No builds yet.
Firmware target
System
Used for SSH login and AdGuard Home admin.
One key per line.
Network
Networks & addressing
| On | Network | IP prefix | VLAN ID | Subnet | Router IP |
|---|---|---|---|---|---|
| LAN | — | ||||
| Guest | — | ||||
| IoT | — | ||||
| WireGuard VPN | — |
WireGuard VPN network is a dedicated network with its own WiFi SSID; all its traffic is routed through the WireGuard VPN client.
Extra VLAN IDs to trunk (tagged) through every port on this device. Space-separated; ranges as low-high.
WAN
WAN options
WiFi
Note: Wired backhaul is always better when feasible
Network SSIDs
Default to 12345678 when password is empty
Advanced channels & logging
IPv4 port forwarding
| Hostname | Last octet | Ports (space-separated) |
|---|
Each row create a static DHCPv4 lease and add port forwarding from WAN. Ports must be unique.
IPv6 server exposure
| Hostname | Last octet | Ports (empty = all) |
|---|
Each row create a static hostid (IPv6 Token) in DHCP leases, IPv6 firewall forward rule, and Cloudflare DDNS entry.
After boot, go to Network -> DHCP Leases and update the DUID for each host to match the actual client DUID.
DDNS (Cloudflare)
DDNS entries for IPv6-exposed hosts are derived from the IPv6 Exposure table — no extra config needed.
Failover
USB tethering
Cellular modem (MBIM)
Additional packages
Appended to the final list. Prefix with - to remove an auto-added package.
Performance & misc
Config preview
Pick a device to enable build.