WrtNova firmware builder

Firmware target

Required: ≥8MB flash, ≥64MB RAM

Mode

In Access Point mode, DHCP is disabled and the device acts as a wireless access point and managed switch.

System

Time format

Requires OpenWrt 25 or newer.

Used for SSH login and AdGuard Home admin.

One key per line.

Advanced System options

Raw NTP server IP to sync the clock every time a WAN interface comes up.

Network

Networks & addressing

On Network Interface name IP prefix VLAN ID Subnet Router IP
LAN
Guest
IoT
VPN

VPN network is a dedicated network with its own WiFi SSID; all its traffic is routed through the WireGuard VPN client.

Extra VLAN IDs to trunk (tagged) through every port on this device. Space-separated; ranges as low-high.

Advanced Network options

Enable packet steering across CPUs. May help or hinder network speed.

Leave empty to auto-generate a random prefix on first boot.

To add DHCP on a new interface, use the built-in dhcp-instance-add command.

WireGuard VPN client

Don't have a WireGuard config? Use Cloudflare's free WARP.

Interface

Peer

You can change to a different WireGuard config later via LuCI → Network → Interfaces → vpn → Edit → Load configuration. After importing a config, remember to enable Route Allowed IPs in the Peers settings.
Advanced WireGuard options

Split tunnel

Destination IPs or subnets to bypass the tunnel. Traffic from VPN-network clients to these destinations uses the normal routing table instead of the tunnel.

WiFi

LAN SSID

Leave password blank to use the default: 12345678

SSID and password must match between nodes for seamless roaming to work.

Advanced WiFi options
Note: Most modern devices support 802.11r, but some older or low-cost devices may not. If a device can't connect, try disabling 802.11r. For IoT devices, use the dedicated IoT: 802.11r toggle.

WAN

Connection type
Advanced WAN options

IPv4 port forwarding

Hostname Last octet Ports (space-separated)
Each row creates a static DHCPv4 lease and NAT port forward. Ports must be unique.

IPv6 server exposure

Hostname Last octet Ports (empty = all)
Each row creates a static hostid (IPv6 Token) in DHCP leases, an IPv6 firewall forward rule, and a Cloudflare DDNS entry. After boot, go to Network -> DHCP Leases and update the DUID for each host to match the actual client DUID.

DDNS (Cloudflare)

DDNS entries for IPv6-exposed hosts are derived from the IPv6 server exposure table.

Failover

DNS & Ad blocking

Advanced DNS options

DoH resolver URLs, one per line. Blank uses Quad9 / Cloudflare / Google.

Extra plain IPs, on top of the ones added automatically for the presets above.

Firewall

Pre-configured IP blocklist feeds for banIP.

Drop WAN traffic from these countries via banIP.

Additional rules

Packages

Final packages

Appended to the final list. Prefix with - to remove an auto-added package.

Performance & misc

Custom script

Config preview

    
Anything you type is sent to the ASU build server and stored in the generated image for up to 30 minutes. Anyone who knows the build hash (though unlikely) can download and read it. Leave sensitive fields empty and configure your real credentials after the first boot via LuCI or SSH.
Pick a device to enable build.

Recent builds

No builds yet.

Tag the LAN VLAN?

Instead of acting as normal access ports (LAN VLAN untagged/PVID), all LAN ports become trunk-only ports. Devices connected to these ports must support VLANs, such as a managed switch or a Linux/macOS computer with VLANs configured on its Ethernet port.