Firmware target
System
Used for SSH login and AdGuard Home admin.
One key per line.
Network
Networks
WireGuard VPN network creates a VLAN, a WiFi SSID, and activates the WireGuard client section. Leave WG fields blank to auto-register Cloudflare WARP.
WAN
WAN options
WiFi
Note: Wired backhaul is always better when feasible
Network SSIDs
Leave blank to use default password:
12345678
Advanced channels & logging
Port forwarding (IPv4)
| Hostname | Last octet | Ports (space-separated) |
|---|
Each row create a static DHCPv4 lease and add port forwarding from WAN. Ports must be unique.
IPv6 exposure
| Hostname | Last octet | Ports (empty = all) |
|---|
Each row create a static hostid (IPv6 Token) in DHCP leases, IPv6 firewall forward rule, and Cloudflare DDNS entry.
After boot, go to Network -> DHCP Leases and update the DUID for each host to match the actual client DUID.
DDNS (Cloudflare)
DDNS entries for IPv6-exposed hosts are derived from the IPv6 Exposure table — no extra config needed.
Failover
Cellular modem (MBIM)
USB tethering
Additional packages
Appended to the final list. Prefix with - to remove an auto-added package.
Performance & misc
Config preview
Pick a device to enable build.