need it after bridge mode, but if you ever need to disable it, you'll need direct Ethernet access.
- Run your router as the Wi-Fi manager, not the gateway. Turn off the gateway's Wi-Fi entirely — two networks in the same space create interference and confuse devices.
- Give your router's network a different name than the old gateway's. Matching SSIDs make the transition, and future troubleshooting, harder than it needs to be.
- Re-run the QoS setup after bridge mode is confirmed. Some routers adjust traffic management once they receive a true public IP rather than a private one through Double NAT.
- Ask your employer to cover the gear. Many companies reimburse networking equipment. Our WFH equipment request form template makes the request quick.
Common Mistakes When Setting Up Bridge Mode
Frequently Asked Questions
Just a Modem Now — and That's Exactly What It's Best At
Bridge mode is the step that transforms a mediocre home office network into a properly configured one — particularly for remote workers who have already invested in a quality router but are still experiencing VPN drops, unreliable QoS, or inconsistent call quality.
The setup takes 15–20 minutes. The improvement lasts for as long as you have that router. Run the traceroute test afterward to confirm single NAT — and then forget the ISP gateway exists.
Network sorted? The next upgrade worth making is your screen. See our best monitors for remote work in 2026.

Add a Comment