No builds yet.
Firmware target
Required: ≥16MB flash, ≥128MB RAM
System
Used for SSH login and AdGuard Home admin.
One key per line.
Network
Networks & addressing
| On | Network | Interface name | IP prefix | VLAN ID | Subnet | Router IP |
|---|---|---|---|---|---|---|
| LAN | — | |||||
| Guest | — | |||||
| IoT | — | |||||
| VPN | — |
VPN network is a dedicated network with its own WiFi SSID; all its traffic is routed through the WireGuard VPN client.
Extra VLAN IDs to trunk (tagged) through every port on this device. Space-separated; ranges as low-high.
Advanced Network options
Enable packet steering across CPUs. May help or hinder network speed.
Leave empty to auto-generate a random prefix on first boot.
dhcp-instance-add command.WireGuard VPN client
Don't have a WireGuard config? Use Cloudflare's free WARP.
Interface
Peer
Advanced WireGuard options
Split tunnel
Destination IPs or subnets to bypass the tunnel. Traffic from VPN-network clients to these destinations uses the normal routing table instead of the tunnel.
WiFi
Tip: Prefer wired backhaul over wireless whenever feasible.
Network SSIDs
Leave password blank to use the default: 12345678
SSID and password must match between nodes for seamless roaming to work.
Advanced WiFi options
Longer range than 5GHz but requires tuning for higher throughput.
WAN
Advanced WAN options
Add WAN port to br-vlan bridge, useful for IPTV, VoIP, and multi-PPPoE setups.
IPv4 port forwarding
| Hostname | Last octet | Ports (space-separated) |
|---|
IPv6 server exposure
| Hostname | Last octet | Ports (empty = all) |
|---|
DDNS (Cloudflare)
Failover
USB tethering
Cellular modem (MBIM)
DNS & Ad blocking
Advanced DNS options
DoH resolver URLs, one per line. Blank uses Quad9 / Cloudflare / Google.
Plain IPs to resolve upstream hostnames + fallback. Blank uses 1.0.0.1 / 9.9.9.9.
Firewall
Threat feeds
Pre-configured IP blocklist feeds for banIP.
Country blocking
Drop WAN traffic from these countries via banIP.
Additional rules
Additional packages
Appended to the final list. Prefix with - to remove an auto-added package.