Don't Panic, You Just Can't Configure Anything
Somewhere in Athens there is a small grey box with four ethernet ports and a Wi-Fi antenna, and it has recently taught me a great deal about the difference between "access" and "control", two words that sound like synonyms right up until an ISP gets involved and turns one of them into a con trick. The box in question is a Vantiva router, supplied by Cosmote, and it is, in the fine tradition of consumer electronics that were quietly designed by people who have never met their customer and never intend to, mostly harmless. It routes packets. It broadcasts Wi-Fi. It sits there blinking its little lights with the serene confidence of a device that knows perfectly well you cannot do anything about it.
I want to be fair to it, because fairness is a virtue and also because I am about to be extremely unfair to it for the next fifteen hundred words, so let's get the credit in early: it works. Packets arrive. Packets leave. If your entire relationship with the internet consists of watching things buffer slightly less than they used to, this router will serve you loyally for years and you will never once think about it, which is, I suspect, precisely the point.
The Four Freedoms, Generously Granted
Through what I can only describe as a genuinely heroic act of spelunking through the Cosmote app, an app that appears to have been designed by someone who was shown a screenshot of a real router admin panel once, briefly, and told to "get the gist of it", I have established the complete and exhaustive list of things Cosmote will permit a paying customer to alter on the device sitting in their own home, on their own electricity, routing their own traffic. There are four. I will list them, because they fit comfortably on one hand with a finger to spare:
You may change the router's IP address and subnet mask. You may adjust the DHCP range, though not any of the settings that actually travel with a DHCP lease, such as which DNS server your devices are told to use. You may toggle uPnP on or off, a binary act of faith. And you may forward individual ports, one at a time, protocol by protocol, in a workflow so tedious that I found myself grateful there wasn't a fifth freedom, because I genuinely do not think my patience would have survived it. Sixty-five thousand five hundred and thirty-five TCP ports and the same again in UDP, entered by hand, one at a time, each with its own little form. Somewhere a UX designer is very pleased with themselves and should not be.
The Console That Isn't There
Here is the detail that elevates this from "mildly restrictive consumer router" to "genuinely remarkable feat of engineering, in the wrong direction": there is no web admin console at all. None. Point a browser at 192.168.1.1, the address every router on Earth has answered to since roughly the Precambrian era of home networking, and you get an information page. It tells you things about the router. It does not ask you for a password, because there is nothing behind the door for a password to protect. The entire administrative surface of this device has been surgically relocated into a mobile app, which is a curious choice for a piece of infrastructure that is, definitionally, supposed to keep working when your phone is dead, your data plan has run out, or you would simply prefer to sit at a desk with a keyboard like a civilised person solving a network problem rather than pinching and zooming through a settings screen designed for adjusting your Wi-Fi name.
The maddening part is that this is the same Vantiva hardware, more or less, that ships to other ISPs and other countries with a perfectly serviceable web GUI attached, the sort with tabs and menus and the vague, old-fashioned dignity of a device that assumes its owner might know what they're doing. Cosmote didn't build a worse router. They built the same router and then took a very deliberate pair of scissors to the parts that let you drive it. That's not an engineering constraint. That's a policy decision, dressed up as a feature, and it's worth naming as such.
Three Things They Quietly Took Away
Let's be specific, because vague grumbling is easy and specific grumbling is useful. Here are three capabilities that exist in every unlocked version of this hardware, that you are paying the same monthly fee for, and that you simply do not get.
Bridge mode. This is the big one. Bridge mode, or PPPoE passthrough if you prefer the more formal name, lets a router step out of the way and hand the public IP address straight through to whatever you plug in behind it. Without it, the Cosmote router does Network Address Translation whether you want it to or not, which means anything you connect downstream, your own firewall, your own router, your own carefully assembled small empire of home lab equipment, ends up behind two layers of NAT instead of one. Double NAT isn't fatal, but it's the networking equivalent of being handed your post already opened, resealed, and re-addressed by an intermediary who insists this is for your own good. Certain VPN configurations get temperamental. Certain peer-to-peer protocols stop working entirely. And you get to debug all of it with no visibility into what the first NAT layer is actually doing, because, and I cannot stress this enough, there is no console.
DNS assignment via DHCP. You can change the DHCP range. You cannot change what DNS server gets handed out alongside it. On the surface this sounds like a footnote, and for most households it is, but for anyone running their own internal DNS resolution, their own blocklists, their own private domain namespace, this is the difference between "my network resolves the way I designed it to" and "my network resolves however Cosmote's upstream resolver feels like resolving it today". It is a small lock on a door you didn't know you needed until you noticed it was there.
Anything resembling a firewall you can actually see. Port forwarding is not a firewall. Port forwarding is a hole. A proper firewall lets you write rules, inspect logs, understand what's being blocked and why, and adjust your defences as your network changes. What Cosmote offers is the ability to poke individual, unauditable holes in a wall you're not allowed to look at, from either side. You cannot see the rule set. You cannot see the logs. You are asked to trust that the wall is doing its job, on the word of a company whose business model is measured in gigabytes sold, not security postures maintained.
The uncomfortable truth buried under all the jokes: a device you cannot inspect is a device you cannot trust, and a device you cannot trust that also sits at the very edge of your network, mediating every packet in and out, is not a minor inconvenience. It's a single point of both failure and opacity, sitting exactly where you'd most want visibility, and you were never given a vote on the trade-off.
Why This Isn't Just Pedantry
I can already hear the reasonable objection, because I am occasionally reasonable myself: most people don't need bridge mode, most people don't run their own DNS, most people would not know what to do with a firewall rule editor if you handed them one gift-wrapped. That's true, and it's also not really the point. The point is that the option has been removed rather than merely unused. There's a meaningful difference between a tool that's simple because its owner chose simplicity, and a tool that's simple because someone else decided, on your behalf and without asking, that you couldn't be trusted with the advanced settings. One is a design philosophy. The other is a company optimising for fewer support tickets at the direct expense of the technically capable minority who would genuinely benefit from, and correctly use, the features being withheld.
And the risk isn't hypothetical. A locked router with no visible logs means that when something goes wrong, and something eventually always goes wrong, you are troubleshooting blind, restarting things and hoping, because the actual diagnostic information lives on a device you're not permitted to query. A router that forces double NAT on everything downstream quietly breaks assumptions that half the internet's peer-to-peer and VPN tooling was built on. And a router that can't tell you its own firewall state is a router you're trusting entirely on faith, which is a peculiar thing to be asked to do with the one box that stands between your home network and the entire rest of the internet.
The good news, such as it is, is that none of this actually requires Cosmote's cooperation to fix. The honest answer to "my ISP router won't let me be a network engineer in my own home" isn't to keep filing support tickets asking nicely for a feature that was removed on purpose. It's to leave their box doing the one job it can't be prevented from doing, being a dumb, NATed pipe to the internet, and put a proper router behind it that does everything Cosmote decided you didn't need: DHCP, DNS, firewall rules you can actually read, VLANs, the works. Their router stays. It just stops being in charge of anything that matters. There is something quietly satisfying about routing around a restriction rather than arguing with it, and if there's a lesson the Guide would approve of here, it's that one: when the instructions say "Don't Panic" but conveniently omit "and also you can't configure the DNS server", the correct response isn't panic. It's a second router.
Previous Post
Astra and the Group That Broke the Rules