GL-X3000 - Bridge Mode WAN IP Passthrough

This is the answer from Gemini as of 10.03.2024
(I asked if one could save the profile to the card from the a phone)

***—
Unfortunately, that functionality is no longer available on SIM cards.
The profile is stored on the phone’s internal storage.

Here’s why saving APN profiles directly to SIM cards isn’t possible anymore:

  • Limited SIM Card Storage:
    SIM cards have very limited storage capacity, typically only enough for basic information like your carrier ID, phone number, and maybe some temporary settings. They aren’t designed to store complex configurations like APN details.

  • Security Concerns:
    Storing sensitive information like APN credentials (username and password) directly on the SIM card could pose security risks in case the SIM card is lost or stolen.


Even if the APN name itself is simple, like “abcde.ab.ab”, it wouldn’t be possible to save it directly to a modern SIM card. Here’s why:

APN profile includes more than name: The APN name is just one part of the entire APN configuration. Other details like proxy, port, username, and password (if required) are also crucial for connecting to a specific network. These additional details can make the overall profile more complex than just a simple name.

So, even with a seemingly simple APN name, the limitations and security concerns around SIM card storage prevent saving the entire profile directly.

—***

I can say though that i have tried the latest Firmware “Snapshot”
version: 4.6.0 (2024-03-08) openwrt-xe3000-4.6.0-0308-1709834947.bin
and it does save the profile to the router after a restart, but doesn’t have any internet connectivity when used injunction with with this passthrough method mentioned in the above post… “yet”.

I looking forward to the fix for the stable version. :smiley:

any idea when this fix/update will roll out?

Can you program the router to save the manually added APN(in my case "fixip.a1.net) after a restart?
—>Do you mean that multiple APNs can be stored in the same SIM?

I’m assuming that the profiles of manually configured APNs are saved on the router.

With the current version the saved setting become null and void after a restart.

Thus I would like to see the option to save profile in the next update. Like on the last updated snap shot version that I mentioned before.

What ever they did there worked. Only problem with the snapshot is that the internet connection doesn’t work with the passthrough script when activated in ssh.

1 Like

Other 5G routers like Chester Cheetah recommend using DMZ as that works as a pseudo passthrough. Would that work in the scenario until the bridge feature is launched?

No, that is different than passthrough / bridging.

I was excited to try this out and feel like I’m ALMOST there.

Setup is a Tmobile SIM card for WAN and a OPNSense firewall for LAN. After doing a system reset, I enable bridging and see the WAN IP on the FW change from a private one to a public address. However, at that point the internet stops working. I can ping the FW gateway (which has a public address) but can’t get any further. If I set the GL-X3000 back to Router mode everything starts working again.

Trying to think of anything I might have missed or could try. Any ideas?

I tinkered around with this passthrough mode for a few hours today. I could get the X3000 into passthrough just fine but could not get an internet connection. I had excellent signal as shown by the on board (green) meter on the X3000, but I just couldn’t get a connection. A few times it did show as connected but again I still could not access a web page. I tried rebooting devices etc with no success.

This morning I powered up my X3000 in passthrough mode with my T-Mobile phone SIM. Again it showed Internet access but I couldn’t load a web page. As mentioned earlier in this thread, I changed the DNS server and everything works fine now.

Getting great speeds.

1 Like

Hi All. I've been playing with this for a few hours and have had mostly success but one thing eludes me...

My X3000 is in passthrough mode right now and is sending on the IP to my UniFi Gateway. I'm getting a private 10.x IP as the WAN IP but I presume that's because my cellular provider (Smarty / Three) is sending me a private address rather than the public address. When my X3000 was in Router mode my WAN IP in Unifi was a 192.168.1.x address, as given by the DHCP server of my X3000.

I have manually set DNS servers in my Unifi Gateway and I can successfully get to the internet from my LAN. The X3000 is not broadcasting WiFi and I presume DHCP is also disabled as part of the passthrough as it's no longer in Router mode (which is what I wanted). So far so good.

My only issue is that I can no longer get to the X3000 device via the web GUI or via SSH.

I've tried using the original IP from when the X3000 was in Router mode (192.168.1.1) and I get no connection. Same in SSH. I've also tried using the new WAN IP I'm getting (10.79.x) but that just takes me to the console of my Unifi Gateway, not the X3000.

Any ideas?

Sounds normal to me. In bridge mode, you usually can't reach the modem anymore if there is no secondary IP mapped.

Oh, maybe I misunderstood some of the posts in the above chain where they mentioned still being able to get to the X3000 interface via the original IP assigned when in Router mode or using the ISP provided IP address. Any idea what they were alluding to if not access to the X3000?

You can still get to it, just need to use the default IP of 192.168.8.1

Thanks for that. Sadly, that also didn't work. So I have tried:

  • the original IP (192.168.1.1)
  • the new WAN IP as seen by my UniFi Gateway (10.79.x)
  • the default IP (192.168.8.1).

The 10.79x address just routes me back to the Unifi console (my LAN is coincidentally also configured on a 10.x network), but both the 192.x addresses are unreachable for me.

In terms of connections, the Ethernet 1 port on the X3000 is connected to the WAN port of my UniFi Gateway, which is the only connection combination that worked.

I owe everyone an apology - I found the issue - in my browser when typing in the IP address for the X3000, it was autofilling the address bar using the details I had connected with before, in this case https://192.168.1.1

Connecting with http rather than https sorted the problem and it works just fine now. Apologies and thanks to those that gave their time to help.

1 Like

@lizh & @yuxin.zou

Any update on the Passthrough/Bridge mode for the GL-X3000? I've read this post up and down but don't see the solution. I've downloaded the 4.4.9 release and installed it but still no Bridge Mode in the Network Mode screen/module. Am I missing something? Is the only workaround to really SSH into the box and sling code?

Not yet... we're discussing whether to open it up to users via a generic experimental feature enablement page (something like chrome://flags).

I had my GL-X3000 in pass through mode, unplugged it, and upon plugging it back in, all that would happen is power light lights up and 2.4 WiFi light flashes twice. I cannot get back into the router. Holding down reset for four seconds didn’t do anything. I resorted to trying uboot upgrade and that doesn’t help, I would assume because the router is still stuck in pass through mode. Any ideas?

In general, after the router uboot succeeds (make sure it have succeed), the router will not only upgrade version, but also restore to the default setting. Please try another version firmware.

You certainly would think it should revert to default settings but it doesn’t appear to be. I had tried the most recent firmware and the very first firmware. Both successfully upload, upgrade, reboot, but then two flashes of 2.4GHz WiFi light, and then nothing. I’ve tried manually setting the IP on my computer hoping that the router would be back at 192.168.8.1, but I get nothing.

Could you see the broadcast SSID: GL-X3000-XXX when it booted-up 2 mins?