Connect Your Own Router to an Openreach ONT on FTTP
On full-fibre, the box that matters is not your ISP hub; it is the small white Openreach unit on the wall. Once you understand what that box actually does, the whole question of running your own router gets a lot simpler. There is no bridge mode to hunt for and no clever toggle to find. You just plug in and authenticate.
We have run our own routers off Openreach lines across a few different providers, so here is the plain-English version. We will cover what the ONT is, why you can skip the ISP hub entirely, and the exact connection settings for the big names.
Key Takeaways
- An Openreach ONT is a media converter, not a router, so there is no bridge mode to enable on FTTP.
- For most Openreach ISPs you set your router's WAN to PPPoE and enter the username and password your provider issues.
- Sky UK home broadband is the odd one out: there is no PPPoE login, so set the WAN to automatic DHCP first and add a DHCP Option 61 client ID only if the line will not come up.
- VLAN tagging like VLAN 911 belongs to CityFibre and other alt-nets, not Openreach; leave VLAN off on a genuine Openreach FTTP line.
- Virgin Media has no Openreach ONT at all, so its own modem mode is the route there instead, though Virgin says modem mode is not currently available on the Hub 5x.
An Openreach ONT is a media converter, not a router
The ONT, short for Optical Network Terminal, is the small white Openreach box on your wall. A thin fibre cable feeds it through an SC/APC connector, and its job is narrow: convert the incoming light signal into ordinary Ethernet. That is the lot.
Here is the bit that clears up most of the confusion. The ONT does not route, it does no NAT, it runs no WiFi, and it holds no login. It is already the modem stage of your connection. So when you plug your own router into it, you are not putting anything into bridge mode; there simply is no router in the ONT to bridge in the first place.
That is different from the old FTTC and ADSL world, where the ISP hub was the modem and you had to either disable its WiFi or wrestle it into bridge mode. On FTTP that role moves to the ONT, which means your own router becomes the only router on the line. Cleaner, and far less fiddly.
The connection point is a single Ethernet socket on the ONT, usually labelled LAN or Port 1. Run a standard Cat5e or Cat6 cable from there to your router's WAN or Internet port and you are physically done. Before you touch any router settings, glance at the ONT's lights: a steady Power, a steady PON, and LOS off means the fibre side is healthy. If LOS is flashing red, that is a line fault to report, not something a router will fix.
Worth saying plainly: this is the full-fibre branch of the broader decision about running your kit. If you want the bigger picture of which method applies to which provider, start with our guide to using your own router with any UK ISP. And leaving the ISP hub inline behind your router is exactly what causes the mess we describe in what double NAT is and how to fix it; going router-direct avoids it entirely.
Most Openreach ISPs authenticate over PPPoE
PPPoE, Point-to-Point Protocol over Ethernet, is just your router opening a session across the ONT using credentials your ISP issues. That session is how the network confirms it is really your account on the line.
The generic recipe looks the same everywhere on Openreach. Set the WAN or Internet connection type to PPPoE, enter the username and password, leave the IP as automatic, and leave VLAN tagging off. Openreach FTTP lines do not need a VLAN, so do not add one. Part-fibre FTTC is a different case, and EE for one specifies VLAN 101 at priority 0 there.
BT and EE sit on exactly the same Openreach PPPoE method, which makes sense given EE broadband is BT-owned. EE states the requirement outright: to work on the EE broadband network, your router must support PPPoE, and that applies to every broadband type EE sells rather than only the older ones. The settings BT Community threads report are [email protected] as the username, BT or a blank field as the password, CHAP authentication and DNS left on automatic, with the router's Ethernet WAN port going straight into the ONT. The classic [email protected] with a blank or BT-supplied password works on a lot of BT lines too. The reliable route, though, is to ring the ISP and ask for the account's PPPoE or network user ID and password rather than guessing. If you ever need to undo a change and start fresh, our notes on resetting a BT broadband router cover the basics. For EE specifically, we have a fuller walkthrough on how to use any router with EE broadband.
Zen, Plusnet, Aquiss and similar issue a per-account username, something like zen123456@zen, plus a password. Same PPPoE settings, VLAN left disabled. Zen's own guidance is explicit that you leave VLAN tagging unchecked, which is a useful sanity check if a setup screen tempts you to fill it in.
