What your ISP router can really do — and what just vanished from the menu: dissecting the Telekom F@st 5670
A story about what you can learn about your own router once you stop arguing with the menu and start asking the firmware directly — and when the right move is to stop and buy a different box.
How it started
My home router is a Sagemcom F@st 5670 from Telekom — the standard box everyone gets with their connection. At home I run my own Pi-hole as DNS, so the router's configuration interests me a little more than the average user's.
The trigger was a small thing. After one firmware update, the page for setting the DNS server disappeared from the admin menu. I wanted to confirm the router was still handing out my own DNS to clients, and suddenly there was nowhere to look. A normal person shrugs. It wouldn't let me rest — not because there was a looming problem, but because something was there and now it isn't is exactly the kind of question I have to see through.
Don't argue with the menu — ask the firmware
The admin GUI of a router like this is, these days, an ordinary web app (Angular). It runs in the browser and talks to the router through its internal API. What you see in the menu is only what the app chooses to show — not necessarily everything the router can do.
So, logged in as admin, I downloaded and cleaned up every part of that web app (vendor libraries, scripts, configuration). In one of them I found a profile that says exactly which features should be shown for this router variant and which not — and 95 of 169 features were turned off. The DNS page among them. It wasn't removed, just hidden by this operator's profile.
That still wasn't the answer to my question. A hidden page doesn't mean the setting is correct. So I asked directly: the router has an API (in a standard called TR-181 — a shared "data model" for devices like this) that the app uses to ask for every value. I asked the same way — and got a clear answer: DNS for clients was set correctly, Pi-hole primary and a public resolver as fallback. Confirmed afterwards from a second machine. Question answered, guessing over.
The more interesting find: what isn't there at all
Since I was already inside, I looked at what else the app knows about. And here it got interesting. The router's code contains definitions for VPN, firewall and QoS — that is, traffic prioritisation. It looked like they were just hidden by the same profile as the DNS page.
They aren't. When I asked for them through the same API, the router answered plainly: I don't know that path. Their screens returned an error and the features themselves physically aren't in this firmware build. Not hidden — removed. That's an important distinction: hidden can be unlocked, missing cannot. No API, no trick brings them back, because there's simply nothing there.
Incidentally, the same firmware carries traces of being shared across several countries and operators — just dressed differently. Each operator enables a different slice of features. That's common practice, and it explains why the definitions stay in the code even when the feature isn't available in a given country.
When to stop
Here the story breaks the way I like best: the right answer was to stop.
I could have kept going, looking for a way to get a firewall or QoS back into the box. But it can't be done — they aren't there. Every additional hour would be a fight with someone else's firmware with no chance of a result. Once it's clear the path really leads nowhere, stubbornness stops being a virtue.
Instead, I put a separate ASUS RT-AX53U behind the Telekom box. It gives me exactly what the operator's box lacks: a proper firewall, isolated guest Wi-Fi, QoS and parental controls. The operator's router does the one thing it has to — it holds the internet — and a device I fully control handles the rest.
What I take from this
- The GUI isn't the truth, just a view of it. When something leaves the menu, it doesn't mean it left the device — and the reverse, that it's there because you see it in the menu. Only the device itself can tell you the truth.
- The difference between "hidden" and "doesn't exist" is fundamental. Without looking inside, I'd have spent a month looking for a way to unlock something that isn't there at all.
- Understanding the limits is as valuable as finding a way. Learning that it genuinely can't be done saves more time than any trick — and tells you when the better solution is to bring it in from outside.
This was all my own router, logged in as admin, without a single touch to anyone else's network — just thoroughly understanding the device my whole household flows through. And the result isn't some secret unlocked super-router, but a sober decision: this box can't do it and never will, so let it do the one thing it can, and I'll take the rest into my own hands.