Running a Rogers XB8 with your own router plugged into it creates double NAT — two devices doing network address translation on the same connection — which breaks port forwarding, disrupts VPNs, and leaves your DNS controlled by hardware you can't fully configure. Enabling IP Passthrough (Rogers' term for bridge mode) eliminates this by handing your router the public IP and full control over DHCP and DNS. This guide walks through the exact XB8 admin paths, the DNS changes that follow, how to configure your resolver correctly, and how to verify everything with CLI tools across Windows, macOS, and Linux.
What XB8 IP Passthrough Actually Does
The Rogers XB8 firmware does not use the label "bridge mode" — the setting is called IP Passthrough. The result is the same: the XB8 stops acting as a router and forwards your Rogers public IP directly to the WAN port of your own router. The XB8 continues handling the DOCSIS cable modem functions and stays reachable at 10.0.0.1 for management purposes, but routing, NAT, DHCP, and DNS shift entirely to your hardware.
Two passthrough sub-modes are available:
- DHCPS-Fixed — pins the passthrough to a specific MAC address you enter manually. This is the recommended choice: it survives XB8 reboots and firmware updates reliably.
- DHCPS-Dynamic — passes through to whatever device first requests a DHCP lease on the LAN side. Less predictable if you ever swap routers or power-cycle devices in the wrong order.
Before You Start
Collect two pieces of information before touching the XB8 admin panel:
- Your router's WAN MAC address — printed on the label on the bottom or back of your router, usually listed separately from the LAN/Wi-Fi MAC. Do not use the LAN MAC; they are different on every router.
- Your current Rogers DNS server IPs — check your laptop's network settings now, before enabling passthrough. If you later want CDN-aware resolution for Rogers-hosted content, you'll need these.
Step-by-Step: Enable IP Passthrough on the Rogers XB8
1. Log In to the XB8 Admin Panel
From any device connected to the XB8's network, navigate to http://10.0.0.1 in a browser. The login credentials are printed on the sticker on the bottom of the XB8:
- Username: cusadmin
- Password: the random alphanumeric string on the device label — not "admin" or "password"
If the label password fails, it was changed at some point. A factory reset (hold the recessed reset button for 30 seconds) restores it, but also wipes all custom Wi-Fi SSIDs and passwords.
2. Navigate to IP Passthrough
The menu path differs by firmware generation:
- Older firmware (pre-2024): Gateway > At a Glance > scroll to the bottom of the summary page > IP Passthrough section
- Current Rogers Ignite firmware (2024 onward): Gateway > Connection > IP Passthrough
If you see no "Connection" submenu under Gateway, you are on older firmware — use the At a Glance path and scroll past the network status cards.
3. Configure the Passthrough Settings
- Set the Passthrough Mode toggle to Enabled.
- Set Passthrough Type to DHCPS-Fixed.
- In the Fixed Device MAC Address field, enter your router's WAN MAC address in the format
AA:BB:CC:DD:EE:FF. - Click Save Settings (labelled "Apply" on some firmware versions).
4. Reboot in the Correct Order
The reboot sequence is where most failures happen. Wrong order = your router DHCP-requests before the XB8 applies the passthrough config.
- Power off your router completely.
- Reboot the XB8 via Gateway > Reboot, or unplug it from the wall.
- Wait until the XB8 is fully back online — the online/internet indicator solid, typically 2 to 3 minutes.
- Power on your router.
- Your router's WAN interface should receive your Rogers public IP via DHCP within 60 seconds.
Accessing the XB8 Admin Panel After Passthrough Is Enabled
This is a common surprise: once passthrough is active, devices behind your router cannot reach 10.0.0.1 because they are on your router's subnet (typically 192.168.1.x or 192.168.0.x), not the XB8's 10.0.0.x segment. To access the XB8 admin after enabling passthrough, either connect a laptop directly to one of the XB8's LAN ports with an Ethernet cable and manually set your laptop's IP to 10.0.0.2 / mask 255.0.0.0 / gateway 10.0.0.1 — or add a static route on your router pointing 10.0.0.0/8 toward the WAN interface. Most users just plug in directly when they need to change XB8 settings.
What Changes with DNS After Passthrough
Before passthrough, the XB8 hands out its own IP (10.0.0.1) as the DNS server to every device on your network. That resolver proxies queries upstream to Rogers' recursive resolvers. After passthrough, your router becomes the DHCP server and tells every client to use your router's IP (e.g., 192.168.1.1) as their DNS server. Whatever upstream DNS your router is configured to use is now what resolves every hostname on your network.
