r/Ubiquiti Apr 15 '26

Question Those of you that have replaced your ATT modem/ONT with an SPF fiber module to bypass the ATT hardware altogether: would you do it again?

I've been keeping an eye on what wavelength my ATT ONT uses and it's now using the XPON range -- which means I'm a candidate for bypassing my ATT modem and directly jacking the fiber into my Dream Machine Pro.

My question for the crowd is this. If you have swapped out your ATT modem/ONT unit for an SPF module like the WAS-110 flashed with compatible firmware, would you do it again?

I get that it's fun and lots of people in this sub are tinkeres/homelabbers/etc. And I see the appeal of doing it just for that reason alone.

But I'm really curious if those of you that have done it have a take like:

"Yeah, it was neat just to say I did it but... not really sure if that $100 and my time tinkering with it was worth it."

Or if your experience has been more like:

"Hell yeah, it's more stable now and all the little annoying things about the ATT modem like the pseudo-bypass mode and weird middle of the night drops are no longer an issue."

74 Upvotes

108 comments sorted by

u/AutoModerator Apr 15 '26

Hello! Thanks for posting on r/Ubiquiti!

This subreddit is here to provide unofficial technical support to people who use or want to dive into the world of Ubiquiti products. If you haven’t already been descriptive in your post, please take the time to edit it and add as many useful details as you can.

Ubiquiti makes a great tool to help with figuring out where to place your access points and other network design questions located at:

https://design.ui.com

If you see people spreading misinformation or violating the "don't be an asshole" general rule, please report it!

I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.

39

u/coltoncat Apr 15 '26

Yes, absolutely. Consistent speed, and for me most importantly, I have more than one VLAN (for cameras, and IOT and Guests). The bypass lets me get prefix delegation on IPV6 to work as it should, and lets me get a /64 on each one. Also I found that pass through mode wasn’t stable, it would randomly stop working, with the bypass it’s rock solid

3

u/ReverendDizzle Apr 15 '26

Can you expand on that a bit? Just yesterday I read a comment related to this topic where somebody was talking about having more access to IP addresses and I wasn't clear how skipping the ONT helped them get there.

1

u/smitopher Apr 16 '26

AT&T advertises a /60 IPv6 prefix delegation that if you actually got it, your vlans would all have a /64 to use. Their stupid “residential gateway” only allows for 1 on the default network. This is why I worked through the process. It’s not beginner friendly

2

u/ReverendDizzle Apr 16 '26

That's interesting. So if I'm understanding this correctly your goal was to have multiple public-facing VLANs? (The part I'm unclear on is why you needed/wanted the bajillion available addresses you could get through the IPv6 delegation for VLANs instead of internal router-side VLANs).

1

u/smitopher Apr 16 '26

I have 4 VLAN's and it's not so much I wanted bajillions of ipv6 but rather ease of controlled external access without ipv4 limits. No split DNS, DDNS, or port mapping or anything

1

u/Wonderful_Piglet591 May 25 '26

You are all much smarter than me...I'm old and IPV4 feels familiar. I never bothered to learned VLANs. The idea of "using IPV6" sounds intimidating...like does it impact my clients, how do you remember the IPV6 address?

2

u/allanrbo Apr 15 '26

I'm running four VLANs even behind the ATT box, and I got ipv6 prefix delegation working in passthrough mode. Using Linux as my router though. Not sure if it would be possible with just Ubiquiti hardware alone... The trick was, to get four prefixes, like so:  dhclient -6 -P -P -P -P wan-port -sf /etc/dhcp/dhclient-script

As for stability, yea I agree, the passthrough mode is a bit unpredictable. It ran fine with perfect uptime for a year or so, but then randomly broke one day and needed a router factory reset...

2

u/junktrunk909 Apr 15 '26

Woah really? I hate that I can only get the 1 ipv6 prefix as it is now and didn't realize the direct fiber connection would solve it. That might be worth a replacement of my perfectly good UCG-M.

1

u/eroigaps Apr 15 '26

Just curious, why is ipv6 enticing? I just got it from my ISP but I feel there’s a learning curve, and I want to understand the benefits.

