WrtNova firmware builder

Firmware target

System

Used for SSH login and AdGuard Home admin.

One key per line.

Network

Networks & addressing

On Network IP prefix VLAN ID Subnet Router IP
LAN
Guest
IoT
WireGuard VPN

WireGuard VPN network is a dedicated network with its own WiFi SSID; all its traffic is routed through the WireGuard VPN client.

Extra VLAN IDs to trunk (tagged) through every port on this device. Space-separated; ranges as low-high.

WiFi

Note: Wired backhaul is always better when feasible

Network SSIDs

Leave password blank to use the default: 12345678

SSID and password must match between nodes for seamless roaming to work.

Advanced channels & logging

WAN

Advanced WAN options
WAN VLAN ID 802.1Q VLAN tag for the WAN interface.
WAN-B VLAN ID 802.1Q VLAN tag for WAN-B.

Add WAN port to br-vlan bridge, useful for IPTV, VoIP, and multi-PPPoE setups.

IPv4 port forwarding

Hostname Last octet Ports (space-separated)
Each row create a static DHCPv4 lease and add port forwarding from WAN. Ports must be unique.

IPv6 server exposure

Hostname Last octet Ports (empty = all)
Each row create a static hostid (IPv6 Token) in DHCP leases, IPv6 firewall forward rule, and Cloudflare DDNS entry. After boot, go to Network -> DHCP Leases and update the DUID for each host to match the actual client DUID.

DDNS (Cloudflare)

DDNS entries for IPv6-exposed hosts are derived from the IPv6 server exposure table.

Failover

USB tethering

Cellular modem (MBIM)

Encrypted DNS & ad blocking

Additional packages

Appended to the final list. Prefix with - to remove an auto-added package.

Performance & misc

Config preview

    
Leave passwords and sensitive fields empty. Defaults are safe for first boot: no root password, Wi-Fi password is 12345678. Anything you enter is sent to the ASU build server and baked into the firmware — set real credentials after first boot via LuCI or SSH.
Pick a device to enable build.

Recent builds

No builds yet.