No builds yet.
Firmware target
Required: ≥8MB flash, ≥64MB RAM
In Access Point mode, DHCP is disabled and the device acts as a wireless access point and managed switch.
System
Requires OpenWrt 25 or newer.
Used for SSH login and AdGuard Home admin.
One key per line.
Advanced System options
Raw NTP server IP to sync the clock every time a WAN interface comes up.
Network
Networks & addressing
| On | Network | Interface name | IP prefix | VLAN ID | Subnet | Router IP |
|---|---|---|---|---|---|---|
| LAN | — | |||||
| Guest | — | |||||
| IoT | — | |||||
| VPN | — |
VPN network is a dedicated network with its own WiFi SSID; all its traffic is routed through the WireGuard VPN client.
Extra VLAN IDs to trunk (tagged) through every port on this device. Space-separated; ranges as low-high.
Advanced Network options
Enable packet steering across CPUs. May help or hinder network speed.
Leave empty to auto-generate a random prefix on first boot.
dhcp-instance-add command.WireGuard VPN client
Don't have a WireGuard config? Use Cloudflare's free WARP.
Interface
Peer
Advanced WireGuard options
Split tunnel
Destination IPs or subnets to bypass the tunnel. Traffic from VPN-network clients to these destinations uses the normal routing table instead of the tunnel.
WiFi
Leave password blank to use the default: 12345678
SSID and password must match between nodes for seamless roaming to work.
Advanced WiFi options
WAN
Advanced WAN options
IPv4 port forwarding
| Hostname | Last octet | Ports (space-separated) |
|---|
IPv6 server exposure
| Hostname | Last octet | Ports (empty = all) |
|---|
DDNS (Cloudflare)
Failover
DNS & Ad blocking
Advanced DNS options
DoH resolver URLs, one per line. Blank uses Quad9 / Cloudflare / Google.
Extra plain IPs, on top of the ones added automatically for the presets above.
Firewall
Pre-configured IP blocklist feeds for banIP.
Drop WAN traffic from these countries via banIP.
Additional rules
Packages
Appended to the final list. Prefix with - to remove an auto-added package.