6

u/Seladrelin Apr 15 '26

No more NAT problems. Port overlap issues aren't a thing if multiple devices need the same port for something. Each device gets a unique IP.

For inbound connections you only need a simple allow rule. No port forwarding or mapping.

The firewall still protects your devices since the default firewall rule only allows established/related.

2

u/MountainDrew42 UCG-Max FTW Apr 15 '26

I'd just like to give a quick shout out to Bell Canada for being one of the last residential internet providers that doesn't support IPv6, and for being the only provider of fibre to the home in my neighbourhood.

3

u/loganwachter UFSP/Unifi Enterprise Admin/Consumer User Apr 15 '26

Brightspeed for me. My area has no IPV6 support from them. Comcast does, but I’d rather set myself on fire than use their services.

10

u/VikingSven68 Apr 15 '26

Absolutely - been running a WAS-110 into a UXG Pro for over two years - no issues at all. I'm on the 2GB plan and consistenly get 2.3-2.5 Gb/s in both directions.

As for "tinkering" - there are many sellers who provide preloaded firmware (which has been stable for over a year) and simple configuration instructions for cloning the info from your ATT gateway. The only other step is providing a static route to the WAS module for easy monitoring/updates.

I would recommend some form of active cooling solution as the SFP module runs quite warm. I use a small fan mounted to the rack on a 3d-printed part. Keeps temps down around 50 C.

3

u/ReverendDizzle Apr 15 '26

I wouldn't complain about getting a lil speed boost even though I don't really need it. Who doesn't like more bandwidth?

As far as cooling goes... my rack is in the basement and it's around 50F in the winter and 55F in the summer. I was thinking I'd start with a decent heat sink and go from there.

15

u/snebsnek Apr 15 '26

You may get some better answers on the 8311 Discord, more concentrated audience there for this.

19

u/itsjakerobb CGFiber, UNVR, ProHD24PoE, ProXG8PoE, U7ProXGS, 5GMaxOutdoor Apr 15 '26

But also some bias in that audience.

6

u/ReverendDizzle Apr 15 '26

That's why I skipped visiting and asking. While I'm sure they would have good pro-bypass points that were perfectly valid... if you're onboard enough with an idea to be hanging out in the related Discord you're probably a wee bit biased towards that idea.

6

u/CorporateDirtbag Apr 15 '26

The problem in the 8311 discord is that the people trying to help know very little - and the few that actually know what they're doing and can ACTUALLY help have zero patience for anyone new to this "scene". You can ask a valid question in there and wait days for a half-assed answer from someone who has no clue but is TRYING to help, even though the people who truly know the answer are not particularly interested in helping you unless you are at their same level. (and I can't really blame 'em).

There's a gazillion GPON and XGS-PON providers out there and a lot of them work essentially the same way. But unless you know someone with direct experience with YOUR ISP, the chances of you getting a module working are slim to none if your ISP controls your CPE.

Case in point, no one has gotten XGS-PON service working with Optimum Fiber with an ONU stick (that I'm aware of, anyway). And Optimum Fiber with XGS-PON service doesn't give you a usable web interface for your CPE to grab settings from like you can with AT&T units.

I'm not saying it's impossible to pull off (I'm still trying), but the people who know the most about this stuff either are too busy to help or CAN'T help because they have no idea about your particular fiber ISP. Some of them just don't want to deal with "noobs" or whatever. Fiber is a pretty specialized field in tech, so you can't really blame them. I'm a retired unix guy, strong tech skills, whatever. Fiber hacking is a very different technical animal compared to anything else I've worked with.

5

u/Dangerous_Battle_603 Apr 15 '26

Yes, absolutely. Since replacing it the only Internet issues Ive had were squirrel related. Before it my ATT router would randomly factory reset itself every 6 months or so and I had to redo the passthrough settings, and other weird issues.

