# Table of Contents
- [[OpenWrt Wiki] User guide](#-openwrt-wiki-user-guide)
- [[OpenWrt Wiki] ar:docs:guide-user:start](#-openwrt-wiki-ar-docs-guide-user-start)
- [[OpenWrt Wiki] cs:docs:guide-user:start](#-openwrt-wiki-cs-docs-guide-user-start)
- [[OpenWrt Wiki] de:docs:guide-user:start](#-openwrt-wiki-de-docs-guide-user-start)
- [[OpenWrt Wiki] hu:docs:guide-user:start](#-openwrt-wiki-hu-docs-guide-user-start)
- [[OpenWrt Wiki] fr:docs:guide-user:start](#-openwrt-wiki-fr-docs-guide-user-start)
- [[OpenWrt Wiki] it:docs:guide-user:start](#-openwrt-wiki-it-docs-guide-user-start)
- [[OpenWrt Wiki] pt:docs:guide-user:start](#-openwrt-wiki-pt-docs-guide-user-start)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [Testing to determine if you are a bot!](#testing-to-determine-if-you-are-a-bot-)
- [[OpenWrt Wiki] Tor onion services](#-openwrt-wiki-tor-onion-services)
- [[OpenWrt Wiki] Installing and trusting a root CA certificate in a PKI](#-openwrt-wiki-installing-and-trusting-a-root-ca-certificate-in-a-pki)
- [[OpenWrt Wiki] chan-lantiq for Asterisk](#-openwrt-wiki-chan-lantiq-for-asterisk)
- [[OpenWrt Wiki] NUT (Network UPS Tools)](#-openwrt-wiki-nut-network-ups-tools-)
- [[OpenWrt Wiki] Cloudflare tunnel](#-openwrt-wiki-cloudflare-tunnel)
- [[OpenWrt Wiki] Netbird](#-openwrt-wiki-netbird)
- [[OpenWrt Wiki] Siproxd on OpenWrt intro](#-openwrt-wiki-siproxd-on-openwrt-intro)
- [[OpenWrt Wiki] Hiawatha webserver](#-openwrt-wiki-hiawatha-webserver)
- [[OpenWrt Wiki] Zerotier](#-openwrt-wiki-zerotier)
- [[OpenWrt Wiki] Netcat as Webserver](#-openwrt-wiki-netcat-as-webserver)
- [[OpenWrt Wiki] SSH tunnel](#-openwrt-wiki-ssh-tunnel)
- [[OpenWrt Wiki] µMurmur](#-openwrt-wiki-murmur)
- [[OpenWrt Wiki] FreeSWITCH on OpenWrt intro](#-openwrt-wiki-freeswitch-on-openwrt-intro)
- [[OpenWrt Wiki] Pseudowire](#-openwrt-wiki-pseudowire)
- [[OpenWrt Wiki] Wake on LAN configuration](#-openwrt-wiki-wake-on-lan-configuration)
- [[OpenWrt Wiki] mini-httpd webserver](#-openwrt-wiki-mini-httpd-webserver)
- [[OpenWrt Wiki] Wake on LAN (sending Ethernet messages to power up network devices)](#-openwrt-wiki-wake-on-lan-sending-ethernet-messages-to-power-up-network-devices-)
- [[OpenWrt Wiki] TLS/SSL certificates for a server](#-openwrt-wiki-tls-ssl-certificates-for-a-server)
- [[OpenWrt Wiki] Etherwake configuration](#-openwrt-wiki-etherwake-configuration)
- [[OpenWrt Wiki] Tinydns](#-openwrt-wiki-tinydns)
- [[OpenWrt Wiki] DLNA Media Server](#-openwrt-wiki-dlna-media-server)
- [[OpenWrt Wiki] docs:guide-user:services:network_monitoring:collectd.rrdtool](#-openwrt-wiki-docs-guide-user-services-network-monitoring-collectd-rrdtool)
- [[OpenWrt Wiki] Bandwidthd](#-openwrt-wiki-bandwidthd)
- [[OpenWrt Wiki] Zabbix network monitoring](#-openwrt-wiki-zabbix-network-monitoring)
- [[OpenWrt Wiki] Bandwith Monitoring with wrtbwmon](#-openwrt-wiki-bandwith-monitoring-with-wrtbwmon)
- [[OpenWrt Wiki] Minimal SNMP Daemon (mini_snmpd) configuration](#-openwrt-wiki-minimal-snmp-daemon-mini-snmpd-configuration)
- [[OpenWrt Wiki] daloRADIUS management system](#-openwrt-wiki-daloradius-management-system)
- [[OpenWrt Wiki] ZNC IRC network bouncer](#-openwrt-wiki-znc-irc-network-bouncer)
- [[OpenWrt Wiki] TLS libraries](#-openwrt-wiki-tls-libraries)
- [[OpenWrt Wiki] How to add data from a TP9605BT multimeter to apcupsd rrd and graphs.](#-openwrt-wiki-how-to-add-data-from-a-tp9605bt-multimeter-to-apcupsd-rrd-and-graphs-)
- [[OpenWrt Wiki] OpenSSH Multi Factor Authentication](#-openwrt-wiki-openssh-multi-factor-authentication)
- [[OpenWrt Wiki] APC SmartUps SU-700 - Linksys EA3500 - LuCI graphs](#-openwrt-wiki-apc-smartups-su-700-linksys-ea3500-luci-graphs)
- [[OpenWrt Wiki] Using OpenWrt to build a LAMP/WordPress server](#-openwrt-wiki-using-openwrt-to-build-a-lamp-wordpress-server)
- [[OpenWrt Wiki] uHTTPd webserver](#-openwrt-wiki-uhttpd-webserver)
- [[OpenWrt Wiki] PHP](#-openwrt-wiki-php)
- [[OpenWrt Wiki] BusyBox HTTP Daemon (httpd) webserver](#-openwrt-wiki-busybox-http-daemon-httpd-webserver)
- [[OpenWrt Wiki] BitTorrent](#-openwrt-wiki-bittorrent)
- [[OpenWrt Wiki] E-MailRelay](#-openwrt-wiki-e-mailrelay)
- [[OpenWrt Wiki] Samba Advanced Settings](#-openwrt-wiki-samba-advanced-settings)
- [[OpenWrt Wiki] APC BackUps ES-500 - Linksys EA3500 - LuCI graphs](#-openwrt-wiki-apc-backups-es-500-linksys-ea3500-luci-graphs)
- [[OpenWrt Wiki] VPN (Virtual Private Network)](#-openwrt-wiki-vpn-virtual-private-network-)
- [[OpenWrt Wiki] Network Traffic Monitor with vnStat](#-openwrt-wiki-network-traffic-monitor-with-vnstat)
- [[OpenWrt Wiki] Darkstat](#-openwrt-wiki-darkstat)
- [[OpenWrt Wiki] Ostiary Client (run a fixed set of commands remotely)](#-openwrt-wiki-ostiary-client-run-a-fixed-set-of-commands-remotely-)
- [[OpenWrt Wiki] saned Scanner Server](#-openwrt-wiki-saned-scanner-server)
- [[OpenWrt Wiki] Autossh](#-openwrt-wiki-autossh)
- [[OpenWrt Wiki] Get a free HTTPS certificate from LetsEncrypt for OpenWrt with ACME.sh](#-openwrt-wiki-get-a-free-https-certificate-from-letsencrypt-for-openwrt-with-acme-sh)
- [[OpenWrt Wiki] Share USB hard-drive with Samba using LuCI](#-openwrt-wiki-share-usb-hard-drive-with-samba-using-luci)
- [[OpenWrt Wiki] Tor client](#-openwrt-wiki-tor-client)
- [[OpenWrt Wiki] uHTTPd Web Server Configuration](#-openwrt-wiki-uhttpd-web-server-configuration)
- [[OpenWrt Wiki] Apache HTTP Server](#-openwrt-wiki-apache-http-server)
- [[OpenWrt Wiki] Transmission configuration](#-openwrt-wiki-transmission-configuration)
- [[OpenWrt Wiki] Tor extras](#-openwrt-wiki-tor-extras)
- [[OpenWrt Wiki] Lighttpd webserver](#-openwrt-wiki-lighttpd-webserver)
- [[OpenWrt Wiki] NTP (time synchronization over Network Time Protocol)](#-openwrt-wiki-ntp-time-synchronization-over-network-time-protocol-)
- [[OpenWrt Wiki] SNMP (Simple Network Management Protocol)](#-openwrt-wiki-snmp-simple-network-management-protocol-)
- [[OpenWrt Wiki] Asterisk](#-openwrt-wiki-asterisk)
- [[OpenWrt Wiki] Tor](#-openwrt-wiki-tor)
- [[OpenWrt Wiki] Set up a LAMP webserver stack](#-openwrt-wiki-set-up-a-lamp-webserver-stack)
- [[OpenWrt Wiki] Ostiary Daemon (run a fixed set of commands remotely)](#-openwrt-wiki-ostiary-daemon-run-a-fixed-set-of-commands-remotely-)
- [[OpenWrt Wiki] UPS (Uninterruptible Power Supply)](#-openwrt-wiki-ups-uninterruptible-power-supply-)
- [[OpenWrt Wiki] Control your device remotely without direct SSH access](#-openwrt-wiki-control-your-device-remotely-without-direct-ssh-access)
- [[OpenWrt Wiki] VoIP (Voice over Internet Protocol)](#-openwrt-wiki-voip-voice-over-internet-protocol-)
- [[OpenWrt Wiki] Web servers](#-openwrt-wiki-web-servers)
- [[OpenWrt Wiki] Network monitoring](#-openwrt-wiki-network-monitoring)
- [[OpenWrt Wiki] For Developers: Activating EAD (Emergency Access Daemon) Before Running into Problems](#-openwrt-wiki-for-developers-activating-ead-emergency-access-daemon-before-running-into-problems)
- [[OpenWrt Wiki] OpenWrt as a Xen DomU guest](#-openwrt-wiki-openwrt-as-a-xen-domu-guest)
- [[OpenWrt Wiki] OpenWrt security features](#-openwrt-wiki-openwrt-security-features)
- [[OpenWrt Wiki] Security Guide for the Paranoid](#-openwrt-wiki-security-guide-for-the-paranoid)
- [[OpenWrt Wiki] Regaining access to an OpenWrt device in client mode](#-openwrt-wiki-regaining-access-to-an-openwrt-device-in-client-mode)
- [[OpenWrt Wiki] OpenWrt as a Docker Image](#-openwrt-wiki-openwrt-as-a-docker-image)
- [[OpenWrt Wiki] Docker OpenWrt Image Generation](#-openwrt-wiki-docker-openwrt-image-generation)
- [[OpenWrt Wiki] Metarouter Virtualization on Mikrotik RouterBoard](#-openwrt-wiki-metarouter-virtualization-on-mikrotik-routerboard)
- [[OpenWrt Wiki] Resetting the root password](#-openwrt-wiki-resetting-the-root-password)
- [[OpenWrt Wiki] OpenWrt Public Keys](#-openwrt-wiki-openwrt-public-keys)
- [[OpenWrt Wiki] OpenWrt in LXC containers](#-openwrt-wiki-openwrt-in-lxc-containers)
- [[OpenWrt Wiki] Key Generation](#-openwrt-wiki-key-generation)
- [[OpenWrt Wiki] OpenWrt Debricking Guide](#-openwrt-wiki-openwrt-debricking-guide)
- [[OpenWrt Wiki] Failsafe mode, factory reset, and recovery mode](#-openwrt-wiki-failsafe-mode-factory-reset-and-recovery-mode)
- [[OpenWrt Wiki] Release Signing](#-openwrt-wiki-release-signing)
- [[OpenWrt Wiki] What is TFTP Recovery over Ethernet?](#-openwrt-wiki-what-is-tftp-recovery-over-ethernet-)
- [[OpenWrt Wiki] OpenWrt as DomU in Debian Xen4 in a private network](#-openwrt-wiki-openwrt-as-domu-in-debian-xen4-in-a-private-network)
- [[OpenWrt Wiki] OpenWrt as QEMU/KVM host server](#-openwrt-wiki-openwrt-as-qemu-kvm-host-server)
- [[OpenWrt Wiki] Podman Containers](#-openwrt-wiki-podman-containers)
- [[OpenWrt Wiki] OpenWrt on VMware HowTo](#-openwrt-wiki-openwrt-on-vmware-howto)
- [[OpenWrt Wiki] Rescue from failed firmware upgrade](#-openwrt-wiki-rescue-from-failed-firmware-upgrade)
- [[OpenWrt Wiki] OpenWrt in QEMU](#-openwrt-wiki-openwrt-in-qemu)
- [[OpenWrt Wiki] OpenWrt running as metarouter on mikrotik routerOS](#-openwrt-wiki-openwrt-running-as-metarouter-on-mikrotik-routeros)
- [[OpenWrt Wiki] OpenWrt security hardening](#-openwrt-wiki-openwrt-security-hardening)
- [[OpenWrt Wiki] OpenWrt as Docker container host](#-openwrt-wiki-openwrt-as-docker-container-host)
- [[OpenWrt Wiki] Troubleshooting](#-openwrt-wiki-troubleshooting)
- [[OpenWrt Wiki] Backup and restore](#-openwrt-wiki-backup-and-restore)
- [[OpenWrt Wiki] OpenWrt on VirtualBox HowTo](#-openwrt-wiki-openwrt-on-virtualbox-howto)
- [[OpenWrt Wiki] Elevating privileges with sudo](#-openwrt-wiki-elevating-privileges-with-sudo)
- [[OpenWrt Wiki] OpenWrt on UTM on Apple Silicon HowTo](#-openwrt-wiki-openwrt-on-utm-on-apple-silicon-howto)
- [[OpenWrt Wiki] VirtualBox Advanced](#-openwrt-wiki-virtualbox-advanced)
- [[OpenWrt Wiki] Secure access to your router](#-openwrt-wiki-secure-access-to-your-router)
- [[OpenWrt Wiki] Dropbear key-based authentication](#-openwrt-wiki-dropbear-key-based-authentication)
- [[OpenWrt Wiki] OpenWrt on VMware Fusion on Apple Silicon HowTo](#-openwrt-wiki-openwrt-on-vmware-fusion-on-apple-silicon-howto)
- [[OpenWrt Wiki] Security](#-openwrt-wiki-security)
- [[OpenWrt Wiki] Virtualization](#-openwrt-wiki-virtualization)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-ar-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-ar-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] docs:guide-user:firewall:shorewall:shorewall-on-openwrt](#-openwrt-wiki-docs-guide-user-firewall-shorewall-shorewall-on-openwrt)
- [[OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-es-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] de:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-de-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] docs:guide-user:services:nas:pure-ftpd](#-openwrt-wiki-docs-guide-user-services-nas-pure-ftpd)
- [[OpenWrt Wiki] docs:guide-user:services:voip:stund](#-openwrt-wiki-docs-guide-user-services-voip-stund)
- [[OpenWrt Wiki] docs:guide-user:services:vpn:tinc](#-openwrt-wiki-docs-guide-user-services-vpn-tinc)
- [[OpenWrt Wiki] docs:guide-user:firewall:netfilter-iptables:iptables_and_firewall](#-openwrt-wiki-docs-guide-user-firewall-netfilter-iptables-iptables-and-firewall)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] es:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-es-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:start](#-openwrt-wiki-es-docs-guide-user-base-system-start)
- [[OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-es-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.sysupgrade](#-openwrt-wiki-es-docs-guide-user-installation-generic-sysupgrade)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:user.beginner.cli](#-openwrt-wiki-es-docs-guide-user-base-system-user-beginner-cli)
- [[OpenWrt Wiki] es:docs:guide-user:luci:start](#-openwrt-wiki-es-docs-guide-user-luci-start)
- [[OpenWrt Wiki] es:docs:guide-user:network:start](#-openwrt-wiki-es-docs-guide-user-network-start)
- [[OpenWrt Wiki] es:docs:guide-user:luci:luci.themes](#-openwrt-wiki-es-docs-guide-user-luci-luci-themes)
- [[OpenWrt Wiki] es:docs:guide-user:network:openwrt_as_routerdevice](#-openwrt-wiki-es-docs-guide-user-network-openwrt-as-routerdevice)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:start](#-openwrt-wiki-es-docs-guide-user-firewall-start)
- [[OpenWrt Wiki] es:docs:guide-user:luci:statistics.chart.public](#-openwrt-wiki-es-docs-guide-user-luci-statistics-chart-public)
- [[OpenWrt Wiki] es:docs:guide-user:network:architecture](#-openwrt-wiki-es-docs-guide-user-network-architecture)
- [[OpenWrt Wiki] es:docs:guide-user:luci:static_ip](#-openwrt-wiki-es-docs-guide-user-luci-static-ip)
- [[OpenWrt Wiki] es:docs:guide-user:network:bonding](#-openwrt-wiki-es-docs-guide-user-network-bonding)
- [[OpenWrt Wiki] es:docs:guide-user:network:integrating-openwrt-introduction](#-openwrt-wiki-es-docs-guide-user-network-integrating-openwrt-introduction)
- [[OpenWrt Wiki] es:docs:guide-user:network:protocol.dhcp](#-openwrt-wiki-es-docs-guide-user-network-protocol-dhcp)
- [[OpenWrt Wiki] es:docs:guide-user:network:network_interface_alias](#-openwrt-wiki-es-docs-guide-user-network-network-interface-alias)
- [[OpenWrt Wiki] es:docs:guide-user:network:routedclient](#-openwrt-wiki-es-docs-guide-user-network-routedclient)
- [[OpenWrt Wiki] es:docs:guide-user:network:network_configuration](#-openwrt-wiki-es-docs-guide-user-network-network-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:network:switch_router_gateway_and_nat](#-openwrt-wiki-es-docs-guide-user-network-switch-router-gateway-and-nat)
- [[OpenWrt Wiki] es:docs:guide-user:network:map](#-openwrt-wiki-es-docs-guide-user-network-map)
- [[OpenWrt Wiki] es:docs:guide-user:luci:webinterface.overview](#-openwrt-wiki-es-docs-guide-user-luci-webinterface-overview)
- [[OpenWrt Wiki] es:docs:guide-user:network:high-availability](#-openwrt-wiki-es-docs-guide-user-network-high-availability)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:lirc](#-openwrt-wiki-es-docs-guide-user-hardware-lirc)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:watchdog](#-openwrt-wiki-es-docs-guide-user-hardware-watchdog)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:pwm](#-openwrt-wiki-es-docs-guide-user-hardware-pwm)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns](#-openwrt-wiki-es-docs-guide-user-firewall-filtering-traffic-at-ip-addresses-by-dns)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:firewall_components](#-openwrt-wiki-es-docs-guide-user-firewall-firewall-components)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:basic](#-openwrt-wiki-es-docs-guide-user-base-system-basic)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:clarifying_interface_usage](#-openwrt-wiki-es-docs-guide-user-base-system-clarifying-interface-usage)
- [[OpenWrt Wiki] es:docs:guide-user:advanced:ntp_configuration](#-openwrt-wiki-es-docs-guide-user-advanced-ntp-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:fw3_network](#-openwrt-wiki-es-docs-guide-user-firewall-fw3-network)
- [[OpenWrt Wiki] es:docs:guide-user:network:openwrt_as_clientdevice](#-openwrt-wiki-es-docs-guide-user-network-openwrt-as-clientdevice)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:overview](#-openwrt-wiki-es-docs-guide-user-firewall-overview)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:terminate.console.on.serial](#-openwrt-wiki-es-docs-guide-user-hardware-terminate-console-on-serial)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:turnoff.uart.to.gpio](#-openwrt-wiki-es-docs-guide-user-hardware-turnoff-uart-to-gpio)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:owsip](#-openwrt-wiki-es-docs-guide-user-hardware-owsip)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:usb.i2c-tiny-usb](#-openwrt-wiki-es-docs-guide-user-hardware-usb-i2c-tiny-usb)
- [[OpenWrt Wiki] es:docs:guide-user:storage:start](#-openwrt-wiki-es-docs-guide-user-storage-start)
- [[OpenWrt Wiki] es:docs:guide-user:services:start](#-openwrt-wiki-es-docs-guide-user-services-start)
- [[OpenWrt Wiki] docs:guide-user:services:bbstored](#-openwrt-wiki-docs-guide-user-services-bbstored)
- [[OpenWrt Wiki] docs:guide-user:firewall:freifunk_p2pblock](#-openwrt-wiki-docs-guide-user-firewall-freifunk-p2pblock)
- [[OpenWrt Wiki] syslog-ng](#-openwrt-wiki-syslog-ng)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:esp8266-serial-bridge](#-openwrt-wiki-es-docs-guide-user-hardware-esp8266-serial-bridge)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:usb_gadget](#-openwrt-wiki-es-docs-guide-user-hardware-usb-gadget)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:usb.overview](#-openwrt-wiki-es-docs-guide-user-hardware-usb-overview)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:mmc_over_gpio](#-openwrt-wiki-es-docs-guide-user-hardware-mmc-over-gpio)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:lirc-audio_alsa](#-openwrt-wiki-es-docs-guide-user-hardware-lirc-audio-alsa)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:debrick.ath79.using.jtag](#-openwrt-wiki-es-docs-guide-user-hardware-debrick-ath79-using-jtag)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:lirc-gpioblaster](#-openwrt-wiki-es-docs-guide-user-hardware-lirc-gpioblaster)
- [[OpenWrt Wiki] es:docs:guide-user:storage:writable_ntfs](#-openwrt-wiki-es-docs-guide-user-storage-writable-ntfs)
- [[OpenWrt Wiki] es:docs:guide-user:storage:disk.encryption](#-openwrt-wiki-es-docs-guide-user-storage-disk-encryption)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:piratebox.librarybox.openwrt.routers](#-openwrt-wiki-es-docs-guide-user-hardware-piratebox-librarybox-openwrt-routers)
- [[OpenWrt Wiki] es:docs:guide-user:services:babeld](#-openwrt-wiki-es-docs-guide-user-services-babeld)
- [[OpenWrt Wiki] es:docs:guide-user:services:crowdsec](#-openwrt-wiki-es-docs-guide-user-services-crowdsec)
- [[OpenWrt Wiki] es:docs:guide-user:storage:usb-installing](#-openwrt-wiki-es-docs-guide-user-storage-usb-installing)
- [[OpenWrt Wiki] es:docs:guide-user:storage:filesystems-and-partitions](#-openwrt-wiki-es-docs-guide-user-storage-filesystems-and-partitions)
- [[OpenWrt Wiki] es:docs:guide-user:storage:mountd](#-openwrt-wiki-es-docs-guide-user-storage-mountd)
- [[OpenWrt Wiki] es:docs:guide-user:storage:fstab](#-openwrt-wiki-es-docs-guide-user-storage-fstab)
- [[OpenWrt Wiki] es:docs:guide-user:services:vblade](#-openwrt-wiki-es-docs-guide-user-services-vblade)
- [[OpenWrt Wiki] es:docs:guide-user:storage:hd-idle](#-openwrt-wiki-es-docs-guide-user-storage-hd-idle)
- [[OpenWrt Wiki] es:docs:guide-user:hardware:devolo-stream-radio](#-openwrt-wiki-es-docs-guide-user-hardware-devolo-stream-radio)
- [[OpenWrt Wiki] Ad blocking](#-openwrt-wiki-ad-blocking)
- [[OpenWrt Wiki] es:docs:guide-user:services:gitolite](#-openwrt-wiki-es-docs-guide-user-services-gitolite)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:dns_configuration](#-openwrt-wiki-es-docs-guide-user-base-system-dns-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:notuci.config](#-openwrt-wiki-es-docs-guide-user-base-system-notuci-config)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:log.essentials](#-openwrt-wiki-es-docs-guide-user-base-system-log-essentials)
- [[OpenWrt Wiki] es:docs:guide-user:network:mptcp](#-openwrt-wiki-es-docs-guide-user-network-mptcp)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:managing_services](#-openwrt-wiki-es-docs-guide-user-base-system-managing-services)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:ddns](#-openwrt-wiki-es-docs-guide-user-base-system-ddns)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:system_configuration](#-openwrt-wiki-es-docs-guide-user-base-system-system-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings](#-openwrt-wiki-es-docs-guide-user-luci-getting-rid-of-luci-https-certificate-warnings)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address](#-openwrt-wiki-es-docs-guide-user-base-system-persistent-ethernet-interface-naming-by-mac-address)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:dropbear](#-openwrt-wiki-es-docs-guide-user-base-system-dropbear)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:httpd](#-openwrt-wiki-es-docs-guide-user-base-system-httpd)
- [[OpenWrt Wiki] es:docs:guide-user:luci:luci_app_statistics](#-openwrt-wiki-es-docs-guide-user-luci-luci-app-statistics)
- [[OpenWrt Wiki] es:docs:guide-user:luci:luci.on.lighttpd](#-openwrt-wiki-es-docs-guide-user-luci-luci-on-lighttpd)
- [[OpenWrt Wiki] es:docs:guide-user:network:singleportrouter](#-openwrt-wiki-es-docs-guide-user-network-singleportrouter)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:dhcp.dnsmasq](#-openwrt-wiki-es-docs-guide-user-base-system-dhcp-dnsmasq)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:led_configuration](#-openwrt-wiki-es-docs-guide-user-base-system-led-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:users](#-openwrt-wiki-es-docs-guide-user-base-system-users)
- [[OpenWrt Wiki] es:docs:guide-user:luci:luci.secure](#-openwrt-wiki-es-docs-guide-user-luci-luci-secure)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:basic-networking](#-openwrt-wiki-es-docs-guide-user-base-system-basic-networking)
- [[OpenWrt Wiki] es:docs:guide-user:network:protocol.static](#-openwrt-wiki-es-docs-guide-user-network-protocol-static)
- [[OpenWrt Wiki] Quick Start for Adding a USB drive](#-openwrt-wiki-quick-start-for-adding-a-usb-drive)
- [[OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-es-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] es:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-es-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] rsyslog](#-openwrt-wiki-rsyslog)
- [[OpenWrt Wiki] Dashboard](#-openwrt-wiki-dashboard)
- [[OpenWrt Wiki] es:docs:guide-user:luci:luci.essentials](#-openwrt-wiki-es-docs-guide-user-luci-luci-essentials)
- [[OpenWrt Wiki] Usar dispositivos de almacenamiento](#-openwrt-wiki-usar-dispositivos-de-almacenamiento)
- [[OpenWrt Wiki] es:docs:guide-user:additional-software:opkg](#-openwrt-wiki-es-docs-guide-user-additional-software-opkg)
- [[OpenWrt Wiki] es:docs:guide-user:additional-software:smartmontools](#-openwrt-wiki-es-docs-guide-user-additional-software-smartmontools)
- [[OpenWrt Wiki] es:docs:guide-user:additional-software:opkg-to-apk-cheatsheet](#-openwrt-wiki-es-docs-guide-user-additional-software-opkg-to-apk-cheatsheet)
- [[OpenWrt Wiki] es:docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login](#-openwrt-wiki-es-docs-guide-user-additional-software-show-upgradable-packages-after-ssh-login)
- [[OpenWrt Wiki] es:docs:guide-user:services:kerberos](#-openwrt-wiki-es-docs-guide-user-services-kerberos)
- [[OpenWrt Wiki] es:docs:guide-user:additional-software:imagebuilder](#-openwrt-wiki-es-docs-guide-user-additional-software-imagebuilder)
- [[OpenWrt Wiki] es:docs:guide-user:services:irqbalance](#-openwrt-wiki-es-docs-guide-user-services-irqbalance)
- [[OpenWrt Wiki] es:docs:guide-user:services:banip](#-openwrt-wiki-es-docs-guide-user-services-banip)
- [[OpenWrt Wiki] SSH 설정](#-openwrt-wiki-ssh-)
- [[OpenWrt Wiki] IPv4/IPv6 transition technologies](#-openwrt-wiki-ipv4-ipv6-transition-technologies)
- [[OpenWrt Wiki] Programar tareas con cron](#-openwrt-wiki-programar-tareas-con-cron)
- [[OpenWrt Wiki] es:docs:guide-user:services:chroot](#-openwrt-wiki-es-docs-guide-user-services-chroot)
- [[OpenWrt Wiki] es:docs:guide-user:services:snort](#-openwrt-wiki-es-docs-guide-user-services-snort)
- [[OpenWrt Wiki] es:docs:guide-user:services:rng](#-openwrt-wiki-es-docs-guide-user-services-rng)
- [[OpenWrt Wiki] es:docs:guide-user:services:python](#-openwrt-wiki-es-docs-guide-user-services-python)
- [[OpenWrt Wiki] es:docs:guide-user:services:ugps](#-openwrt-wiki-es-docs-guide-user-services-ugps)
- [[OpenWrt Wiki] es:docs:guide-user:services:fwknop](#-openwrt-wiki-es-docs-guide-user-services-fwknop)
- [[OpenWrt Wiki] es:docs:guide-user:services:usb.iptunnel](#-openwrt-wiki-es-docs-guide-user-services-usb-iptunnel)
- [[OpenWrt Wiki] es:docs:guide-user:services:honeypots](#-openwrt-wiki-es-docs-guide-user-services-honeypots)
- [[OpenWrt Wiki] es:docs:guide-user:services:xmpp.server](#-openwrt-wiki-es-docs-guide-user-services-xmpp-server)
- [[OpenWrt Wiki] es:docs:guide-user:services:geoip-shell](#-openwrt-wiki-es-docs-guide-user-services-geoip-shell)
- [[OpenWrt Wiki] es:docs:guide-user:services:telegraf](#-openwrt-wiki-es-docs-guide-user-services-telegraf)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:dhcp_configuration](#-openwrt-wiki-es-docs-guide-user-base-system-dhcp-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:services:tftp.pxe-server](#-openwrt-wiki-es-docs-guide-user-services-tftp-pxe-server)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:start](#-openwrt-wiki-es-docs-guide-user-troubleshooting-start)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:fusion](#-openwrt-wiki-es-docs-guide-user-virtualization-fusion)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:virtualbox-advanced](#-openwrt-wiki-es-docs-guide-user-virtualization-virtualbox-advanced)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:mikrotik_metarouter_openwrt](#-openwrt-wiki-es-docs-guide-user-virtualization-mikrotik-metarouter-openwrt)
- [[OpenWrt Wiki] es:docs:guide-user:security:sudo](#-openwrt-wiki-es-docs-guide-user-security-sudo)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:dhcp](#-openwrt-wiki-es-docs-guide-user-base-system-dhcp)
- [[OpenWrt Wiki] es:docs:guide-user:firewall:firewall_configuration](#-openwrt-wiki-es-docs-guide-user-firewall-firewall-configuration)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:hotplug](#-openwrt-wiki-es-docs-guide-user-base-system-hotplug)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:backup_restore](#-openwrt-wiki-es-docs-guide-user-troubleshooting-backup-restore)
- [[OpenWrt Wiki] es:docs:guide-user:base-system:uci](#-openwrt-wiki-es-docs-guide-user-base-system-uci)
- [[OpenWrt Wiki] es:docs:guide-user:security:start](#-openwrt-wiki-es-docs-guide-user-security-start)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:vmware](#-openwrt-wiki-es-docs-guide-user-virtualization-vmware)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:qemu](#-openwrt-wiki-es-docs-guide-user-virtualization-qemu)
- [[OpenWrt Wiki] es:docs:guide-user:network:ucicheatsheet](#-openwrt-wiki-es-docs-guide-user-network-ucicheatsheet)
- [[OpenWrt Wiki] es:docs:guide-user:security:dropbear.public-key.auth](#-openwrt-wiki-es-docs-guide-user-security-dropbear-public-key-auth)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:start](#-openwrt-wiki-es-docs-guide-user-virtualization-start)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:vendor_specific_rescue](#-openwrt-wiki-es-docs-guide-user-troubleshooting-vendor-specific-rescue)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:xen](#-openwrt-wiki-es-docs-guide-user-virtualization-xen)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:generic.debrick](#-openwrt-wiki-es-docs-guide-user-troubleshooting-generic-debrick)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:metarouter](#-openwrt-wiki-es-docs-guide-user-virtualization-metarouter)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:obtain.firmware.docker](#-openwrt-wiki-es-docs-guide-user-virtualization-obtain-firmware-docker)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:ead](#-openwrt-wiki-es-docs-guide-user-troubleshooting-ead)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:docker_openwrt_image](#-openwrt-wiki-es-docs-guide-user-virtualization-docker-openwrt-image)
- [[OpenWrt Wiki] es:docs:guide-user:network:tunneling_interface_protocols](#-openwrt-wiki-es-docs-guide-user-network-tunneling-interface-protocols)
- [[OpenWrt Wiki] OpenWrt como host de contenedor Docker](#-openwrt-wiki-openwrt-como-host-de-contenedor-docker)
- [[OpenWrt Wiki] es:docs:guide-user:security:security_guide_for_the_paranoid](#-openwrt-wiki-es-docs-guide-user-security-security-guide-for-the-paranoid)
- [[OpenWrt Wiki] es:docs:guide-user:security:recovering_from_clientmode](#-openwrt-wiki-es-docs-guide-user-security-recovering-from-clientmode)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:tftpserver](#-openwrt-wiki-es-docs-guide-user-troubleshooting-tftpserver)
- [[OpenWrt Wiki] es:docs:guide-user:security:secure.access](#-openwrt-wiki-es-docs-guide-user-security-secure-access)
- [[OpenWrt Wiki] OpenWrt en contenedores LXC](#-openwrt-wiki-openwrt-en-contenedores-lxc)
- [[OpenWrt Wiki] es:docs:guide-user:security:openwrt_security](#-openwrt-wiki-es-docs-guide-user-security-openwrt-security)
- [[OpenWrt Wiki] Como correr OpenWrt en VirtualBox](#-openwrt-wiki-como-correr-openwrt-en-virtualbox)
- [[OpenWrt Wiki] es:docs:guide-user:security:signatures](#-openwrt-wiki-es-docs-guide-user-security-signatures)
- [[OpenWrt Wiki] es:docs:guide-user:security:release_signatures](#-openwrt-wiki-es-docs-guide-user-security-release-signatures)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:start](#-openwrt-wiki-fr-docs-guide-user-installation-start)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:root_password_reset](#-openwrt-wiki-es-docs-guide-user-troubleshooting-root-password-reset)
- [[OpenWrt Wiki] es:docs:guide-user:troubleshooting:failsafe_and_factory_reset](#-openwrt-wiki-es-docs-guide-user-troubleshooting-failsafe-and-factory-reset)
- [[OpenWrt Wiki] es:docs:guide-user:security:security-features](#-openwrt-wiki-es-docs-guide-user-security-security-features)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:qemu_host](#-openwrt-wiki-es-docs-guide-user-virtualization-qemu-host)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:podman](#-openwrt-wiki-es-docs-guide-user-virtualization-podman)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:xen_debian_private_network](#-openwrt-wiki-es-docs-guide-user-virtualization-xen-debian-private-network)
- [[OpenWrt Wiki] es:docs:guide-user:virtualization:utm](#-openwrt-wiki-es-docs-guide-user-virtualization-utm)
- [[OpenWrt Wiki] es:docs:guide-user:security:keygen](#-openwrt-wiki-es-docs-guide-user-security-keygen)
