The double-NAT trap catches most people the moment they plug a second router behind their TELUS gateway. Two devices performing Network Address Translation simultaneously creates routing conflicts, kills UPnP negotiation, breaks site-to-site VPNs, degrades gaming performance, and turns port forwarding into a two-firewall puzzle with no clean answer. Putting the TELUS WiFi Hub into bridge mode — or its functional equivalent — hands full routing control to your own device and removes the redundant NAT layer entirely. This guide covers every current TELUS gateway model with exact web UI paths, the correct reboot order, and what changes in your DNS configuration the moment passthrough goes live.
What TELUS Calls Bridge Mode and Why the Name Differs
Most residential ISP gateways do not expose a true Layer 2 bridge toggle, and TELUS hardware is no exception. What the firmware offers instead is IP Passthrough or DMZ — both of which forward all inbound traffic and the public IP assignment directly to one downstream device. The practical result is identical to bridge mode: your router receives the ISP-assigned IP, handles all NAT decisions, and the TELUS hub becomes a dumb WAN-side pass-through. The hub still manages the physical WAN layer — the DSL line, GPON fibre handshake, or LTE radio — but routing, firewall policy, DHCP, and DNS move entirely to your equipment.
A separate option on some models, PPPoE passthrough, lets your own router dial TELUS directly over the DSL or fibre link, bypassing the hub's session management entirely. That path is covered further down for customers who want the deepest level of WAN control.
Identify Your TELUS Hub Model First
TELUS has deployed four main gateway generations across its DSL, PureFibre, and LTE networks. The procedure differs by model, so check the label on the bottom or back of the unit before proceeding. Firmware version matters too — TELUS stages OTA updates between 1 and 4 a.m. that occasionally rename or relocate menu items.
- ActionTec T3200M — the most-deployed PureFibre unit since 2015. White wedge shape. Admin URL: http://192.168.1.1. Default login: admin with the password printed on the device label.
- Sagemcom Fast 5566 — common on newer fibre-to-premises installs. Nearly identical form factor to the T3200M. Admin URL: http://192.168.1.1. Firmware varies more between units than the T3200M.
- Nokia G-240W-B / G-2425G — ONT+router combo on GPON builds from 2022 onward. Admin URL: http://192.168.1.254 (try http://192.168.1.1 if that does not respond). Default password on device label; the WiFi password and admin password are the same on most units.
- TELUS Smart Hub (LTE) — cellular gateway for rural service areas. Admin: http://192.168.1.1 or http://192.168.0.1 depending on the firmware revision installed.
Bridge Mode on the ActionTec T3200M
The T3200M labels this feature IP Passthrough, not bridge mode. There are three steps and the order matters — skipping the DHCP reservation is the single most common reason passthrough silently stops working after a gateway reboot.
Step 1 — Reserve a Static DHCP Lease for Your Router
Before touching the passthrough toggle, assign your downstream router a permanent LAN IP on the T3200M. Navigate to http://192.168.1.1 → Advanced Setup → DHCP Reservation. Find your downstream router's MAC address — printed on its label or visible under its own status or WAN info page — and assign it a fixed IP such as 192.168.1.2. Click Apply and note the assigned address before moving on.
Step 2 — Enable IP Passthrough
Navigate to http://192.168.1.1 → Advanced Setup → IP Passthrough. Set Passthrough Mode to DHCPS-fixed rather than plain DMZ. DHCPS-fixed persists across T3200M firmware updates; plain DMZ can silently drop after an overnight OTA push from TELUS. In the Fixed Device field, select the MAC address of your downstream router from the dropdown or enter it manually. Click Apply.
Step 3 — Reboot in the Correct Order
Power-cycle the T3200M first. Wait a full 60 seconds for its WAN connection to re-establish and for the status LEDs to stabilize. Then reboot your downstream router. Its WAN interface will now request an address via DHCP and receive the TELUS-assigned public IP instead of a private 192.168.1.x address. If you rush the reboot sequence and the T3200M's WAN is not yet up, the downstream router may lock onto a private lease from the hub's own DHCP pool and you will need to force-renew the WAN lease manually.
Bridge Mode on the Sagemcom Fast 5566
The 5566 firmware varies more across units than the T3200M, so the exact path depends on which firmware generation is installed on your specific unit.
Firmware v3.x and later: Navigate to Advanced → WAN Services → Bridge Mode. Enable the toggle and enter your downstream router's reserved IP. This version performs true IP passthrough without a separate DMZ rule and is the cleanest option available on the 5566.
