Digi Portugal 1 Gbps + OpenWrt: Your Own Router, Better Security and Less Bufferbloat

A practical guide to replacing the Digi router with your own OpenWrt router on Digi's 500 Mbps and 1 Gbps fibre services. Configure VLAN 20, PPPoE, IPv6, firewalling, banIP and SQM/CAKE for better security and lower latency. Includes important limitations: own routers are not supported with Digi's PRO-DIGI 10 Gbps or fixed-line telephone service.

Digi Portugal 1 Gbps + OpenWrt: Your Own Router, Better Security and Less Bufferbloat

Digi Portugal 1 Gbps + OpenWrt: Your Own Router, Better Security and Less Bufferbloat

If you have Digi fibre in Portugal and subscribe to the 500 Mbps or 1 Gbps service, you can use your own OpenWrt-compatible router instead of the router supplied by Digi.

This gives you much more control over your home network: you can configure IPv6 properly, apply a stricter firewall policy, control DNS, block known malicious IP addresses, and tune the connection to reduce bufferbloat.

This guide is specifically about Digi’s supported own-router configuration for 500 Mbps and 1 Gbps fibre. The configuration described here has been validated with a Digi 1 Gbps / 1 Gbps FTTH connection.

There are two important limitations to understand before starting:

Digi’s own-router configuration is not applicable to the PRO-DIGI 10 Gbps service.

And:

Digi’s own-router configuration is not compatible with Digi’s fixed-line telephone service. If you need Digi’s landline telephone, keep using the Digi-provided router.

Digi currently documents that customers can use their own router and obtain PPPoE credentials, while explicitly excluding fixed-line telephone and PRO-DIGI 10 Gbps.

At a glance

Digi serviceOwn OpenWrt router
500 Mbps fibre✅ Supported
1 Gbps fibre✅ Supported — configuration validated
PRO-DIGI 10 Gbps❌ Not applicable
Digi fixed-line telephone❌ Not compatible

So, if you have Digi 1 Gbps fibre and don’t need the Digi landline service, this guide is for you.

If you need the Digi fixed-line telephone service, do not replace the Digi router with your own OpenWrt router.


1. Why use your own OpenWrt router?

The Digi gateway is sufficient for basic Internet access, but an OpenWrt router gives you considerably more control over your network.

With OpenWrt you can configure:

  • A stateful firewall
  • Proper IPv6 firewalling
  • IPv6 Prefix Delegation
  • CAKE/SQM for bufferbloat control
  • banIP IP reputation lists
  • DNS filtering with Pi-hole
  • Restricted router management interfaces
  • Custom VLANs and LAN segmentation
  • More predictable network behaviour

There is also an important security consideration with IPv6.

Digi uses CGNAT for IPv4.

IPv6 works differently. Your router can receive a globally routable IPv6 prefix, and your LAN devices can receive globally routable addresses.

That means IPv6 does not provide the protection people sometimes incorrectly associate with NAT.

Instead, your firewall needs to explicitly prevent unsolicited inbound connections.

The configuration described in this article was validated on a GL.iNet GL-MT6000 running OpenWrt 25.12.5 with a Digi Portugal 1 Gbps / 1 Gbps FTTH connection. The observed configuration uses VLAN 20 on the WAN interface, followed by PPPoE with an MTU of 1492.


2. Digi 1 Gbps: the configuration this guide targets

The important distinction is between Digi’s 1 Gbps service and its newer PRO-DIGI 10 Gbps service.

Digi’s FAQ explicitly states that the own-router option is not applicable to PRO-DIGI 10 Gbps.

Therefore, this article should be understood as:

Digi 500 Mbps / 1 Gbps + your own OpenWrt router

The configuration has specifically been tested with:

Digi 1 Gbps download / 1 Gbps upload

It is not a 10 Gbps OpenWrt configuration.

Digi’s current documentation describes PRO-DIGI 10 Gbps as using XGS-PON and its own PRO-DIGI router.

Don’t assume that the VLAN/PPPoE configuration in this article can simply be transferred to that service.


3. Important: Digi fixed-line telephone is not supported

Before doing anything else, check whether you use Digi’s fixed-line telephone service.

Digi explicitly states that using your own router is not compatible with fixed-line telephone.

Therefore:

If you need Digi’s landline telephone service, do not use your own OpenWrt router. Keep the Digi router.

This is not simply a matter of configuring another option on OpenWrt.

The own-router service provided by Digi is explicitly documented as incompatible with the fixed-line telephone service.

The decision is therefore:

Do you need Digi fixed-line telephone?
                 │
          ┌──────┴──────┐
          │             │
         YES            NO
          │             │
          ▼             ▼
    Keep Digi router   OpenWrt

If you only need Internet access, you can continue with this guide.


