AT&T U-verse Pace Plc 5268AC bridge mode (with caveat)

Steps to enable bridge mode on Pace Plc 5268AC (tested with software version Bridge mode is needed to use your own router (but it still needs to be plugged into the 5268AC). Here is the caveat: ipsec (site-to-site VPN) will not work. AT&T blocks it, so you have to upgrade to business class service to get it unblocked. This instruction is aimed for regular U-verse service w/o static IP/block. If you have a static block, you should use the Cascaded Router feature.
