PLDT Home Fibr router admin and access point (AP) isolation

Published 11 Aug 2019 in Hardware, Networking, Philippines, Servers by ZigPress

This post is clearly not our normal fare – it’s not about WordPress or ClassicPress, or Mac computers. We’ve written this in order to help out fellow users of PLDT Home Fibr internet connections here in the Philippines, following our own extremely frustrating experiences with this provider.

PLDT Router AP (Access Point) Isolation

The standard PLDT Home Fibr ONU (modem/router) – see image above – implements access point isolation, which means that while it has 4 LAN ports as well as both 2.4GHz and 5GHz wifi, any device connected via wifi cannot communicate with a device connected to a LAN port, and vice versa. Apparently this is done for “security reasons” (in other words, PLDT views its users as stupid and is looking for ways to minimise the time it spends on technical support).

What this means in practical terms is that if you have a home server (e.g. a Synology Diskstation or something like it that connects to the LAN via an ethernet cable), your wifi-connected devices cannot see it on the network, rendering it useless.

Potential Solutions

  1. Add a USB wifi adaptor to your server, if you can (only certain adaptors will work and it will also depend on your server operating system)
  2. Put your PLDT Home Fibr modem/router into bridge mode, so it just acts as a modem, and connect another wifi router to it via an ethernet cable – this involves getting the configuration of the second router just right in order for things to work, and makes it harder to access the admin screens of your PLDT box
  3. Find a way to turn off the access point isolation

We decided against solution 1, since getting the configuration right will still depend on having a second router set up in order to talk to the server while setting up the USB wifi adaptor, and tutorials showing exactly how to sort it out seem hard to find.

On researching solution 2 it seems that putting the PLDT modem/router into bridge mode can cripple the throughput speeds, so we’ve decided not to mess with that.

That leaves solution 3 – finding a way to turn off the AP isolation, and after several hours of googling various relevant-sounding phrases we found an article that linked to another article that linked to another article that linked to a Discord chat room where a search of the chats revealed a way to do it. Then we had to go to a different source, also challenging to find, in order to get the latest superadmin username and password. Phew.

The only trouble is, whenever you restart your router (or there is a power cut, which can be quite frequent here in the Philippines) you have to repeat the process of disabling the AP isolation. Still, it’s better than no solution at all, and it actually only takes a minute to do.

Disabling AP Isolation

Note: this works on our particular firmware version (RP2631) – we have no idea which other versions it works on. Try it and see.

You’ll need a Telnet client installed – here’s how to set one up on Mac or on Windows.

  1. First you have to enable the Telnet interface on your PLDT box.
    Go to (bookmark it) and log in with the following details:
    Administrator: f~i!b@e#r$h%o^m*esuperadmin (make sure the screen prompt says ‘Administrator’ NOT ‘Username’)
    Password: s(f)u_h+g|u
    For older firmware versions, a different superadmin username and password may apply
  2. Once logged in, select ‘Debug Switch’ on the sidebar menu
  3. Enable the Telnet switch and click Apply
  4. Log out
  5. Open a terminal window or command prompt
  6. telnet and use gpon as the login and as the password
  7. When it says ‘User’, type enable and press Enter, then enter gpon again as the password
  8. Type cd switch and press Enter
  9. Type control port_fw_eligiblity_switch disable and press Enter (no that’s not a typo in the word eligiblity!)
  10. Done. Close the command prompt window.

This worked a treat and we were instantly able to see and connect to our Synology Diskstation (hooked up to the PLDT box via LAN cable) from a Mac via wifi, without using an extra router.

Our intention now is to contact PLDT technical support and request that they permanently turn off AP isolation on our PLDT box, to save us having to follow the above procedure each time the PLDT box restarts following a power cut.

Please note that no systems were hacked or attacked in the making of this post – all we did was spend an afternoon fishing for information via Google and trying things out. All the information presented is already out there to be found with some effort.


  1. On 02 Oct 2019 at 03:12, Cyrian said:

    I had to make an account to thank you for this! One thing though, you need to enable the Telnet on Windows before you can enter the command line here. Thanks so much!

  2. On 08 Oct 2019 at 13:52, Bruce Wayne said:

    Hi Andy, any update on permanent disable of AP Isolation?

  3. On 15 Oct 2019 at 04:20, mike Lim said:

    Thank you for this. I don’t understand how PLDT can just keep on changing our firmwares/admin access. I’ve had this configured nicely about 1 year ago, then they suddenly decide they want to “tinker” with my, and probably everyone else’s config.

  4. On 15 Oct 2019 at 08:25, ZigPress said:

    Mike, one option (if you still have admin access) might be to turn off remote access in the router settings, and only turn it on again if you need to call PLDT for support.

  5. On 18 Feb 2020 at 21:42, Rip said:

    Instead of closing the prompt window add one more step:
    Revert back to the Config# and type ‘save’. This will save the new config commands just typed to the router flash. That way you won’t have to re-do config every power cycle.

  6. On 20 Feb 2020 at 13:18, ZigPress said:

    Wow, thanks Rip. I will try that. I wasn’t aware of that command.

  7. On 12 Jul 2020 at 08:51, Jack said:

    I did enable the 2 3 4 LAN ports. Thanks

    But I am not able to share files thru LAN connection.

    Appreciate it if you can help. THANKS!

  8. On 25 Jul 2020 at 11:25, Buggy said:

    @ Rip
    Does the save function work for every version of the modem? I have a unit with firmware version RP2631 and the “save” function does nothing. I have to do the entire “control port_fw_eligiblity_switch disable” routine again.

    What version is your modem running at?

  9. On 08 Aug 2020 at 12:15, John said:

    Hi guys!. Everything on your guide works except the last. “%Unknown command”. Not sure why I’m doing this but I just wanted to connect my printer to the my router. Router is HG6245D.
    I need to connect my USB printer AND external HDD to router.
    Is this possible?

  10. On 03 Sep 2020 at 13:27, JOEL DIMASACAT said:

    Hi bro, I plan to replace my PLDT Fiber modem with the Huawei HG8346R wireless Epon Terminal. Do you think this device can work?

  11. On 02 Dec 2020 at 14:47, cyb3rv3nom said:

    the username and password is update to “gepon”

Add a Comment

If you have used this form and would like a copy of the information held about you on this website, or would like the information deleted, please email