ISP Line Migration — Firewall / Router Config Handover
Section: Network & Connectivity Tags: isp, broadband, migration, draytek, firewall, vdsl, router, line-migration, 4com, openreach Source tickets: #23962 Confidence: High — confirmed procedure used on client line changeoverOverview
When a client changes ISP or a third-party ISP migrates the client's data service (e.g., 4Com, Gradwell, Openreach FTTP upgrade), the firewall/router must be reconfigured with new credentials while preserving existing Wi-Fi and LAN settings. This article covers the handover and reconfiguration procedure, specifically for Draytek routers (most common in Purple Computing client sites).
Common Scenario
A third-party provider (e.g., 4Com) notifies Purple Computing that they are migrating a mutual client's broadband circuit. They will provide new VDSL/PPPoE credentials and potentially a new router. The goal is to retain existing firewall rules, Wi-Fi SSIDs, and LAN config while switching to the new credentials.
Prerequisites
- Current router admin access (Draytek web UI — typically
192.168.1.1or192.168.0.1) - New ISP credentials: PPPoE/VDSL username and password (request from the new ISP before the migration date — do not wait until cutover)
- Agreed migration date and time window (request a 2-hour window; actual cutover is typically 15–30 minutes)
- Remote access method for configuration (if not on-site): an iMac connected to Wi-Fi that can be accessed via TeamViewer before the ethernet reconfiguration
Pre-Migration: Preparation
- Export the current router config: Log in to the Draytek → System Maintenance → Configuration Backup → Backup — save the
.cfgfile in the client's notes - Document current LAN settings:
192.168.1.0/24 or 192.168.16.0/24)
- Default gateway IP (e.g., .1 or .254)
- DHCP range
- Any port-forward rules or firewall rules
- Document current Wi-Fi SSIDs: names and passwords for all SSIDs
- Obtain new credentials: PPPoE username, PPPoE password, and any VDSL profile details from the new ISP
- Plan remote access: If configuring remotely, ensure at least one machine on-site is reachable via Wi-Fi (TeamViewer) before ethernet changes are made
Migration Day Procedure
Step 1 — Set up remote access
Ask the client (or an on-site contact) to confirm TeamViewer is running on a machine connected to Wi-Fi. This is the recovery path if ethernet connectivity is lost during reconfiguration.
Step 2 — Update WAN credentials on existing router (preferred — no hardware swap)
This approach retains all existing firewall, Wi-Fi, and LAN configuration:
- Log in to the Draytek web UI (
192.168.1.1) - Go to WAN → General Setup → WAN1 (or the relevant WAN interface)
- Change the PPPoE username and password to the new ISP credentials
- Click OK and then Connect (or save and reboot)
- Allow 2–3 minutes for the line to re-authenticate
- Confirm internet connectivity: ping test from the router's Diagnostics → Ping →
8.8.8.8
Step 3 — If the new ISP insists on their router
If the ISP is providing a new router (e.g., 4Com's own device) and it cannot be bypassed:
- Ask the ISP to provide the VDSL/PPPoE credentials so you can enter them into the existing Draytek instead — explain this preserves the firewall and Wi-Fi configuration
- Most ISPs will agree to this — push for it before accepting a hardware swap
- If the ISP's router must be used:
Step 4 — Reconfigure LAN subnet if required
If the new ISP or router uses a conflicting LAN range (e.g., 4Com defaults to 192.168.1.x but client uses 192.168.16.x):
- In the new/reconfigured router: change the LAN subnet to match the existing client subnet (e.g.,
192.168.16.0/24, gateway.1) - Update DHCP range to match
- Reboot the router — all DHCP clients will renew within a few minutes
Post-Migration Checks
- [ ] Internet connectivity confirmed (ping to external IP + browse to a website)
- [ ] All Wi-Fi SSIDs visible and connecting correctly
- [ ] DHCP assigning correct IPs (check a few client machines)
- [ ] Any VPN or port-forward rules still working
- [ ] NAS and other fixed-IP devices reachable (confirm DHCP reservations survived config)
- [ ] Notify the new ISP that connectivity is confirmed and migration is complete
Verification
From the client's office: run a speed test (fast.com or speedtest.net). Confirm speeds match the contracted speed. Run a 5-minute ping test to 8.8.8.8 — zero drops expected on a fresh FTTC/FTTP circuit.
If This Fails
- No WAN connection after credential change: Confirm the line is actually live at the exchange (ask the ISP for line status). Some ISPs have a brief provisioning window after cutover during which the line is not yet active.
- Router not recognising new VDSL credentials: Check whether the ISP requires a specific VDSL profile (
VDSL2 17aor35b) — set this in Draytek WAN → DSL Parameter - All LAN devices lose connectivity after LAN subnet change: DHCP will renew within 60 seconds on most devices. Manually renew on any device that does not auto-recover:
ipconfig /release && ipconfig /renew(Windows) orsudo ipconfig set en0 DHCP(Mac)
Comments
0 comments
Please sign in to leave a comment.