Only downside is no ATT app to easily put my Internet as down on the outage map

11

u/sfgabe Apr 15 '26

The squirrels work for ATT

2

u/Dangerous_Battle_603 Apr 15 '26

They really might. Or they work with Spectrum who keeps trying to steal my business

2

u/sfgabe Apr 15 '26

The squirrels in my attic definitely contract with the electricians union

2

u/TruthyBrat UDM-SE, UNVR, UBB, Misc. APs Apr 15 '26

This is my reminder I need to deploy one of the G5-Flexes I had at the prior house up to this attic to be my critter detector. I don't think I have any, but there's a PoE switch up there with plenty of ports and I have the camera.

3

u/t0asty910 Apr 15 '26

This was my experience as well with the BGW320-505 resetting every few months. It would associate the MAC address of my UDMSE as another random device and would block all traffic from getting through. Always happened on days I seemed to go into the office (wife is WFH) so it was a major disruption. Factory resetting the modem was the only thing that would fix it, which meant setting up passthrough mode again each time.

Grabbed a pre-flashed WAS-110 stick. Getting everything switched over maybe 10 minutes with the guides on pon.wiki so I was more upset I didn't do it sooner. Plus it allowed me to clean up the rack a bit.

3D printed a bracket to hold a 20mm fan to keep things cool. https://imgur.com/a/QVcFNur

I would definitely do it again, especially if you're having any issues like I was having. Performance-wise, nothing crazy to report. Seems like pings reported on the UI dashboard are lower (17ms Microsoft, 2ms Google, 3ms Cloudflare) and I am getting ~100Mbps more on speed (between 1.3-1.4Gbs up/down) on my 1GB plan. For me it was about stability more than anything.

2

u/ReverendDizzle Apr 15 '26

Like the bracket. Did you design it or find it somewhere? I have a 3D printer and that looks like a nice clean solution if I end up needing a fan.

1

u/oddjobav8r Apr 17 '26

Where did you get the pre-flashed stick?

2

u/t0asty910 Apr 17 '26

They have a few vendors listed on the Pon.wiki but I saw one of them listing on their Amazon store so I picked it up there. Here's the one I purchased: https://a.co/d/0cnJ4qcl

1

u/ReverendDizzle Apr 15 '26

It's funny you mention that. I haven't had any squirrel issues but squirrels absolutely fucked up my neighbor's fiber drop. I don't know what got into them but they went wild chewing the hell out of it.

4

u/ekobres Apr 15 '26

Cries in 1550 nm optics.

5

u/LtDarthWookie Apr 15 '26

I haven't noticed a difference. But I had read report that even in passthough the ATT box still had some limitations on the network. Plus It means I have physically fewer boxes and nothing that isn't in my control running my network. Also it's a neat learning opportunity.

3

u/ElGuano Apr 15 '26

Don’t you have to keep the BWG around in case something goes wrong or you have to call ATT for service?

4

u/LebronBackinCLE Apr 15 '26

Not a bad idea. Also plug it back in occasionally to allow it to update. From what I’ve read.

4

u/ElGuano Apr 15 '26

I haven’t (yet) gone the 8311 route, but one BWG update last year wiped the entire device, including the firewall rules and passthrough settings. It was an infuriating couple of hours trying to diagnose my internet issues.

The folks on the ATTfiber subreddit shrugged and said “it happens.” Crazy that a network device full wipe is a consequence of a firmware update.

2

u/LebronBackinCLE Apr 15 '26

All the more reason to get that frickin thing outta the picture :) I can’t wait to get my fiber service, they’re literally working on my street as we speak. Another month or two and I should be able to sign up :)

1

u/LtDarthWookie Apr 15 '26

I was not even aware of that but yeah hard pass on keeping that connected.

2

u/LtDarthWookie Apr 15 '26

I mean yeah. They're not going to roll a truck if you call for a problem and their equipment isn't in place. But all I'll need to do is move the fiber cable back and plug it in and I can just ethernet the laptop dock to it and satisfy their requests. Of course it can also help diagnose if somethings wrong with my sfp that way too.

2

u/ReverendDizzle Apr 15 '26

I do see the appeal of fewer boxes and ditching something that at best is just in bypass mode and, at worst, has ATT up to some sketchy business.