Two practical notes before you commit. First, the Digital Voice caveat: on FTTP the home phone usually plugs into a port on the ISP hub, not the ONT. Run your router straight to the ONT and that phone port goes quiet. If the landline still matters, keep the ISP hub for voice or ask your provider about moving the line. EE puts this in writing and goes further: third-party routers are not compatible with EE Digital Home Phone, so you have to keep the EE or BT hub as your main router, and the same holds for EE TV, the EE WiFi Extender, Connectivity Backup and WiFi Optimiser. Sky Talk with Internet Calls has the same shape, since the phone plugs into the Sky hub. Second, for the keen: enabling jumbo frames or RFC4638 lets you keep a full 1500-byte MTU over PPPoE. If your router does not offer that, 1492 is the safe default and nobody will notice the difference in daily use.
Sky UK home broadband is the exception: DHCP, not PPPoE
This one trips people up, so let us be blunt. Sky UK home broadband does not use PPPoE. Enter a PPPoE username and password on one of those lines and it will simply refuse to connect, no matter how many times you retype it. Check which Sky you are on first, though: Sky Ireland uses PPPoE on VLAN 10, and Sky Business UK is reported to use PPPoE as well.
There are two paths onto a Sky line rather than one rule, and the order you try them in matters. Start with the simple one: set the router's WAN to dynamic/automatic IP (DHCP), plug it into the ONT and see whether the line comes up. Plenty of Sky full-fibre lines authenticate on that alone, and there are reports through 2025 and 2026 of a working line breaking once a client ID was added on top.
Only if plain DHCP fails should you reach for DHCP Option 61, a client ID typed into a vendor or host ID field. The mechanism is genuine: DrayTek's UK guide describes the router sending DHCP option 61 along with its address request to authenticate its access to the Sky network. Mind the scope of that guide, though. It is written for VDSL2 lines, and the client ID it gives is the router's MAC address followed by @skydsl, a pipe and eight hex characters, not the free-text anything@skydsl that circulates on forums. Sky itself documents none of this either way. That same guide is also the reason to be careful with VLAN advice: it tells routers with a built-in VDSL modem to enable VLAN tag insertion with tag 101, and leaving VLAN off applies to a router on an Ethernet WAN behind a separate modem or ONT that is already handling the tagging.
That makes router choice matter on Sky, because not every consumer router exposes an Option 61 field. ASUS documents one at brand level in ASUS FAQ 1011715, though it names neither Sky nor the UK, nor any specific model. TP-Link's online firmware emulator for the Archer BE550 recommended below, a US version 2.0 build, shows no Option 61 field in its Dynamic IP settings, so on Sky full fibre the BE550 runs behind the Sky Hub unless the line comes up on plain automatic DHCP. Netgear publishes a list of models that support it, but the list is ageing, contains no WiFi 6E or WiFi 7 model and never mentions Sky, so check your exact model against it rather than assuming a current Nighthawk is covered. For the full Sky-specific walkthrough, read the surprising answer on Sky hub bridge mode. Once the WAN is set correctly, the rest behaves like any other own-router FTTP setup; WiFi, NAT and devices all act normally.
VLAN tagging is for alt-nets like CityFibre, not Openreach
The rule is short: on a genuine Openreach ONT you do not set a VLAN. Leave VLAN tagging off and move on.
It is worth explaining where VLAN 911 keeps coming from in those forum threads. It is a CityFibre requirement. CityFibre is an alternative full-fibre network, not Openreach, and on it the router must talk PPPoE tagged on VLAN 911. Brilliant advice for a CityFibre line; poison for an Openreach one.
Telling the two apart is easy once you look. An Openreach ONT is branded Openreach, and your order or ISP will confirm an Openreach line. CityFibre and the other alt-nets ship their own, differently branded ONT. The common mistake is copying an alt-net guide wholesale and bolting VLAN 911 onto an Openreach connection, which stops it working stone dead. Other alt-nets vary too; some use no VLAN, some use their own tag, so verify the exact setting with that specific network rather than assuming.
Virgin Media does not use an Openreach ONT
If you are on Virgin Media, none of the above applies, and that is not a small caveat. Virgin runs on its own cable network, DOCSIS over coax, not Openreach fibre. There is no Openreach ONT on a Virgin install to plug into.