- [[OpenWrt Wiki] Retour au firmware du fabricant](#-openwrt-wiki-retour-au-firmware-du-fabricant)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:snapshot](#-openwrt-wiki-fr-docs-guide-user-installation-snapshot)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot](#-openwrt-wiki-fr-docs-guide-user-installation-flashing-openwrt-with-wifi-enabled-on-first-boot)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:openwrt-as-stock-firmware](#-openwrt-wiki-fr-docs-guide-user-installation-openwrt-as-stock-firmware)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:before.installation](#-openwrt-wiki-fr-docs-guide-user-installation-before-installation)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:generic.backup](#-openwrt-wiki-fr-docs-guide-user-installation-generic-backup)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:generic.flashing.serial](#-openwrt-wiki-fr-docs-guide-user-installation-generic-flashing-serial)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:generic.flashing](#-openwrt-wiki-fr-docs-guide-user-installation-generic-flashing)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:restore_art_partition](#-openwrt-wiki-fr-docs-guide-user-installation-restore-art-partition)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:after.installation](#-openwrt-wiki-fr-docs-guide-user-installation-after-installation)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:start](#-openwrt-wiki-de-docs-guide-user-base-system-start)
- [[OpenWrt Wiki] es:docs:guide-user:installation:openwrt_x86](#-openwrt-wiki-es-docs-guide-user-installation-openwrt-x86)
- [[OpenWrt Wiki] de:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-de-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.tftp](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing-tftp)
- [[OpenWrt Wiki] de:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-de-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.backup](#-openwrt-wiki-es-docs-guide-user-installation-generic-backup)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:basic](#-openwrt-wiki-de-docs-guide-user-base-system-basic)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:user.beginner.cli](#-openwrt-wiki-de-docs-guide-user-base-system-user-beginner-cli)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:notuci.config](#-openwrt-wiki-de-docs-guide-user-base-system-notuci-config)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.ftp](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing-ftp)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:clarifying_interface_usage](#-openwrt-wiki-de-docs-guide-user-base-system-clarifying-interface-usage)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.tftp.easy-ubuntu](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing-tftp-easy-ubuntu)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:dropbear](#-openwrt-wiki-de-docs-guide-user-base-system-dropbear)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address](#-openwrt-wiki-de-docs-guide-user-base-system-persistent-ethernet-interface-naming-by-mac-address)
- [[OpenWrt Wiki] de:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings](#-openwrt-wiki-de-docs-guide-user-luci-getting-rid-of-luci-https-certificate-warnings)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:ddns](#-openwrt-wiki-de-docs-guide-user-base-system-ddns)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:httpd](#-openwrt-wiki-de-docs-guide-user-base-system-httpd)
- [[OpenWrt Wiki] OpenWrt Sysupgrade](#-openwrt-wiki-openwrt-sysupgrade)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:managing_services](#-openwrt-wiki-de-docs-guide-user-base-system-managing-services)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:dns_configuration](#-openwrt-wiki-de-docs-guide-user-base-system-dns-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:network:ipv6_ipv4_transitioning](#-openwrt-wiki-de-docs-guide-user-network-ipv6-ipv4-transitioning)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:log.essentials](#-openwrt-wiki-de-docs-guide-user-base-system-log-essentials)
- [[OpenWrt Wiki] de:docs:guide-user:network:mptcp](#-openwrt-wiki-de-docs-guide-user-network-mptcp)
- [[OpenWrt Wiki] de:docs:guide-user:network:singleportrouter](#-openwrt-wiki-de-docs-guide-user-network-singleportrouter)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:led_configuration](#-openwrt-wiki-de-docs-guide-user-base-system-led-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:luci:luci.secure](#-openwrt-wiki-de-docs-guide-user-luci-luci-secure)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:cron](#-openwrt-wiki-de-docs-guide-user-base-system-cron)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:basic-networking](#-openwrt-wiki-de-docs-guide-user-base-system-basic-networking)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:users](#-openwrt-wiki-de-docs-guide-user-base-system-users)
- [[OpenWrt Wiki] de:docs:guide-user:luci:dashboard](#-openwrt-wiki-de-docs-guide-user-luci-dashboard)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:system_configuration](#-openwrt-wiki-de-docs-guide-user-base-system-system-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:dhcp.dnsmasq](#-openwrt-wiki-de-docs-guide-user-base-system-dhcp-dnsmasq)
- [[OpenWrt Wiki] de:docs:guide-user:luci:start](#-openwrt-wiki-de-docs-guide-user-luci-start)
- [[OpenWrt Wiki] de:docs:guide-user:network:integrating-openwrt-introduction](#-openwrt-wiki-de-docs-guide-user-network-integrating-openwrt-introduction)
- [[OpenWrt Wiki] de:docs:guide-user:network:openwrt_as_routerdevice](#-openwrt-wiki-de-docs-guide-user-network-openwrt-as-routerdevice)
- [[OpenWrt Wiki] de:docs:guide-user:luci:luci.themes](#-openwrt-wiki-de-docs-guide-user-luci-luci-themes)
- [[OpenWrt Wiki] de:docs:guide-user:luci:statistics.chart.public](#-openwrt-wiki-de-docs-guide-user-luci-statistics-chart-public)
- [[OpenWrt Wiki] de:docs:guide-user:luci:luci_app_statistics](#-openwrt-wiki-de-docs-guide-user-luci-luci-app-statistics)
- [[OpenWrt Wiki] de:docs:guide-user:luci:luci.essentials](#-openwrt-wiki-de-docs-guide-user-luci-luci-essentials)
- [[OpenWrt Wiki] de:docs:guide-user:network:protocol.static](#-openwrt-wiki-de-docs-guide-user-network-protocol-static)
- [[OpenWrt Wiki] de:docs:guide-user:luci:luci.on.lighttpd](#-openwrt-wiki-de-docs-guide-user-luci-luci-on-lighttpd)
- [[OpenWrt Wiki] de:docs:guide-user:luci:static_ip](#-openwrt-wiki-de-docs-guide-user-luci-static-ip)
- [[OpenWrt Wiki] de:docs:guide-user:network:high-availability](#-openwrt-wiki-de-docs-guide-user-network-high-availability)
- [[OpenWrt Wiki] de:docs:guide-user:network:protocol.dhcp](#-openwrt-wiki-de-docs-guide-user-network-protocol-dhcp)
- [[OpenWrt Wiki] de:docs:guide-user:network:routedclient](#-openwrt-wiki-de-docs-guide-user-network-routedclient)
- [[OpenWrt Wiki] de:docs:guide-user:network:switch_router_gateway_and_nat](#-openwrt-wiki-de-docs-guide-user-network-switch-router-gateway-and-nat)
- [[OpenWrt Wiki] de:docs:guide-user:network:start](#-openwrt-wiki-de-docs-guide-user-network-start)
- [[OpenWrt Wiki] de:docs:guide-user:network:network_interface_alias](#-openwrt-wiki-de-docs-guide-user-network-network-interface-alias)
- [[OpenWrt Wiki] de:docs:guide-user:network:map](#-openwrt-wiki-de-docs-guide-user-network-map)
- [[OpenWrt Wiki] de:docs:guide-user:network:network_configuration](#-openwrt-wiki-de-docs-guide-user-network-network-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:luci:webinterface.overview](#-openwrt-wiki-de-docs-guide-user-luci-webinterface-overview)
- [[OpenWrt Wiki] de:docs:guide-user:network:bonding](#-openwrt-wiki-de-docs-guide-user-network-bonding)
- [[OpenWrt Wiki] de:docs:guide-user:network:architecture](#-openwrt-wiki-de-docs-guide-user-network-architecture)
- [[OpenWrt Wiki] de:docs:guide-user:network:openwrt_as_clientdevice](#-openwrt-wiki-de-docs-guide-user-network-openwrt-as-clientdevice)
- [[OpenWrt Wiki] LEDE 설정 방법](#-openwrt-wiki-lede-)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:start](#-openwrt-wiki-de-docs-guide-user-firewall-start)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:fw3_network](#-openwrt-wiki-de-docs-guide-user-firewall-fw3-network)
- [[OpenWrt Wiki] de:docs:guide-user:advanced:ntp_configuration](#-openwrt-wiki-de-docs-guide-user-advanced-ntp-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:firewall_components](#-openwrt-wiki-de-docs-guide-user-firewall-firewall-components)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:overview](#-openwrt-wiki-de-docs-guide-user-firewall-overview)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:usb_gadget](#-openwrt-wiki-de-docs-guide-user-hardware-usb-gadget)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:usb.i2c-tiny-usb](#-openwrt-wiki-de-docs-guide-user-hardware-usb-i2c-tiny-usb)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:turnoff.uart.to.gpio](#-openwrt-wiki-de-docs-guide-user-hardware-turnoff-uart-to-gpio)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:terminate.console.on.serial](#-openwrt-wiki-de-docs-guide-user-hardware-terminate-console-on-serial)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:owsip](#-openwrt-wiki-de-docs-guide-user-hardware-owsip)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:debrick.ath79.using.jtag](#-openwrt-wiki-de-docs-guide-user-hardware-debrick-ath79-using-jtag)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:pwm](#-openwrt-wiki-de-docs-guide-user-hardware-pwm)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:lirc-audio_alsa](#-openwrt-wiki-de-docs-guide-user-hardware-lirc-audio-alsa)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:esp8266-serial-bridge](#-openwrt-wiki-de-docs-guide-user-hardware-esp8266-serial-bridge)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns](#-openwrt-wiki-de-docs-guide-user-firewall-filtering-traffic-at-ip-addresses-by-dns)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:mmc_over_gpio](#-openwrt-wiki-de-docs-guide-user-hardware-mmc-over-gpio)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:lirc](#-openwrt-wiki-de-docs-guide-user-hardware-lirc)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:watchdog](#-openwrt-wiki-de-docs-guide-user-hardware-watchdog)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:usb.overview](#-openwrt-wiki-de-docs-guide-user-hardware-usb-overview)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:lirc-gpioblaster](#-openwrt-wiki-de-docs-guide-user-hardware-lirc-gpioblaster)
- [[OpenWrt Wiki] de:docs:guide-user:storage:start](#-openwrt-wiki-de-docs-guide-user-storage-start)
- [[OpenWrt Wiki] de:docs:guide-user:storage:writable_ntfs](#-openwrt-wiki-de-docs-guide-user-storage-writable-ntfs)
- [[OpenWrt Wiki] de:docs:guide-user:storage:usb-drives](#-openwrt-wiki-de-docs-guide-user-storage-usb-drives)
- [[OpenWrt Wiki] de:docs:guide-user:services:start](#-openwrt-wiki-de-docs-guide-user-services-start)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:piratebox.librarybox.openwrt.routers](#-openwrt-wiki-de-docs-guide-user-hardware-piratebox-librarybox-openwrt-routers)
- [[OpenWrt Wiki] de:docs:guide-user:storage:disk.encryption](#-openwrt-wiki-de-docs-guide-user-storage-disk-encryption)
- [[OpenWrt Wiki] de:docs:guide-user:storage:fstab](#-openwrt-wiki-de-docs-guide-user-storage-fstab)
- [[OpenWrt Wiki] de:docs:guide-user:storage:hd-idle](#-openwrt-wiki-de-docs-guide-user-storage-hd-idle)
- [[OpenWrt Wiki] de:docs:guide-user:storage:filesystems-and-partitions](#-openwrt-wiki-de-docs-guide-user-storage-filesystems-and-partitions)
- [[OpenWrt Wiki] de:docs:guide-user:services:vblade](#-openwrt-wiki-de-docs-guide-user-services-vblade)
- [[OpenWrt Wiki] de:docs:guide-user:services:ad-blocking](#-openwrt-wiki-de-docs-guide-user-services-ad-blocking)
- [[OpenWrt Wiki] de:docs:guide-user:services:crowdsec](#-openwrt-wiki-de-docs-guide-user-services-crowdsec)
- [[OpenWrt Wiki] de:docs:guide-user:services:babeld](#-openwrt-wiki-de-docs-guide-user-services-babeld)
- [[OpenWrt Wiki] de:docs:guide-user:storage:mountd](#-openwrt-wiki-de-docs-guide-user-storage-mountd)
- [[OpenWrt Wiki] de:docs:guide-user:hardware:devolo-stream-radio](#-openwrt-wiki-de-docs-guide-user-hardware-devolo-stream-radio)
- [[OpenWrt Wiki] de:docs:guide-user:storage:usb-installing](#-openwrt-wiki-de-docs-guide-user-storage-usb-installing)
- [[OpenWrt Wiki] de:docs:guide-user:additional-software:smartmontools](#-openwrt-wiki-de-docs-guide-user-additional-software-smartmontools)
- [[OpenWrt Wiki] de:docs:guide-user:additional-software:opkg](#-openwrt-wiki-de-docs-guide-user-additional-software-opkg)
- [[OpenWrt Wiki] docs:guide-user:network:wan:yet_on_current_versions_of_openwrt](#-openwrt-wiki-docs-guide-user-network-wan-yet-on-current-versions-of-openwrt)
- [[OpenWrt Wiki] de:docs:guide-user:additional-software:opkg-to-apk-cheatsheet](#-openwrt-wiki-de-docs-guide-user-additional-software-opkg-to-apk-cheatsheet)
- [[OpenWrt Wiki] de:docs:guide-user:additional-software:imagebuilder](#-openwrt-wiki-de-docs-guide-user-additional-software-imagebuilder)
- [[OpenWrt Wiki] de:docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login](#-openwrt-wiki-de-docs-guide-user-additional-software-show-upgradable-packages-after-ssh-login)
- [[OpenWrt Wiki] de:docs:guide-user:services:kerberos](#-openwrt-wiki-de-docs-guide-user-services-kerberos)
- [[OpenWrt Wiki] de:docs:guide-user:services:gitolite](#-openwrt-wiki-de-docs-guide-user-services-gitolite)
- [[OpenWrt Wiki] de:docs:guide-user:services:usb.iptunnel](#-openwrt-wiki-de-docs-guide-user-services-usb-iptunnel)
- [[OpenWrt Wiki] de:docs:guide-user:services:ugps](#-openwrt-wiki-de-docs-guide-user-services-ugps)
- [[OpenWrt Wiki] de:docs:guide-user:services:fwknop](#-openwrt-wiki-de-docs-guide-user-services-fwknop)
- [[OpenWrt Wiki] de:docs:guide-user:services:honeypots](#-openwrt-wiki-de-docs-guide-user-services-honeypots)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:dhcp_configuration](#-openwrt-wiki-de-docs-guide-user-base-system-dhcp-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:services:chroot](#-openwrt-wiki-de-docs-guide-user-services-chroot)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:hotplug](#-openwrt-wiki-de-docs-guide-user-base-system-hotplug)
- [[OpenWrt Wiki] de:docs:guide-user:services:banip](#-openwrt-wiki-de-docs-guide-user-services-banip)
- [[OpenWrt Wiki] de:docs:guide-user:services:geoip-shell](#-openwrt-wiki-de-docs-guide-user-services-geoip-shell)
- [[OpenWrt Wiki] de:docs:guide-user:services:python](#-openwrt-wiki-de-docs-guide-user-services-python)
- [[OpenWrt Wiki] de:docs:guide-user:services:snort](#-openwrt-wiki-de-docs-guide-user-services-snort)
- [[OpenWrt Wiki] de:docs:guide-user:services:rng](#-openwrt-wiki-de-docs-guide-user-services-rng)
- [[OpenWrt Wiki] de:docs:guide-user:services:tftp.pxe-server](#-openwrt-wiki-de-docs-guide-user-services-tftp-pxe-server)
- [[OpenWrt Wiki] de:docs:guide-user:services:xmpp.server](#-openwrt-wiki-de-docs-guide-user-services-xmpp-server)
- [[OpenWrt Wiki] de:docs:guide-user:services:telegraf](#-openwrt-wiki-de-docs-guide-user-services-telegraf)
- [[OpenWrt Wiki] de:docs:guide-user:services:irqbalance](#-openwrt-wiki-de-docs-guide-user-services-irqbalance)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:vmware](#-openwrt-wiki-de-docs-guide-user-virtualization-vmware)
- [[OpenWrt Wiki] de:docs:guide-user:network:ucicheatsheet](#-openwrt-wiki-de-docs-guide-user-network-ucicheatsheet)
- [[OpenWrt Wiki] de:docs:guide-user:base-system:dhcp](#-openwrt-wiki-de-docs-guide-user-base-system-dhcp)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-de-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] de:docs:guide-user:security:start](#-openwrt-wiki-de-docs-guide-user-security-start)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:docker_host](#-openwrt-wiki-de-docs-guide-user-virtualization-docker-host)
- [[OpenWrt Wiki] de:docs:guide-user:security:dropbear.public-key.auth](#-openwrt-wiki-de-docs-guide-user-security-dropbear-public-key-auth)
- [[OpenWrt Wiki] de:docs:guide-user:security:sudo](#-openwrt-wiki-de-docs-guide-user-security-sudo)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:fusion](#-openwrt-wiki-de-docs-guide-user-virtualization-fusion)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:qemu](#-openwrt-wiki-de-docs-guide-user-virtualization-qemu)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:mikrotik_metarouter_openwrt](#-openwrt-wiki-de-docs-guide-user-virtualization-mikrotik-metarouter-openwrt)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:metarouter](#-openwrt-wiki-de-docs-guide-user-virtualization-metarouter)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:vendor_specific_rescue](#-openwrt-wiki-de-docs-guide-user-troubleshooting-vendor-specific-rescue)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:xen](#-openwrt-wiki-de-docs-guide-user-virtualization-xen)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:root_password_reset](#-openwrt-wiki-de-docs-guide-user-troubleshooting-root-password-reset)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:start](#-openwrt-wiki-de-docs-guide-user-troubleshooting-start)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:start](#-openwrt-wiki-de-docs-guide-user-virtualization-start)
- [[OpenWrt Wiki] de:docs:guide-user:security:openwrt_security](#-openwrt-wiki-de-docs-guide-user-security-openwrt-security)
- [[OpenWrt Wiki] de:docs:guide-user:security:security-features](#-openwrt-wiki-de-docs-guide-user-security-security-features)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:backup_restore](#-openwrt-wiki-de-docs-guide-user-troubleshooting-backup-restore)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:virtualbox-advanced](#-openwrt-wiki-de-docs-guide-user-virtualization-virtualbox-advanced)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:docker_openwrt_image](#-openwrt-wiki-de-docs-guide-user-virtualization-docker-openwrt-image)
- [[OpenWrt Wiki] de:docs:guide-user:firewall:firewall_configuration](#-openwrt-wiki-de-docs-guide-user-firewall-firewall-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:network:tunneling_interface_protocols](#-openwrt-wiki-de-docs-guide-user-network-tunneling-interface-protocols)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:ead](#-openwrt-wiki-de-docs-guide-user-troubleshooting-ead)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:obtain.firmware.docker](#-openwrt-wiki-de-docs-guide-user-virtualization-obtain-firmware-docker)
- [[OpenWrt Wiki] de:docs:guide-user:security:secure.access](#-openwrt-wiki-de-docs-guide-user-security-secure-access)
- [[OpenWrt Wiki] de:docs:guide-user:security:signatures](#-openwrt-wiki-de-docs-guide-user-security-signatures)
- [[OpenWrt Wiki] de:docs:guide-user:security:release_signatures](#-openwrt-wiki-de-docs-guide-user-security-release-signatures)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:tftpserver](#-openwrt-wiki-de-docs-guide-user-troubleshooting-tftpserver)
- [[OpenWrt Wiki] de:docs:guide-user:security:security_guide_for_the_paranoid](#-openwrt-wiki-de-docs-guide-user-security-security-guide-for-the-paranoid)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:lxc](#-openwrt-wiki-de-docs-guide-user-virtualization-lxc)
- [[OpenWrt Wiki] de:docs:guide-user:security:recovering_from_clientmode](#-openwrt-wiki-de-docs-guide-user-security-recovering-from-clientmode)
- [[OpenWrt Wiki] de:docs:guide-user:troubleshooting:failsafe_and_factory_reset](#-openwrt-wiki-de-docs-guide-user-troubleshooting-failsafe-and-factory-reset)
- [[OpenWrt Wiki] Debricking OpenWrt (generic)](#-openwrt-wiki-debricking-openwrt-generic-)
- [[OpenWrt Wiki] es:docs:guide-user:installation:start](#-openwrt-wiki-es-docs-guide-user-installation-start)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:qemu_host](#-openwrt-wiki-de-docs-guide-user-virtualization-qemu-host)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:xen_debian_private_network](#-openwrt-wiki-de-docs-guide-user-virtualization-xen-debian-private-network)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:utm](#-openwrt-wiki-de-docs-guide-user-virtualization-utm)
- [[OpenWrt Wiki] de:docs:guide-user:security:keygen](#-openwrt-wiki-de-docs-guide-user-security-keygen)
- [[OpenWrt Wiki] de:docs:guide-user:virtualization:podman](#-openwrt-wiki-de-docs-guide-user-virtualization-podman)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-de-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] es:docs:guide-user:installation:before.installation](#-openwrt-wiki-es-docs-guide-user-installation-before-installation)
- [[OpenWrt Wiki] es:docs:guide-user:installation:snapshot](#-openwrt-wiki-es-docs-guide-user-installation-snapshot)
- [[OpenWrt Wiki] es:docs:guide-user:installation:restore_art_partition](#-openwrt-wiki-es-docs-guide-user-installation-restore-art-partition)
- [[OpenWrt Wiki] es:docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot](#-openwrt-wiki-es-docs-guide-user-installation-flashing-openwrt-with-wifi-enabled-on-first-boot)
- [[OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.serial](#-openwrt-wiki-es-docs-guide-user-installation-generic-flashing-serial)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.flashing.ftp](#-openwrt-wiki-de-docs-guide-user-installation-generic-flashing-ftp)
- [[OpenWrt Wiki] de:docs:guide-user:installation:openwrt_x86](#-openwrt-wiki-de-docs-guide-user-installation-openwrt-x86)
- [[OpenWrt Wiki] de:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-de-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:fw3_network](#-openwrt-wiki-cs-docs-guide-user-firewall-fw3-network)
- [[OpenWrt Wiki] cs:docs:guide-user:advanced:ntp_configuration](#-openwrt-wiki-cs-docs-guide-user-advanced-ntp-configuration)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.flashing.tftp.easy-ubuntu](#-openwrt-wiki-de-docs-guide-user-installation-generic-flashing-tftp-easy-ubuntu)
- [[OpenWrt Wiki] de:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-de-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.flashing.tftp](#-openwrt-wiki-de-docs-guide-user-installation-generic-flashing-tftp)
- [[OpenWrt Wiki] Regresar al Firmware Original del Fabricante](#-openwrt-wiki-regresar-al-firmware-original-del-fabricante)
- [[OpenWrt Wiki] Dispositivos que usan OpenWrt como firmware estándar](#-openwrt-wiki-dispositivos-que-usan-openwrt-como-firmware-est-ndar)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:overview](#-openwrt-wiki-cs-docs-guide-user-firewall-overview)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:start](#-openwrt-wiki-cs-docs-guide-user-firewall-start)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:start](#-openwrt-wiki-cs-docs-guide-user-storage-start)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:turnoff.uart.to.gpio](#-openwrt-wiki-cs-docs-guide-user-hardware-turnoff-uart-to-gpio)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:firewall_components](#-openwrt-wiki-cs-docs-guide-user-firewall-firewall-components)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns](#-openwrt-wiki-cs-docs-guide-user-firewall-filtering-traffic-at-ip-addresses-by-dns)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:lirc](#-openwrt-wiki-cs-docs-guide-user-hardware-lirc)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:usb_gadget](#-openwrt-wiki-cs-docs-guide-user-hardware-usb-gadget)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:mmc_over_gpio](#-openwrt-wiki-cs-docs-guide-user-hardware-mmc-over-gpio)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:usb.i2c-tiny-usb](#-openwrt-wiki-cs-docs-guide-user-hardware-usb-i2c-tiny-usb)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:terminate.console.on.serial](#-openwrt-wiki-cs-docs-guide-user-hardware-terminate-console-on-serial)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:lirc-audio_alsa](#-openwrt-wiki-cs-docs-guide-user-hardware-lirc-audio-alsa)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:debrick.ath79.using.jtag](#-openwrt-wiki-cs-docs-guide-user-hardware-debrick-ath79-using-jtag)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:pwm](#-openwrt-wiki-cs-docs-guide-user-hardware-pwm)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:lirc-gpioblaster](#-openwrt-wiki-cs-docs-guide-user-hardware-lirc-gpioblaster)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:owsip](#-openwrt-wiki-cs-docs-guide-user-hardware-owsip)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:usb.overview](#-openwrt-wiki-cs-docs-guide-user-hardware-usb-overview)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:watchdog](#-openwrt-wiki-cs-docs-guide-user-hardware-watchdog)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:piratebox.librarybox.openwrt.routers](#-openwrt-wiki-cs-docs-guide-user-hardware-piratebox-librarybox-openwrt-routers)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:esp8266-serial-bridge](#-openwrt-wiki-cs-docs-guide-user-hardware-esp8266-serial-bridge)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:usb-drives](#-openwrt-wiki-cs-docs-guide-user-storage-usb-drives)
- [[OpenWrt Wiki] cs:docs:guide-user:services:ad-blocking](#-openwrt-wiki-cs-docs-guide-user-services-ad-blocking)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:disk.encryption](#-openwrt-wiki-cs-docs-guide-user-storage-disk-encryption)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:writable_ntfs](#-openwrt-wiki-cs-docs-guide-user-storage-writable-ntfs)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:fstab](#-openwrt-wiki-cs-docs-guide-user-storage-fstab)
- [[OpenWrt Wiki] cs:docs:guide-user:services:crowdsec](#-openwrt-wiki-cs-docs-guide-user-services-crowdsec)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:filesystems-and-partitions](#-openwrt-wiki-cs-docs-guide-user-storage-filesystems-and-partitions)
- [[OpenWrt Wiki] Preguntas Frecuentes: Después de Instalar OpenWrt](#-openwrt-wiki-preguntas-frecuentes-despu-s-de-instalar-openwrt)
- [[OpenWrt Wiki] cs:docs:guide-user:services:start](#-openwrt-wiki-cs-docs-guide-user-services-start)
- [[OpenWrt Wiki] cs:docs:guide-user:services:babeld](#-openwrt-wiki-cs-docs-guide-user-services-babeld)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:hd-idle](#-openwrt-wiki-cs-docs-guide-user-storage-hd-idle)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:mountd](#-openwrt-wiki-cs-docs-guide-user-storage-mountd)
- [[OpenWrt Wiki] cs:docs:guide-user:services:vblade](#-openwrt-wiki-cs-docs-guide-user-services-vblade)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:usb-installing](#-openwrt-wiki-cs-docs-guide-user-storage-usb-installing)
- [[OpenWrt Wiki] cs:docs:guide-user:hardware:devolo-stream-radio](#-openwrt-wiki-cs-docs-guide-user-hardware-devolo-stream-radio)
- [[OpenWrt Wiki] cs:docs:guide-user:services:rng](#-openwrt-wiki-cs-docs-guide-user-services-rng)
- [[OpenWrt Wiki] cs:docs:guide-user:services:snort](#-openwrt-wiki-cs-docs-guide-user-services-snort)
- [[OpenWrt Wiki] cs:docs:guide-user:services:irqbalance](#-openwrt-wiki-cs-docs-guide-user-services-irqbalance)
- [[OpenWrt Wiki] cs:docs:guide-user:services:banip](#-openwrt-wiki-cs-docs-guide-user-services-banip)
- [[OpenWrt Wiki] cs:docs:guide-user:additional-software:smartmontools](#-openwrt-wiki-cs-docs-guide-user-additional-software-smartmontools)
- [[OpenWrt Wiki] cs:docs:guide-user:services:chroot](#-openwrt-wiki-cs-docs-guide-user-services-chroot)
- [[OpenWrt Wiki] cs:docs:guide-user:additional-software:opkg](#-openwrt-wiki-cs-docs-guide-user-additional-software-opkg)
- [[OpenWrt Wiki] cs:docs:guide-user:services:gitolite](#-openwrt-wiki-cs-docs-guide-user-services-gitolite)
- [[OpenWrt Wiki] cs:docs:guide-user:services:kerberos](#-openwrt-wiki-cs-docs-guide-user-services-kerberos)
- [[OpenWrt Wiki] cs:docs:guide-user:additional-software:opkg-to-apk-cheatsheet](#-openwrt-wiki-cs-docs-guide-user-additional-software-opkg-to-apk-cheatsheet)
- [[OpenWrt Wiki] cs:docs:guide-user:additional-software:imagebuilder](#-openwrt-wiki-cs-docs-guide-user-additional-software-imagebuilder)
- [[OpenWrt Wiki] cs:docs:guide-user:services:python](#-openwrt-wiki-cs-docs-guide-user-services-python)
- [[OpenWrt Wiki] cs:docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login](#-openwrt-wiki-cs-docs-guide-user-additional-software-show-upgradable-packages-after-ssh-login)
- [[OpenWrt Wiki] Das UCI System](#-openwrt-wiki-das-uci-system)
- [[OpenWrt Wiki] cs:docs:guide-user:services:tftp.pxe-server](#-openwrt-wiki-cs-docs-guide-user-services-tftp-pxe-server)
- [[OpenWrt Wiki] cs:docs:guide-user:services:geoip-shell](#-openwrt-wiki-cs-docs-guide-user-services-geoip-shell)
- [[OpenWrt Wiki] cs:docs:guide-user:services:xmpp.server](#-openwrt-wiki-cs-docs-guide-user-services-xmpp-server)
- [[OpenWrt Wiki] cs:docs:guide-user:services:telegraf](#-openwrt-wiki-cs-docs-guide-user-services-telegraf)
- [[OpenWrt Wiki] cs:docs:guide-user:services:honeypots](#-openwrt-wiki-cs-docs-guide-user-services-honeypots)
- [[OpenWrt Wiki] cs:docs:guide-user:services:usb.iptunnel](#-openwrt-wiki-cs-docs-guide-user-services-usb-iptunnel)
- [[OpenWrt Wiki] cs:docs:guide-user:services:fwknop](#-openwrt-wiki-cs-docs-guide-user-services-fwknop)
- [[OpenWrt Wiki] cs:docs:guide-user:security:start](#-openwrt-wiki-cs-docs-guide-user-security-start)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:docker_host](#-openwrt-wiki-cs-docs-guide-user-virtualization-docker-host)
- [[OpenWrt Wiki] cs:docs:guide-user:services:ugps](#-openwrt-wiki-cs-docs-guide-user-services-ugps)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:dhcp_configuration](#-openwrt-wiki-cs-docs-guide-user-base-system-dhcp-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:uci](#-openwrt-wiki-cs-docs-guide-user-base-system-uci)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:vmware](#-openwrt-wiki-cs-docs-guide-user-virtualization-vmware)