4. Get your Digi PPPoE credentials

Digi provides PPPoE credentials for customers who want to use their own router.

Contact Digi customer support:

Digi Apoio ao Cliente

Ask specifically for:

PPPoE credentials to use my own router/OpenWrt router.

You should receive information including:

  • PPPoE username
  • PPPoE password
  • VLAN ID

In the configuration described in this guide, the VLAN ID is 20.

Use the VLAN ID supplied by Digi for your connection rather than blindly assuming it is always 20.

Never publish your real PPPoE username or password.

Use placeholders such as:

YOUR_ID@digi
YOUR_PPPOE_PASSWORD

5. Configure the Digi WAN connection

There are two layers to the Digi connection:

  1. VLAN tagging
  2. PPPoE

The physical Ethernet interface carries VLAN 20, and PPPoE runs on top of that VLAN.

Conceptually:

Digi FTTH
    │
   ONT
    │
 Ethernet WAN
    │
  VLAN 20
    │
  PPPoE
    │
pppoe-wan

The exact physical interface name depends on your OpenWrt router.

On the GL-MT6000 used for this configuration, the WAN interface was eth1.

Create the VLAN

For example:

uci set network.wan_eth=device
uci set network.wan_eth.name='eth1.20'
uci set network.wan_eth.ifname='eth1'
uci set network.wan_eth.type='8021q'
uci set network.wan_eth.vid='20'

Then configure PPPoE:

uci set network.wan=interface
uci set network.wan.proto='pppoe'
uci set network.wan.device='eth1.20'
uci set network.wan.username='YOUR_ID@digi'
uci set network.wan.password='YOUR_PPPOE_PASSWORD'
uci set network.wan.ipv6='1'

Configure the LAN:

uci set network.lan=interface
uci set network.lan.proto='static'
uci set network.lan.device='br-lan'
uci set network.lan.ipaddr='192.168.1.1'
uci set network.lan.netmask='255.255.255.0'

uci commit network

Then:

ifup wan

This will briefly interrupt Internet connectivity while the PPPoE session is established.


6. Configure the IPv4 firewall

A good baseline is:

WAN:
    Input:   REJECT
    Forward: REJECT
    Masquerading: enabled
    MTU fix: enabled

LAN:
    Input:   ACCEPT
    Forward: ACCEPT

Forwarding:
    LAN → WAN

Digi uses CGNAT for its Internet connections, so the WAN IPv4 address may be in:

100.0.0.0/8

This is normal.

Check the connection:

ubus call network.interface.wan status

Then:

ping -c 3 1.1.1.1

7. Configure IPv6 correctly

Digi provides native IPv6 Prefix Delegation.

The working OpenWrt model is:

PPPoE
  │
  └── IPV6CP
        │
      DHCPv6
        │
   Prefix Delegation
        │
       LAN
        │
   Router Advertisements
        │
    LAN clients

The tested configuration received either a /56 or /64 delegated prefix, and the prefix can change after PPP reauthentication.

Configure:

uci set network.wan.ipv6='1'

uci set network.wan6=interface
uci set network.wan6.proto='dhcpv6'
uci set network.wan6.device='@wan'
uci set network.wan6.reqaddress='try'
uci set network.wan6.reqprefix='auto'
uci set network.wan6.norelease='1'
uci set network.wan6.extendprefix='1'
uci set network.wan6.auto='1'

uci set network.lan.delegate='1'
uci set network.lan.ip6assign='64'

uci commit network

Don’t configure two competing IPv6 clients

Avoid configuring:

wan.ipv6=auto

together with a separate DHCPv6 wan6 interface.

For this Digi configuration, use:

wan.ipv6=1

with one dedicated:

wan6 = DHCPv6

configuration.


8. Enable Router Advertisements

DHCPv6 Prefix Delegation on the router isn’t enough.

LAN clients need Router Advertisements to learn about the IPv6 network and default route.

Configure:

uci set dhcp.lan.dhcpv6='server'
uci set dhcp.lan.ra='server'
uci set dhcp.lan.ra_slaac='1'

uci -q delete dhcp.lan.ra_flags
uci add_list dhcp.lan.ra_flags='managed-config'
uci add_list dhcp.lan.ra_flags='other-config'

uci commit dhcp

/etc/init.d/odhcpd restart

Without:

ra='server'

the router can have IPv6 connectivity while your phones, laptops and other LAN devices don’t get a usable IPv6 path.


9. Allow DHCPv6 and ICMPv6

IPv6 relies heavily on ICMPv6.

