AT&T U-verse 2wire Gateway and DD-WRT Router in DMZ Mode…

ddwrt_logo
We’ve recently upgraded our ISP to AT&T U-verse. With this switch AT&T pro­vided a 2wire gate­way. So far the ser­vice has been excel­lent. Recently we setup a live chat sup­port fea­ture on the web­site, as you can see to the right. With this fea­ture we also plan to inte­grate a remote desk­top fea­ture, to allow us to pro­vide our clients with live and instant support.

While set­ting up our new live ser­vices, it became appar­ent that we would need an exter­nal IP address issued to our WRT54GL router run­ning DD-WRT. Our first attempt led to suc­cess, but our con­nec­tion was drop­ping every 10 min­utes. This was caus­ing our dowloads to drop and fail, IM dis­con­nects, and live sup­port drop­ping our sup­port ses­sions. After read­ing the router logs, we found that our WAN DHCP lease was run­ning out after 10 min­utes. After that 10 minute time frame the con­nec­tion was dropped, and the lease renewed. Obvi­ously this is a major problem.

With a bit more research we found that the DD-WRT SPI fire­wall is block­ing responses from the DCHP server. UDP requests are sent to the DHCP server at 50% inter­vals, but the response is actu­ally com­ing from a dif­fer­ent server, and is thus blocked by the firewall.

The eas­i­est fix for this is to add the fol­low­ing com­mand to your fire­wall rules.

1
iptables -I INPUT -p udp --sport 67 --dport 68 -j ACCEPT

After enter­ing this com­mand into our fire­wall rules, our issues with dropped down­loads, and inter­mit­tent web sig­nals van­ished. It ended up just being a case of a pow­er­ful fire­wall, doing its job just a lit­tle to well.

Let us know if this arti­cle was help­ful to you. We pro­vide all of our arti­cles free of charge, and free of ads, with the hope that our users find them use­ful. We even find our­selves refer­ring to our own arti­cles while in the field mak­ing repairs. Happy com­put­ing. :)


Was this article helpful? Here's a few related articles which may also interest you.

Related Posts:


17 Comments to “AT&T U-verse 2wire Gateway and DD-WRT Router in DMZ Mode…”

  1. Ryan says:

    ¡Muchísi­mas gra­cias! This arti­cle helped me so much!

  2. Mike says:

    I was so glad some­one posted this. I was on the phone with att sup­port for 4 hours before look­ing through ddwrt com­mand data­base and fig­ur­ing this out on my own.

    The sad part is the fact that no one at Att could tell me why there DMZ+mode assigned 10 minute lease times, nor how it imper­son­ates (bridges) the pub­lic dhcp server.

    never had this prob­lem with Com­cast, but at least my con­nec­tion stays up for more than 30 days at time with att…

  3. Todd says:

    Just wanted to thank you for post­ing this. I have had Youtube and large (long time­frame) down­load inter­rup­tions since I switched to Uverse with my DD-WRT router and didn’t know why. I had searched before and this time found your site.

    Thanks!

  4. Kurt says:

    Thanks alot. Just got Uverse yes­ter­day and my DDWRT router was hang­ing up on large down­loads. This seems to have fixed it.

  5. orange80 says:

    Where exactly do you add this rule with DD-WRT?

    Thanks!

  6. Admin says:

    Under the “Admin­is­tra­tion” tab, click the “Com­mand” tab. Copy the rule into the “Com­mands” box and click “Save Fire­wall” below that. You may or may not need to restart your router. If you’re suc­cess­ful, you should see your lease time being renewed every 5 min­utes. You can val­i­date this by going to the “Sta­tus” tab, and under that the “WAN” tab. Your lease should be for 10 min­utes, with a renewal at the 5 minute mark. So essen­tially, if you see any­thing under 5 min­utes under Remain­ing Lease Time you need to check that you’ve added the rule cor­rectly. Good Luck… :-)

  7. alper gurdal says:

    Thank you so much. Now I can watch youtube and use skype with­out drops.

  8. TechNazgul says:

    You, sir, are a genius! Thank you so much for post­ing this. Fan­tas­tic tip.

  9. Sean Smith says:

    Thank you so very much for this arti­cle. It lit­er­ally has saved me from rip­ping out my hair try­ing to fig­ure out why I could never fin­ish down­load­ing the iPhone firmware updates for my phone from Apple. The past twenty or so attempts that I had tried all failed at seem­ingly ran­dom points in the down­load and after apply­ing this fire­wall rule I was able to directly down­load the firmware file on the first attempt.

    Is it okay if I repub­lish this infor­ma­tion on my own site and pro­vide a link back to this address? I want to be able to pre­serve this valu­able infor­ma­tion in case I need it again quickly.

    Thanks again!

  10. […] up empty-handed for a long time, I was ready to throw in the towel. And then I stum­bled across this arti­cle. It turns out that the 2wire device only gives a ten minute lease time for the pub­lic IP address it […]

  11. Jaime says:

    Thank you so much for this tip. Like oth­ers have stated, it has save my hair from the wrath of frustration!

  12. Dan Woodard says:

    This has been an issue for me for some time now. Each time I would stream audio, it would crash after a few min­utes (maybe 10 as it turns out) or so. Thanks!

  13. Nate says:

    Bril­liant!!! I have been strug­gling with this for months — Youtube stream­ing, down­load­ing files, Android phone updates… what a mess. The DMZ+ “fea­ture” has caused me mul­ti­ple headaches, but I’m hope­ful that this is the last one I will need to fix!

    Thanks again!

  14. T Roy says:

    This was exactly what I was look­ing for. You guys saved me count­less headaches.

    The par­tial pod­casts and down­loads were one thing. Hav­ing to drive into work on the week­ends for fail­ing file downloads/uploads was another.

    Thanks so much!

  15. JP White says:

    Bril­liant article/fix.

    I too upgraded to Uverse and had file down­load inter­rup­tions once I con­fig­ured the 2Wire router to put my DD-WRT router into the DMZ and sup­ply it with a pub­lic IP to play with.

    I did not need to reboot the router after inputting the fire­wall ip tables com­mand given in the above arti­cle. Sav­ing the fire­wall rule forced the router to restart the WAN con­nec­tion in real-time after which it stayed up.

  16. Sebastien says:

    Thanks!
    Was los­ing my mind.… found some other fire­wall rules, but yours was work­ing great (Tomato and ATT Uverse with the 2wire).

    Just one ques­tion: is there any way to lock down the open ports to the MAC address of the modem?

  17. Jesse Gearhart says:

    I have the exact same con­fig­u­ra­tion (DD-WRT device behind U-VERSE RG) and I’ve been try­ing to solve this prob­lem for months, I’ve tried three dif­fer­ent routers and every­thing I could pos­si­bly think of. Thank you soooooooo much!!!!

Leave a Comment