- [[OpenWrt Wiki] cs:docs:guide-user:network:ucicheatsheet](#-openwrt-wiki-cs-docs-guide-user-network-ucicheatsheet)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:dhcp](#-openwrt-wiki-cs-docs-guide-user-base-system-dhcp)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:hotplug](#-openwrt-wiki-cs-docs-guide-user-base-system-hotplug)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:fusion](#-openwrt-wiki-cs-docs-guide-user-virtualization-fusion)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-cs-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:qemu](#-openwrt-wiki-cs-docs-guide-user-virtualization-qemu)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:mikrotik_metarouter_openwrt](#-openwrt-wiki-cs-docs-guide-user-virtualization-mikrotik-metarouter-openwrt)
- [[OpenWrt Wiki] cs:docs:guide-user:security:sudo](#-openwrt-wiki-cs-docs-guide-user-security-sudo)
- [[OpenWrt Wiki] cs:docs:guide-user:security:dropbear.public-key.auth](#-openwrt-wiki-cs-docs-guide-user-security-dropbear-public-key-auth)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:virtualbox-advanced](#-openwrt-wiki-cs-docs-guide-user-virtualization-virtualbox-advanced)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:firewall_configuration](#-openwrt-wiki-cs-docs-guide-user-firewall-firewall-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:start](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-start)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:start](#-openwrt-wiki-cs-docs-guide-user-virtualization-start)
- [[OpenWrt Wiki] cs:docs:guide-user:network:tunneling_interface_protocols](#-openwrt-wiki-cs-docs-guide-user-network-tunneling-interface-protocols)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:docker_openwrt_image](#-openwrt-wiki-cs-docs-guide-user-virtualization-docker-openwrt-image)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:backup_restore](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-backup-restore)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:ead](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-ead)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:obtain.firmware.docker](#-openwrt-wiki-cs-docs-guide-user-virtualization-obtain-firmware-docker)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:generic.debrick](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-generic-debrick)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:metarouter](#-openwrt-wiki-cs-docs-guide-user-virtualization-metarouter)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:vendor_specific_rescue](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-vendor-specific-rescue)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:xen](#-openwrt-wiki-cs-docs-guide-user-virtualization-xen)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:lxc](#-openwrt-wiki-cs-docs-guide-user-virtualization-lxc)
- [[OpenWrt Wiki] cs:docs:guide-user:security:openwrt_security](#-openwrt-wiki-cs-docs-guide-user-security-openwrt-security)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:root_password_reset](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-root-password-reset)
- [[OpenWrt Wiki] cs:docs:guide-user:security:security-features](#-openwrt-wiki-cs-docs-guide-user-security-security-features)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:failsafe_and_factory_reset](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-failsafe-and-factory-reset)
- [[OpenWrt Wiki] cs:docs:guide-user:security:release_signatures](#-openwrt-wiki-cs-docs-guide-user-security-release-signatures)
- [[OpenWrt Wiki] cs:docs:guide-user:security:secure.access](#-openwrt-wiki-cs-docs-guide-user-security-secure-access)
- [[OpenWrt Wiki] cs:docs:guide-user:security:signatures](#-openwrt-wiki-cs-docs-guide-user-security-signatures)
- [[OpenWrt Wiki] cs:docs:guide-user:troubleshooting:tftpserver](#-openwrt-wiki-cs-docs-guide-user-troubleshooting-tftpserver)
- [[OpenWrt Wiki] cs:docs:guide-user:security:recovering_from_clientmode](#-openwrt-wiki-cs-docs-guide-user-security-recovering-from-clientmode)
- [[OpenWrt Wiki] cs:docs:guide-user:security:security_guide_for_the_paranoid](#-openwrt-wiki-cs-docs-guide-user-security-security-guide-for-the-paranoid)
- [[OpenWrt Wiki] cs:docs:guide-user:security:keygen](#-openwrt-wiki-cs-docs-guide-user-security-keygen)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:xen_debian_private_network](#-openwrt-wiki-cs-docs-guide-user-virtualization-xen-debian-private-network)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:utm](#-openwrt-wiki-cs-docs-guide-user-virtualization-utm)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:qemu_host](#-openwrt-wiki-cs-docs-guide-user-virtualization-qemu-host)
- [[OpenWrt Wiki] de:docs:guide-user:installation:start](#-openwrt-wiki-de-docs-guide-user-installation-start)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-de-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] de:docs:guide-user:installation:after.installation](#-openwrt-wiki-de-docs-guide-user-installation-after-installation)
- [[OpenWrt Wiki] cs:docs:guide-user:virtualization:podman](#-openwrt-wiki-cs-docs-guide-user-virtualization-podman)
- [[OpenWrt Wiki] de:docs:guide-user:installation:before.installation](#-openwrt-wiki-de-docs-guide-user-installation-before-installation)
- [[OpenWrt Wiki] de:docs:guide-user:installation:openwrt-as-stock-firmware](#-openwrt-wiki-de-docs-guide-user-installation-openwrt-as-stock-firmware)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.flashing.serial](#-openwrt-wiki-de-docs-guide-user-installation-generic-flashing-serial)
- [[OpenWrt Wiki] de:docs:guide-user:installation:snapshot](#-openwrt-wiki-de-docs-guide-user-installation-snapshot)
- [[OpenWrt Wiki] de:docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot](#-openwrt-wiki-de-docs-guide-user-installation-flashing-openwrt-with-wifi-enabled-on-first-boot)
- [[OpenWrt Wiki] de:docs:guide-user:installation:restore_art_partition](#-openwrt-wiki-de-docs-guide-user-installation-restore-art-partition)
- [[OpenWrt Wiki] de:docs:guide-user:installation:generic.backup](#-openwrt-wiki-de-docs-guide-user-installation-generic-backup)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:start](#-openwrt-wiki-cs-docs-guide-user-base-system-start)
- [[OpenWrt Wiki] cs:docs:guide-user:network:mptcp](#-openwrt-wiki-cs-docs-guide-user-network-mptcp)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:managing_services](#-openwrt-wiki-cs-docs-guide-user-base-system-managing-services)
- [[OpenWrt Wiki] cs:docs:guide-user:network:ipv6_ipv4_transitioning](#-openwrt-wiki-cs-docs-guide-user-network-ipv6-ipv4-transitioning)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:log.essentials](#-openwrt-wiki-cs-docs-guide-user-base-system-log-essentials)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:cron](#-openwrt-wiki-cs-docs-guide-user-base-system-cron)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:notuci.config](#-openwrt-wiki-cs-docs-guide-user-base-system-notuci-config)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings](#-openwrt-wiki-cs-docs-guide-user-luci-getting-rid-of-luci-https-certificate-warnings)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:basic](#-openwrt-wiki-cs-docs-guide-user-base-system-basic)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:clarifying_interface_usage](#-openwrt-wiki-cs-docs-guide-user-base-system-clarifying-interface-usage)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:user.beginner.cli](#-openwrt-wiki-cs-docs-guide-user-base-system-user-beginner-cli)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:dns_configuration](#-openwrt-wiki-cs-docs-guide-user-base-system-dns-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:dropbear](#-openwrt-wiki-cs-docs-guide-user-base-system-dropbear)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address](#-openwrt-wiki-cs-docs-guide-user-base-system-persistent-ethernet-interface-naming-by-mac-address)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:ddns](#-openwrt-wiki-cs-docs-guide-user-base-system-ddns)
- [[OpenWrt Wiki] OpenWrt installieren (allgemein)](#-openwrt-wiki-openwrt-installieren-allgemein-)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:httpd](#-openwrt-wiki-cs-docs-guide-user-base-system-httpd)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:system_configuration](#-openwrt-wiki-cs-docs-guide-user-base-system-system-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:dashboard](#-openwrt-wiki-cs-docs-guide-user-luci-dashboard)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:start](#-openwrt-wiki-cs-docs-guide-user-luci-start)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:luci_app_statistics](#-openwrt-wiki-cs-docs-guide-user-luci-luci-app-statistics)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:luci.secure](#-openwrt-wiki-cs-docs-guide-user-luci-luci-secure)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:basic-networking](#-openwrt-wiki-cs-docs-guide-user-base-system-basic-networking)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:dhcp.dnsmasq](#-openwrt-wiki-cs-docs-guide-user-base-system-dhcp-dnsmasq)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:led_configuration](#-openwrt-wiki-cs-docs-guide-user-base-system-led-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:base-system:users](#-openwrt-wiki-cs-docs-guide-user-base-system-users)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:luci.on.lighttpd](#-openwrt-wiki-cs-docs-guide-user-luci-luci-on-lighttpd)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:luci.essentials](#-openwrt-wiki-cs-docs-guide-user-luci-luci-essentials)
- [[OpenWrt Wiki] cs:docs:guide-user:network:singleportrouter](#-openwrt-wiki-cs-docs-guide-user-network-singleportrouter)
- [[OpenWrt Wiki] cs:docs:guide-user:network:protocol.static](#-openwrt-wiki-cs-docs-guide-user-network-protocol-static)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:luci.themes](#-openwrt-wiki-cs-docs-guide-user-luci-luci-themes)
- [[OpenWrt Wiki] cs:docs:guide-user:network:start](#-openwrt-wiki-cs-docs-guide-user-network-start)
- [[OpenWrt Wiki] cs:docs:guide-user:network:openwrt_as_routerdevice](#-openwrt-wiki-cs-docs-guide-user-network-openwrt-as-routerdevice)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:static_ip](#-openwrt-wiki-cs-docs-guide-user-luci-static-ip)
- [[OpenWrt Wiki] cs:docs:guide-user:network:integrating-openwrt-introduction](#-openwrt-wiki-cs-docs-guide-user-network-integrating-openwrt-introduction)
- [[OpenWrt Wiki] cs:docs:guide-user:network:architecture](#-openwrt-wiki-cs-docs-guide-user-network-architecture)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:statistics.chart.public](#-openwrt-wiki-cs-docs-guide-user-luci-statistics-chart-public)
- [[OpenWrt Wiki] cs:docs:guide-user:network:bonding](#-openwrt-wiki-cs-docs-guide-user-network-bonding)
- [[OpenWrt Wiki] cs:docs:guide-user:network:protocol.dhcp](#-openwrt-wiki-cs-docs-guide-user-network-protocol-dhcp)
- [[OpenWrt Wiki] cs:docs:guide-user:luci:webinterface.overview](#-openwrt-wiki-cs-docs-guide-user-luci-webinterface-overview)
- [[OpenWrt Wiki] ar:docs:guide-user:security:start](#-openwrt-wiki-ar-docs-guide-user-security-start)
- [[OpenWrt Wiki] cs:docs:guide-user:network:network_interface_alias](#-openwrt-wiki-cs-docs-guide-user-network-network-interface-alias)
- [[OpenWrt Wiki] cs:docs:guide-user:network:routedclient](#-openwrt-wiki-cs-docs-guide-user-network-routedclient)
- [[OpenWrt Wiki] cs:docs:guide-user:network:switch_router_gateway_and_nat](#-openwrt-wiki-cs-docs-guide-user-network-switch-router-gateway-and-nat)
- [[OpenWrt Wiki] cs:docs:guide-user:network:map](#-openwrt-wiki-cs-docs-guide-user-network-map)
- [[OpenWrt Wiki] cs:docs:guide-user:network:openwrt_as_clientdevice](#-openwrt-wiki-cs-docs-guide-user-network-openwrt-as-clientdevice)
- [[OpenWrt Wiki] cs:docs:guide-user:network:network_configuration](#-openwrt-wiki-cs-docs-guide-user-network-network-configuration)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-cs-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-cs-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] cs:docs:guide-user:network:high-availability](#-openwrt-wiki-cs-docs-guide-user-network-high-availability)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-cs-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-cs-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.sysupgrade](#-openwrt-wiki-cs-docs-guide-user-installation-generic-sysupgrade)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:vmware](#-openwrt-wiki-ar-docs-guide-user-virtualization-vmware)
- [[OpenWrt Wiki] ar:docs:guide-user:security:dropbear.public-key.auth](#-openwrt-wiki-ar-docs-guide-user-security-dropbear-public-key-auth)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-cs-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:docker_host](#-openwrt-wiki-ar-docs-guide-user-virtualization-docker-host)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:mikrotik_metarouter_openwrt](#-openwrt-wiki-ar-docs-guide-user-virtualization-mikrotik-metarouter-openwrt)
- [[OpenWrt Wiki] ar:docs:guide-user:security:sudo](#-openwrt-wiki-ar-docs-guide-user-security-sudo)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:qemu](#-openwrt-wiki-ar-docs-guide-user-virtualization-qemu)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:fusion](#-openwrt-wiki-ar-docs-guide-user-virtualization-fusion)
- [[OpenWrt Wiki] Flow Offloading](#-openwrt-wiki-flow-offloading)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:backup_restore](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-backup-restore)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:virtualbox-advanced](#-openwrt-wiki-ar-docs-guide-user-virtualization-virtualbox-advanced)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:start](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-start)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:start](#-openwrt-wiki-ar-docs-guide-user-virtualization-start)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:ead](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-ead)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:firewall_configuration](#-openwrt-wiki-ar-docs-guide-user-firewall-firewall-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:docker_openwrt_image](#-openwrt-wiki-ar-docs-guide-user-virtualization-docker-openwrt-image)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:obtain.firmware.docker](#-openwrt-wiki-ar-docs-guide-user-virtualization-obtain-firmware-docker)
- [[OpenWrt Wiki] ar:docs:guide-user:network:tunneling_interface_protocols](#-openwrt-wiki-ar-docs-guide-user-network-tunneling-interface-protocols)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:generic.debrick](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-generic-debrick)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:metarouter](#-openwrt-wiki-ar-docs-guide-user-virtualization-metarouter)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:vendor_specific_rescue](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-vendor-specific-rescue)
- [[OpenWrt Wiki] ar:docs:guide-user:security:security-features](#-openwrt-wiki-ar-docs-guide-user-security-security-features)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:root_password_reset](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-root-password-reset)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:xen](#-openwrt-wiki-ar-docs-guide-user-virtualization-xen)
- [[OpenWrt Wiki] ar:docs:guide-user:security:openwrt_security](#-openwrt-wiki-ar-docs-guide-user-security-openwrt-security)
- [[OpenWrt Wiki] ar:docs:guide-user:security:secure.access](#-openwrt-wiki-ar-docs-guide-user-security-secure-access)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:lxc](#-openwrt-wiki-ar-docs-guide-user-virtualization-lxc)
- [[OpenWrt Wiki] ar:docs:guide-user:security:recovering_from_clientmode](#-openwrt-wiki-ar-docs-guide-user-security-recovering-from-clientmode)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:failsafe_and_factory_reset](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-failsafe-and-factory-reset)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:start](#-openwrt-wiki-cs-docs-guide-user-installation-start)
- [[OpenWrt Wiki] ar:docs:guide-user:security:keygen](#-openwrt-wiki-ar-docs-guide-user-security-keygen)
- [[OpenWrt Wiki] ar:docs:guide-user:security:security_guide_for_the_paranoid](#-openwrt-wiki-ar-docs-guide-user-security-security-guide-for-the-paranoid)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:utm](#-openwrt-wiki-ar-docs-guide-user-virtualization-utm)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:podman](#-openwrt-wiki-ar-docs-guide-user-virtualization-podman)
- [[OpenWrt Wiki] ar:docs:guide-user:security:signatures](#-openwrt-wiki-ar-docs-guide-user-security-signatures)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:qemu_host](#-openwrt-wiki-ar-docs-guide-user-virtualization-qemu-host)
- [[OpenWrt Wiki] ar:docs:guide-user:security:release_signatures](#-openwrt-wiki-ar-docs-guide-user-security-release-signatures)
- [[OpenWrt Wiki] ar:docs:guide-user:virtualization:xen_debian_private_network](#-openwrt-wiki-ar-docs-guide-user-virtualization-xen-debian-private-network)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-cs-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] ar:docs:guide-user:troubleshooting:tftpserver](#-openwrt-wiki-ar-docs-guide-user-troubleshooting-tftpserver)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:openwrt-as-stock-firmware](#-openwrt-wiki-cs-docs-guide-user-installation-openwrt-as-stock-firmware)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:after.installation](#-openwrt-wiki-cs-docs-guide-user-installation-after-installation)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:before.installation](#-openwrt-wiki-cs-docs-guide-user-installation-before-installation)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot](#-openwrt-wiki-cs-docs-guide-user-installation-flashing-openwrt-with-wifi-enabled-on-first-boot)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:restore_art_partition](#-openwrt-wiki-cs-docs-guide-user-installation-restore-art-partition)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:snapshot](#-openwrt-wiki-cs-docs-guide-user-installation-snapshot)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing.serial](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing-serial)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing.tftp.easy-ubuntu](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing-tftp-easy-ubuntu)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:firewall_components](#-openwrt-wiki-ar-docs-guide-user-firewall-firewall-components)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.backup](#-openwrt-wiki-cs-docs-guide-user-installation-generic-backup)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:overview](#-openwrt-wiki-ar-docs-guide-user-firewall-overview)
- [[OpenWrt Wiki] ar:docs:guide-user:advanced:ntp_configuration](#-openwrt-wiki-ar-docs-guide-user-advanced-ntp-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:start](#-openwrt-wiki-ar-docs-guide-user-firewall-start)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing.ftp](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing-ftp)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:fw3_network](#-openwrt-wiki-ar-docs-guide-user-firewall-fw3-network)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:generic.flashing.tftp](#-openwrt-wiki-cs-docs-guide-user-installation-generic-flashing-tftp)
- [[OpenWrt Wiki] cs:docs:guide-user:installation:openwrt_x86](#-openwrt-wiki-cs-docs-guide-user-installation-openwrt-x86)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:pwm](#-openwrt-wiki-ar-docs-guide-user-hardware-pwm)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:lirc](#-openwrt-wiki-ar-docs-guide-user-hardware-lirc)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns](#-openwrt-wiki-ar-docs-guide-user-firewall-filtering-traffic-at-ip-addresses-by-dns)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:turnoff.uart.to.gpio](#-openwrt-wiki-ar-docs-guide-user-hardware-turnoff-uart-to-gpio)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:mmc_over_gpio](#-openwrt-wiki-ar-docs-guide-user-hardware-mmc-over-gpio)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:watchdog](#-openwrt-wiki-ar-docs-guide-user-hardware-watchdog)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:esp8266-serial-bridge](#-openwrt-wiki-ar-docs-guide-user-hardware-esp8266-serial-bridge)
- [[OpenWrt Wiki] ar:docs:guide-user:services:crowdsec](#-openwrt-wiki-ar-docs-guide-user-services-crowdsec)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:writable_ntfs](#-openwrt-wiki-ar-docs-guide-user-storage-writable-ntfs)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:start](#-openwrt-wiki-ar-docs-guide-user-storage-start)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:debrick.ath79.using.jtag](#-openwrt-wiki-ar-docs-guide-user-hardware-debrick-ath79-using-jtag)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:piratebox.librarybox.openwrt.routers](#-openwrt-wiki-ar-docs-guide-user-hardware-piratebox-librarybox-openwrt-routers)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:disk.encryption](#-openwrt-wiki-ar-docs-guide-user-storage-disk-encryption)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:usb-drives](#-openwrt-wiki-ar-docs-guide-user-storage-usb-drives)
- [[OpenWrt Wiki] ar:docs:guide-user:services:start](#-openwrt-wiki-ar-docs-guide-user-services-start)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:usb.i2c-tiny-usb](#-openwrt-wiki-ar-docs-guide-user-hardware-usb-i2c-tiny-usb)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:usb.overview](#-openwrt-wiki-ar-docs-guide-user-hardware-usb-overview)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:lirc-audio_alsa](#-openwrt-wiki-ar-docs-guide-user-hardware-lirc-audio-alsa)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:terminate.console.on.serial](#-openwrt-wiki-ar-docs-guide-user-hardware-terminate-console-on-serial)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:usb_gadget](#-openwrt-wiki-ar-docs-guide-user-hardware-usb-gadget)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:owsip](#-openwrt-wiki-ar-docs-guide-user-hardware-owsip)
- [[OpenWrt Wiki] ar:docs:guide-user:services:babeld](#-openwrt-wiki-ar-docs-guide-user-services-babeld)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:lirc-gpioblaster](#-openwrt-wiki-ar-docs-guide-user-hardware-lirc-gpioblaster)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:hd-idle](#-openwrt-wiki-ar-docs-guide-user-storage-hd-idle)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:usb-installing](#-openwrt-wiki-ar-docs-guide-user-storage-usb-installing)
- [[OpenWrt Wiki] ar:docs:guide-user:services:ad-blocking](#-openwrt-wiki-ar-docs-guide-user-services-ad-blocking)
- [[OpenWrt Wiki] ar:docs:guide-user:additional-software:smartmontools](#-openwrt-wiki-ar-docs-guide-user-additional-software-smartmontools)
- [[OpenWrt Wiki] ar:docs:guide-user:services:vblade](#-openwrt-wiki-ar-docs-guide-user-services-vblade)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:filesystems-and-partitions](#-openwrt-wiki-ar-docs-guide-user-storage-filesystems-and-partitions)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:fstab](#-openwrt-wiki-ar-docs-guide-user-storage-fstab)
- [[OpenWrt Wiki] ar:docs:guide-user:hardware:devolo-stream-radio](#-openwrt-wiki-ar-docs-guide-user-hardware-devolo-stream-radio)
- [[OpenWrt Wiki] ar:docs:guide-user:services:irqbalance](#-openwrt-wiki-ar-docs-guide-user-services-irqbalance)
- [[OpenWrt Wiki] ar:docs:guide-user:additional-software:opkg-to-apk-cheatsheet](#-openwrt-wiki-ar-docs-guide-user-additional-software-opkg-to-apk-cheatsheet)
- [[OpenWrt Wiki] ar:docs:guide-user:services:gitolite](#-openwrt-wiki-ar-docs-guide-user-services-gitolite)
- [[OpenWrt Wiki] ar:docs:guide-user:services:kerberos](#-openwrt-wiki-ar-docs-guide-user-services-kerberos)
- [[OpenWrt Wiki] ar:docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login](#-openwrt-wiki-ar-docs-guide-user-additional-software-show-upgradable-packages-after-ssh-login)
- [[OpenWrt Wiki] ar:docs:guide-user:services:banip](#-openwrt-wiki-ar-docs-guide-user-services-banip)
- [[OpenWrt Wiki] ar:docs:guide-user:services:chroot](#-openwrt-wiki-ar-docs-guide-user-services-chroot)
- [[OpenWrt Wiki] ar:docs:guide-user:additional-software:imagebuilder](#-openwrt-wiki-ar-docs-guide-user-additional-software-imagebuilder)
- [[OpenWrt Wiki] ar:docs:guide-user:services:python](#-openwrt-wiki-ar-docs-guide-user-services-python)
- [[OpenWrt Wiki] ar:docs:guide-user:additional-software:opkg](#-openwrt-wiki-ar-docs-guide-user-additional-software-opkg)
- [[OpenWrt Wiki] ar:docs:guide-user:services:rng](#-openwrt-wiki-ar-docs-guide-user-services-rng)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:mountd](#-openwrt-wiki-ar-docs-guide-user-storage-mountd)
- [[OpenWrt Wiki] ar:docs:guide-user:services:honeypots](#-openwrt-wiki-ar-docs-guide-user-services-honeypots)
- [[OpenWrt Wiki] ar:docs:guide-user:services:ugps](#-openwrt-wiki-ar-docs-guide-user-services-ugps)
- [[OpenWrt Wiki] ar:docs:guide-user:services:usb.iptunnel](#-openwrt-wiki-ar-docs-guide-user-services-usb-iptunnel)
- [[OpenWrt Wiki] ar:docs:guide-user:services:fwknop](#-openwrt-wiki-ar-docs-guide-user-services-fwknop)
- [[OpenWrt Wiki] ar:docs:guide-user:services:xmpp.server](#-openwrt-wiki-ar-docs-guide-user-services-xmpp-server)
- [[OpenWrt Wiki] ar:docs:guide-user:services:geoip-shell](#-openwrt-wiki-ar-docs-guide-user-services-geoip-shell)
- [[OpenWrt Wiki] ar:docs:guide-user:services:snort](#-openwrt-wiki-ar-docs-guide-user-services-snort)
- [[OpenWrt Wiki] ar:docs:guide-user:services:telegraf](#-openwrt-wiki-ar-docs-guide-user-services-telegraf)
- [[OpenWrt Wiki] ar:docs:guide-user:services:tftp.pxe-server](#-openwrt-wiki-ar-docs-guide-user-services-tftp-pxe-server)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:dhcp_configuration](#-openwrt-wiki-ar-docs-guide-user-base-system-dhcp-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:uci](#-openwrt-wiki-ar-docs-guide-user-base-system-uci)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:start](#-openwrt-wiki-ar-docs-guide-user-installation-start)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.backup](#-openwrt-wiki-ar-docs-guide-user-installation-generic-backup)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:hotplug](#-openwrt-wiki-ar-docs-guide-user-base-system-hotplug)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot](#-openwrt-wiki-ar-docs-guide-user-installation-flashing-openwrt-with-wifi-enabled-on-first-boot)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:snapshot](#-openwrt-wiki-ar-docs-guide-user-installation-snapshot)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:before.installation](#-openwrt-wiki-ar-docs-guide-user-installation-before-installation)
- [[OpenWrt Wiki] ar:docs:guide-user:network:ucicheatsheet](#-openwrt-wiki-ar-docs-guide-user-network-ucicheatsheet)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:openwrt-as-stock-firmware](#-openwrt-wiki-ar-docs-guide-user-installation-openwrt-as-stock-firmware)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:dhcp](#-openwrt-wiki-ar-docs-guide-user-base-system-dhcp)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:after.installation](#-openwrt-wiki-ar-docs-guide-user-installation-after-installation)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:restore_art_partition](#-openwrt-wiki-ar-docs-guide-user-installation-restore-art-partition)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing.serial](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing-serial)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-ar-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-ar-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.sysupgrade](#-openwrt-wiki-ar-docs-guide-user-installation-generic-sysupgrade)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-ar-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:user.beginner.cli](#-openwrt-wiki-ar-docs-guide-user-base-system-user-beginner-cli)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-ar-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:managing_services](#-openwrt-wiki-ar-docs-guide-user-base-system-managing-services)
- [[OpenWrt Wiki] ar:docs:guide-user:network:ipv6_ipv4_transitioning](#-openwrt-wiki-ar-docs-guide-user-network-ipv6-ipv4-transitioning)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:basic](#-openwrt-wiki-ar-docs-guide-user-base-system-basic)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:dns_configuration](#-openwrt-wiki-ar-docs-guide-user-base-system-dns-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:clarifying_interface_usage](#-openwrt-wiki-ar-docs-guide-user-base-system-clarifying-interface-usage)