The Virgin equivalent is to put the Virgin hub into modem mode, which Virgin's reset and modem mode help page says turns the Hub into a cable modem so you can connect your own WiFi kit. Virgin's modem mode steps give no PPPoE username or password for your router, and Virgin Media's static versus dynamic IP explainer says residential customers get a dynamic IP address, which it describes as assigned automatically by DHCP, so set the router's WAN to automatic/DHCP once modem mode is enabled. To confirm the router now holds a public address, compare its WAN IP with the one a "what is my IP" site shows; Xbox Support's NAT troubleshooting page says a match means the router is being assigned a public IP address. If that is your line, head over to our Virgin Media Hub 5 modem mode guide instead of following this page.
One more thing for the future-proofers: Virgin's Hub spec table lists the Hub 5x on XGS-PON, and Virgin's Hub 5 article says the Hub 5x is used on full-fibre connections and that Virgin provides the right Hub based on your broadband connection. Virgin's reset and modem mode help page gives modem mode steps for the Hub 3, 4 and 5, but says modem mode is not currently available for the Hub 5x. Virgin's Connect app page says the sticker on the Hub or the Connect app shows which Hub you have, so check before you rely on modem mode; on a Hub 5x, the alternative is to leave the Hub routing and run your own router or mesh in access-point mode behind it.
A short note on which routers handle PPPoE and 2.5G WAN well
Honest take first: almost any decent router does PPPoE fine. The reason kit matters at all is line rate. On FTTP tiers at 900Mbps-plus, or the new gigabit-and-beyond packages, you want a fast WAN port and a router that holds full speed while running the PPPoE session rather than choking on it.
For an all-rounder, the TP-Link Archer BE550 is the recommendation. TP-Link's spec page lists PPPoE among its WAN connection types, alongside Tag VLAN for the alt-net lines that need a tag, and TP-Link lists a dedicated 2.5 Gbps WAN port and four 2.5 Gbps LAN ports, so a faster-than-gigabit line plugs straight into the WAN. It is a tri-band WiFi 7 router. That covers sub-gig, gigabit and beyond-gigabit Openreach tiers from the one box, so there is no separate premium standalone tier to buy here. The one exception is Sky, where the missing Option 61 field noted above puts it behind the Sky Hub.
The port layout is the detail that matters most. Because TP-Link lists the 2.5 Gbps WAN as a dedicated port, there is no port to reassign during setup, and because the four LAN ports are 2.5 Gbps as well, a wired PC with a 2.5G network card is not held to a gigabit link by the router.
For typical FTTP speeds where a 1G WAN is plenty, the TP-Link Archer AX73 is the value standalone option. WiFi 6, good coverage for a normal house, and a price that stings far less.
When coverage across a larger home is the real goal, mesh makes more sense. The TP-Link Deco X10 and X60, and the eero Pro 6E, all run PPPoE at the gateway node, so the ONT feeds the main unit and the mesh handles the rest of the house. Size the pack to the house rather than the badge: the Deco links below are multi-packs, while the eero Pro 6E link is a single unit that you expand by adding nodes.
Check the TP-Link Deco X10 price on Amazon UK →
Check the TP-Link Deco X60 price on Amazon UK →
Check the eero Pro 6E price on Amazon UK →
One last point of honesty on the 2.5G question, because the marketing muddies it. Within the kit above, only two can take a faster-than-gigabit line: the Archer BE550, for which TP-Link lists a dedicated 2.5 Gbps WAN port, and the eero Pro 6E, which has a 2.5G port that can serve as the WAN. The Archer AX73 and the Deco X10/X60 top out at a gigabit WAN, and that is a hard ceiling rather than a tuning issue. So on a faster-than-gigabit Openreach tier those two are the ones to look at, and the eero Pro 6E is the pick if you also want mesh. Note that the eero's other port is gigabit, so once the 2.5G port is carrying the internet feed, a single wired device is back to 1Gbps. A gigabit WAN is perfectly fine for the vast majority of lines.
Once the cable is in and the WAN is set, the rest is the easy part. If you want to sanity-check what your kit is telling you along the way, our guide to what every router light colour means is a handy companion. Plug in, authenticate, done.