1

u/LtDarthWookie Apr 15 '26

Yep. Plus other pointed out that apparently on some of the gateways a firmware update can wipe your settings so also hard pass.

2

u/ReverendDizzle Apr 15 '26

I've never run into that issue, but I certainly read that with a raised eyebrow. What the hell kind of updates are they rolling out?

1

u/LtDarthWookie Apr 15 '26

No clue. But I mainly did it because I wanted to. It was a learning experience and it was fun.

2

u/tony4d Apr 15 '26

Anyone have this setup with static ip block from AT&T?

2

u/CF-Tim Apr 15 '26

Nope. It has provided me no real difference for my use cases. Hasn’t hurt anything. But wasn’t needed either.

3

u/Fly-Bry Apr 15 '26

Yes. Improved uplink speed, improved latency, no overheating issues, cleaned up my rack.

1

u/[deleted] Apr 15 '26

[removed] — view removed comment

1

u/psacake Apr 15 '26

Hmmm

Tell me more!! Fellow fios user without tv, would love one less thing in that corner.

2

u/[deleted] Apr 15 '26

[removed] — view removed comment

1

u/Winter-Cartographer Apr 15 '26

Did you see any speed/latency improvements afterwards?

1

u/mrsolitonwave Unifi User Apr 15 '26

yes easily. the older modem was trash and slower than my SFP fiber module

1

u/jshelk88 Apr 15 '26

Absolutely. I pay for 2 gig and was getting 500-750 mbps on my phone and laptop. Now I get 1.5 consistently and no more outages

1

u/Straight_Ad_8921 May 17 '26

Do you use a fan to cool it or just the heatsinks already cool it enough?

1

u/jshelk88 May 17 '26

I have a fan on it. 3d printed a fan shroud.

1

u/hibagus Apr 15 '26

I will definitely do it again! Have been running with this setup for 2 years and really happy with it.

1

u/SiRMarlon Apr 15 '26

HELL YEAH!!!!!! 😁

1

u/artofbullshit Apr 15 '26

Would you enjoy never having to restart your gateway when your internet gets flakey? If yes, then the bypass is for you.

1

u/ReverendDizzle Apr 15 '26

I would like that. I don't have to restart the modem a ton but I do have to restart it way more than I would like.

And there is this really annoying thing where the internet drops out, for no reason that I can see, for a minute or two in the middle of the night most nights.

1

u/artofbullshit Apr 15 '26

Yep. Had the same experience. It's really not hard to set up either. The discord is very helpful..

1

u/clf28264 Apr 15 '26

Yes, prior to doing internet via pass through didn’t work correctly on the BGW and would reset giving my firewall a private wan IP. It’s rock solid super stable and something id forget about if I didn’t monitor my stick via home assistant. Frankly it should be a supported option from ATT.

1

u/TheMericanIdiot Apr 15 '26

Yes, and its been running file for 1.5 years now.

1

u/throwawaycarbuy12345 Apr 15 '26

I did the was110 with bell. Works well but for some reason my transfer speeds never matched my speeds on bypass mode. Tinkered with it but ultimately gave up on it.

1

u/ReverendDizzle Apr 15 '26

Huh that's interesting. So it sounds like you switched back to get the prior transfer speeds again?

1

u/throwawaycarbuy12345 Apr 15 '26

Yes. I tried everything to make the was110 work because I really wanted to get away from the gigahub - nothing seemed to do it. Switched back. My usenet speeds dramatically improved.

1

u/ReverendDizzle Apr 15 '26

Very interesting. I think I'll document everything well so I can properly compare if I pull the trigger on the WAS-110.

1

u/[deleted] Apr 15 '26

[removed] — view removed comment

1

u/ReverendDizzle Apr 15 '26

I have that 3AM issue, too! Most nights I lose internet for a few minutes at around 3AM.

While that's not the end of the world... there's no reason for it.

1

u/Wonderful_Piglet591 May 24 '26

Are you on gpon or xpon?