- [[OpenWrt Wiki] ar:docs:guide-user:network:mptcp](#-openwrt-wiki-ar-docs-guide-user-network-mptcp)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing.tftp](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing-tftp)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing.ftp](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing-ftp)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:openwrt_x86](#-openwrt-wiki-ar-docs-guide-user-installation-openwrt-x86)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-ar-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] ar:docs:guide-user:installation:generic.flashing.tftp.easy-ubuntu](#-openwrt-wiki-ar-docs-guide-user-installation-generic-flashing-tftp-easy-ubuntu)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:start](#-openwrt-wiki-ar-docs-guide-user-base-system-start)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:notuci.config](#-openwrt-wiki-ar-docs-guide-user-base-system-notuci-config)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:log.essentials](#-openwrt-wiki-ar-docs-guide-user-base-system-log-essentials)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address](#-openwrt-wiki-ar-docs-guide-user-base-system-persistent-ethernet-interface-naming-by-mac-address)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings](#-openwrt-wiki-ar-docs-guide-user-luci-getting-rid-of-luci-https-certificate-warnings)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:dropbear](#-openwrt-wiki-ar-docs-guide-user-base-system-dropbear)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:ddns](#-openwrt-wiki-ar-docs-guide-user-base-system-ddns)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:cron](#-openwrt-wiki-ar-docs-guide-user-base-system-cron)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:httpd](#-openwrt-wiki-ar-docs-guide-user-base-system-httpd)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:system_configuration](#-openwrt-wiki-ar-docs-guide-user-base-system-system-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:users](#-openwrt-wiki-ar-docs-guide-user-base-system-users)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:dashboard](#-openwrt-wiki-ar-docs-guide-user-luci-dashboard)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:dhcp.dnsmasq](#-openwrt-wiki-ar-docs-guide-user-base-system-dhcp-dnsmasq)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:luci.secure](#-openwrt-wiki-ar-docs-guide-user-luci-luci-secure)
- [[OpenWrt Wiki] ar:docs:guide-user:network:singleportrouter](#-openwrt-wiki-ar-docs-guide-user-network-singleportrouter)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:basic-networking](#-openwrt-wiki-ar-docs-guide-user-base-system-basic-networking)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:luci_app_statistics](#-openwrt-wiki-ar-docs-guide-user-luci-luci-app-statistics)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:statistics.chart.public](#-openwrt-wiki-ar-docs-guide-user-luci-statistics-chart-public)
- [[OpenWrt Wiki] ar:docs:guide-user:network:integrating-openwrt-introduction](#-openwrt-wiki-ar-docs-guide-user-network-integrating-openwrt-introduction)
- [[OpenWrt Wiki] ar:docs:guide-user:base-system:led_configuration](#-openwrt-wiki-ar-docs-guide-user-base-system-led-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:network:start](#-openwrt-wiki-ar-docs-guide-user-network-start)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:start](#-openwrt-wiki-ar-docs-guide-user-luci-start)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:luci.on.lighttpd](#-openwrt-wiki-ar-docs-guide-user-luci-luci-on-lighttpd)
- [[OpenWrt Wiki] ar:docs:guide-user:network:openwrt_as_routerdevice](#-openwrt-wiki-ar-docs-guide-user-network-openwrt-as-routerdevice)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:luci.essentials](#-openwrt-wiki-ar-docs-guide-user-luci-luci-essentials)
- [[OpenWrt Wiki] ar:docs:guide-user:network:protocol.static](#-openwrt-wiki-ar-docs-guide-user-network-protocol-static)
- [[OpenWrt Wiki] ar:docs:guide-user:network:architecture](#-openwrt-wiki-ar-docs-guide-user-network-architecture)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:static_ip](#-openwrt-wiki-ar-docs-guide-user-luci-static-ip)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:luci.themes](#-openwrt-wiki-ar-docs-guide-user-luci-luci-themes)
- [[OpenWrt Wiki] ar:docs:guide-user:network:bonding](#-openwrt-wiki-ar-docs-guide-user-network-bonding)
- [[OpenWrt Wiki] ar:docs:guide-user:network:protocol.dhcp](#-openwrt-wiki-ar-docs-guide-user-network-protocol-dhcp)
- [[OpenWrt Wiki] ar:docs:guide-user:network:routedclient](#-openwrt-wiki-ar-docs-guide-user-network-routedclient)
- [[OpenWrt Wiki] ar:docs:guide-user:luci:webinterface.overview](#-openwrt-wiki-ar-docs-guide-user-luci-webinterface-overview)
- [[OpenWrt Wiki] ar:docs:guide-user:network:high-availability](#-openwrt-wiki-ar-docs-guide-user-network-high-availability)
- [[OpenWrt Wiki] ar:docs:guide-user:network:network_interface_alias](#-openwrt-wiki-ar-docs-guide-user-network-network-interface-alias)
- [[OpenWrt Wiki] ar:docs:guide-user:network:map](#-openwrt-wiki-ar-docs-guide-user-network-map)
- [[OpenWrt Wiki] ar:docs:guide-user:network:switch_router_gateway_and_nat](#-openwrt-wiki-ar-docs-guide-user-network-switch-router-gateway-and-nat)
- [[OpenWrt Wiki] ar:docs:guide-user:network:network_configuration](#-openwrt-wiki-ar-docs-guide-user-network-network-configuration)
- [[OpenWrt Wiki] ar:docs:guide-user:network:openwrt_as_clientdevice](#-openwrt-wiki-ar-docs-guide-user-network-openwrt-as-clientdevice)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-hu-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] it:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-it-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] ko:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-ko-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] pl:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-pl-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] オリジナル・ファームウェアに戻す](#-openwrt-wiki-)
- [[OpenWrt Wiki] pt:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-pt-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] pt-br:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-pt-br-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] tr:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-tr-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] Назад, к родной прошивке](#-openwrt-wiki-)
- [[OpenWrt Wiki] vi:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-vi-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] 恢复原始固件](#-openwrt-wiki-)
- [[OpenWrt Wiki] Повернення до оригінальної прошивки](#-openwrt-wiki-)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:installation:generic.uninstall](#-openwrt-wiki-zh-tw-docs-guide-user-installation-generic-uninstall)
- [[OpenWrt Wiki] fr:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-fr-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] hu:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-hu-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] ja:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-ja-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] ko:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-ko-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] it:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-it-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] pl:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-pl-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] pt:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-pt-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] pt-br:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-pt-br-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] ru:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-ru-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] tr:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-tr-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] uk:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-uk-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] vi:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-vi-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] docs:guide-user:firewall:shorewall:start](#-openwrt-wiki-docs-guide-user-firewall-shorewall-start)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:virtualization:virtualbox-vm](#-openwrt-wiki-zh-tw-docs-guide-user-virtualization-virtualbox-vm)
- [[OpenWrt Wiki] 在Virtualbox虚拟机中运行OpenWrt](#-openwrt-wiki-virtualbox-openwrt)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-fr-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-fr-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-fr-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-fr-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-hu-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-hu-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-hu-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-hu-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] it:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-it-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] it:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-it-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] it:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-it-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] it:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-it-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] ja:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-ja-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ja:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-ja-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] ja:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-ja-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] ja:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-ja-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] ko:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-ko-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] ko:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-ko-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ko:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-ko-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] ko:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-ko-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] pl:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-pl-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] pt:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-pt-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] docs:guide-user:firewall:netfilter-iptables:start](#-openwrt-wiki-docs-guide-user-firewall-netfilter-iptables-start)
- [[OpenWrt Wiki] zh:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-zh-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] ar:docs:guide-user:storage:usb-drives-quickstart](#-openwrt-wiki-ar-docs-guide-user-storage-usb-drives-quickstart)
- [[OpenWrt Wiki] cs:docs:guide-user:perf_and_log:log.rsyslog](#-openwrt-wiki-cs-docs-guide-user-perf-and-log-log-rsyslog)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:clarifying_interface_usage](#-openwrt-wiki-fr-docs-guide-user-base-system-clarifying-interface-usage)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:start](#-openwrt-wiki-fr-docs-guide-user-base-system-start)
- [[OpenWrt Wiki] pl:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-pl-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:generic.sysupgrade](#-openwrt-wiki-fr-docs-guide-user-installation-generic-sysupgrade)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-fr-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] fr:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-fr-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:basic](#-openwrt-wiki-fr-docs-guide-user-base-system-basic)
- [[OpenWrt Wiki] zh:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-zh-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] tr:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-tr-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:user.beginner.cli](#-openwrt-wiki-fr-docs-guide-user-base-system-user-beginner-cli)
- [[OpenWrt Wiki] pt:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-pt-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:system_configuration](#-openwrt-wiki-fr-docs-guide-user-base-system-system-configuration)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings](#-openwrt-wiki-fr-docs-guide-user-luci-getting-rid-of-luci-https-certificate-warnings)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:luci_app_statistics](#-openwrt-wiki-fr-docs-guide-user-luci-luci-app-statistics)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:dropbear](#-openwrt-wiki-fr-docs-guide-user-base-system-dropbear)
- [[OpenWrt Wiki] pt-br:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-pt-br-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ru:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-ru-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] pl:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-pl-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] pt:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-pt-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] pt-br:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-pt-br-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:cron](#-openwrt-wiki-fr-docs-guide-user-base-system-cron)
- [[OpenWrt Wiki] ru:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-ru-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address](#-openwrt-wiki-fr-docs-guide-user-base-system-persistent-ethernet-interface-naming-by-mac-address)
- [[OpenWrt Wiki] ru:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-ru-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] fr:docs:guide-user:network:singleportrouter](#-openwrt-wiki-fr-docs-guide-user-network-singleportrouter)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:dhcp.dnsmasq](#-openwrt-wiki-fr-docs-guide-user-base-system-dhcp-dnsmasq)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:users](#-openwrt-wiki-fr-docs-guide-user-base-system-users)
- [[OpenWrt Wiki] ru:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-ru-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-zh-tw-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:luci.secure](#-openwrt-wiki-fr-docs-guide-user-luci-luci-secure)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:httpd](#-openwrt-wiki-fr-docs-guide-user-base-system-httpd)
- [[OpenWrt Wiki] tr:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-tr-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] tr:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-tr-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] tr:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-tr-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] docs:guide-user:ssh_configuration](#-openwrt-wiki-docs-guide-user-ssh-configuration)
- [[OpenWrt Wiki] pt-br:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-pt-br-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:luci.on.lighttpd](#-openwrt-wiki-fr-docs-guide-user-luci-luci-on-lighttpd)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:managing_services](#-openwrt-wiki-fr-docs-guide-user-base-system-managing-services)
- [[OpenWrt Wiki] vi:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-vi-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] Встановлення OpenWrt через XMODEM](#-openwrt-wiki-openwrt-xmodem)
- [[OpenWrt Wiki] vi:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-vi-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] vi:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-vi-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ar:docs:guide-user:perf_and_log:log.rsyslog](#-openwrt-wiki-ar-docs-guide-user-perf-and-log-log-rsyslog)
- [[OpenWrt Wiki] zh:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-zh-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] ar:docs:guide-user:services:bbstored](#-openwrt-wiki-ar-docs-guide-user-services-bbstored)
- [[OpenWrt Wiki] pt:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-pt-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] ar:docs:guide-user:firewall:freifunk_p2pblock](#-openwrt-wiki-ar-docs-guide-user-firewall-freifunk-p2pblock)
- [[OpenWrt Wiki] ar:docs:guide-user:perf_and_log:log.syslog-ng3](#-openwrt-wiki-ar-docs-guide-user-perf-and-log-log-syslog-ng3)
- [[OpenWrt Wiki] pl:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-pl-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:led_configuration](#-openwrt-wiki-fr-docs-guide-user-base-system-led-configuration)
- [[OpenWrt Wiki] fr:docs:guide-user:network:protocol.static](#-openwrt-wiki-fr-docs-guide-user-network-protocol-static)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:basic-networking](#-openwrt-wiki-fr-docs-guide-user-base-system-basic-networking)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:luci.essentials](#-openwrt-wiki-fr-docs-guide-user-luci-luci-essentials)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-zh-tw-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:attended.sysupgrade](#-openwrt-wiki-hu-docs-guide-user-installation-attended-sysupgrade)
- [[OpenWrt Wiki] hu:docs:guide-user:installation:sysupgrade.cli](#-openwrt-wiki-hu-docs-guide-user-installation-sysupgrade-cli)
- [[OpenWrt Wiki] pt-br:docs:guide-user:installation:sysupgrade.owut](#-openwrt-wiki-pt-br-docs-guide-user-installation-sysupgrade-owut)
- [[OpenWrt Wiki] cs:docs:guide-user:firewall:freifunk_p2pblock](#-openwrt-wiki-cs-docs-guide-user-firewall-freifunk-p2pblock)
- [[OpenWrt Wiki] cs:docs:guide-user:services:bbstored](#-openwrt-wiki-cs-docs-guide-user-services-bbstored)
- [[OpenWrt Wiki] vi:docs:guide-user:installation:sysupgrade.packages](#-openwrt-wiki-vi-docs-guide-user-installation-sysupgrade-packages)
- [[OpenWrt Wiki] cs:docs:guide-user:storage:usb-drives-quickstart](#-openwrt-wiki-cs-docs-guide-user-storage-usb-drives-quickstart)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:installation:generic.flashing.xmodem](#-openwrt-wiki-zh-tw-docs-guide-user-installation-generic-flashing-xmodem)
- [[OpenWrt Wiki] de:docs:guide-user:perf_and_log:log.rsyslog](#-openwrt-wiki-de-docs-guide-user-perf-and-log-log-rsyslog)
- [[OpenWrt Wiki] cs:docs:guide-user:perf_and_log:log.syslog-ng3](#-openwrt-wiki-cs-docs-guide-user-perf-and-log-log-syslog-ng3)
- [[OpenWrt Wiki] zh-tw:docs:guide-user:installation:ar71xx.to.ath79](#-openwrt-wiki-zh-tw-docs-guide-user-installation-ar71xx-to-ath79)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:notuci.config](#-openwrt-wiki-fr-docs-guide-user-base-system-notuci-config)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:dns_configuration](#-openwrt-wiki-fr-docs-guide-user-base-system-dns-configuration)
- [[OpenWrt Wiki] fr:docs:guide-user:network:mptcp](#-openwrt-wiki-fr-docs-guide-user-network-mptcp)
- [[OpenWrt Wiki] Оновлення застарілого ar71xx до ath79](#-openwrt-wiki-ar71xx-ath79)
- [[OpenWrt Wiki] owut: OpenWrt 升级工具](#-openwrt-wiki-owut-openwrt-)
- [[OpenWrt Wiki] fr:docs:guide-user:luci:dashboard](#-openwrt-wiki-fr-docs-guide-user-luci-dashboard)
- [[OpenWrt Wiki] fr:docs:guide-user:network:ipv6_ipv4_transitioning](#-openwrt-wiki-fr-docs-guide-user-network-ipv6-ipv4-transitioning)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:log.essentials](#-openwrt-wiki-fr-docs-guide-user-base-system-log-essentials)
- [[OpenWrt Wiki] fr:docs:guide-user:base-system:ddns](#-openwrt-wiki-fr-docs-guide-user-base-system-ddns)
- [[OpenWrt Wiki] Збереження пакетів OpenWrt після оновлення](#-openwrt-wiki-openwrt-)
- [[OpenWrt Wiki] owut: OpenWrt Upgrade Tool](#-openwrt-wiki-owut-openwrt-upgrade-tool)
---
# [OpenWrt Wiki] User guide
User guide
==========
Installation
------------
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[Installation](https://openwrt.org/docs/guide-user/installation/start "docs:guide-user:installation:start")
* [Back to original firmware](https://openwrt.org/docs/guide-user/installation/generic.uninstall "docs:guide-user:installation:generic.uninstall")
* [Devices with OpenWrt as a stock firmware](https://openwrt.org/docs/guide-user/installation/openwrt-as-stock-firmware "docs:guide-user:installation:openwrt-as-stock-firmware")
* [FAQ after Installation of OpenWrt](https://openwrt.org/docs/guide-user/installation/after.installation "docs:guide-user:installation:after.installation")
* [FAQ before installing OpenWrt](https://openwrt.org/docs/guide-user/installation/before.installation "docs:guide-user:installation:before.installation")
* [Filesystem snapshot feature: /sbin/snapshot](https://openwrt.org/docs/guide-user/installation/snapshot "docs:guide-user:installation:snapshot")
* [Flashing OpenWrt with Wi-Fi enabled on first boot](https://openwrt.org/docs/guide-user/installation/flashing_openwrt_with_wifi_enabled_on_first_boot "docs:guide-user:installation:flashing_openwrt_with_wifi_enabled_on_first_boot")
* [Generic flashing over the Serial port](https://openwrt.org/docs/guide-user/installation/generic.flashing.serial "docs:guide-user:installation:generic.flashing.serial")
* [Generic NOR backup](https://openwrt.org/docs/guide-user/installation/generic.backup "docs:guide-user:installation:generic.backup")
* [How to restore ART partition](https://openwrt.org/docs/guide-user/installation/restore_art_partition "docs:guide-user:installation:restore_art_partition")
* [Installing OpenWrt](https://openwrt.org/docs/guide-user/installation/generic.flashing "docs:guide-user:installation:generic.flashing")
* [Installing OpenWrt over FTP (generic)](https://openwrt.org/docs/guide-user/installation/generic.flashing.ftp "docs:guide-user:installation:generic.flashing.ftp")
* [Installing OpenWrt over XMODEM](https://openwrt.org/docs/guide-user/installation/generic.flashing.xmodem "docs:guide-user:installation:generic.flashing.xmodem")
* [Installing OpenWrt via TFTP](https://openwrt.org/docs/guide-user/installation/generic.flashing.tftp "docs:guide-user:installation:generic.flashing.tftp")
* [Installing OpenWrt with TFTP from a Linux computer](https://openwrt.org/docs/guide-user/installation/generic.flashing.tftp.easy-ubuntu "docs:guide-user:installation:generic.flashing.tftp.easy-ubuntu")
* [OpenWrt on x86 hardware (PC / VM / server)](https://openwrt.org/docs/guide-user/installation/openwrt_x86 "docs:guide-user:installation:openwrt_x86")
* [owut: OpenWrt Upgrade Tool](https://openwrt.org/docs/guide-user/installation/sysupgrade.owut "docs:guide-user:installation:sysupgrade.owut")
* [Preserving OpenWrt packages](https://openwrt.org/docs/guide-user/installation/sysupgrade.packages "docs:guide-user:installation:sysupgrade.packages")
* [Upgrade from (old) ar71xx to ath79](https://openwrt.org/docs/guide-user/installation/ar71xx.to.ath79 "docs:guide-user:installation:ar71xx.to.ath79")
* [Upgrade using Attended Sysupgrade](https://openwrt.org/docs/guide-user/installation/attended.sysupgrade "docs:guide-user:installation:attended.sysupgrade")
* [Upgrading OpenWrt firmware using CLI](https://openwrt.org/docs/guide-user/installation/sysupgrade.cli "docs:guide-user:installation:sysupgrade.cli")
* [Upgrading OpenWrt firmware using LuCI and CLI](https://openwrt.org/docs/guide-user/installation/generic.sysupgrade "docs:guide-user:installation:generic.sysupgrade")
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[Installation methods](https://openwrt.org/docs/guide-user/installation/installation_methods/start "docs:guide-user:installation:installation_methods:start")
* [ADAM2 FTP](https://openwrt.org/docs/guide-user/installation/installation_methods/adam2_ftp "docs:guide-user:installation:installation_methods:adam2_ftp")
* [ap51-flash](https://openwrt.org/docs/guide-user/installation/installation_methods/ap51-flash "docs:guide-user:installation:installation_methods:ap51-flash")
* [Asus Firmware Restoration Tool](https://openwrt.org/docs/guide-user/installation/installation_methods/asus_firmware_restoration_tool "docs:guide-user:installation:installation_methods:asus_firmware_restoration_tool")
* [brnboot web recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/brnboot_web_recovery "docs:guide-user:installation:installation_methods:brnboot_web_recovery")
* [CF card](https://openwrt.org/docs/guide-user/installation/installation_methods/cf_card "docs:guide-user:installation:installation_methods:cf_card")
* [CFE TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/cfe_tftp_serial_recovery "docs:guide-user:installation:installation_methods:cfe_tftp_serial_recovery")
* [CFE TFTP recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/cfe_tftp_recovery "docs:guide-user:installation:installation_methods:cfe_tftp_recovery")
* [CFE web recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/cfe_web_recovery "docs:guide-user:installation:installation_methods:cfe_web_recovery")
* [CLI generic](https://openwrt.org/docs/guide-user/installation/installation_methods/cli_generic "docs:guide-user:installation:installation_methods:cli_generic")
* [D-Link Recovery GUI](https://openwrt.org/docs/guide-user/installation/installation_methods/d-link_recovery_gui "docs:guide-user:installation:installation_methods:d-link_recovery_gui")
* [dataclouds](https://openwrt.org/docs/guide-user/installation/installation_methods/dataclouds "docs:guide-user:installation:installation_methods:dataclouds")
* [EVA FTP](https://openwrt.org/docs/guide-user/installation/installation_methods/eva_ftp "docs:guide-user:installation:installation_methods:eva_ftp")
* [fritzflash](https://openwrt.org/docs/guide-user/installation/installation_methods/fritzflash "docs:guide-user:installation:installation_methods:fritzflash")
* [GL.iNET installation](https://openwrt.org/docs/guide-user/installation/installation_methods/gl.inet_installation "docs:guide-user:installation:installation_methods:gl.inet_installation")
* [GUI generic](https://openwrt.org/docs/guide-user/installation/installation_methods/gui_generic "docs:guide-user:installation:installation_methods:gui_generic")
* [GUI OEM](https://openwrt.org/docs/guide-user/installation/installation_methods/gui_oem "docs:guide-user:installation:installation_methods:gui_oem")
* [JBoot web recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/jboot_web_recovery "docs:guide-user:installation:installation_methods:jboot_web_recovery")
* [JTAG](https://openwrt.org/docs/guide-user/installation/installation_methods/jtag "docs:guide-user:installation:installation_methods:jtag")
* [Linksys TFTP](https://openwrt.org/docs/guide-user/installation/installation_methods/linksys_tftp "docs:guide-user:installation:installation_methods:linksys_tftp")
* [Mikrotik TFTP](https://openwrt.org/docs/guide-user/installation/installation_methods/mikrotik_tftp "docs:guide-user:installation:installation_methods:mikrotik_tftp")
* [Netboot](https://openwrt.org/docs/guide-user/installation/installation_methods/netboot "docs:guide-user:installation:installation_methods:netboot")
* [nmrpflash](https://openwrt.org/docs/guide-user/installation/installation_methods/nmrpflash "docs:guide-user:installation:installation_methods:nmrpflash")
* [RedBoot TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/redboot_tftp_serial_recovery "docs:guide-user:installation:installation_methods:redboot_tftp_serial_recovery")
* [RedBoot TFTP recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/redboot_tftp_recovery "docs:guide-user:installation:installation_methods:redboot_tftp_recovery")
* [SD card](https://openwrt.org/docs/guide-user/installation/installation_methods/sd_card "docs:guide-user:installation:installation_methods:sd_card")
* [see devicepage](https://openwrt.org/docs/guide-user/installation/installation_methods/see_devicepage "docs:guide-user:installation:installation_methods:see_devicepage")
* [see forum](https://openwrt.org/docs/guide-user/installation/installation_methods/see_forum "docs:guide-user:installation:installation_methods:see_forum")
* [see git-commit](https://openwrt.org/docs/guide-user/installation/installation_methods/see_git-commit "docs:guide-user:installation:installation_methods:see_git-commit")
* [Serial](https://openwrt.org/docs/guide-user/installation/installation_methods/serial "docs:guide-user:installation:installation_methods:serial")
* [Sunxi installation](https://openwrt.org/docs/guide-user/installation/installation_methods/sunxi_installation "docs:guide-user:installation:installation_methods:sunxi_installation")
* [Sysupgrade](https://openwrt.org/docs/guide-user/installation/installation_methods/sysupgrade "docs:guide-user:installation:installation_methods:sysupgrade")
* [Telnet](https://openwrt.org/docs/guide-user/installation/installation_methods/telnet "docs:guide-user:installation:installation_methods:telnet")
* [TFTP generic](https://openwrt.org/docs/guide-user/installation/installation_methods/tftp_generic "docs:guide-user:installation:installation_methods:tftp_generic")
* [TP-Link TFTP](https://openwrt.org/docs/guide-user/installation/installation_methods/tp-link_tftp "docs:guide-user:installation:installation_methods:tp-link_tftp")
* [U-Boot TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/u-boot_tftp_serial_recovery "docs:guide-user:installation:installation_methods:u-boot_tftp_serial_recovery")
* [U-Boot TFTP recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/u-boot_tftp_recovery "docs:guide-user:installation:installation_methods:u-boot_tftp_recovery")
* [U-Boot USB recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/u-boot_usb_recovery "docs:guide-user:installation:installation_methods:u-boot_usb_recovery")
* [U-Boot web recovery](https://openwrt.org/docs/guide-user/installation/installation_methods/u-boot_web_recovery "docs:guide-user:installation:installation_methods:u-boot_web_recovery")
* [Ubiquiti 2WA](https://openwrt.org/docs/guide-user/installation/installation_methods/ubiquiti_2wa "docs:guide-user:installation:installation_methods:ubiquiti_2wa")
* [Ubiquiti WA](https://openwrt.org/docs/guide-user/installation/installation_methods/ubiquiti_wa "docs:guide-user:installation:installation_methods:ubiquiti_wa")
* [Ubiquiti XC](https://openwrt.org/docs/guide-user/installation/installation_methods/ubiquiti_xc "docs:guide-user:installation:installation_methods:ubiquiti_xc")
* [Ubiquiti XM](https://openwrt.org/docs/guide-user/installation/installation_methods/ubiquiti_xm "docs:guide-user:installation:installation_methods:ubiquiti_xm")
* [Ubiquiti XW](https://openwrt.org/docs/guide-user/installation/installation_methods/ubiquiti_xw "docs:guide-user:installation:installation_methods:ubiquiti_xw")
* [unknown](https://openwrt.org/docs/guide-user/installation/installation_methods/unknown "docs:guide-user:installation:installation_methods:unknown")
* [x86 installation](https://openwrt.org/docs/guide-user/installation/installation_methods/x86_installation "docs:guide-user:installation:installation_methods:x86_installation")
[](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802646366 "Continue with the « docs » section at the top...")