If you have not changed your router's upstream DNS settings, it will forward queries to whatever it learned from the XB8 via DHCP (typically Rogers' own servers), or fall back to the router vendor's hardcoded defaults. In either case, you likely want to set an explicit upstream resolver now that you have control.
Configuring DNS on Your Router After Passthrough
Open your router's admin panel and locate the WAN or Internet DNS settings. Exact paths by brand:
- Asus (asusrouter.com or 192.168.1.1): WAN > Internet Connection > WAN DNS Setting — set "Connect to DNS Server automatically" to No, then enter servers manually
- TP-Link (tplinkwifi.net or 192.168.0.1): Advanced > Network > Internet > DNS Address — enter Primary and Secondary DNS
- Netgear (routerlogin.net or 192.168.1.1): Internet > scroll to Domain Name Server (DNS) Address > select "Use These DNS Servers"
- Linksys (linksyssmartwifi.com or 192.168.1.1): Connectivity > Internet Settings > scroll to DNS > change to Manual
- Ubiquiti UniFi: Networks > [WAN network] > Edit > Advanced > DNS Server
- OpenWrt: Network > Interfaces > WAN > Edit > Advanced Settings > Use custom DNS servers
- DD-WRT: Setup > Basic Setup > Network Address Server Settings (DHCP) > Static DNS 1 and Static DNS 2
Recommended upstream resolvers in 2026:
- Cloudflare: 1.1.1.1 and 1.0.0.1 — fastest average latency from most Canadian ISPs
- Google Public DNS: 8.8.8.8 and 8.8.4.4 — see the Google Public DNS documentation for full configuration details and supported protocols
- Quad9: 9.9.9.9 and 149.112.112.112 — blocks known malicious domains at the resolver level
- NextDNS: custom resolver endpoint per account — excellent for per-device filtering and DoH/DoT
One caveat specific to Rogers: their CDN (used by Rogers TV, Sportsnet streaming, and some Bell-adjacent properties) uses DNS-based traffic steering. Switching to Cloudflare or Google DNS may direct you to non-optimal CDN edge nodes for those services. If you notice Rogers-branded streaming degrades after the switch, a split DNS configuration on your router — where Rogers-specific domains resolve via the original Rogers servers and everything else goes to Cloudflare — resolves this.
Verifying DNS with CLI Tools
After setting your router's DNS, confirm from a client machine that queries are going where you expect them to.
On iOS (17+): Settings > Wi-Fi > tap your network name > Configure DNS > Manual. You can override DNS per-network even when your router is the DHCP server.
On Android (9+): Settings > Network & Internet > Private DNS — enter a DoT hostname like 1dot1dot1dot1.cloudflare-dns.com to bypass router DNS entirely for that device. Useful on untrusted networks; on your own LAN it bypasses any Pi-hole or AdGuard Home filtering you have set up.
IPv6 After Enabling XB8 Passthrough
Rogers supports dual-stack IPv6 on most Ignite tiers as of 2026. After enabling IP Passthrough, your router needs to request an IPv6 prefix via DHCPv6-PD (Prefix Delegation). If your router has IPv6 disabled or doesn't request a prefix, clients fall back to IPv4 only — which works, but leaves IPv6-preferred services slower.
Configuration by router:
- Asus: WAN > IPv6 > Connection Type > Native or DHCPv6
- OpenWrt: Network > Interfaces > WAN6 > Protocol: DHCPv6
- Netgear: Advanced > Advanced Setup > IPv6 > Connection Type: DHCPv6
- TP-Link: Advanced > IPv6 > Internet Connection Type: DHCPv6
DNS-over-HTTPS and DNS-over-TLS in 2026
With your own router behind the XB8 in passthrough mode, you can now enable encrypted DNS at the resolver level — something the XB8 in normal router mode either doesn't support or handles opaquely. Options:
- Router-level DoT: Asus Merlin firmware, OpenWrt (via the stubby or unbound packages), and DD-WRT all support DNS-over-TLS to upstream resolvers. This encrypts queries between your router and Cloudflare or Google, preventing Rogers' network infrastructure from logging query content.
- Router-level DoH: OpenWrt supports DoH via the https-dns-proxy package. Some newer Asus Merlin builds include it natively.
- Per-device DoH: Chrome, Firefox, and Edge all have built-in Secure DNS settings (browser Privacy settings > Use secure DNS). These bypass your router's DNS entirely for that browser.
Important operational note: enabling DoH or DoT on individual devices means those devices bypass your router's resolver — so if you're running Pi-hole, AdGuard Home, or NextDNS locally, per-device encrypted DNS will circumvent your filtering for those clients. Centralize encrypted DNS at the router level if network-wide filtering is a goal.