Don’t block ICMPv6 indiscriminately.

The WAN firewall needs to allow the IPv6 traffic required for normal operation, including DHCPv6:

UDP 547 → 546
IPv6
WAN → router

The tested configuration also uses:

Allow-DHCPv6
Allow-ICMPv6-Input
Allow-ICMPv6-Forward

Check the firewall:

fw4 check
/etc/init.d/firewall reload

10. The Digi IPv6 reauthentication gotcha

One interesting behaviour observed during the setup is that IPv6 Prefix Delegation may not immediately appear even when the configuration is correct.

You may see:

solicit → advertise=0

until the PPPoE session is renewed.

After verifying the configuration, try:

ifdown wan
sleep 3
ifup wan

Then:

ubus call odhcp6c.pppoe-wan get_statistics

and:

ubus call network.interface.wan6 status

Check the LAN:

ip -6 addr show br-lan

Finally:

ping -6 -c 3 2001:4860:4860::8888

and:

ubus call dhcp ipv6ra

should show the prefix advertised to the LAN.

One important lesson:

Don’t necessarily trust the prefix displayed by the ISP portal. Verify the prefix actually delegated to your router with OpenWrt.


11. The most important security improvement: IPv6 firewalling

With IPv6, your LAN devices can receive globally routable addresses.

There is no NAT66 protecting them.

Therefore, your firewall becomes the actual security boundary.

Set the default forwarding policy to:

REJECT

For example:

uci set firewall.@defaults[0].forward='REJECT'

uci commit firewall

fw4 check
/etc/init.d/firewall reload

The desired traffic model is:

LAN → Internet
    NEW        ALLOW

Internet → LAN
    REPLY      ALLOW
    NEW        REJECT

Internet → Router
    NEW        REJECT

with only the IPv6 control traffic explicitly required by the configuration being allowed.

This is particularly important for IPv6.

If you accidentally configure:

forward = ACCEPT

globally routable IPv6 addresses on your LAN could potentially be reachable from the Internet.


12. Harden OpenWrt management

SSH should only be available from the LAN:

uci set dropbear.main.Interface='lan'
uci commit dropbear

/etc/init.d/dropbear restart

Likewise, configure LuCI so that it listens only on your LAN management address.

For example:

192.168.1.1:80
192.168.1.1:443

rather than exposing management interfaces on the WAN.

The goal is defence in depth:

Internet
   │
   X── SSH
   X── LuCI
   X── arbitrary forwarding
   │
 Firewall
   │
  LAN

13. Add banIP

OpenWrt’s banIP can provide another layer of protection by loading IP blocklists into nftables.

It can block traffic associated with known malicious, botnet, scanner or other listed IP addresses.

It is not:

  • Deep packet inspection
  • An antivirus
  • A malware sandbox
  • Protection against every attacker
  • A replacement for keeping devices patched

Example configuration:

uci set banip.global.ban_enabled='1'
uci set banip.global.ban_protov4='1'
uci set banip.global.ban_protov6='1'

uci -q delete banip.global.ban_feed
uci add_list banip.global.ban_feed='doh'
uci add_list banip.global.ban_feed='firehol1'
uci add_list banip.global.ban_feed='threat'

uci commit banip

/etc/init.d/banip restart
/etc/init.d/banip status

The feed names must actually be present in ban_feed.

Check that the feeds have been loaded:

/etc/init.d/banip status

Think of this as an additional IP reputation layer rather than a complete security solution.


14. Optional: force DNS through Pi-hole

If you run Pi-hole on your LAN, you can configure OpenWrt to advertise it as the DNS server.

For example:

192.168.1.53

The setup can combine:

  • DHCP DNS configuration
  • IPv6 DNS configuration
  • Firewall restrictions on outbound DNS
  • DNS redirection
  • banIP’s doh feed

One important detail:

DNS-over-TLS uses port 853, not 953.


15. Improve performance with SQM and CAKE

A 1 Gbps connection can still feel slow when it is saturated.

This is the classic bufferbloat problem.

For example:

Normal Internet usage
       │
       ▼
     Great
       │
       │ Start a large upload/download
       ▼
   Huge queues
       │
       ▼
   Ping increases
       │
       ▼
 Video calls / gaming / SSH become sluggish

OpenWrt’s SQM implementation with CAKE can control these queues.