Older firmware builds: Navigate to Advanced → DMZ and enter the reserved LAN IP of your downstream router, for example 192.168.1.2. Create the DHCP reservation first under Advanced → Local Network → DHCP Reservation using the same logic as the T3200M. The result is functionally identical to the newer bridge mode toggle even though the label reads DMZ.
After applying either setting, reboot the 5566 before rebooting your downstream router. Wait for the 5566's WAN LED to go solid — if you trigger the downstream reboot while the 5566 is still negotiating its WAN session, the downstream router will receive a private lease from the hub instead of the public address.
Newer Nokia TELUS WiFi Hub Models
The Nokia G-2425G and related units deployed by TELUS from 2022 onward have a cleaner interface but introduce one extra consideration: the default admin address is 192.168.1.254, not the .1 address most people expect. If .254 is unreachable, try .1 — some units were provisioned with the alternate address at installation time.
- Open http://192.168.1.254 in a browser. Log in with admin and the password from the device label.
- Navigate to WAN → IP Passthrough. Some firmware builds label this Advanced → Passthrough.
- Set mode to Passthrough and select the target device by MAC address from the connected devices list.
- Optionally, disable the Nokia unit's WiFi radios under Wireless → Radio if you are running your own access point. This eliminates SSID conflicts and prevents two radios from competing on the same 2.4 GHz channels in the same room.
Nokia units on GPON connections sometimes require a call to TELUS Tier 2 support to enable transparent bridging at the ONT provisioning level. If your downstream router does not receive the public IP within five minutes of completing the web UI steps, contact TELUS and ask Tier 2 specifically to enable transparent bridging on your ONT port. The web UI toggle alone is occasionally insufficient on freshly provisioned GPON lines where the provisioning profile has not been updated to match.
PPPoE Passthrough for Full WAN Control
If you want your own router to own the WAN session entirely — negotiating its own MTU, initiating the PPPoE dial, and receiving the IPv6 prefix delegation natively — some T3200M and 5566 units support PPPoE passthrough. This is primarily relevant for TELUS DSL customers; most PureFibre connections use DHCP at the WAN layer rather than PPPoE, so IP Passthrough is the right tool there.
On the T3200M, navigate to Advanced Setup → WAN IP Address → Connection Type and switch from DHCP to PPPoE, then configure your downstream router's WAN as PPPoE with your TELUS credentials. The username format for most residential DSL accounts is youraccountnumber@telus.net with password telus. Call TELUS residential support if you do not have the credentials or if you are on a newer account format. For fibre accounts where the hub uses DHCP, stay with IP passthrough mode and leave the downstream router on DHCP WAN — adding PPPoE on top is unnecessary and will break the connection.
Configure Your Own Router After Passthrough
Once passthrough is active, set your downstream router's WAN interface to DHCP / Dynamic IP. Three settings to check immediately:
- MTU: Set to 1500 for PureFibre, 1492 for DSL or PPPoE. Leave at auto if unsure — most modern routers negotiate correctly without manual input.
- DNS servers: Now that the TELUS hub is out of the DNS query path, set your preferred resolvers directly on the router so they apply to every device on the LAN. 1.1.1.1 and 1.0.0.1 (Cloudflare) or 8.8.8.8 and 8.8.4.4 (Google) are reliable defaults. See the Google Public DNS documentation for full setup details and resolver policies.
- LAN subnet: Use a range that does not overlap with the T3200M's default 192.168.1.0/24. A range like 192.168.10.0/24 or 10.0.0.0/24 avoids IP conflicts if you ever need to access the hub's admin page while both devices are on.
Use the DNS Lookup tool to confirm your new resolver is returning records correctly after the switch — run a lookup on a live domain and verify the response is clean and matches expected records.
DNS After Bridge Mode — What Actually Changes
TELUS gateways intercept all DNS queries on port 53 by default, forwarding them through TELUS resolvers at 206.47.200.200 and 206.47.200.201, even when individual client devices have different DNS servers manually configured. Once the hub is in passthrough mode, it is no longer in the query path at all. Your own router becomes the DNS authority for the entire LAN.
This opens up several options that were not accessible before:
- Set global resolvers on the router that apply to every connected device without touching individual client settings
- Enable DNS-over-TLS or DNS-over-HTTPS at the router level — supported natively on Asus Merlin firmware, OpenWrt, pfSense, OPNsense, and UniFi Dream Machine
- Deploy a local resolver such as Pi-hole or Unbound for network-wide filtering and recursive resolution that bypasses any upstream resolver entirely
- Enforce DNSSEC validation — TELUS resolvers support DNSSEC, but so do 1.1.1.1 and 9.9.9.9 without the associated query logging
Verify the Fix with CLI Tools
Do not rely only on the admin UI to confirm passthrough is working. Run these checks from a machine connected to your downstream router's network.