[Recovery methods](https://openwrt.org/docs/guide-user/installation/recovery_methods/start "docs:guide-user:installation:recovery_methods:start")
* [ADAM2 FTP](https://openwrt.org/docs/guide-user/installation/recovery_methods/adam2_ftp "docs:guide-user:installation:recovery_methods:adam2_ftp")
* [Asus Firmware Restoration Tool](https://openwrt.org/docs/guide-user/installation/recovery_methods/asus_firmware_restoration_tool "docs:guide-user:installation:recovery_methods:asus_firmware_restoration_tool")
* [AVM recovery tool](https://openwrt.org/docs/guide-user/installation/recovery_methods/avm_recovery_tool "docs:guide-user:installation:recovery_methods:avm_recovery_tool")
* [Breed web recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/breed_web_recovery "docs:guide-user:installation:recovery_methods:breed_web_recovery")
* [brnboot web recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/brnboot_web_recovery "docs:guide-user:installation:recovery_methods:brnboot_web_recovery")
* [CF card](https://openwrt.org/docs/guide-user/installation/recovery_methods/cf_card "docs:guide-user:installation:recovery_methods:cf_card")
* [CFE TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/cfe_tftp_serial_recovery "docs:guide-user:installation:recovery_methods:cfe_tftp_serial_recovery")
* [CFE TFTP recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/cfe_tftp_recovery "docs:guide-user:installation:recovery_methods:cfe_tftp_recovery")
* [CFE web recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/cfe_web_recovery "docs:guide-user:installation:recovery_methods:cfe_web_recovery")
* [D-Link Recovery GUI](https://openwrt.org/docs/guide-user/installation/recovery_methods/d-link_recovery_gui "docs:guide-user:installation:recovery_methods:d-link_recovery_gui")
* [EVA FTP](https://openwrt.org/docs/guide-user/installation/recovery_methods/eva_ftp "docs:guide-user:installation:recovery_methods:eva_ftp")
* [GUI generic](https://openwrt.org/docs/guide-user/installation/recovery_methods/gui_generic "docs:guide-user:installation:recovery_methods:gui_generic")
* [JBoot web recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/jboot_web_recovery "docs:guide-user:installation:recovery_methods:jboot_web_recovery")
* [JTAG](https://openwrt.org/docs/guide-user/installation/recovery_methods/jtag "docs:guide-user:installation:recovery_methods:jtag")
* [Linksys TFTP](https://openwrt.org/docs/guide-user/installation/recovery_methods/linksys_tftp "docs:guide-user:installation:recovery_methods:linksys_tftp")
* [Mikrotik TFTP](https://openwrt.org/docs/guide-user/installation/recovery_methods/mikrotik_tftp "docs:guide-user:installation:recovery_methods:mikrotik_tftp")
* [nmrpflash](https://openwrt.org/docs/guide-user/installation/recovery_methods/nmrpflash "docs:guide-user:installation:recovery_methods:nmrpflash")
* [RedBoot TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/redboot_tftp_serial_recovery "docs:guide-user:installation:recovery_methods:redboot_tftp_serial_recovery")
* [RedBoot TFTP recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/redboot_tftp_recovery "docs:guide-user:installation:recovery_methods:redboot_tftp_recovery")
* [SD card](https://openwrt.org/docs/guide-user/installation/recovery_methods/sd_card "docs:guide-user:installation:recovery_methods:sd_card")
* [see devicepage](https://openwrt.org/docs/guide-user/installation/recovery_methods/see_devicepage "docs:guide-user:installation:recovery_methods:see_devicepage")
* [see forum](https://openwrt.org/docs/guide-user/installation/recovery_methods/see_forum "docs:guide-user:installation:recovery_methods:see_forum")
* [see git-commit](https://openwrt.org/docs/guide-user/installation/recovery_methods/see_git-commit "docs:guide-user:installation:recovery_methods:see_git-commit")
* [TFTP generic](https://openwrt.org/docs/guide-user/installation/recovery_methods/tftp_generic "docs:guide-user:installation:recovery_methods:tftp_generic")
* [TP-Link TFTP](https://openwrt.org/docs/guide-user/installation/recovery_methods/tp-link_tftp "docs:guide-user:installation:recovery_methods:tp-link_tftp")
* [U-Boot TFTP + serial recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/u-boot_tftp_serial_recovery "docs:guide-user:installation:recovery_methods:u-boot_tftp_serial_recovery")
* [U-Boot TFTP recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/u-boot_tftp_recovery "docs:guide-user:installation:recovery_methods:u-boot_tftp_recovery")
* [U-Boot USB recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/u-boot_usb_recovery "docs:guide-user:installation:recovery_methods:u-boot_usb_recovery")
* [U-Boot web recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/u-boot_web_recovery "docs:guide-user:installation:recovery_methods:u-boot_web_recovery")
* [Ubiquiti TFTP recovery](https://openwrt.org/docs/guide-user/installation/recovery_methods/ubiquiti_tftp "docs:guide-user:installation:recovery_methods:ubiquiti_tftp")
* [unknown](https://openwrt.org/docs/guide-user/installation/recovery_methods/unknown "docs:guide-user:installation:recovery_methods:unknown")
Basic configuration
-------------------
[](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1057539099 "Continue with the « docs » section at the top...")
[Base system](https://openwrt.org/docs/guide-user/base-system/start "docs:guide-user:base-system:start")
* [Basic configuration](https://openwrt.org/docs/guide-user/base-system/basic "docs:guide-user:base-system:basic")
* [Clarifying the term "Interface"](https://openwrt.org/docs/guide-user/base-system/clarifying_interface_usage "docs:guide-user:base-system:clarifying_interface_usage")
* [Command-line interpreter](https://openwrt.org/docs/guide-user/base-system/user.beginner.cli "docs:guide-user:base-system:user.beginner.cli")
* [DDNS client configuration](https://openwrt.org/docs/guide-user/base-system/ddns "docs:guide-user:base-system:ddns")
* [DHCP and DNS configuration /etc/config/dhcp](https://openwrt.org/docs/guide-user/base-system/dhcp "docs:guide-user:base-system:dhcp")
* [DHCP and DNS examples](https://openwrt.org/docs/guide-user/base-system/dhcp_configuration "docs:guide-user:base-system:dhcp_configuration")
* [DNS configuration](https://openwrt.org/docs/guide-user/base-system/dns_configuration "docs:guide-user:base-system:dns_configuration")
* [Dnsmasq DHCP server](https://openwrt.org/docs/guide-user/base-system/dhcp.dnsmasq "docs:guide-user:base-system:dhcp.dnsmasq")
* [Dropbear configuration](https://openwrt.org/docs/guide-user/base-system/dropbear "docs:guide-user:base-system:dropbear")
* [Hotplug](https://openwrt.org/docs/guide-user/base-system/hotplug "docs:guide-user:base-system:hotplug")
* [LED Configuration](https://openwrt.org/docs/guide-user/base-system/led_configuration "docs:guide-user:base-system:led_configuration")
* [Logging messages](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
* [Managing services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
* [Network basics](https://openwrt.org/docs/guide-user/base-system/basic-networking "docs:guide-user:base-system:basic-networking")
* [Persistent Ethernet Interface Naming by MAC Address](https://openwrt.org/docs/guide-user/base-system/persistent-ethernet-interface-naming-by-mac-address "docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address")
* [Scheduling tasks with cron](https://openwrt.org/docs/guide-user/base-system/cron "docs:guide-user:base-system:cron")
* [System configuration /etc/config/system](https://openwrt.org/docs/guide-user/base-system/system_configuration "docs:guide-user:base-system:system_configuration")
* [System configuration not handled by UCI](https://openwrt.org/docs/guide-user/base-system/notuci.config "docs:guide-user:base-system:notuci.config")
* [The UCI system](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
* [User Configuration](https://openwrt.org/docs/guide-user/base-system/users "docs:guide-user:base-system:users")
* [Web Server Configuration](https://openwrt.org/docs/guide-user/base-system/httpd "docs:guide-user:base-system:httpd")
LuCI web interface
------------------
[](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-848850938 "Continue with the « docs » section at the top...")
[LuCI web interface](https://openwrt.org/docs/guide-user/luci/start "docs:guide-user:luci:start")
* [Accessing LuCI web interface securely](https://openwrt.org/docs/guide-user/luci/luci.secure "docs:guide-user:luci:luci.secure")
* [Dashboard](https://openwrt.org/docs/guide-user/luci/dashboard "docs:guide-user:luci:dashboard")
* [How to get rid of LuCI HTTPS certificate warnings](https://openwrt.org/docs/guide-user/luci/getting_rid_of_luci_https_certificate_warnings "docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings")
* [LuCI essentials](https://openwrt.org/docs/guide-user/luci/luci.essentials "docs:guide-user:luci:luci.essentials")
* [LuCI on lighttpd](https://openwrt.org/docs/guide-user/luci/luci.on.lighttpd "docs:guide-user:luci:luci.on.lighttpd")
* [LuCI themes](https://openwrt.org/docs/guide-user/luci/luci.themes "docs:guide-user:luci:luci.themes")
* [luci-app-statistics](https://openwrt.org/docs/guide-user/luci/luci_app_statistics "docs:guide-user:luci:luci_app_statistics")
* [Make luci-app-statistics graphs public](https://openwrt.org/docs/guide-user/luci/statistics.chart.public "docs:guide-user:luci:statistics.chart.public")
* [Static IP](https://openwrt.org/docs/guide-user/luci/static_ip "docs:guide-user:luci:static_ip")
* [Web interface overview](https://openwrt.org/docs/guide-user/luci/webinterface.overview "docs:guide-user:luci:webinterface.overview")
Network configuration
---------------------
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Network](https://openwrt.org/docs/guide-user/network/start "docs:guide-user:network:start")
* [Architecture](https://openwrt.org/docs/guide-user/network/architecture "docs:guide-user:network:architecture")
* [Bonding](https://openwrt.org/docs/guide-user/network/bonding "docs:guide-user:network:bonding")
* [DHCP client scripts](https://openwrt.org/docs/guide-user/network/protocol.dhcp "docs:guide-user:network:protocol.dhcp")
* [High availability](https://openwrt.org/docs/guide-user/network/high-availability "docs:guide-user:network:high-availability")
* [Integrating an OpenWrt network device in your network](https://openwrt.org/docs/guide-user/network/integrating-openwrt-introduction "docs:guide-user:network:integrating-openwrt-introduction")
* [IPv4/IPv6 transition technologies](https://openwrt.org/docs/guide-user/network/ipv6_ipv4_transitioning "docs:guide-user:network:ipv6_ipv4_transitioning")
* [MAP IPv4-over-IPv6 encapsulation](https://openwrt.org/docs/guide-user/network/map "docs:guide-user:network:map")
* [Multipath TCP and OpenWrt](https://openwrt.org/docs/guide-user/network/mptcp "docs:guide-user:network:mptcp")
* [Network configuration /etc/config/network](https://openwrt.org/docs/guide-user/network/network_configuration "docs:guide-user:network:network_configuration")
* [Network interface aliases](https://openwrt.org/docs/guide-user/network/network_interface_alias "docs:guide-user:network:network_interface_alias")
* [OpenWrt as client device](https://openwrt.org/docs/guide-user/network/openwrt_as_clientdevice "docs:guide-user:network:openwrt_as_clientdevice")
* [OpenWrt as router device](https://openwrt.org/docs/guide-user/network/openwrt_as_routerdevice "docs:guide-user:network:openwrt_as_routerdevice")
* [Particularities of Single-Port Devices](https://openwrt.org/docs/guide-user/network/singleportrouter "docs:guide-user:network:singleportrouter")
* [Routed Client](https://openwrt.org/docs/guide-user/network/routedclient "docs:guide-user:network:routedclient")
* [Router vs switch vs gateway and NAT](https://openwrt.org/docs/guide-user/network/switch_router_gateway_and_nat "docs:guide-user:network:switch_router_gateway_and_nat")
* [Static configuration](https://openwrt.org/docs/guide-user/network/protocol.static "docs:guide-user:network:protocol.static")
* [Tunneling interface protocols](https://openwrt.org/docs/guide-user/network/tunneling_interface_protocols "docs:guide-user:network:tunneling_interface_protocols")
* [UCI networking options cheatsheet](https://openwrt.org/docs/guide-user/network/ucicheatsheet "docs:guide-user:network:ucicheatsheet")
[#### architecture](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
* [Network Components](https://openwrt.org/docs/guide-user/network/architecture/components "docs:guide-user:network:architecture:components")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Converting to DSA](https://openwrt.org/docs/guide-user/network/dsa/converting-to-dsa "docs:guide-user:network:dsa:converting-to-dsa")
* [DSA Mini-Tutorial](https://openwrt.org/docs/guide-user/network/dsa/dsa-mini-tutorial "docs:guide-user:network:dsa:dsa-mini-tutorial")
* [Upgrading to OpenWrt 21.02.0](https://openwrt.org/docs/guide-user/network/dsa/upgrading-to-2102 "docs:guide-user:network:dsa:upgrading-to-2102")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[IPv4](https://openwrt.org/docs/guide-user/network/ipv4/start "docs:guide-user:network:ipv4:start")
* [IPv4 configuration](https://openwrt.org/docs/guide-user/network/ipv4/configuration "docs:guide-user:network:ipv4:configuration")
* [IPv4 examples](https://openwrt.org/docs/guide-user/network/ipv4/examples "docs:guide-user:network:ipv4:examples")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[IPv6](https://openwrt.org/docs/guide-user/network/ipv6/start "docs:guide-user:network:ipv6:start")
* [How to use OpenWrt behind a Freebox Crystal with IPv6 bridge](https://openwrt.org/docs/guide-user/network/ipv6/freeboxcrystal "docs:guide-user:network:ipv6:freeboxcrystal")
* [How to use OpenWrt behind a Freebox with IPv6 delegation](https://openwrt.org/docs/guide-user/network/ipv6/freebox "docs:guide-user:network:ipv6:freebox")
* [IPv6 configuration](https://openwrt.org/docs/guide-user/network/ipv6/configuration "docs:guide-user:network:ipv6:configuration")
* [IPv6 extras](https://openwrt.org/docs/guide-user/network/ipv6/ipv6_extras "docs:guide-user:network:ipv6:ipv6_extras")
* [IPv6 multicast](https://openwrt.org/docs/guide-user/network/ipv6/multicast "docs:guide-user:network:ipv6:multicast")
* [IPv6 on L2TP softwire](https://openwrt.org/docs/guide-user/network/ipv6/ipv6.softwire "docs:guide-user:network:ipv6:ipv6.softwire")
* [IPv6 troubleshooting](https://openwrt.org/docs/guide-user/network/ipv6/troubleshooting "docs:guide-user:network:ipv6:troubleshooting")
* [IPv6 with Hurricane Electric](https://openwrt.org/docs/guide-user/network/ipv6/ipv6_henet "docs:guide-user:network:ipv6:ipv6_henet")
* [IPv6 with Hurricane Electric using LuCI](https://openwrt.org/docs/guide-user/network/ipv6/ipv6tunnel-luci "docs:guide-user:network:ipv6:ipv6tunnel-luci")
* [NAT64 for a IPv6-only network (Jool / TAYGA)](https://openwrt.org/docs/guide-user/network/ipv6/nat64 "docs:guide-user:network:ipv6:nat64")
* [NAT66 and IPv6 masquerading](https://openwrt.org/docs/guide-user/network/ipv6/ipv6.nat6 "docs:guide-user:network:ipv6:ipv6.nat6")
* [WIDE-DHCPv6 client configuration](https://openwrt.org/docs/guide-user/network/ipv6/dhcp6c "docs:guide-user:network:ipv6:dhcp6c")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Routing](https://openwrt.org/docs/guide-user/network/routing/start "docs:guide-user:network:routing:start")
* [PBR (Policy-Based Routing)](https://openwrt.org/docs/guide-user/network/routing/pbr "docs:guide-user:network:routing:pbr")
* [PBR app](https://openwrt.org/docs/guide-user/network/routing/pbr_app "docs:guide-user:network:routing:pbr_app")
* [PBR with netifd](https://openwrt.org/docs/guide-user/network/routing/pbr_netifd "docs:guide-user:network:routing:pbr_netifd")
* [Routing basics](https://openwrt.org/docs/guide-user/network/routing/basics "docs:guide-user:network:routing:basics")
* [Routing rules](https://openwrt.org/docs/guide-user/network/routing/ip_rules "docs:guide-user:network:routing:ip_rules")
* [Static routes](https://openwrt.org/docs/guide-user/network/routing/routes_configuration "docs:guide-user:network:routing:routes_configuration")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Routing examples](https://openwrt.org/docs/guide-user/network/routing/examples/start "docs:guide-user:network:routing:examples:start")
* [Routing example: Bridged DMZ](https://openwrt.org/docs/guide-user/network/routing/examples/routing.example.1.bridged.dmz "docs:guide-user:network:routing:examples:routing.example.1.bridged.dmz")
* [Routing example: GRE](https://openwrt.org/docs/guide-user/network/routing/examples/routing_in_gre "docs:guide-user:network:routing:examples:routing_in_gre")
* [Routing example: IPv4](https://openwrt.org/docs/guide-user/network/routing/examples/routing_in_ipv4 "docs:guide-user:network:routing:examples:routing_in_ipv4")
* [Routing example: IPv6](https://openwrt.org/docs/guide-user/network/routing/examples/routing_with_ipv6 "docs:guide-user:network:routing:examples:routing_with_ipv6")
* [Routing example: OpenVPN](https://openwrt.org/docs/guide-user/network/routing/examples/routing_in_openvpn "docs:guide-user:network:routing:examples:routing_in_openvpn")
* [Routing example: PBR with iproute2](https://openwrt.org/docs/guide-user/network/routing/examples/pbr_iproute2 "docs:guide-user:network:routing:examples:pbr_iproute2")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Traffic shaping](https://openwrt.org/docs/guide-user/network/traffic-shaping/start "docs:guide-user:network:traffic-shaping:start")
* [Brain Fuck Scheduler](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_bfs "docs:guide-user:network:traffic-shaping:sch_bfs")
* [CHOKe](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_choke "docs:guide-user:network:traffic-shaping:sch_choke")
* [Class Based Queueing](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_cbq "docs:guide-user:network:traffic-shaping:sch_cbq")
* [CoDel](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_codel "docs:guide-user:network:traffic-shaping:sch_codel")
* [Deficit Round Robin](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_drr "docs:guide-user:network:traffic-shaping:sch_drr")
* [Example1: Traffic Prioritizing with PRIO](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.example1 "docs:guide-user:network:traffic-shaping:packet.scheduler.example1")
* [Example2: plain simple bandwidth/traffic sharing with HTB](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.example2 "docs:guide-user:network:traffic-shaping:packet.scheduler.example2")
* [Example3: traffic shaping and prioriziting for multiple users with HFSC](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.example3 "docs:guide-user:network:traffic-shaping:packet.scheduler.example3")
* [Example4: HFSC + FQ\_CODEL + FLOW classifier](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.example4 "docs:guide-user:network:traffic-shaping:packet.scheduler.example4")
* [Example5: Traffic Prioritizing with HTB and MAC filtering](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.example5 "docs:guide-user:network:traffic-shaping:packet.scheduler.example5")
* [Fair Queue CoDel](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_fq_codel "docs:guide-user:network:traffic-shaping:sch_fq_codel")
* [Hierarchical Fair Service Curve (HFSC)](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_hfsc "docs:guide-user:network:traffic-shaping:sch_hfsc")
* [Hierarchy Token Bucket](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_htb "docs:guide-user:network:traffic-shaping:sch_htb")
* [Linux Packet Scheduling](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler.theory "docs:guide-user:network:traffic-shaping:packet.scheduler.theory")
* [Netem (Network Emulator)](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_netem "docs:guide-user:network:traffic-shaping:sch_netem")
* [QoS (Network Traffic Control)](https://openwrt.org/docs/guide-user/network/traffic-shaping/packet.scheduler "docs:guide-user:network:traffic-shaping:packet.scheduler")
* [QoS configuration /etc/config/qos](https://openwrt.org/docs/guide-user/network/traffic-shaping/traffic_shaping "docs:guide-user:network:traffic-shaping:traffic_shaping")
* [Random Early Detection](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_red "docs:guide-user:network:traffic-shaping:sch_red")
* [SQM (Smart Queue Management)](https://openwrt.org/docs/guide-user/network/traffic-shaping/sqm "docs:guide-user:network:traffic-shaping:sqm")
* [SQM configuration /etc/config/sqm](https://openwrt.org/docs/guide-user/network/traffic-shaping/sqm_configuration "docs:guide-user:network:traffic-shaping:sqm_configuration")
* [SQM Details](https://openwrt.org/docs/guide-user/network/traffic-shaping/sqm-details "docs:guide-user:network:traffic-shaping:sqm-details")
* [Stochastic Fairness Queueing](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_sfq "docs:guide-user:network:traffic-shaping:sch_sfq")
* [Token Bucket Filter](https://openwrt.org/docs/guide-user/network/traffic-shaping/sch_tbf "docs:guide-user:network:traffic-shaping:sch_tbf")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[VLAN (Virtual LAN)](https://openwrt.org/docs/guide-user/network/vlan/start "docs:guide-user:network:vlan:start")
* [Extending the router ports with a managed switch with VLANs](https://openwrt.org/docs/guide-user/network/vlan/managed_switch "docs:guide-user:network:vlan:managed_switch")
* [Splitting VLANs](https://openwrt.org/docs/guide-user/network/vlan/creating_virtual_switches "docs:guide-user:network:vlan:creating_virtual_switches")
* [Switch documentation](https://openwrt.org/docs/guide-user/network/vlan/switch "docs:guide-user:network:vlan:switch")
* [VLAN](https://openwrt.org/docs/guide-user/network/vlan/switch_configuration "docs:guide-user:network:vlan:switch_configuration")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[WAN (Internet access)](https://openwrt.org/docs/guide-user/network/wan/start "docs:guide-user:network:wan:start")
* [Accessing the modem through the router](https://openwrt.org/docs/guide-user/network/wan/access.modem.through.nat "docs:guide-user:network:wan:access.modem.through.nat")
* [Bridge mode](https://openwrt.org/docs/guide-user/network/wan/bridge-mode "docs:guide-user:network:wan:bridge-mode")
* [Connect to ISP using L2TP with dual access](https://openwrt.org/docs/guide-user/network/wan/connect_by_l2tp "docs:guide-user:network:wan:connect_by_l2tp")
* [EasyCwmp (CPE WAN Management Protocol daemon)](https://openwrt.org/docs/guide-user/network/wan/easycwmp "docs:guide-user:network:wan:easycwmp")
* [How to configure Motorola cable modems (DOCSIS)](https://openwrt.org/docs/guide-user/network/wan/configurecablemodem "docs:guide-user:network:wan:configurecablemodem")
* [Internet connection](https://openwrt.org/docs/guide-user/network/wan/internet.connection "docs:guide-user:network:wan:internet.connection")
* [IPTV / UDP multicast](https://openwrt.org/docs/guide-user/network/wan/udp_multicast "docs:guide-user:network:wan:udp_multicast")
* [ISP Configurations](https://openwrt.org/docs/guide-user/network/wan/isp-configurations "docs:guide-user:network:wan:isp-configurations")