For the validated Digi 1 Gbps / 1 Gbps configuration, the tested settings are approximately:

Download: 950 Mbps
Upload:   950 Mbps
Qdisc:    CAKE
Interface: pppoe-wan
Link layer: ethernet
Overhead: 34

Example:

uci set sqm.eth1.enabled='1'
uci set sqm.eth1.interface='pppoe-wan'
uci set sqm.eth1.download='950000'
uci set sqm.eth1.upload='950000'
uci set sqm.eth1.qdisc='cake'
uci set sqm.eth1.script='piece_of_cake.qos'
uci set sqm.eth1.linklayer='ethernet'
uci set sqm.eth1.overhead='34'

uci commit sqm

/etc/init.d/sqm restart

Important: shape the PPPoE interface

The SQM interface should be:

pppoe-wan

not simply:

eth1

Also keep flow offloading disabled when using SQM because offloading can bypass the queue discipline.

The tested configuration uses approximately 950 Mbps in both directions rather than attempting to shape at the full 1000 Mbps line rate.


16. Test your bufferbloat

After configuring SQM, don’t only run a normal speed test.

You want to see what happens to latency while the connection is busy.

A very useful tool is the Waveform Bufferbloat Test:

https://www.waveform.com/tools/bufferbloat

Run it before enabling SQM to establish a baseline.

Then enable SQM and run it again.

You’re looking for lower latency under load.

The important measurements aren’t just:

Download: 950 Mbps
Upload:   950 Mbps

You should also look at:

Idle latency
        ↓
Latency while downloading
        ↓
Latency while uploading

The goal of SQM is to keep latency under control while the connection is saturated.

You can also verify CAKE directly:

tc qdisc show dev pppoe-wan

Waveform provides the Bufferbloat test here:

https://www.waveform.com/tools/bufferbloat


17. Validation checklist

Once everything is configured, verify each layer separately.

TestCommand / checkExpected
IPv4ifstatus wanWAN up, PPPoE active
IPv6 PDifstatus wan6IPv6 prefix present
LAN IPv6ip -6 addr show br-lanDigi global address
Router Advertisementubus call dhcp ipv6raLAN prefix present
IPv6 Internetping6Successful
Firewallfw4 checkPass
SQMtc qdisc show dev pppoe-wanCAKE active
BufferbloatWaveform testLow latency under load
banIP/etc/init.d/banip statusFeeds loaded

18. Common problems

IPv4 works but IPv6 doesn’t

Check:

ifstatus wan6

If there is no delegated prefix, renew the PPPoE session:

ifdown wan
sleep 3
ifup wan

Also verify that DHCPv6 is allowed through the WAN firewall.

The router has IPv6 but phones and laptops don’t

Check:

uci get dhcp.lan.ra

It should be:

server

Restart:

/etc/init.d/odhcpd restart

odhcp6c shows advertise=0

Check that DHCPv6 traffic is allowed:

UDP 547 → 546
IPv6
WAN → router

Then renew the PPPoE session.

IPv6 devices appear reachable from the Internet

Check:

uci get firewall.@defaults[0].forward

It should be:

REJECT

Also verify that you haven’t created an explicit WAN → LAN forwarding rule.

SQM is enabled but latency is still terrible

Check:

tc qdisc show dev pppoe-wan

Verify:

  • SQM is attached to pppoe-wan
  • CAKE is being used
  • Download/upload rates are realistic
  • Ethernet link-layer mode is used
  • Overhead is configured
  • Flow offloading is disabled

banIP isn’t blocking the feeds you expected

Check that the feeds are actually configured in:

ban_feed

Then:

/etc/init.d/banip status

Confirm that the feeds have been loaded.


19. Before replacing the Digi router

Before disconnecting the Digi router, make sure:

  • You have Digi 500 Mbps or 1 Gbps fibre
  • You have a compatible OpenWrt router
  • You have Digi PPPoE credentials
  • You have the VLAN ID supplied by Digi
  • You don’t require Digi fixed-line telephone service

And importantly:

  • You are not using Digi PRO-DIGI 10 Gbps

The own-router configuration documented by Digi is not applicable to PRO-DIGI 10 Gbps and is not compatible with fixed-line telephone.

So the decision is simple:

Digi 500 Mbps / 1 Gbps?
        │
       YES
        │
        ▼
Need fixed-line telephone?
        │
   ┌────┴────┐
  YES       NO
   │          │
   ▼          ▼
Digi       OpenWrt
router     possible

20. Final architecture

After completing the configuration:

                         DIGI
                          │
                        FTTH
                          │
                         ONT
                          │
                     Ethernet WAN
                          │
                      VLAN 20
                          │
                        PPPoE
                          │
                    ┌────────────┐
                    │  OpenWrt   │
                    │   Router   │
                    └────────────┘
                      │    │    │
                      │    │    └── SQM / CAKE
                      │    │
                      │    └────── banIP
                      │
                Stateful fw4
                      │
             ┌────────┴────────┐
             │                 │
          IPv4 LAN          IPv6 LAN
        192.168.1.0/24       Digi /64
             │                 │
             └────────┬────────┘
                      │
                Home devices

The security model is:

                    Internet
                       │
                       ▼
                ┌─────────────┐
                │    fw4      │
                │ Stateful    │
                │ Firewall    │
                └──────┬──────┘
                       │
              ┌────────┴────────┐
              │                 │
          Established        NEW inbound
           traffic              │
              │                  X
              ▼                REJECT
             LAN

Here are the official projects, documentation and tools referenced in this guide.