Confirm your public IP as seen from outside your network:
Confirm which DNS resolver your operating system is actually querying:
Test IPv6 connectivity if you configured DHCPv6-PD:
If Windows nslookup still shows 192.168.1.1 as the server after passthrough is enabled, the TELUS hub is still handing out its own IP as the DNS server via DHCP. Check your downstream router's DHCP scope settings — the DNS server field should list your router's own LAN IP, not the hub's address. This is usually a misconfigured DHCP scope on the downstream router, not a passthrough failure.
Common Misdiagnoses
- Double NAT persists after enabling passthrough — the DHCP reservation was not created before activating IP passthrough, so the hub assigned passthrough to the wrong device. Fix: disable IP passthrough, create the MAC reservation explicitly, then re-enable passthrough in that order.
- Downstream router WAN IP is still a private address — TELUS Fibre customers behind CGNAT will see a WAN IP in the 100.64.0.0/10 range regardless of passthrough state. Passthrough is functioning correctly; TELUS is sharing public IPv4 addresses at their edge. A TELUS Static IP add-on is required for a true routable public address.
- Port forwarding still fails after passthrough — if the downstream router's WAN IP is in the 100.64.0.0/10 CGNAT range, inbound port forwarding cannot work without a Static IP add-on, full stop. If the WAN IP is genuinely public, check that the downstream router's own firewall rules accept the traffic on the intended port and that the rule targets the correct internal host.
- Client devices lost internet after enabling passthrough — devices that were connected to the TELUS hub's WiFi SSID are now on an isolated subnet that may not route correctly through passthrough. They need to connect to your downstream router or AP instead. Disable the hub's WiFi radios under its admin page to eliminate the confusion entirely.
- Cannot reach the TELUS hub admin page after enabling passthrough — the hub always responds at 192.168.1.1 from any device connected to its LAN port or its WiFi SSID. A factory reset is not required. Connect a laptop directly to one of the hub's LAN ports with an Ethernet cable and access the admin page normally.
IPv6 and Encrypted DNS in 2026
TELUS began rolling out IPv6 prefix delegation to residential PureFibre customers across BC and Alberta in 2023, with coverage expanding significantly through 2025 and into 2026. In passthrough mode, the hub forwards a /56 IPv6 prefix to your downstream router via DHCPv6-PD — but only if your router requests it with the correct prefix size. Without this, IPv6 drops entirely after passthrough even if it worked before.
Verify immediately after the change with test-ipv6.com — if the result shows no IPv6 address, the prefix delegation request is failing and your router's WAN IPv6 settings need adjustment before the hub can pass the prefix through.
TELUS resolvers at 206.47.200.200 do not support DNS-over-TLS or DNS-over-HTTPS as of September 2026. Once the hub is bypassed, enforcing encrypted DNS at the router level is straightforward. On OpenWrt, install luci-app-https-dns-proxy and point it at 1.1.1.1 or 9.9.9.9. On Asus Merlin, use WAN → DNS Privacy Protocol → DNS-over-TLS. On pfSense and OPNsense, enable DoT forwarding in the Unbound DNS Resolver configuration. Enabling encrypted DNS at the router intercepts all port 53 queries from LAN clients and forwards them encrypted over port 853 — no per-device configuration required, and no way for an individual device to bypass it by hardcoding a plain-text resolver.
DNSSEC validation is also worth enabling on your local resolver while you are in the configuration. All major public resolvers — Cloudflare, Google, and Quad9 — perform DNSSEC chain validation. Running Unbound locally with DNSSEC enabled adds the strongest guarantee that DNS records received by your network have not been tampered with between the authoritative server and your router.
Confirm Everything Is Working
Run this checklist after completing the full setup to verify passthrough is functioning correctly end-to-end:
- Downstream router's WAN IP is not in any 192.168.x.x range
- dig +short myip.opendns.com @resolver1.opendns.com returns an address that matches the WAN IP shown on your router's status page
- Speed test shows throughput comparable to your TELUS plan rate — IP passthrough adds under one millisecond of additional latency and should not reduce throughput at all
- A port forwarding rule on the downstream router is reachable from an external checker (only applicable if not on CGNAT)
- test-ipv6.com shows a valid non-null result if you configured DHCPv6-PD on the WAN interface
- DNS resolver shown in nslookup or resolvectl status on client devices shows your router's LAN IP, not 192.168.1.1
- Any VPN connection, hosted game server, or forwarded service that was broken by double NAT now connects cleanly without manual workarounds