* [Poor Man's Bridge Mode](https://openwrt.org/docs/guide-user/network/wan/dmz-based-bridge-mode "docs:guide-user:network:wan:dmz-based-bridge-mode")
* [Scripts to get information from modems](https://openwrt.org/docs/guide-user/network/wan/ddns.ipscript "docs:guide-user:network:wan:ddns.ipscript")
* [Simple WAN Failover with 3G/LTE WWAN - Using a second router in the same LAN](https://openwrt.org/docs/guide-user/network/wan/simple_wan_failover "docs:guide-user:network:wan:simple_wan_failover")
* [Smartphone USB reverse tethering with OpenWrt](https://openwrt.org/docs/guide-user/network/wan/smartphone.usb.reverse.tethering "docs:guide-user:network:wan:smartphone.usb.reverse.tethering")
* [Smartphone USB tethering](https://openwrt.org/docs/guide-user/network/wan/smartphone.usb.tethering "docs:guide-user:network:wan:smartphone.usb.tethering")
* [TR-069 / CWMP](https://openwrt.org/docs/guide-user/network/wan/tr-069 "docs:guide-user:network:wan:tr-069")
* [Using multiple WAN IPs](https://openwrt.org/docs/guide-user/network/wan/multiple_public_ips "docs:guide-user:network:wan:multiple_public_ips")
* [Using multiple wan with multiple routers](https://openwrt.org/docs/guide-user/network/wan/multiple_wan_multiple_routers "docs:guide-user:network:wan:multiple_wan_multiple_routers")
* [WAN interface protocols](https://openwrt.org/docs/guide-user/network/wan/wan_interface_protocols "docs:guide-user:network:wan:wan_interface_protocols")
* [X Play](https://openwrt.org/docs/guide-user/network/wan/x.play "docs:guide-user:network:wan:x.play")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Multi-WAN (Internet access through more than one modem/device)](https://openwrt.org/docs/guide-user/network/wan/multiwan/start "docs:guide-user:network:wan:multiwan:start")
* [Creating additional WAN interfaces for multi-WAN](https://openwrt.org/docs/guide-user/network/wan/multiwan/creating-additional-wan-interfaces "docs:guide-user:network:wan:multiwan:creating-additional-wan-interfaces")
* [Multiwan (no longer supported)](https://openwrt.org/docs/guide-user/network/wan/multiwan/multiwan_package "docs:guide-user:network:wan:multiwan:multiwan_package")
* [multiwan: Connection to spare internet provider](https://openwrt.org/docs/guide-user/network/wan/multiwan/failower "docs:guide-user:network:wan:multiwan:failower")
* [MWAN with netifd](https://openwrt.org/docs/guide-user/network/wan/multiwan/mwan_netifd "docs:guide-user:network:wan:multiwan:mwan_netifd")
* [mwan3 (iptables)](https://openwrt.org/docs/guide-user/network/wan/multiwan/mwan3 "docs:guide-user:network:wan:multiwan:mwan3")
* [mwan3 (nftables)](https://openwrt.org/docs/guide-user/network/wan/multiwan/mwan3-nft "docs:guide-user:network:wan:multiwan:mwan3-nft")
* [mwan3 install using filesystem (not luci)](https://openwrt.org/docs/guide-user/network/wan/multiwan/mwan3_install_without_luci "docs:guide-user:network:wan:multiwan:mwan3_install_without_luci")
* [mwan4](https://openwrt.org/docs/guide-user/network/wan/multiwan/mwan4 "docs:guide-user:network:wan:multiwan:mwan4")
* [Preparing and verifying the default routing table for any WAN interface for multi-WAN](https://openwrt.org/docs/guide-user/network/wan/multiwan/preparing-wan-interfaces-for-multi-wan "docs:guide-user:network:wan:multiwan:preparing-wan-interfaces-for-multi-wan")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[WWAN (3G/4G/5G and similar)](https://openwrt.org/docs/guide-user/network/wan/wwan/start "docs:guide-user:network:wan:wwan:start")
* [Dealing with monthly GB quotas](https://openwrt.org/docs/guide-user/network/wan/wwan/bandwith_caps_gb_quota "docs:guide-user:network:wan:wwan:bandwith_caps_gb_quota")
* [How to send AT commands to device](https://openwrt.org/docs/guide-user/network/wan/wwan/at_commands "docs:guide-user:network:wan:wwan:at_commands")
* [ModemManager](https://openwrt.org/docs/guide-user/network/wan/wwan/modemmanager "docs:guide-user:network:wan:wwan:modemmanager")
* [USB mode switch](https://openwrt.org/docs/guide-user/network/wan/wwan/usb-modeswitching "docs:guide-user:network:wan:wwan:usb-modeswitching")
* [Use RNDIS USB Dongle for WAN connection](https://openwrt.org/docs/guide-user/network/wan/wwan/ethernetoverusb_rndis "docs:guide-user:network:wan:wwan:ethernetoverusb_rndis")
* [Use USB CDC-ECM capable dongles for WWAN connection](https://openwrt.org/docs/guide-user/network/wan/wwan/ethernetoverusb_cdc "docs:guide-user:network:wan:wwan:ethernetoverusb_cdc")
* [Use USB CDC-NCM capable dongles for WWAN connection](https://openwrt.org/docs/guide-user/network/wan/wwan/ethernetoverusb_ncm "docs:guide-user:network:wan:wwan:ethernetoverusb_ncm")
* [Use USB QMI or CDC-MBIM capable dongles for WWAN connection](https://openwrt.org/docs/guide-user/network/wan/wwan/ltedongle "docs:guide-user:network:wan:wwan:ltedongle")
* [Use USB serial modem dongles for WWAN connection](https://openwrt.org/docs/guide-user/network/wan/wwan/3gdongle "docs:guide-user:network:wan:wwan:3gdongle")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Wi-Fi configuration](https://openwrt.org/docs/guide-user/network/wifi/start "docs:guide-user:network:wifi:start")
* [Bridged AP](https://openwrt.org/docs/guide-user/network/wifi/bridgedap "docs:guide-user:network:wifi:bridgedap")
* [Configure A(ccess) P(oint or 'hotspot') + STA(tion or 'client')](https://openwrt.org/docs/guide-user/network/wifi/ap_sta "docs:guide-user:network:wifi:ap_sta")
* [Configure Wi-Fi encryption](https://openwrt.org/docs/guide-user/network/wifi/encryption "docs:guide-user:network:wifi:encryption")
* [Connect to client Wi-Fi network](https://openwrt.org/docs/guide-user/network/wifi/connect_client_wifi "docs:guide-user:network:wifi:connect_client_wifi")
* [Country code for Wi-Fi operation](https://openwrt.org/docs/guide-user/network/wifi/wifi_countrycode "docs:guide-user:network:wifi:wifi_countrycode")
* [Exceeding transmit power limits](https://openwrt.org/docs/guide-user/network/wifi/transmit.power.limits "docs:guide-user:network:wifi:transmit.power.limits")
* [FreeRADIUS](https://openwrt.org/docs/guide-user/network/wifi/freeradius "docs:guide-user:network:wifi:freeradius")
* [Identify Wi-Fi connection as metered on Android automatically](https://openwrt.org/docs/guide-user/network/wifi/android-meteredconnection "docs:guide-user:network:wifi:android-meteredconnection")
* [Identify Wi-Fi connection as metered on Linux automatically](https://openwrt.org/docs/guide-user/network/wifi/linux-meteredconnection "docs:guide-user:network:wifi:linux-meteredconnection")
* [Identify Wi-Fi connection as metered on Windows automatically](https://openwrt.org/docs/guide-user/network/wifi/ms-meteredconnection "docs:guide-user:network:wifi:ms-meteredconnection")
* [Introduction to 802.1X](https://openwrt.org/docs/guide-user/network/wifi/wireless.security.8021x "docs:guide-user:network:wifi:wireless.security.8021x")
* [Opportunistic Wireless Encryption (OWE) and OWE Transition Mode](https://openwrt.org/docs/guide-user/network/wifi/owe_encryption "docs:guide-user:network:wifi:owe_encryption")
* [Routed AP](https://openwrt.org/docs/guide-user/network/wifi/routedap "docs:guide-user:network:wifi:routedap")
* [RSN preauthentication](https://openwrt.org/docs/guide-user/network/wifi/rsn_preauthentication "docs:guide-user:network:wifi:rsn_preauthentication")
* [Setting up DAWN and band-steering](https://openwrt.org/docs/guide-user/network/wifi/dawn "docs:guide-user:network:wifi:dawn")
* [Setting up usteer and band-steering](https://openwrt.org/docs/guide-user/network/wifi/usteer "docs:guide-user:network:wifi:usteer")
* [Setting up Wi-Fi repeaters with multiple SSIDs with separated private, tor and guest network](https://openwrt.org/docs/guide-user/network/wifi/vlan-multiple-wifi-ssid-repeater "docs:guide-user:network:wifi:vlan-multiple-wifi-ssid-repeater")
* [Table of capabilities for wireless chipsets](https://openwrt.org/docs/guide-user/network/wifi/chipset.capabilities "docs:guide-user:network:wifi:chipset.capabilities")
* [USB 3.0 and Wi-Fi problems](https://openwrt.org/docs/guide-user/network/wifi/usb3.0-wifi-issues "docs:guide-user:network:wifi:usb3.0-wifi-issues")
* [Wi-Fi /etc/config/wireless](https://openwrt.org/docs/guide-user/network/wifi/basic "docs:guide-user:network:wifi:basic")
* [Wi-Fi Extender/Repeater with relayd](https://openwrt.org/docs/guide-user/network/wifi/relay_configuration "docs:guide-user:network:wifi:relay_configuration")
* [Wi-Fi on/off buttons](https://openwrt.org/docs/guide-user/network/wifi/wifi_toggle "docs:guide-user:network:wifi:wifi_toggle")
* [Wi-Fi toggle](https://openwrt.org/docs/guide-user/network/wifi/wifitoggle "docs:guide-user:network:wifi:wifitoggle")
* [Wide area Wi-Fi coverage](https://openwrt.org/docs/guide-user/network/wifi/wide.area.wifi "docs:guide-user:network:wifi:wide.area.wifi")
* [Wifi Roaming](https://openwrt.org/docs/guide-user/network/wifi/roaming "docs:guide-user:network:wifi:roaming")
* [Wireless Access Point (aka "Dumb" Access Point)](https://openwrt.org/docs/guide-user/network/wifi/dumbap "docs:guide-user:network:wifi:dumbap")
* [Wireless Ethernet Dispatch (WED)](https://openwrt.org/docs/guide-user/network/wifi/wed "docs:guide-user:network:wifi:wed")
* [Wireless overview](https://openwrt.org/docs/guide-user/network/wifi/wireless.overview "docs:guide-user:network:wifi:wireless.overview")
* [Wireless Repeater/Extender with WDS](https://openwrt.org/docs/guide-user/network/wifi/atheroswds "docs:guide-user:network:wifi:atheroswds")
* [wpa\_supplicant](https://openwrt.org/docs/guide-user/network/wifi/wireless.utilities.wpa-supplicant "docs:guide-user:network:wifi:wireless.utilities.wpa-supplicant")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Guest Wi-Fi](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/start "docs:guide-user:network:wifi:guestwifi:start")
* [Guest Wi-Fi basics](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/guest-wlan "docs:guide-user:network:wifi:guestwifi:guest-wlan")
* [Guest Wi-Fi extras](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/extras "docs:guide-user:network:wifi:guestwifi:extras")
* [Guest Wi-Fi on a dumb wireless AP using LuCI](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/guestwifi_dumbap "docs:guide-user:network:wifi:guestwifi:guestwifi_dumbap")
* [Guest Wi-Fi using CLI](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/configuration_command_line_interface "docs:guide-user:network:wifi:guestwifi:configuration_command_line_interface")
* [Guest Wi-Fi using LuCI](https://openwrt.org/docs/guide-user/network/wifi/guestwifi/configuration_webinterface "docs:guide-user:network:wifi:guestwifi:configuration_webinterface")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Mesh Wi-Fi](https://openwrt.org/docs/guide-user/network/wifi/mesh/start "docs:guide-user:network:wifi:mesh:start")
* [802.11s - The Mesh11sd Project](https://openwrt.org/docs/guide-user/network/wifi/mesh/mesh11sd "docs:guide-user:network:wifi:mesh:mesh11sd")
* [802.11s Rapid Deployment](https://openwrt.org/docs/guide-user/network/wifi/mesh/rapiddeployment "docs:guide-user:network:wifi:mesh:rapiddeployment")
* [802.11s Wireless Mesh Networking](https://openwrt.org/docs/guide-user/network/wifi/mesh/802-11s "docs:guide-user:network:wifi:mesh:802-11s")
* [B.A.T.M.A.N. / batman-adv](https://openwrt.org/docs/guide-user/network/wifi/mesh/batman "docs:guide-user:network:wifi:mesh:batman")
* [IEEE 802.11s Wireless Mesh Networking](https://openwrt.org/docs/guide-user/network/wifi/mesh/80211s "docs:guide-user:network:wifi:mesh:80211s")
* [OLSR Mesh](https://openwrt.org/docs/guide-user/network/wifi/mesh/olsr "docs:guide-user:network:wifi:mesh:olsr")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Wi-Fi Extenders/Repeaters](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/start "docs:guide-user:network:wifi:wifiextenders:start")
* [Extenders/Repeaters - an Overview](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/overview "docs:guide-user:network:wifi:wifiextenders:overview")
* [Multiple Wi-Fi Extender/Repeaters over 802.11s Mesh](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/mesh "docs:guide-user:network:wifi:wifiextenders:mesh")
* [Travelmate, a connection manager for travel routers](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/travelmate "docs:guide-user:network:wifi:wifiextenders:travelmate")
* [Wi-Fi Extender/Repeater with Bridged AP](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/bridgedap "docs:guide-user:network:wifi:wifiextenders:bridgedap")
* [Wi-Fi Extender/Repeater with RelayD](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/relay_configuration "docs:guide-user:network:wifi:wifiextenders:relay_configuration")
* [Wi-Fi Extender/Repeater with WDS](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/wds "docs:guide-user:network:wifi:wifiextenders:wds")
* [Wi-Fi Repeater using AP+STA mode](https://openwrt.org/docs/guide-user/network/wifi/wifiextenders/ap_sta "docs:guide-user:network:wifi:wifiextenders:ap_sta")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Wi-Fi network tools](https://openwrt.org/docs/guide-user/network/wifi/wireless-tool/start "docs:guide-user:network:wifi:wireless-tool:start")
* [Aircrack](https://openwrt.org/docs/guide-user/network/wifi/wireless-tool/aircrack-ng "docs:guide-user:network:wifi:wireless-tool:aircrack-ng")
* [Horst](https://openwrt.org/docs/guide-user/network/wifi/wireless-tool/horst "docs:guide-user:network:wifi:wireless-tool:horst")
* [Kismet](https://openwrt.org/docs/guide-user/network/wifi/wireless-tool/kismet "docs:guide-user:network:wifi:wireless-tool:kismet")
* [Wireless Utilities](https://openwrt.org/docs/guide-user/network/wifi/wireless-tool/wireless.utilities "docs:guide-user:network:wifi:wireless-tool:wireless.utilities")
[](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1802861049 "Continue with the « docs » section at the top...")
[Zero configuration network setup](https://openwrt.org/docs/guide-user/network/zeroconfig/start "docs:guide-user:network:zeroconfig:start")
* [The Homenet Control Protocol (HNCP)](https://openwrt.org/docs/guide-user/network/zeroconfig/hncp_configuration "docs:guide-user:network:zeroconfig:hncp_configuration")
* [Zero configuration networking in OpenWrt](https://openwrt.org/docs/guide-user/network/zeroconfig/zeroconf "docs:guide-user:network:zeroconfig:zeroconf")
Firewall configuration
----------------------
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[Firewall configuration](https://openwrt.org/docs/guide-user/firewall/start "docs:guide-user:firewall:start")
* [Firewall and network interfaces](https://openwrt.org/docs/guide-user/firewall/fw3_network "docs:guide-user:firewall:fw3_network")
* [Firewall components](https://openwrt.org/docs/guide-user/firewall/firewall_components "docs:guide-user:firewall:firewall_components")
* [Firewall configuration /etc/config/firewall](https://openwrt.org/docs/guide-user/firewall/firewall_configuration "docs:guide-user:firewall:firewall_configuration")
* [Firewall overview](https://openwrt.org/docs/guide-user/firewall/overview "docs:guide-user:firewall:overview")
* [fw4 Filtering traffic with IP sets by DNS](https://openwrt.org/docs/guide-user/firewall/filtering_traffic_at_ip_addresses_by_dns "docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[Firewall configuration](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/start "docs:guide-user:firewall:fw3_configurations:start")
* [Bridge firewall](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/bridge "docs:guide-user:firewall:fw3_configurations:bridge")
* [DMZ configuration using VLANs](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_dmz "docs:guide-user:firewall:fw3_configurations:fw3_dmz")
* [DNS hijacking](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/intercept_dns "docs:guide-user:firewall:fw3_configurations:intercept_dns")
* [Filtering traffic with IP sets by DNS](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/dns_ipset "docs:guide-user:firewall:fw3_configurations:dns_ipset")
* [Firewall usage guide](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_guide "docs:guide-user:firewall:fw3_configurations:fw3_config_guide")
* [IP set examples](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_ipset "docs:guide-user:firewall:fw3_configurations:fw3_config_ipset")
* [IPv4 firewall examples](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_examples "docs:guide-user:firewall:fw3_configurations:fw3_config_examples")
* [IPv6 firewall examples](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_ipv6_examples "docs:guide-user:firewall:fw3_configurations:fw3_ipv6_examples")
* [Logging rejected packets](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_traffic_logging "docs:guide-user:firewall:fw3_configurations:fw3_traffic_logging")
* [NAT examples](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_nat "docs:guide-user:firewall:fw3_configurations:fw3_nat")
* [Parental controls](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_parent_controls "docs:guide-user:firewall:fw3_configurations:fw3_parent_controls")
* [Port forwarding](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/port_forwarding "docs:guide-user:firewall:fw3_configurations:port_forwarding")
* [Reference network topology](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_ref_topo "docs:guide-user:firewall:fw3_configurations:fw3_ref_topo")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[Firewall miscellaneous pages](https://openwrt.org/docs/guide-user/firewall/misc/start "docs:guide-user:firewall:misc:start")
* [How to capture, filter and inspect packets using tcpdump or wireshark tools](https://openwrt.org/docs/guide-user/firewall/misc/tcpdump_wireshark "docs:guide-user:firewall:misc:tcpdump_wireshark")
* [nftables](https://openwrt.org/docs/guide-user/firewall/misc/nftables "docs:guide-user:firewall:misc:nftables")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[netfilter and iptables](https://openwrt.org/docs/guide-user/firewall/netfilter_iptables/start "docs:guide-user:firewall:netfilter_iptables:start")
* [Logging Forwarded Packets in OpenWrt](https://openwrt.org/docs/guide-user/firewall/netfilter_iptables/iptables_log_targets "docs:guide-user:firewall:netfilter_iptables:iptables_log_targets")
* [netfilter Configuration Examples](https://openwrt.org/docs/guide-user/firewall/netfilter_iptables/netfilter_examples "docs:guide-user:firewall:netfilter_iptables:netfilter_examples")
* [Netfilter In OpenWrt](https://openwrt.org/docs/guide-user/firewall/netfilter_iptables/netfilter_openwrt "docs:guide-user:firewall:netfilter_iptables:netfilter_openwrt")
* [Netfilter Management](https://openwrt.org/docs/guide-user/firewall/netfilter_iptables/netfilter_management "docs:guide-user:firewall:netfilter_iptables:netfilter_management")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[Alternate firewall builders](https://openwrt.org/docs/guide-user/firewall/other_firewall_rules_builders/start "docs:guide-user:firewall:other_firewall_rules_builders:start")
* [Firewall Builder: Essence Reloaded](https://openwrt.org/docs/guide-user/firewall/other_firewall_rules_builders/essence "docs:guide-user:firewall:other_firewall_rules_builders:essence")
* [Firewall Builder: fwBuilder GUI](https://openwrt.org/docs/guide-user/firewall/other_firewall_rules_builders/fwbuilder "docs:guide-user:firewall:other_firewall_rules_builders:fwbuilder")
* [Firewall Builder: Shell scripts](https://openwrt.org/docs/guide-user/firewall/other_firewall_rules_builders/fw_shell_scripts "docs:guide-user:firewall:other_firewall_rules_builders:fw_shell_scripts")
* [Firewall Builder: Shorewall-lite](https://openwrt.org/docs/guide-user/firewall/other_firewall_rules_builders/shorewall "docs:guide-user:firewall:other_firewall_rules_builders:shorewall")
[](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-981396032 "Continue with the « docs » section at the top...")
[UPnP IGD & PCP/NAT-PMP](https://openwrt.org/docs/guide-user/firewall/upnp/start "docs:guide-user:firewall:upnp:start")
* [UPnP IGD & PCP/NAT-PMP on OpenWrt](https://openwrt.org/docs/guide-user/firewall/upnp/upnp_setup "docs:guide-user:firewall:upnp:upnp_setup")
* [upnpd](https://openwrt.org/docs/guide-user/firewall/upnp/miniupnpd "docs:guide-user:firewall:upnp:miniupnpd")
Advanced configuration
----------------------
[](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1521731081 "Continue with the « docs » section at the top...")
[Advanced configuration](https://openwrt.org/docs/guide-user/advanced/start "docs:guide-user:advanced:start")
* [Auto Wake On LAN script for hosts](https://openwrt.org/docs/guide-user/advanced/auto_wake_on_lan "docs:guide-user:advanced:auto_wake_on_lan")
* [Configuring kexec](https://openwrt.org/docs/guide-user/advanced/kexec "docs:guide-user:advanced:kexec")
* [Connect an Arduino to OpenWrt](https://openwrt.org/docs/guide-user/advanced/arduino "docs:guide-user:advanced:arduino")
* [Expanding root partition and filesystem](https://openwrt.org/docs/guide-user/advanced/expand_root "docs:guide-user:advanced:expand_root")
* [Hotplug extras](https://openwrt.org/docs/guide-user/advanced/hotplug_extras "docs:guide-user:advanced:hotplug_extras")
* [How to Load Balance OpenWrt](https://openwrt.org/docs/guide-user/advanced/load_balancing_-_tuning_smp_irq "docs:guide-user:advanced:load_balancing_-_tuning_smp_irq")
* [IP set extras](https://openwrt.org/docs/guide-user/advanced/ipset_extras "docs:guide-user:advanced:ipset_extras")
* [NTP](https://openwrt.org/docs/guide-user/advanced/ntp_configuration "docs:guide-user:advanced:ntp_configuration")
* [Opkg extras](https://openwrt.org/docs/guide-user/advanced/opkg_extras "docs:guide-user:advanced:opkg_extras")
* [PBR extras](https://openwrt.org/docs/guide-user/advanced/pbr_extras "docs:guide-user:advanced:pbr_extras")
* [SDR](https://openwrt.org/docs/guide-user/advanced/sdr "docs:guide-user:advanced:sdr")
* [Send SMS from Shell](https://openwrt.org/docs/guide-user/advanced/sms-from-shell "docs:guide-user:advanced:sms-from-shell")
* [Send SMS or Email using 3G/GSM modem](https://openwrt.org/docs/guide-user/advanced/howto.send.sms "docs:guide-user:advanced:howto.send.sms")
* [Sharing raw NMEA GPS data over the network with multiple clients](https://openwrt.org/docs/guide-user/advanced/networked.gps "docs:guide-user:advanced:networked.gps")
* [Smartphone USB tethering](https://openwrt.org/docs/guide-user/advanced/smartphone-usb-tether "docs:guide-user:advanced:smartphone-usb-tether")
* [Snippets](https://openwrt.org/docs/guide-user/advanced/snippets "docs:guide-user:advanced:snippets")
* [Steam Caching using Nginx](https://openwrt.org/docs/guide-user/advanced/cache.steam "docs:guide-user:advanced:cache.steam")
* [Sysupgrade extras](https://openwrt.org/docs/guide-user/advanced/sysupgrade_extras "docs:guide-user:advanced:sysupgrade_extras")
* [UCI extras](https://openwrt.org/docs/guide-user/advanced/uci_extras "docs:guide-user:advanced:uci_extras")
* [Watchcat - network watchdog utility](https://openwrt.org/docs/guide-user/advanced/watchcat "docs:guide-user:advanced:watchcat")
Installing additional software
------------------------------
[](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-2078512789 "Continue with the « docs » section at the top...")