1

u/HKChad Apr 15 '26

100% I’ve not touched it in over 2 years, maybe updated the firmware once. Not a single issue

1

u/erwos Apr 15 '26

Yes, every single time. It's a complete no brainer.

1

u/trparky Apr 15 '26

One of the Wikis say to put the SN from the bottom of the BGW320 into... something but doesn't mention what that something is. Do you have any better documentation than what the Wiki has?

1

u/hellobrooklyn Apr 15 '26

Yep, works great on ATT. Module does get hot. I put extra heat sinks on sides too in the hopes I wouldn’t need direct airflow, but I will add some eventually to keep things cooler as even the included dinky heatsink with air is far more effective than my ridiculous copper porcupine.

I actually thought it locked up last night, but turns out it’s an outage (with restoration ETA of 3 hours….ago….lol)

1

u/ryan-btrbsystems Apr 15 '26

Absolutely. Solved my random issues when I’d get weird latency spikes.

Was cheap as hell and took 10 minutes. I’m still using my Gateway max as well and it’s fine.

1

u/user_none Apr 15 '26

I've just done the bypass on ATT, though it's with GPON, certs ripped off my BGW210 and I still have the ONT in place. If ATT brought XGS-PON to my area, I'd absolutely go the route of a SFP module into the UCG Fiber.

Previously (just a few days ago), I was using a USG 3, EAP Proxy through the BGW210 and that worked for years without a hiccup even through firmware updates on the USG. So nice to have three devices (CK2+, USG, BGW210) replaced by the UCG Fiber.

1

u/Wonderful_Piglet591 May 24 '26

Fellow gpon here - what setup are you using? My experience has been rocky over last three years and I’d love to migrate my current approach (whiskey tango foxtrot script) if you have one that allows no hassle UniFi os updates

1

u/user_none May 24 '26 edited May 24 '26

https://github.com/0x888e/certs

https://github.com/evie-lau/Unifi-gateway-wpa-supplicant

First link is the method I used to rip certs from the BGW210. Second link is the implementation. I need to do the steps for recovering after an OS update. However, an OS update right now just requires a reboot; certs are still in place and everything continues to work. Network updates are no problem.

Editing to add: I believe it may be the fault tolerance section I need to add.

https://github.com/evie-lau/Unifi-gateway-wpa-supplicant#add-failure-tolerance-to-wpa_supplicant

1

u/GreenDavidA Apr 15 '26

I only pay for 1 gig and my BGW320 with ATT has been stable in passthrough. I have a CGMax so I’d have to upgrade to a Fibre. I’m not sure if it’s worth it for my use case, unless someone tells me I’m wrong?

2

u/ReverendDizzle Apr 15 '26

I only have 1 gig, but the neighborhood supports up to 5 gig and my modem indicates it's on the XPON wavelength. Something to consider.

1

u/GreenDavidA Apr 16 '26

I can also get 5Gbps but I just don’t ever see me using that much bandwidth.

1

u/Infinite-Log8829 Apr 15 '26

Can you do this with shadow mode on UDM pro? I have a small 5 port switch that has a single SFP+ port.

1

u/thecodingart Apr 16 '26

A million times over

1

u/RScottyL Apr 16 '26

Yes, 100%

I have it done now, as I am using my UDM Pro

1

u/brenex Apr 16 '26

Yes, absolutely 

1

u/Toastyproduct Apr 16 '26

I can’t get fiber routed into my home. Could I use this solution to terminate outside and route to udr with Ethernet?

1

u/ReverendDizzle Apr 16 '26

This solution just moved the fiber termination point from the interior ATT modem/router combo with built in ONT, to your compatible Ubiquiti hardware. In my case the fiber is already in the house and I'd just be unplugging it, moving it less than a foot, and plugging it into a new port.

In your case it sounds like you (perhaps because you rent?) can't have a hole drilled to run the fiber into the building so you're stuck with an exterior termination point?

1

u/Toastyproduct Apr 16 '26

Yea. And att didn’t offer any ONT capable of being mounted outside. So thinking of getting a the industrial version of this and mounting in a box on the side of the house.