Common Problems After Enabling XB8 Passthrough
Router WAN Shows 10.0.0.x Instead of a Public IP
The most frequent failure. Causes in order of frequency:
- MAC address mismatch — you entered the LAN MAC instead of the WAN MAC. They are different on every router. Double-check the label; the WAN MAC is sometimes labelled "Internet MAC" or found in your router's admin under WAN settings.
- Wrong reboot sequence — your router sent a DHCP request before the XB8 finished applying the passthrough config. Power-cycle your router again after confirming the XB8 is fully online.
- Stale DHCP lease on the XB8 — the XB8 has a cached lease tied to a different MAC. In the XB8 admin under Gateway > Connected Devices, find and release the old entry, then reboot your router.
Passthrough Reverts After a Power Outage
A known XB8 firmware bug on some versions: after a power outage, the XB8 comes back in normal router mode. The immediate fix is to log in to 10.0.0.1 from a device connected directly to the XB8 and re-enable passthrough. DHCPS-Fixed is more stable across reboots than DHCPS-Dynamic. If this happens repeatedly, contact Rogers support — firmware updates in late 2024 and 2025 addressed this on most XB8 units.
DNS Works But Rogers Streaming Loads Slowly
After switching to Cloudflare or Google DNS, Rogers CDN-hosted content (Rogers TV, Sportsnet) may route to non-optimal servers because those resolvers don't apply Rogers' geography-based traffic steering. Check your Rogers DNS IPs from before the switch (they typically fall in the 96.116.x.x or 184.151.x.x ranges). Configure split DNS on your router: resolve Rogers-domain queries via Rogers' servers and everything else via Cloudflare.
Home Phone Stops Working
If you have Rogers Home Phone, the XB8 handles the MTA (Multimedia Terminal Adapter) function internally and independently of IP Passthrough. This should continue working normally after enabling passthrough. If home phone breaks, verify you have not accidentally modified anything under the Voice tab in the XB8 admin — leave that section completely alone.
Double NAT Persists Despite Passthrough Showing Enabled
Check your router's WAN IP in its admin panel. If it shows a 10.x, 172.16–31.x, or 192.168.x address, passthrough is not fully active — recheck the MAC address entry and reboot sequence. Also verify DNSSEC isn't causing apparent resolution failures you're misreading as a NAT problem: run dig +dnssec google.com and confirm the AD (Authenticated Data) flag appears in a healthy response.
How to Confirm Bridge Mode Is Working
Reverting to Normal Mode
To restore the XB8 as the main router: connect a device directly to an XB8 LAN port (remember, you may not be able to reach 10.0.0.1 through your downstream router), navigate to Gateway > Connection > IP Passthrough, disable Passthrough Mode, save, and reboot the XB8. Power-cycle your downstream router afterward. Your devices will start receiving 10.0.0.x DHCP leases from the XB8 again, and DNS will revert to Rogers' servers automatically.
Common Misdiagnoses
- Blaming bridge mode for slow DNS — if DNS was slow before passthrough, the issue was Rogers' resolvers, not the XB8's routing role. Switch to Cloudflare and benchmark:
dig google.com @1.1.1.1 | grep "Query time". - Assuming passthrough disables XB8 Wi-Fi — IP Passthrough does not automatically turn off the XB8's built-in radios. Both the 2.4 GHz and 5 GHz bands stay active. Disable them manually under Gateway > Wi-Fi if you want your own router's Wi-Fi to be the sole access point; otherwise clients may connect to the XB8 and bypass your router's DNS entirely.
- Thinking Rogers blocks inbound ports after passthrough — Rogers does not block common inbound ports on residential Ignite plans in passthrough mode. The XB8 firewall is bypassed; your router's firewall is now the only perimeter. Verify port forwarding rules are set on your router, not on the XB8.
Preventing Future Issues
- Record your router's WAN MAC address somewhere accessible. Rogers occasionally replaces XB8 units and the new unit needs passthrough reconfigured from scratch with the same MAC.
- Set DHCP reservations on your router for key devices so IP assignments survive reboots — especially relevant if you run Pi-hole or AdGuard Home as a local resolver.
- If running Pi-hole behind your router: point your router's upstream DNS to the Pi-hole IP, and configure Pi-hole's upstream to Cloudflare or Quad9. This preserves network-wide filtering while maintaining fast, reliable resolution.
- Re-test passthrough status after any Rogers-initiated XB8 firmware update — some firmware pushes have been observed resetting passthrough mode on a subset of units.