[Installing additional software](https://openwrt.org/docs/guide-user/additional-software/start "docs:guide-user:additional-software:start")
* [apk package manager](https://openwrt.org/docs/guide-user/additional-software/apk "docs:guide-user:additional-software:apk")
* [Create new users and groups for applications or system services](https://openwrt.org/docs/guide-user/additional-software/create-new-users "docs:guide-user:additional-software:create-new-users")
* [Extroot configuration](https://openwrt.org/docs/guide-user/additional-software/extroot_configuration "docs:guide-user:additional-software:extroot_configuration")
* [Managing packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
* [Opkg package manager](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
* [opkg to apk cheat sheet](https://openwrt.org/docs/guide-user/additional-software/opkg-to-apk-cheatsheet "docs:guide-user:additional-software:opkg-to-apk-cheatsheet")
* [Saving firmware space and RAM](https://openwrt.org/docs/guide-user/additional-software/saving_space "docs:guide-user:additional-software:saving_space")
* [Show available package upgrades after SSH login](https://openwrt.org/docs/guide-user/additional-software/show_upgradable_packages_after_ssh_login "docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login")
* [Smartmontools](https://openwrt.org/docs/guide-user/additional-software/smartmontools "docs:guide-user:additional-software:smartmontools")
* [Using the Image Builder](https://openwrt.org/docs/guide-user/additional-software/imagebuilder "docs:guide-user:additional-software:imagebuilder")
Hardware-specific configuration
-------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Hardware features and modifications](https://openwrt.org/docs/guide-user/hardware/start "docs:guide-user:hardware:start")
* [Add a buzzer (beeper) to the router](https://openwrt.org/docs/guide-user/hardware/buzzer-mod "docs:guide-user:hardware:buzzer-mod")
* [Attach functions to a push button](https://openwrt.org/docs/guide-user/hardware/hardware.button "docs:guide-user:hardware:hardware.button")
* [Change UART serial port speed (baud rate) on OpenWrt](https://openwrt.org/docs/guide-user/hardware/serialbaudratespeed "docs:guide-user:hardware:serialbaudratespeed")
* [Debrick ath79 using JTAG](https://openwrt.org/docs/guide-user/hardware/debrick.ath79.using.jtag "docs:guide-user:hardware:debrick.ath79.using.jtag")
* [Devolo Streaming Radio](https://openwrt.org/docs/guide-user/hardware/devolo-stream-radio "docs:guide-user:hardware:devolo-stream-radio")
* [ESP8266 serial bridge](https://openwrt.org/docs/guide-user/hardware/esp8266-serial-bridge "docs:guide-user:hardware:esp8266-serial-bridge")
* [Gigabit Passive Optical Network (GPON) support](https://openwrt.org/docs/guide-user/hardware/gpon "docs:guide-user:hardware:gpon")
* [Hardware watchdog](https://openwrt.org/docs/guide-user/hardware/watchdog "docs:guide-user:hardware:watchdog")
* [How to turnoff JTAG to free GPIO (only on ath79 processors)](https://openwrt.org/docs/guide-user/hardware/turnoff.jtag.to.gpio "docs:guide-user:hardware:turnoff.jtag.to.gpio")
* [How to turnoff UART to free GPIO (only on ath79 processors)](https://openwrt.org/docs/guide-user/hardware/turnoff.uart.to.gpio "docs:guide-user:hardware:turnoff.uart.to.gpio")
* [How to use I²C over USB](https://openwrt.org/docs/guide-user/hardware/usb.i2c-tiny-usb "docs:guide-user:hardware:usb.i2c-tiny-usb")
* [LIRC audio\_alsa](https://openwrt.org/docs/guide-user/hardware/lirc-audio_alsa "docs:guide-user:hardware:lirc-audio_alsa")
* [LIRC GPIO blaster](https://openwrt.org/docs/guide-user/hardware/lirc-gpioblaster "docs:guide-user:hardware:lirc-gpioblaster")
* [LIRC GPIO receiver / blaster](https://openwrt.org/docs/guide-user/hardware/lirc "docs:guide-user:hardware:lirc")
* [MMC/SD card over GPIO howto](https://openwrt.org/docs/guide-user/hardware/mmc_over_gpio "docs:guide-user:hardware:mmc_over_gpio")
* [PirateBox & LibraryBox](https://openwrt.org/docs/guide-user/hardware/piratebox.librarybox.openwrt.routers "docs:guide-user:hardware:piratebox.librarybox.openwrt.routers")
* [PWM emulation with GPIO](https://openwrt.org/docs/guide-user/hardware/pwm "docs:guide-user:hardware:pwm")
* [SIP daemon for Lantiq devices with owsip](https://openwrt.org/docs/guide-user/hardware/owsip "docs:guide-user:hardware:owsip")
* [Terminate UART Console](https://openwrt.org/docs/guide-user/hardware/terminate.console.on.serial "docs:guide-user:hardware:terminate.console.on.serial")
* [Turning USB power on and off](https://openwrt.org/docs/guide-user/hardware/usb.overview "docs:guide-user:hardware:usb.overview")
* [USB Guest configuration](https://openwrt.org/docs/guide-user/hardware/usb_gadget "docs:guide-user:hardware:usb_gadget")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Audio support](https://openwrt.org/docs/guide-user/hardware/audio/start "docs:guide-user:hardware:audio:start")
* [PulseAudio](https://openwrt.org/docs/guide-user/hardware/audio/pulseaudio "docs:guide-user:hardware:audio:pulseaudio")
* [USB audio support](https://openwrt.org/docs/guide-user/hardware/audio/usb.audio "docs:guide-user:hardware:audio:usb.audio")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Bluetooth in OpenWrt](https://openwrt.org/docs/guide-user/hardware/bluetooth/start "docs:guide-user:hardware:bluetooth:start")
* [Bluetooth Audio](https://openwrt.org/docs/guide-user/hardware/bluetooth/bluetooth.audio "docs:guide-user:hardware:bluetooth:bluetooth.audio")
* [Bluetooth presence detection](https://openwrt.org/docs/guide-user/hardware/bluetooth/bluetooth_presence_detection "docs:guide-user:hardware:bluetooth:bluetooth_presence_detection")
* [Bluetooth Speakers/Headphones](https://openwrt.org/docs/guide-user/hardware/bluetooth/bluetooth.speakers "docs:guide-user:hardware:bluetooth:bluetooth.speakers")
* [IPv6 over Bluetooth Smart (Low Energy)](https://openwrt.org/docs/guide-user/hardware/bluetooth/bluetooth.6lowpan "docs:guide-user:hardware:bluetooth:bluetooth.6lowpan")
* [Smartphone Bluetooth Tethering](https://openwrt.org/docs/guide-user/hardware/bluetooth/bluetooth.tether "docs:guide-user:hardware:bluetooth:bluetooth.tether")
* [USB Bluetooth support](https://openwrt.org/docs/guide-user/hardware/bluetooth/usb.bluetooth "docs:guide-user:hardware:bluetooth:usb.bluetooth")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Gigabit Passive Optical Network (GPON) support](https://openwrt.org/docs/guide-user/hardware/gpon/start "docs:guide-user:hardware:gpon:start")
* [Luleey (Vendor)](https://openwrt.org/docs/guide-user/hardware/gpon/luleey "docs:guide-user:hardware:gpon:luleey")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[LED manipulation and setup](https://openwrt.org/docs/guide-user/hardware/led/start "docs:guide-user:hardware:led:start")
* [Signal strength LED meter](https://openwrt.org/docs/guide-user/hardware/led/wifi.meter "docs:guide-user:hardware:led:wifi.meter")
* [Use LEDs to show signal strength with rssileds](https://openwrt.org/docs/guide-user/hardware/led/generic.rssileds "docs:guide-user:hardware:led:generic.rssileds")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « docs » section at the top...")
[Video support](https://openwrt.org/docs/guide-user/hardware/video/start "docs:guide-user:hardware:video:start")
* [USB Video Support](https://openwrt.org/docs/guide-user/hardware/video/usb.video "docs:guide-user:hardware:video:usb.video")
[](https://openwrt.org/docs/guide-user/start#top-1046656114 "Continue with the « » section at the top...")
##### ...
* [Webcam with the Linux UVC driver](https://openwrt.org/docs/guide-user/hardware/video/webcam "docs:guide-user:hardware:video:webcam")
Storage devices
---------------
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « docs » section at the top...")
[Storage functions](https://openwrt.org/docs/guide-user/storage/start "docs:guide-user:storage:start")
* [Disk Encryption](https://openwrt.org/docs/guide-user/storage/disk.encryption "docs:guide-user:storage:disk.encryption")
* [Filesystems](https://openwrt.org/docs/guide-user/storage/filesystems-and-partitions "docs:guide-user:storage:filesystems-and-partitions")
* [Fstab Configuration](https://openwrt.org/docs/guide-user/storage/fstab "docs:guide-user:storage:fstab")
* [hd-idle Configuration](https://openwrt.org/docs/guide-user/storage/hd-idle "docs:guide-user:storage:hd-idle")
* [Installing and troubleshooting USB Drivers](https://openwrt.org/docs/guide-user/storage/usb-installing "docs:guide-user:storage:usb-installing")
* [mountd Configuration](https://openwrt.org/docs/guide-user/storage/mountd "docs:guide-user:storage:mountd")
* [Using storage devices](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
[](https://openwrt.org/docs/guide-user/start#top-1053712197 "Continue with the « » section at the top...")
#### ...
* [Writable NTFS](https://openwrt.org/docs/guide-user/storage/writable_ntfs "docs:guide-user:storage:writable_ntfs")
Additional services
-------------------
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
* [Ad blocking](https://openwrt.org/docs/guide-user/services/ad-blocking "docs:guide-user:services:ad-blocking")
* [AOE ((s)ATA over Ethernet) with vblade](https://openwrt.org/docs/guide-user/services/vblade "docs:guide-user:services:vblade")
* [Babel routing protocol (babeld)](https://openwrt.org/docs/guide-user/services/babeld "docs:guide-user:services:babeld")
* [banIP](https://openwrt.org/docs/guide-user/services/banip "docs:guide-user:services:banip")
* [CHROOT](https://openwrt.org/docs/guide-user/services/chroot "docs:guide-user:services:chroot")
* [CrowdSec](https://openwrt.org/docs/guide-user/services/crowdsec "docs:guide-user:services:crowdsec")
* [geoip-shell](https://openwrt.org/docs/guide-user/services/geoip-shell "docs:guide-user:services:geoip-shell")
* [Gitolite user-restricted git hosting](https://openwrt.org/docs/guide-user/services/gitolite "docs:guide-user:services:gitolite")
* [Honeypots](https://openwrt.org/docs/guide-user/services/honeypots "docs:guide-user:services:honeypots")
* [Irqbalance](https://openwrt.org/docs/guide-user/services/irqbalance "docs:guide-user:services:irqbalance")
* [Kerberos Server HowTo](https://openwrt.org/docs/guide-user/services/kerberos "docs:guide-user:services:kerberos")
* [Prosody XMPP Server (open messaging protocol)](https://openwrt.org/docs/guide-user/services/xmpp.server "docs:guide-user:services:xmpp.server")
* [PXE-Boot network boot server](https://openwrt.org/docs/guide-user/services/tftp.pxe-server "docs:guide-user:services:tftp.pxe-server")
* [Python](https://openwrt.org/docs/guide-user/services/python "docs:guide-user:services:python")
* [Random Number Generator](https://openwrt.org/docs/guide-user/services/rng "docs:guide-user:services:rng")
* [Single Packet Authorization with Fwknop](https://openwrt.org/docs/guide-user/services/fwknop "docs:guide-user:services:fwknop")
* [Snort](https://openwrt.org/docs/guide-user/services/snort "docs:guide-user:services:snort")
* [Telegraf](https://openwrt.org/docs/guide-user/services/telegraf "docs:guide-user:services:telegraf")
* [ugps - OpenWrt GPS Daemon](https://openwrt.org/docs/guide-user/services/ugps "docs:guide-user:services:ugps")
* [USB over IP tunnel](https://openwrt.org/docs/guide-user/services/usb.iptunnel "docs:guide-user:services:usb.iptunnel")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Automation, home automation and similar](https://openwrt.org/docs/guide-user/services/automation/start "docs:guide-user:services:automation:start")
* [Crelay](https://openwrt.org/docs/guide-user/services/automation/crelay "docs:guide-user:services:automation:crelay")
* [Domoticz on OpenWrt](https://openwrt.org/docs/guide-user/services/automation/domoticz "docs:guide-user:services:automation:domoticz")
* [FHEM on OpenWrt](https://openwrt.org/docs/guide-user/services/automation/fhem "docs:guide-user:services:automation:fhem")
* [pywws Python Weather Station HowTo](https://openwrt.org/docs/guide-user/services/automation/pywws "docs:guide-user:services:automation:pywws")
* [Weather station control with WeeWX](https://openwrt.org/docs/guide-user/services/automation/weewx "docs:guide-user:services:automation:weewx")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Captive portals (splash pages for free or paid WiFi)](https://openwrt.org/docs/guide-user/services/captive-portal/start "docs:guide-user:services:captive-portal:start")
* [CoovaChilli captive portal](https://openwrt.org/docs/guide-user/services/captive-portal/wireless.hotspot.coova-chilli "docs:guide-user:services:captive-portal:wireless.hotspot.coova-chilli")
* [Nodogsplash (Outdated document)](https://openwrt.org/docs/guide-user/services/captive-portal/wireless.hotspot.nodogsplash "docs:guide-user:services:captive-portal:wireless.hotspot.nodogsplash")
* [NoDogSplash Captive Portal](https://openwrt.org/docs/guide-user/services/captive-portal/nodogsplash "docs:guide-user:services:captive-portal:nodogsplash")
* [OpenNDS Captive Portal](https://openwrt.org/docs/guide-user/services/captive-portal/opennds "docs:guide-user:services:captive-portal:opennds")
* [WiFiDog captive portal (defunct)](https://openwrt.org/docs/guide-user/services/captive-portal/wireless.hotspot.wifidog "docs:guide-user:services:captive-portal:wireless.hotspot.wifidog")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[DC (Direct Connect file sharing)](https://openwrt.org/docs/guide-user/services/dc/start "docs:guide-user:services:dc:start")
* [DC overview](https://openwrt.org/docs/guide-user/services/dc/dc.overview "docs:guide-user:services:dc:dc.overview")
* [Direct Connect and Advanced Direct Connect](https://openwrt.org/docs/guide-user/services/dc/direct.connect "docs:guide-user:services:dc:direct.connect")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[DDNS (Dynamic Domain Name System)](https://openwrt.org/docs/guide-user/services/ddns/start "docs:guide-user:services:ddns:start")
* [DDNS client](https://openwrt.org/docs/guide-user/services/ddns/client "docs:guide-user:services:ddns:client")
* [DDNS Client Cloudflare](https://openwrt.org/docs/guide-user/services/ddns/cloudflare "docs:guide-user:services:ddns:cloudflare")
* [DDNS Client DuckDNS](https://openwrt.org/docs/guide-user/services/ddns/duckdns "docs:guide-user:services:ddns:duckdns")
* [DDNS Client Hurricane Electric](https://openwrt.org/docs/guide-user/services/ddns/hurricaneelectricfreedns "docs:guide-user:services:ddns:hurricaneelectricfreedns")
* [DDNS with bind as own DNS server](https://openwrt.org/docs/guide-user/services/ddns/bind "docs:guide-user:services:ddns:bind")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[DNS (Domain Name System)](https://openwrt.org/docs/guide-user/services/dns/start "docs:guide-user:services:dns:start")
* [AdGuard Home](https://openwrt.org/docs/guide-user/services/dns/adguard-home "docs:guide-user:services:dns:adguard-home")
* [Bind](https://openwrt.org/docs/guide-user/services/dns/bind "docs:guide-user:services:dns:bind")
* [bind-server-filter-aaaa: forcing domains to resolve only to IPv4 addresses](https://openwrt.org/docs/guide-user/services/dns/bind-server-filter-aaaa "docs:guide-user:services:dns:bind-server-filter-aaaa")
* [DNSCrypt with Dnsmasq and dnscrypt-proxy](https://openwrt.org/docs/guide-user/services/dns/dnscrypt_dnsmasq_dnscrypt-proxy "docs:guide-user:services:dns:dnscrypt_dnsmasq_dnscrypt-proxy")
* [DNSCrypt with Dnsmasq and dnscrypt-proxy2](https://openwrt.org/docs/guide-user/services/dns/dnscrypt_dnsmasq_dnscrypt-proxy2 "docs:guide-user:services:dns:dnscrypt_dnsmasq_dnscrypt-proxy2")
* [dnscrypt-proxy](https://openwrt.org/docs/guide-user/services/dns/dnscrypt-proxy "docs:guide-user:services:dns:dnscrypt-proxy")
* [DoH with Dnsmasq and Cloudflared](https://openwrt.org/docs/guide-user/services/dns/doh_cloudflared "docs:guide-user:services:dns:doh_cloudflared")
* [DoH with Dnsmasq and https-dns-proxy](https://openwrt.org/docs/guide-user/services/dns/doh_dnsmasq_https-dns-proxy "docs:guide-user:services:dns:doh_dnsmasq_https-dns-proxy")
* [DoH/DoH3, DoT, DoQ and DNSCrypt with Dnsmasq and dnsproxy](https://openwrt.org/docs/guide-user/services/dns/dot_dnsmasq_dnsproxy "docs:guide-user:services:dns:dot_dnsmasq_dnsproxy")
* [DoT with Dnsmasq and Stubby](https://openwrt.org/docs/guide-user/services/dns/dot_dnsmasq_stubby "docs:guide-user:services:dns:dot_dnsmasq_stubby")
* [DoT with Unbound](https://openwrt.org/docs/guide-user/services/dns/dot_unbound "docs:guide-user:services:dns:dot_unbound")
* [ipset-dns](https://openwrt.org/docs/guide-user/services/dns/ipset-dns "docs:guide-user:services:dns:ipset-dns")
* [KadNode](https://openwrt.org/docs/guide-user/services/dns/kadnode "docs:guide-user:services:dns:kadnode")
* [Stubby](https://openwrt.org/docs/guide-user/services/dns/stubby "docs:guide-user:services:dns:stubby")
* [Tinydns](https://openwrt.org/docs/guide-user/services/dns/tinydns "docs:guide-user:services:dns:tinydns")
* [Unbound](https://openwrt.org/docs/guide-user/services/dns/unbound "docs:guide-user:services:dns:unbound")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Downloading and P2P file sharing](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/start "docs:guide-user:services:downloading_and_filesharing:start")
* [BitTorrent](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/bittorrent "docs:guide-user:services:downloading_and_filesharing:bittorrent")
* [NZBGet](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/nzbget "docs:guide-user:services:downloading_and_filesharing:nzbget")
* [Transmission configuration](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission "docs:guide-user:services:downloading_and_filesharing:transmission")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Email server and functionality](https://openwrt.org/docs/guide-user/services/email/start "docs:guide-user:services:email:start")
* [E-MailRelay](https://openwrt.org/docs/guide-user/services/email/emailrelay "docs:guide-user:services:email:emailrelay")
* [SMTP clients](https://openwrt.org/docs/guide-user/services/email/smtp.client "docs:guide-user:services:email:smtp.client")
* [XMail mail server](https://openwrt.org/docs/guide-user/services/email/xmail "docs:guide-user:services:email:xmail")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Media server (stream media to devices in the local network)](https://openwrt.org/docs/guide-user/services/media_server/start "docs:guide-user:services:media_server:start")
* [DLNA Media Server](https://openwrt.org/docs/guide-user/services/media_server/dlna "docs:guide-user:services:media_server:dlna")
* [iTunes server (forked-daapd)](https://openwrt.org/docs/guide-user/services/media_server/forked-daapd "docs:guide-user:services:media_server:forked-daapd")
* [MiniDLNA](https://openwrt.org/docs/guide-user/services/media_server/minidlna "docs:guide-user:services:media_server:minidlna")
* [Rygel DLNA Media Server](https://openwrt.org/docs/guide-user/services/media_server/rygel "docs:guide-user:services:media_server:rygel")
* [uShare configuration](https://openwrt.org/docs/guide-user/services/media_server/ushare "docs:guide-user:services:media_server:ushare")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[NAS (Network Attached Storage)](https://openwrt.org/docs/guide-user/services/nas/start "docs:guide-user:services:nas:start")
* [AFP Netatalk share configuration (Apple Time Machine)](https://openwrt.org/docs/guide-user/services/nas/netatalk_configuration "docs:guide-user:services:nas:netatalk_configuration")
* [CIFS Client](https://openwrt.org/docs/guide-user/services/nas/cifs.client "docs:guide-user:services:nas:cifs.client")
* [FTP servers](https://openwrt.org/docs/guide-user/services/nas/ftp.overview "docs:guide-user:services:nas:ftp.overview")
* [iSCSI](https://openwrt.org/docs/guide-user/services/nas/iscsi "docs:guide-user:services:nas:iscsi")
* [ksmbd](https://openwrt.org/docs/guide-user/services/nas/ksmbd "docs:guide-user:services:nas:ksmbd")
* [Network File System (NFS)](https://openwrt.org/docs/guide-user/services/nas/nfs.server "docs:guide-user:services:nas:nfs.server")
* [NFS client](https://openwrt.org/docs/guide-user/services/nas/nfs.client "docs:guide-user:services:nas:nfs.client")
* [NFS share configuration](https://openwrt.org/docs/guide-user/services/nas/nfs_configuration "docs:guide-user:services:nas:nfs_configuration")
* [ownCloud or NextCloud](https://openwrt.org/docs/guide-user/services/nas/owncloud "docs:guide-user:services:nas:owncloud")
* [RemoteFS Client](https://openwrt.org/docs/guide-user/services/nas/remotefs.client "docs:guide-user:services:nas:remotefs.client")
* [RemoteFS Server](https://openwrt.org/docs/guide-user/services/nas/remotefs.server "docs:guide-user:services:nas:remotefs.server")
* [Samba](https://openwrt.org/docs/guide-user/services/nas/cifs.server "docs:guide-user:services:nas:cifs.server")
* [Samba 3 (old version)](https://openwrt.org/docs/guide-user/services/nas/samba_configuration "docs:guide-user:services:nas:samba_configuration")
* [Samba Advanced Settings](https://openwrt.org/docs/guide-user/services/nas/samba "docs:guide-user:services:nas:samba")
* [SFTP server](https://openwrt.org/docs/guide-user/services/nas/sftp.server "docs:guide-user:services:nas:sftp.server")
* [Share USB hard-drive with Samba using LuCI](https://openwrt.org/docs/guide-user/services/nas/usb-storage-samba-webinterface "docs:guide-user:services:nas:usb-storage-samba-webinterface")
* [WebDAV Share](https://openwrt.org/docs/guide-user/services/nas/webdav "docs:guide-user:services:nas:webdav")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Network monitoring](https://openwrt.org/docs/guide-user/services/network_monitoring/start "docs:guide-user:services:network_monitoring:start")
* [Bandwidth Monitoring Guide](https://openwrt.org/docs/guide-user/services/network_monitoring/bwmon "docs:guide-user:services:network_monitoring:bwmon")
* [Bandwidth Monitoring through scripts](https://openwrt.org/docs/guide-user/services/network_monitoring/bandwidth-monitoring-scripts "docs:guide-user:services:network_monitoring:bandwidth-monitoring-scripts")
* [Bandwidthd](https://openwrt.org/docs/guide-user/services/network_monitoring/bandwidthd "docs:guide-user:services:network_monitoring:bandwidthd")
* [Bandwith Monitoring with wrtbwmon](https://openwrt.org/docs/guide-user/services/network_monitoring/wrtbwmon "docs:guide-user:services:network_monitoring:wrtbwmon")
* [collectd.rrdtool](https://openwrt.org/docs/guide-user/services/network_monitoring/collectd.rrdtool "docs:guide-user:services:network_monitoring:collectd.rrdtool")
* [Darkstat](https://openwrt.org/docs/guide-user/services/network_monitoring/darkstat "docs:guide-user:services:network_monitoring:darkstat")
* [Network Traffic Monitor with vnStat](https://openwrt.org/docs/guide-user/services/network_monitoring/vnstat "docs:guide-user:services:network_monitoring:vnstat")
* [Zabbix network monitoring](https://openwrt.org/docs/guide-user/services/network_monitoring/zabbix "docs:guide-user:services:network_monitoring:zabbix")
[##### zabbix](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
* [Zabbix Server Frontend Tutorial](https://openwrt.org/docs/guide-user/services/network_monitoring/zabbix/frontend_tutorial "docs:guide-user:services:network_monitoring:zabbix:frontend_tutorial")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[NTP (time synchronization over Network Time Protocol)](https://openwrt.org/docs/guide-user/services/ntp/start "docs:guide-user:services:ntp:start")
* [NTP client / NTP server](https://openwrt.org/docs/guide-user/services/ntp/client-server "docs:guide-user:services:ntp:client-server")
* [Ntpclient configuration](https://openwrt.org/docs/guide-user/services/ntp/client "docs:guide-user:services:ntp:client")
* [Stratum 1 NTP server using USB GPS](https://openwrt.org/docs/guide-user/services/ntp/gps "docs:guide-user:services:ntp:gps")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Print server (printing over the network)](https://openwrt.org/docs/guide-user/services/print_server/start "docs:guide-user:services:print_server:start")
* [CUPS Print Server](https://openwrt.org/docs/guide-user/services/print_server/cups.server "docs:guide-user:services:print_server:cups.server")
* [p910nd](https://openwrt.org/docs/guide-user/services/print_server/p910nd "docs:guide-user:services:print_server:p910nd")
* [p910nd Print Server](https://openwrt.org/docs/guide-user/services/print_server/p910ndprinterserver "docs:guide-user:services:print_server:p910ndprinterserver")
* [p910nd Printer Server](https://openwrt.org/docs/guide-user/services/print_server/p910nd.server "docs:guide-user:services:print_server:p910nd.server")
* [Printing over SSH](https://openwrt.org/docs/guide-user/services/print_server/printer.ssh "docs:guide-user:services:print_server:printer.ssh")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Proxy server](https://openwrt.org/docs/guide-user/services/proxy/start "docs:guide-user:services:proxy:start")
* [Privoxy](https://openwrt.org/docs/guide-user/services/proxy/privoxy "docs:guide-user:services:proxy:privoxy")
* [Proxy server overview](https://openwrt.org/docs/guide-user/services/proxy/overview "docs:guide-user:services:proxy:overview")
* [Shadowsocks](https://openwrt.org/docs/guide-user/services/proxy/shadowsocks "docs:guide-user:services:proxy:shadowsocks")
* [Squid](https://openwrt.org/docs/guide-user/services/proxy/proxy.squid "docs:guide-user:services:proxy:proxy.squid")
* [Tinyproxy](https://openwrt.org/docs/guide-user/services/proxy/tinyproxy "docs:guide-user:services:proxy:tinyproxy")
* [udpxy](https://openwrt.org/docs/guide-user/services/proxy/udpxy "docs:guide-user:services:proxy:udpxy")
* [VNC repeater](https://openwrt.org/docs/guide-user/services/proxy/vncrepeater "docs:guide-user:services:proxy:vncrepeater")
* [ZNC IRC network bouncer](https://openwrt.org/docs/guide-user/services/proxy/znc "docs:guide-user:services:proxy:znc")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Control your device remotely without direct SSH access](https://openwrt.org/docs/guide-user/services/remote_control/start "docs:guide-user:services:remote_control:start")
* [daloRADIUS management system](https://openwrt.org/docs/guide-user/services/remote_control/daloradius "docs:guide-user:services:remote_control:daloradius")
* [Ostiary Client (run a fixed set of commands remotely)](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.client "docs:guide-user:services:remote_control:ostiary.client")
* [Ostiary Daemon (run a fixed set of commands remotely)](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.server "docs:guide-user:services:remote_control:ostiary.server")
* [Port knocking server knockd](https://openwrt.org/docs/guide-user/services/remote_control/portknock.server "docs:guide-user:services:remote_control:portknock.server")
* [Remote control OpenWrt device via instant messengers (Telegram, XMPP) and EMail](https://openwrt.org/docs/guide-user/services/remote_control/im_email "docs:guide-user:services:remote_control:im_email")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Scanner server](https://openwrt.org/docs/guide-user/services/scanner_server/start "docs:guide-user:services:scanner_server:start")
* [saned Scanner Server](https://openwrt.org/docs/guide-user/services/scanner_server/saned "docs:guide-user:services:scanner_server:saned")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[SNMP (Simple Network Management Protocol)](https://openwrt.org/docs/guide-user/services/snmp/start "docs:guide-user:services:snmp:start")
* [Minimal SNMP Daemon (mini\_snmpd) configuration](https://openwrt.org/docs/guide-user/services/snmp/mini_snmpd "docs:guide-user:services:snmp:mini_snmpd")
* [SNMPD](https://openwrt.org/docs/guide-user/services/snmp/server "docs:guide-user:services:snmp:server")
* [snmpd](https://openwrt.org/docs/guide-user/services/snmp/snmpd "docs:guide-user:services:snmp:snmpd")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[SSH (Secure Shell remote access)](https://openwrt.org/docs/guide-user/services/ssh/start "docs:guide-user:services:ssh:start")
* [Autossh](https://openwrt.org/docs/guide-user/services/ssh/autossh "docs:guide-user:services:ssh:autossh")
* [Converting Dropbear Keys to Use Within OpenSSH](https://openwrt.org/docs/guide-user/services/ssh/transfer_dropbear_keys_to_openssh "docs:guide-user:services:ssh:transfer_dropbear_keys_to_openssh")
