OpenWrt · Browser-built · Zero SSH
Flash once.
Everything's
already set up.
Build a fully-configured OpenWrt image — VLANs, WiFi, VPN, ad-blocking — in your browser.
What first boot configures
VLANs without learning VLANs
Segment into LAN, Guest, and IoT zones. WrtNova detects your switch hardware and wires the tagging correctly — no DSA-vs-swconfig rabbit hole.
Roaming tuned out of the box
Every SSID ships with 802.11k/v/r fast transition and usteer band steering, thresholds pre-tuned. IoT stays on plain 2.4 GHz so older devices never meet 11r/k/v quirks.
Mesh backhaul, VLANs included
802.11s mesh with SAE encryption and tuned peering, optional batman-adv on top. All VLANs are trunked over the mesh link, so guest stays guest on every node.
VPN built in — or one click to WARP
Route through your own WireGuard VPN provider, or prefill a free Cloudflare WARP config in one click. It gets its own network and SSID automatically.
Failover that is already wired
Second WAN, LTE modem, or a phone on USB. mwan3 arrives configured: health-tracked failover, load balancing, sticky HTTPS sessions.
Private and ad-free out of the box
Network-wide ad blocking and encrypted DNS. AdGuard Home on capable hardware, a lightweight fallback on smaller routers.
Port forwards as one-liners
One line per host creates the static lease and its WAN port forwards together, named in the firewall. The reservation and the redirect can never drift apart.
IPv6 servers, no NAT hacks
Each host gets a stable ::N address that survives prefix changes, its own Cloudflare DDNS subdomain, and a firewall accept scoped to exactly the ports you list.
One config, a whole fleet
Flash the same image with AP_MODE=1 and it becomes an access point and managed switch: same SSIDs, same VLANs, clients roam between nodes. The fleet builder builds router and APs in one session.
Flash once, fully configured
No LuCI menus, no SSH. WrtNova bakes your whole setup into a first-boot script. Flash the image and the router configures itself.
Plus per-network DHCP instances, Cloudflare DDNS, PPPoE, wan-port bridging, NAT offloading, NTP, zram, and more.
Your router, your config — baked in from the first boot.