Comcast Business IP Gateway overview

Updated 4/8/2014 10:46:01 PM by Comcast Expert


Comcast's IP Gateway (Comcast's firewall, switch and static IP-capable modem) is all you need to take advantage of a static IP and built-in firewall features. Find out what you can do with a static IP, along with the additional features available on the IP Gateway device.

Using a static vs. a dynamic IP address

A static IP address is one that will not change unless there is a network need for it to do so. A static IP will allow you to run an email, web or VPN server, from a device behind the modem (Gateway), with a static (public, routable) address.

A dynamic IP address has the potential to change at any given interval. Normally a lease time is assigned to the IP address and, once it has expired, there is a chance a different IP address will be assigned to you.

Static IPs can be ordered in blocks of 1, 5 and (in select areas) 13 for an additional monthly charge. Once ordered, a custom configuration containing the static IP range is remotely configured in the Comcast IP Gateway with no additional hardware required for you to connect it to your equipment (server, firewall, etc.).

Use your static IPs to run a server

Your server or firewall (behind the modem) should be configured with the following settings:

  • IP address: This will be given to you once it is built.

  • Subnet mask:

    • A CIDR /30 (or 1 routable static IP) -

    • A /29 (or 5 routable static IPs) -

    • A /28 (or 13 static IPs) -

  • Gateway IP: This is the last IP in the range loaded on the Comcast Gateway.

  • Primary DNS:

  • Secondary DNS:

Comcast IP Gateway features

If your specific needs do not require a static IP you may have the option to provide your own standalone cable modem. However, by utilizing the Comcast-provided Gateway you have the option to attach a separate router or hardware firewall, or utilize the built-in firewall functionality provided by the Comcast IP Gateway.

The Comcast IP Gateway's firewall offers:

  • Stateful packet inspection (SPI)

  • Port forwarding (up to 35 forwards)

  • Port blocking

  • Port triggering (up to 50)

  • Keyword blocking (up to 50)

The Comcast firewall will not provide DQOS control or bandwidth usage data. For those functions we recommend that you add your own router with firewall capabilities.

Comcast can configure the Gateway according to customer specifications. However, we will only disable a customer's firewall and DHCP service on the Gateway upon request.

Port forwarding

Port forwarding rules can be set up that will allow you to run servers from your private LAN IP subnet. An IP address is assigned to the Comcast IP Gateway, and the static IP address you purchase is available for your use (whether it's for a server, firewall or other device).

Note: The static IP cannot be port-forwarded unless it is configured for 1-to-1 NAT (forwards every port).

If the Comcast IP Gateway is used as a firewall, you'll be able to port forward traffic from the IP Gateway and use your static IP address however you like. These configurations actually allow you to use two static IP addresses while only purchasing one. The same is true if you purchase five static IP addresses. You'll have six static IP addresses available to use.

Network your computers

You can attach your computers to the IP Gateway using it as your DHCP server. It has 4 available ports and can support up to 256 (by default, this is set to 189) networked devices, however bandwidth needs may necessitate limiting the number of simultaneous connections.

Accessing the Gateway device

Customers who are onsite can make changes by following the instructions in the Comcast IP Gateway User's Guide. (See the "Ports blocked by Comcast Business Internet" article for additional information.)

Comcast does not provide remote access to the Gateway. Customers who are offsite will need to call Comcast Business Customer Support at 1-800-391-3000 to make changes for them.

Didn't find what you're looking for?

Related Articles

» More about Business Internet