DIGI Portugal

  • DIGI Portugal – Customer Support — Contact DIGI to request the PPPoE credentials required when using your own router. DIGI provides support through chat, phone, email and social channels.
  • DIGI Portugal – NET FAQ — Official FAQ covering fibre installation, 500 Mbps / 1 Gbps services, using your own router, CG-NAT and other network-related questions.
  • DIGI Portugal – Fibre Internet — Information about DIGI’s fibre internet services and available speeds.
  • DIGI – Service Status — Check for known incidents or network service issues before troubleshooting your own equipment.

Important: DIGI’s current FAQ explicitly says that using your own router is not compatible with the fixed-line telephone service and does not apply to the PRO-DIGI 10 Gbps service. If you need the DIGI landline telephone service, keep using the DIGI-provided router.

OpenWrt

  • OpenWrt — The open-source router operating system used in this guide. The current stable series is OpenWrt 25.12.
  • OpenWrt Documentation — Official documentation covering configuration, networking, packages and administration.
  • OpenWrt Installation Guide — Instructions for installing and upgrading OpenWrt on supported hardware.
  • OpenWrt SQM Documentation — Detailed information about Smart Queue Management and CAKE traffic shaping.

banIP

banIP can be used as an additional layer of protection by blocking traffic associated with configured IP reputation and threat feeds.

Pi-hole

  • Pi-hole — Network-wide DNS filtering and ad/tracker blocking. Pi-hole is optional in this setup and can be deployed separately from the OpenWrt router.

Bufferbloat & Performance Testing

  • Waveform Bufferbloat Test — Use this before and after enabling SQM/CAKE to measure how much latency increases while the connection is under load. Waveform explains that its test compares idle latency with latency during active download and upload traffic.

For meaningful results, run the test under similar conditions before and after the SQM configuration. Ideally, test using a wired Ethernet connection to avoid Wi-Fi becoming the bottleneck.

Hardware

The configuration described in this article was validated on a GL.iNet GL-MT6000 running OpenWrt. Hardware-specific details may differ depending on the router you choose, particularly around Ethernet interfaces, VLAN configuration and available CPU performance.

  • GL.iNet — Manufacturer of the GL-MT6000 hardware used for the validation described in this guide.

Quick Reference

ComponentResource
ISPDIGI Portugal
DIGI supportCustomer Support
DIGI network FAQNET FAQ
Router OSOpenWrt
OpenWrt documentationDocumentation
SQM / CAKEOpenWrt SQM Documentation
IP reputation / blockingbanIP
DNS filteringPi-hole
Bufferbloat testingWaveform Bufferbloat Test
Tested routerGL.iNet

Conclusion

Using your own OpenWrt router with Digi FTTH gives you much more control over your network.

For the Digi 1 Gbps fibre service, this configuration has been validated using a GL.iNet GL-MT6000 running OpenWrt 25.12.5 and a 1 Gbps / 1 Gbps Digi connection.

The important pieces are:

  1. Obtain your Digi PPPoE credentials.
  2. Configure the Digi VLAN on your WAN interface.
  3. Run PPPoE on top of that VLAN.
  4. Configure IPv6 Prefix Delegation correctly.
  5. Enable Router Advertisements for LAN clients.
  6. Keep the WAN firewall restrictive.
  7. Explicitly reject unsolicited IPv6 forwarding.
  8. Restrict SSH and LuCI to the LAN.
  9. Optionally add banIP.
  10. Optionally enforce DNS through Pi-hole.
  11. Configure SQM/CAKE on the PPPoE interface.
  12. Test the result with the Waveform Bufferbloat Test.

But remember the two important boundaries:

This guide targets Digi’s 500 Mbps / 1 Gbps fibre services. It is not a guide for PRO-DIGI 10 Gbps.

And:

If you need Digi’s fixed-line telephone service, do not replace the Digi router with your own OpenWrt router.

For the supported 1 Gbps setup, OpenWrt gives you a powerful combination of router control, IPv6 security, network hardening and better latency behaviour under load.