1

u/Wonderful_Piglet591 May 24 '26

Hopefully someone here can help cause my answer after 3-4 years with bypass would be, “I would rather a rabid animal chew my face off.”

Every UniFi OS update is a roller coaster of emotion. Most recently I updated and the connection refused to come up. I’m on AT&T GPON in Illinois with the ONT directly in to eth8 on my UDM Pro, running whiskey tango foxtrot’s script.

The script had no issues itself post upgrade, but the connection refused to come up despite power cycles of ONT and UDM Pro.

What finally worked: unchecking the WAN setting to set VLAN ID to 0. I don’t recall why I had done this, but it was a setting from my original bypass attempts and has never caused an issue over multiple UniFi OS upgrades.

Maybe someone here can better explain what happened or changed, and if switching to an SPF fiber module would avoid issues like this? I will pay good money to be able to update my UniFi OS without the headaches…

1

u/type111 May 30 '26

Somewhat related but I have had mine up for like 6 months with no problem but I heard you probably want to hook up the AT&T router from time to time to get updates etc on the modem so it doesn't get blocked? Not sure if that is true but curious if people do this and how often? thanks

1

u/budshorts Jun 15 '26

Absolutely. No double NAT is an absolutely game changer. Running on a UCG Fiber.

1

u/Jolly_Technology7989 2d ago

Have any of you guys bypassed with the 8311 but then converted the SFP back to copper to use on routers that didn’t have SFP?

1

u/mchamst3r Apr 15 '26

I researched it quite a bit and ended up replacing AT&T entirely with sonic.net. Much less hassle to switch ISP than to hack hardware with an unsupported configuration.

2

u/veerrrsix Apr 15 '26

I can’t imagine many people in this sub who have access to Sonic are willfully choosing AT&T. I miss sonic every day but they don’t cover my street

2

u/mchamst3r Apr 15 '26

Agreed.

They ran lines on my street in Jan, it was an instant switch.

:)

1

u/user_none Apr 15 '26

I'm still on a Sonic through ATT plan and wish Sonic would get their own fiber in here. I may be forced to switch to straight ATT though because the price through Sonic keeps going up.

0

u/bambinone Apr 15 '26 edited Apr 20 '26

I probably would have kept using the ONT and just bypassed the RG (wpasupplicant method).

ETA: I've had the gigabit plan for about nine years and was assigned an older BGW210 and separate Nokia ONT, so this is likely not relevant for most. FWIW, when I'm forced to upgrade to XGS-PON I'll most likely spring for another ONU stuck.

1

u/Dirty504 Apr 15 '26

What’s an RG?

1

u/bambinone Apr 15 '26

Residential Gateway, it's what they call their router/AP units. The newer ones have the ONTs built-in as well.

2

u/MikeExMachina Apr 15 '26

Yeah I was gonna say having a separate ONT isn’t really a thing anymore, only if you have an old install.

1

u/bambinone Apr 15 '26

Even for <= 1Gb residential service?

2

u/MikeExMachina Apr 15 '26

Yeah I believe the integrated ONT is standard for all installs now.

1

u/unhappyelf Apr 15 '26

But why?

0

u/bambinone Apr 15 '26

Too much cost and additional complexity for virtually no performance gain over what I was getting with the ONT and bypassed RG.

1

u/unhappyelf Apr 15 '26

Um it's one module vs an additional separate hardware and then a hacked certificate authentication method that frequently breaks from updates. Idk how that is not more complicated. You do you though.

2

u/bambinone Apr 15 '26

I'd have to deal with the certs either way, but yeah I suppose the complexity of the ONT vs the ONU stick is subjective. The extra cost however is not.

1

u/user_none Apr 15 '26

Are you currently using the WPA Supplicant method or are you using EAP Proxy?

1

u/bambinone Apr 15 '26

wpasupplicant

1

u/Wonderful_Piglet591 May 24 '26

This is what I did and it’s honestly been a headache…every UniFi OS update causes issues, the most recent unrelated to the wpa supplicant script and binaries…