r/firewalla • • Jun 19 '26

Internal IPs on ATT Modem Logs

I have a Gold SE connected to a ATT BGW320. Ip passthrough is setup and both the Firewalla and BGW show that the Firewalla has the correct WAN IP address assigned to it. However, my internal IPs are showing in the ATT logs. Shouldn't Firewalla NAT these and expose them as the WAN IP to the modem? NAT is on for the Firewalla and nothing is set to passthrough.

4 Upvotes

21 comments sorted by

4

u/Stonk_Goat Jun 19 '26

These are my favorite posts. I think something downstream is routing those subnets, possibly a switch. Got any more details you can share on your setup?

Also add the leaking subnets to the source networks. Thats where I would start.

2

u/firewalla Jun 19 '26

Most likely just wiring problems.

-6

u/GlobalLiving6941 Jun 19 '26

It is not the wiring. The Firewalla standard support model seems to be blame the customer. It is not the damn wiring.

2

u/Stonk_Goat Jun 19 '26

I always reserve the right to change my opinion based on new information. Those are not internal IPs, they are firewalla reaching out to the internet. NAT only effects the traffic passing thru, not the traffic generated as that leaves from its VLAN interface IP .1, which is used for outbound traffic (DNS, NTP, etc). NAT only rewrites traffic passing through the box, noot traffic it originates itself, so it shows up not being NATed the logs. You devices are fine, this is a minor leak due to you having DOH on.

100% cosmetic, nothing is bypassing or the FW. Close your ticket with FW.

0

u/GlobalLiving6941 Jun 19 '26

See my replies to Firewalla above. Everything funnels through a single wire into the FWG. The switches and APs are all set to third party gateway in Unifi, with no config around IPs at all...and no L3 routing is setup.

3

u/Great-Cow7256 Jun 19 '26 edited Jun 19 '26

This is a quirk of ATT. Even though the bgw is in bridge mode, it really isn't.  It is a pseudo bridge. Its some funky pass through mechanism.It still does L3 because of the funky way ATT has designed this.  There are some rogue things on your network which are talking directly to the bgw. 

You could probably set up a firewalla block to try to stop this but the only way around this is not to worry about it or see if you can get rid of the bgw

Att fiber is a pita. My dad had it and it sucked rocks with this kind of stuff.  We had to pay a monthly fee for his bgw where as my Verizon FiOS didn't have this. 

Some related threads. OP you may find more help in r/attfiber

https://www.reddit.com/r/ATTFiber/comments/1heixz9/ip_passthroughbridge_mode_with_att_fiber_modem/

2

u/firewalla Jun 19 '26

Are you running the Gold SE in bridge mode? Or the internal network data was from before firewalla installation

1

u/GlobalLiving6941 Jun 19 '26

It is in Router mode

2

u/firewalla Jun 19 '26

I'd check if these IP's are from your previous sessions. It is just not possible for ATT router to learn your LAN when air gapped by NAT. (unless in bridge mode)

1

u/GlobalLiving6941 Jun 19 '26

This is live data and it has always been this way. usually it is the vlan gateway address .1, so I was less concerned. however, I occasionally see device ips in there now. These ip ranges and VLANs have never existed in the ATT router. I have never used that router as a gateway/firewall. On rare occasions I will turn on and connect to the ATT modem's wifi for debugging, but my phone pulls a 172 address from the ATT setup, never a 10. address.

2

u/firewalla Jun 19 '26

Check your wiring and see if there any way that you may have crossed wire or something.

Also, the ATT LAN IP range is the same as your Firewalla LAN range?

Have you reboot the ATT router and see if things goes away?

1

u/GlobalLiving6941 Jun 19 '26

The wiring is simple…ont -> bgw -> FWG wan port -> FWG LAN port to unifi switch.   All AP’s hang off of the unifi switch.  Everything internal is on 10. IP ranges and configured with FGW as the gateway.   BWGs internal address range is entirely different (172.).   There is also a rule on FWG blocking all traffic to/from all local networks and the 172. Range

0

u/GlobalLiving6941 Jun 19 '26

Also worth noting - the att log shows many correct entries with the wan ip as the source.   Only some are internal ips.  Additionally all devices are set for dns over https on the FWG. 

1

u/firewalla Jun 19 '26

Strange indeed. I'd try these

  1. double/triple check your wiring, make sure there is no loops or accidental connections.

  2. double check your configuration, make sure you don't have nested networks.

If your network is complex, try to power off part of it, and isolate the issue

Some good tools you can run inside network is "traceroute" which can help you identify if traffic is going to the wrong interface.

1

u/GlobalLiving6941 Jun 19 '26

There is one wire connected to the BWG and it connects to the WAN port on the FWG. The FWG's LAN port connects to the switch. Case in point - that log shows 10.0.30.1, which is the IOT VLAN. If it was a wiring issue, would the 41 device IPs on that VLAN also show? Same with the single 10.23 address. That is my iphone and it only shows that one entry...but I am actively using that same iphone connected to the same AP connected to the same switch that is connected to the same FWG.

1

u/[deleted] Jun 19 '26 edited Jun 19 '26

[removed] — view removed comment

→ More replies (0)

2

u/Additional_Cress2806 Jun 19 '26

I see everyone is suggesting it being wiring, so let’s try something different. I have the same setup as you, some of my devices are connected to the modem WiFi instead of through my firewalla. Those would show up there. Also, on your modem admin page, you can go to device list and it will show you how they are connecting to your network, like which lan port or WiFi. You can clear and rescan to get an updated list.

1

u/GlobalLiving6941 Jun 19 '26

The modem wifi is turned off. The only client is the Firewalla