* [OpenSSH Multi Factor Authentication](https://openwrt.org/docs/guide-user/services/ssh/ssh.mfa.auth "docs:guide-user:services:ssh:ssh.mfa.auth")
* [Replace Dropbear to OpenSSH + SFTP](https://openwrt.org/docs/guide-user/services/ssh/openssh_instead_dropbear "docs:guide-user:services:ssh:openssh_instead_dropbear")
* [SSH FileSystem](https://openwrt.org/docs/guide-user/services/ssh/sshfs.server "docs:guide-user:services:ssh:sshfs.server")
* [SSH tunnel](https://openwrt.org/docs/guide-user/services/ssh/sshtunnel "docs:guide-user:services:ssh:sshtunnel")
* [SSHFS client](https://openwrt.org/docs/guide-user/services/ssh/sshfs.client "docs:guide-user:services:ssh:sshfs.client")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[TLS encryption](https://openwrt.org/docs/guide-user/services/tls/start "docs:guide-user:services:tls:start")
* [Get a free HTTPS certificate from LetsEncrypt for OpenWrt with ACME.sh](https://openwrt.org/docs/guide-user/services/tls/acmesh "docs:guide-user:services:tls:acmesh")
* [Installing and trusting a root CA certificate in a PKI](https://openwrt.org/docs/guide-user/services/tls/pki "docs:guide-user:services:tls:pki")
* [TLS libraries](https://openwrt.org/docs/guide-user/services/tls/libs "docs:guide-user:services:tls:libs")
* [TLS/SSL certificates for a server](https://openwrt.org/docs/guide-user/services/tls/certs "docs:guide-user:services:tls:certs")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Tor](https://openwrt.org/docs/guide-user/services/tor/start "docs:guide-user:services:tor:start")
* [Tor client](https://openwrt.org/docs/guide-user/services/tor/client "docs:guide-user:services:tor:client")
* [Tor extras](https://openwrt.org/docs/guide-user/services/tor/extras "docs:guide-user:services:tor:extras")
* [Tor onion services](https://openwrt.org/docs/guide-user/services/tor/hs "docs:guide-user:services:tor:hs")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[UPS (Uninterruptible Power Supply)](https://openwrt.org/docs/guide-user/services/ups/start "docs:guide-user:services:ups:start")
* [APC BackUps ES-500 - Linksys EA3500 - LuCI graphs](https://openwrt.org/docs/guide-user/services/ups/apcupsd_es500 "docs:guide-user:services:ups:apcupsd_es500")
* [APC SmartUps SU-700 - Linksys EA3500 - LuCI graphs](https://openwrt.org/docs/guide-user/services/ups/apcupsd_su700 "docs:guide-user:services:ups:apcupsd_su700")
* [How to add data from a TP9605BT multimeter to apcupsd rrd and graphs.](https://openwrt.org/docs/guide-user/services/ups/statistics.apcupsd_multimeter "docs:guide-user:services:ups:statistics.apcupsd_multimeter")
* [NUT (Network UPS Tools)](https://openwrt.org/docs/guide-user/services/ups/software.nut "docs:guide-user:services:ups:software.nut")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[VoIP (Voice over Internet Protocol)](https://openwrt.org/docs/guide-user/services/voip/start "docs:guide-user:services:voip:start")
* [Asterisk](https://openwrt.org/docs/guide-user/services/voip/asterisk "docs:guide-user:services:voip:asterisk")
* [chan-lantiq for Asterisk](https://openwrt.org/docs/guide-user/services/voip/chan-lantiq "docs:guide-user:services:voip:chan-lantiq")
* [FreeSWITCH on OpenWrt intro](https://openwrt.org/docs/guide-user/services/voip/freeswitch "docs:guide-user:services:voip:freeswitch")
* [Siproxd on OpenWrt intro](https://openwrt.org/docs/guide-user/services/voip/siproxd "docs:guide-user:services:voip:siproxd")
* [µMurmur](https://openwrt.org/docs/guide-user/services/voip/umurmur "docs:guide-user:services:voip:umurmur")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[VPN (Virtual Private Network)](https://openwrt.org/docs/guide-user/services/vpn/start "docs:guide-user:services:vpn:start")
* [Cloudflare tunnel](https://openwrt.org/docs/guide-user/services/vpn/cloudfare_tunnel "docs:guide-user:services:vpn:cloudfare_tunnel")
* [Netbird](https://openwrt.org/docs/guide-user/services/vpn/netbird "docs:guide-user:services:vpn:netbird")
* [Pseudowire](https://openwrt.org/docs/guide-user/services/vpn/pseudowire "docs:guide-user:services:vpn:pseudowire")
* [Zerotier](https://openwrt.org/docs/guide-user/services/vpn/zerotier "docs:guide-user:services:vpn:zerotier")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Libreswan / IPsec](https://openwrt.org/docs/guide-user/services/vpn/libreswan/start "docs:guide-user:services:vpn:libreswan:start")
* [IPsec site-to-site](https://openwrt.org/docs/guide-user/services/vpn/libreswan/site2site "docs:guide-user:services:vpn:libreswan:site2site")
* [Libreswan L2TP/IPsec](https://openwrt.org/docs/guide-user/services/vpn/libreswan/openswanxl2tpvpn "docs:guide-user:services:vpn:libreswan:openswanxl2tpvpn")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[OpenConnect](https://openwrt.org/docs/guide-user/services/vpn/openconnect/start "docs:guide-user:services:vpn:openconnect:start")
* [OpenConnect client](https://openwrt.org/docs/guide-user/services/vpn/openconnect/client "docs:guide-user:services:vpn:openconnect:client")
* [OpenConnect extras](https://openwrt.org/docs/guide-user/services/vpn/openconnect/extras "docs:guide-user:services:vpn:openconnect:extras")
* [OpenConnect server](https://openwrt.org/docs/guide-user/services/vpn/openconnect/server "docs:guide-user:services:vpn:openconnect:server")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[OpenVPN](https://openwrt.org/docs/guide-user/services/vpn/openvpn/start "docs:guide-user:services:vpn:openvpn:start")
* [OpenVPN client](https://openwrt.org/docs/guide-user/services/vpn/openvpn/client "docs:guide-user:services:vpn:openvpn:client")
* [OpenVPN client using LuCI](https://openwrt.org/docs/guide-user/services/vpn/openvpn/client-luci "docs:guide-user:services:vpn:openvpn:client-luci")
* [OpenVPN extras](https://openwrt.org/docs/guide-user/services/vpn/openvpn/extras "docs:guide-user:services:vpn:openvpn:extras")
* [OpenVPN PC script automated](https://openwrt.org/docs/guide-user/services/vpn/openvpn/automated_pc "docs:guide-user:services:vpn:openvpn:automated_pc")
* [OpenVPN performance](https://openwrt.org/docs/guide-user/services/vpn/openvpn/performance "docs:guide-user:services:vpn:openvpn:performance")
* [OpenVPN server](https://openwrt.org/docs/guide-user/services/vpn/openvpn/server "docs:guide-user:services:vpn:openvpn:server")
* [OpenVPN server with dynamic IPv6 GUA prefix](https://openwrt.org/docs/guide-user/services/vpn/openvpn/server_ip6prefix "docs:guide-user:services:vpn:openvpn:server_ip6prefix")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[PPPoSSH](https://openwrt.org/docs/guide-user/services/vpn/pppossh/start "docs:guide-user:services:vpn:pppossh:start")
* [PPPoSSH client](https://openwrt.org/docs/guide-user/services/vpn/pppossh/client "docs:guide-user:services:vpn:pppossh:client")
* [PPPoSSH extras](https://openwrt.org/docs/guide-user/services/vpn/pppossh/extras "docs:guide-user:services:vpn:pppossh:extras")
* [PPPoSSH server](https://openwrt.org/docs/guide-user/services/vpn/pppossh/server "docs:guide-user:services:vpn:pppossh:server")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[PPTP](https://openwrt.org/docs/guide-user/services/vpn/pptp/start "docs:guide-user:services:vpn:pptp:start")
* [PPTP client](https://openwrt.org/docs/guide-user/services/vpn/pptp/client "docs:guide-user:services:vpn:pptp:client")
* [PPTP extras](https://openwrt.org/docs/guide-user/services/vpn/pptp/extras "docs:guide-user:services:vpn:pptp:extras")
* [PPTP server](https://openwrt.org/docs/guide-user/services/vpn/pptp/server "docs:guide-user:services:vpn:pptp:server")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[SoftEther VPN](https://openwrt.org/docs/guide-user/services/vpn/softethervpn/start "docs:guide-user:services:vpn:softethervpn:start")
* [SoftEther VPN Client](https://openwrt.org/docs/guide-user/services/vpn/softethervpn/client "docs:guide-user:services:vpn:softethervpn:client")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[strongSwan / IPsec](https://openwrt.org/docs/guide-user/services/vpn/strongswan/start "docs:guide-user:services:vpn:strongswan:start")
* [IPsec basics](https://openwrt.org/docs/guide-user/services/vpn/strongswan/basics "docs:guide-user:services:vpn:strongswan:basics")
* [IPsec Firewall](https://openwrt.org/docs/guide-user/services/vpn/strongswan/firewall "docs:guide-user:services:vpn:strongswan:firewall")
* [IPsec Legacy IKEv1 Configuration](https://openwrt.org/docs/guide-user/services/vpn/strongswan/howto "docs:guide-user:services:vpn:strongswan:howto")
* [IPsec Modern IKEv2 Road-Warrior Configuration](https://openwrt.org/docs/guide-user/services/vpn/strongswan/roadwarrior "docs:guide-user:services:vpn:strongswan:roadwarrior")
* [IPsec Performance](https://openwrt.org/docs/guide-user/services/vpn/strongswan/performance "docs:guide-user:services:vpn:strongswan:performance")
* [IPsec Site-to-Site](https://openwrt.org/docs/guide-user/services/vpn/strongswan/site2site "docs:guide-user:services:vpn:strongswan:site2site")
* [IPsec With Overlapping Subnets](https://openwrt.org/docs/guide-user/services/vpn/strongswan/overlappingsubnets "docs:guide-user:services:vpn:strongswan:overlappingsubnets")
* [strongSwan IPsec Configuration via UCI](https://openwrt.org/docs/guide-user/services/vpn/strongswan/configuration "docs:guide-user:services:vpn:strongswan:configuration")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Tinc](https://openwrt.org/docs/guide-user/services/vpn/tinc/start "docs:guide-user:services:vpn:tinc:start")
* [Tinc client](https://openwrt.org/docs/guide-user/services/vpn/tinc/client "docs:guide-user:services:vpn:tinc:client")
* [Tinc extras](https://openwrt.org/docs/guide-user/services/vpn/tinc/extras "docs:guide-user:services:vpn:tinc:extras")
* [Tinc server](https://openwrt.org/docs/guide-user/services/vpn/tinc/server "docs:guide-user:services:vpn:tinc:server")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[WireGuard](https://openwrt.org/docs/guide-user/services/vpn/wireguard/start "docs:guide-user:services:vpn:wireguard:start")
* [WireGuard basics](https://openwrt.org/docs/guide-user/services/vpn/wireguard/basics "docs:guide-user:services:vpn:wireguard:basics")
* [WireGuard client](https://openwrt.org/docs/guide-user/services/vpn/wireguard/client "docs:guide-user:services:vpn:wireguard:client")
* [WireGuard extras](https://openwrt.org/docs/guide-user/services/vpn/wireguard/extras "docs:guide-user:services:vpn:wireguard:extras")
* [WireGuard multi-client server automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/automated "docs:guide-user:services:vpn:wireguard:automated")
* [WireGuard peers](https://openwrt.org/docs/guide-user/services/vpn/wireguard/serverclient "docs:guide-user:services:vpn:wireguard:serverclient")
* [WireGuard performance](https://openwrt.org/docs/guide-user/services/vpn/wireguard/performance "docs:guide-user:services:vpn:wireguard:performance")
* [WireGuard road-warrior automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/road-warrior "docs:guide-user:services:vpn:wireguard:road-warrior")
* [WireGuard routing all traffic](https://openwrt.org/docs/guide-user/services/vpn/wireguard/all-traffic-through-wireguard "docs:guide-user:services:vpn:wireguard:all-traffic-through-wireguard")
* [WireGuard server](https://openwrt.org/docs/guide-user/services/vpn/wireguard/server "docs:guide-user:services:vpn:wireguard:server")
* [WireGuard site-to-site automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/site-to-site "docs:guide-user:services:vpn:wireguard:site-to-site")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Wake on LAN (sending Ethernet messages to power up network devices)](https://openwrt.org/docs/guide-user/services/w_o_l/start "docs:guide-user:services:w_o_l:start")
* [Etherwake configuration](https://openwrt.org/docs/guide-user/services/w_o_l/etherwake "docs:guide-user:services:w_o_l:etherwake")
* [Wake on LAN configuration](https://openwrt.org/docs/guide-user/services/w_o_l/wol "docs:guide-user:services:w_o_l:wol")
[](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/start#top-1333672647 "Continue with the « docs » section at the top...")
[Web servers](https://openwrt.org/docs/guide-user/services/webserver/start "docs:guide-user:services:webserver:start")
* [Apache HTTP Server](https://openwrt.org/docs/guide-user/services/webserver/http.apache "docs:guide-user:services:webserver:http.apache")
* [BusyBox HTTP Daemon (httpd) webserver](https://openwrt.org/docs/guide-user/services/webserver/http.httpd "docs:guide-user:services:webserver:http.httpd")
* [Hiawatha webserver](https://openwrt.org/docs/guide-user/services/webserver/http.hiawatha "docs:guide-user:services:webserver:http.hiawatha")
* [Lighttpd webserver](https://openwrt.org/docs/guide-user/services/webserver/lighttpd "docs:guide-user:services:webserver:lighttpd")
* [mini-httpd webserver](https://openwrt.org/docs/guide-user/services/webserver/http.mini-httpd "docs:guide-user:services:webserver:http.mini-httpd")
* [Netcat as Webserver](https://openwrt.org/docs/guide-user/services/webserver/http.netcat "docs:guide-user:services:webserver:http.netcat")
* [Nginx webserver](https://openwrt.org/docs/guide-user/services/webserver/nginx "docs:guide-user:services:webserver:nginx")
* [PHP](https://openwrt.org/docs/guide-user/services/webserver/php "docs:guide-user:services:webserver:php")
* [Set up a LAMP webserver stack](https://openwrt.org/docs/guide-user/services/webserver/lamp "docs:guide-user:services:webserver:lamp")
* [uHTTPd Web Server Configuration](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
* [uHTTPd webserver](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd")
* [Using OpenWrt to build a LAMP/WordPress server](https://openwrt.org/docs/guide-user/services/webserver/install_wordpress "docs:guide-user:services:webserver:install_wordpress")
Troubleshooting and maintenance
-------------------------------
[](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
===========================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-35861302 "Continue with the « docs » section at the top...")
[Troubleshooting](https://openwrt.org/docs/guide-user/troubleshooting/start "docs:guide-user:troubleshooting:start")
* [Backup and restore](https://openwrt.org/docs/guide-user/troubleshooting/backup_restore "docs:guide-user:troubleshooting:backup_restore")
* [Failsafe mode, factory reset, and recovery mode](https://openwrt.org/docs/guide-user/troubleshooting/failsafe_and_factory_reset "docs:guide-user:troubleshooting:failsafe_and_factory_reset")
* [For Developers: Activating EAD (Emergency Access Daemon) Before Running into Problems](https://openwrt.org/docs/guide-user/troubleshooting/ead "docs:guide-user:troubleshooting:ead")
* [OpenWrt Debricking Guide](https://openwrt.org/docs/guide-user/troubleshooting/generic.debrick "docs:guide-user:troubleshooting:generic.debrick")
* [Rescue from failed firmware upgrade](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue "docs:guide-user:troubleshooting:vendor_specific_rescue")
* [Resetting the root password](https://openwrt.org/docs/guide-user/troubleshooting/root_password_reset "docs:guide-user:troubleshooting:root_password_reset")
* [What is TFTP Recovery over Ethernet?](https://openwrt.org/docs/guide-user/troubleshooting/tftpserver "docs:guide-user:troubleshooting:tftpserver")
Running OpenWrt in a virtual machine or container
-------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-1217606887 "Continue with the « docs » section at the top...")
[Virtualization](https://openwrt.org/docs/guide-user/virtualization/start "docs:guide-user:virtualization:start")
* [Docker OpenWrt Image Generation](https://openwrt.org/docs/guide-user/virtualization/obtain.firmware.docker "docs:guide-user:virtualization:obtain.firmware.docker")
* [Metarouter Virtualization on Mikrotik RouterBoard](https://openwrt.org/docs/guide-user/virtualization/metarouter "docs:guide-user:virtualization:metarouter")
* [OpenWrt as a Docker Image](https://openwrt.org/docs/guide-user/virtualization/docker_openwrt_image "docs:guide-user:virtualization:docker_openwrt_image")
* [OpenWrt as a Xen DomU guest](https://openwrt.org/docs/guide-user/virtualization/xen "docs:guide-user:virtualization:xen")
* [OpenWrt as Docker container host](https://openwrt.org/docs/guide-user/virtualization/docker_host "docs:guide-user:virtualization:docker_host")
* [OpenWrt as DomU in Debian Xen4 in a private network](https://openwrt.org/docs/guide-user/virtualization/xen_debian_private_network "docs:guide-user:virtualization:xen_debian_private_network")
* [OpenWrt as QEMU/KVM host server](https://openwrt.org/docs/guide-user/virtualization/qemu_host "docs:guide-user:virtualization:qemu_host")
* [OpenWrt in LXC containers](https://openwrt.org/docs/guide-user/virtualization/lxc "docs:guide-user:virtualization:lxc")
* [OpenWrt in QEMU](https://openwrt.org/docs/guide-user/virtualization/qemu "docs:guide-user:virtualization:qemu")
* [OpenWrt on UTM on Apple Silicon HowTo](https://openwrt.org/docs/guide-user/virtualization/utm "docs:guide-user:virtualization:utm")
* [OpenWrt on VirtualBox HowTo](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm "docs:guide-user:virtualization:virtualbox-vm")
* [OpenWrt on VMware Fusion on Apple Silicon HowTo](https://openwrt.org/docs/guide-user/virtualization/fusion "docs:guide-user:virtualization:fusion")
* [OpenWrt on VMware HowTo](https://openwrt.org/docs/guide-user/virtualization/vmware "docs:guide-user:virtualization:vmware")
* [OpenWrt running as metarouter on mikrotik routerOS](https://openwrt.org/docs/guide-user/virtualization/mikrotik_metarouter_openwrt "docs:guide-user:virtualization:mikrotik_metarouter_openwrt")
* [Podman Containers](https://openwrt.org/docs/guide-user/virtualization/podman "docs:guide-user:virtualization:podman")
* [VirtualBox Advanced](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced "docs:guide-user:virtualization:virtualbox-advanced")
Security
--------
[](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
============================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
-----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/start#top-708127515 "Continue with the « docs » section at the top...")
[Security](https://openwrt.org/docs/guide-user/security/start "docs:guide-user:security:start")
* [Dropbear key-based authentication](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth "docs:guide-user:security:dropbear.public-key.auth")
* [Elevating privileges with sudo](https://openwrt.org/docs/guide-user/security/sudo "docs:guide-user:security:sudo")
* [Key Generation](https://openwrt.org/docs/guide-user/security/keygen "docs:guide-user:security:keygen")
* [OpenWrt Public Keys](https://openwrt.org/docs/guide-user/security/signatures "docs:guide-user:security:signatures")
* [OpenWrt security features](https://openwrt.org/docs/guide-user/security/security-features "docs:guide-user:security:security-features")
* [OpenWrt security hardening](https://openwrt.org/docs/guide-user/security/openwrt_security "docs:guide-user:security:openwrt_security")
* [Regaining access to an OpenWrt device in client mode](https://openwrt.org/docs/guide-user/security/recovering_from_clientmode "docs:guide-user:security:recovering_from_clientmode")
* [Release Signing](https://openwrt.org/docs/guide-user/security/release_signatures "docs:guide-user:security:release_signatures")
* [Secure access to your router](https://openwrt.org/docs/guide-user/security/secure.access "docs:guide-user:security:secure.access")
* [Security Guide for the Paranoid](https://openwrt.org/docs/guide-user/security/security_guide_for_the_paranoid "docs:guide-user:security:security_guide_for_the_paranoid")
Work-in-progress documentation pages
------------------------------------
| | |
| --- | --- |
| [](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...") [Inbox](https://openwrt.org/inbox/start "inbox:start")
* [Using Eclipse for C/C++ Programming and Debugging](https://openwrt.org/inbox/eclipse "inbox:eclipse")
[docs ----](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...") [### guide-developer](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
* [Gui Development with Luci](https://openwrt.org/inbox/docs/guide-developer/gui-development "inbox:docs:guide-developer:gui-development")
* [Netbooting clients into Archlinux from an OpenWrt device](https://openwrt.org/inbox/howto/setting_up_openwrt_to_serve_archlinux_netboot "inbox:howto:setting_up_openwrt_to_serve_archlinux_netboot")
* [Packet scheduling, Hierarchical Token Bucket : an experience](https://openwrt.org/inbox/howto/packet.scheduler.experience "inbox:howto:packet.scheduler.experience")
[temp ----](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
[](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...") [toh](https://openwrt.org/inbox/toh/start "inbox:toh:start")
[### arcadyan](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...") [#### astoria](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
[### evaluation\_boards](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...") [#### unbranded\_boards](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « inbox » section at the top...")
* [Xiaomi Mi Router 4A (R4AC) 100M (International version)](https://openwrt.org/inbox/toh/xiaomi/r4ac "inbox:toh:xiaomi:r4ac")
* [Xiaomi Mi WiFi Range Extender AC1200 Model RA75](https://openwrt.org/inbox/toh/xiaomi/mi_wifi_range_extender_ac1200_model_ra75 "inbox:toh:xiaomi:mi_wifi_range_extender_ac1200_model_ra75")
[zyxel -----](https://openwrt.org/docs/guide-user/start#top-121140568 "Continue with the « » section at the top...")
* [ZyXEL NWA1123-NI](https://openwrt.org/inbox/zyxel/zyxel_nwa1123-ni "inbox:zyxel:zyxel_nwa1123-ni") |
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/11 01:30
* by vgaetera
[](https://openwrt.org/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] ar:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/ar/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] cs:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/cs/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] hu:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/hu/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] fr:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/fr/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] it:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/it/docs/guide-user/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] pt:docs:guide-user:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/pt/docs/guide-user/start#dokuwiki__top "skip to content")

---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# Testing to determine if you are a bot!
Testing to determine if you are a bot!
======================================
 
Calculating...
Difficulty: 2, Speed: 0kH/s
You are seeing this because the administrator of this website has set up Anubis to protect the server against the scourge of AI companies aggressively scraping websites. This can and does cause downtime for the websites, which makes their resources inaccessible for everyone.
Anubis is a compromise. Anubis uses a Proof-of-Work scheme in the vein of Hashcash, a proposed proof-of-work scheme for reducing email spam. The idea is that at individual scales the additional load is ignorable, but at mass scraper levels it adds up and makes scraping much more expensive.
Ultimately, this is a placeholder solution so that more time can be spent on fingerprinting and identifying headless browsers (EG: via how they do font rendering) so that the challenge proof of work page doesn't need to be presented to users that are much more likely to be legitimate.
Please note that Anubis requires the use of modern JavaScript features that plugins like JShelter will disable. Please disable JShelter or other such plugins for this domain.
---
# [OpenWrt Wiki] Tor onion services
Tor onion services
==================
You can enable a remote access tunnel to your device over the Tor network and use it for SSH or to serve a web site. This is often used not only for privacy but also just a method of NAT traversal to a device that doesn't have a static IP. You can create your own `.onion` domain for free but it will be accessible only with the Tor Browser or via Tor SOCKS proxy.
Introduction
------------
* [How do Onion Services work](https://community.torproject.org/onion-services/overview/ "https://community.torproject.org/onion-services/overview/")
* [How to set up an onion service](https://community.torproject.org/onion-services/setup/ "https://community.torproject.org/onion-services/setup/")
to share your local services with the Tor world.
* [Tor Support Portal](https://forum.torproject.net/c/support/onion-services/16 "https://forum.torproject.net/c/support/onion-services/16")
Tor HS configurator
-------------------
The [tor-hs](https://openwrt.org/packages/pkgdata/tor-hs "packages:pkgdata:tor-hs")
package provides the Tor hidden service configurator that tries to simplify creation of hidden services on OpenWrt routers.
### Installation
To install the package with LUCI: in main menu select `System` / `Software`. Press `Update lists..` and then type into Filter field `tor-hs`.
Or run in terminal:
opkg update
opkg install tor-hs
There is a LUCI app luci-app-tor that provides a GUI for the `tor-hs`. You may install it with `opkg install luci-app-tor`. It may be not yet available in the main packages feed.
### Hidden service configuration
UCI configuration is located in `/etc/config/tor-hs`. You have to edit and adjust from terminal with `vi /etc/config/tor-hs`. If you want to create a new hidden service, you have to add a hidden-service section. For every hidden service, there should be a new `hidden-service` section.
Example of hidden service section for SSH server:
config hidden-service
option Name 'sshd'
option Description 'Hidden service for SSH'
option Enabled 'false'
option IPv4 '127.0.0.1'
list PublicLocalPort '2222;22'
| Name | Example value | Description |
| --- | --- | --- |
| `Name` | `sshd` | Name of hidden service. It is used as directory name in `HSDir` |
| `Description` | `Hidden service for ssh` | Description used in `rpcd` service |
| `Enabled` | `false` | Enable hidden service after running `tor-hs` init script |
| `IPv4` | `127.0.0.1` | Local IPv4 address of service. Service could run on another device, in that case OpenWrt will redirect communication. |
| `PublicLocalPort` | `2222;22` | List of public ports accessible via Tor network. Local port is normal port of service. |
| `HookScript` | `/etc/tor/nextcloud-update.php` | Path to script which is executed after starting tor-hs. Script is executed with parameters `--update-onion hostname`. The hostname is replaced with Onion v3 address for given hidden service. |
### Required section of configuration
There is one required section common. Example:
config tor-hs common
option GenConf "/etc/tor/torrc\_hs"
option HSDir "/etc/tor/hidden\_service"
option RestartTor "true"
option UpdateTorConf "true"
### Options description
| Name | Default | Description |
| --- | --- | --- |
| `GenConf` | `/etc/tor/torrc_generated` | Generated config by tor-hs. |
| `HSDir` | `/etc/tor/hidden_service` | Directory with meta-data for hidden services (hostname, keys, etc). |
| `RestartTor` | `true` | It will restart tor after running starting the `tor-hs` service. |
| `UpdateTorConf` | `true` | Update `/etc/config/tor` with config from `GenConf` option. |
### Setup from command line
Allow remote access to the router with onion services. It's recommended to enable [client authorization](https://openwrt.org/docs/guide-user/services/tor/extras#client_authorization "docs:guide-user:services:tor:extras")
.
\# Configure Tor onion service
uci \-q delete tor-hs.ssh
uci set tor-hs.ssh="hidden-service"
uci set tor-hs.ssh.Name="ssh"
uci set tor-hs.ssh.Enabled="1"
uci set tor-hs.ssh.IPv4="127.0.0.1"
uci add\_list tor-hs.ssh.PublicLocalPort="22;22"
uci commit tor-hs
service tor-hs restart
\# Fetch onion service hostname
cat /etc/tor/hidden\_service/ssh/hostname
Access the onion service from Tor client.
\# Install packages
opkg update
opkg install torsocks
\# Access onion service
torsocks ssh ${TOR\_HOST}
### Client authorization
You can secure access to onion services with [client authorization](https://community.torproject.org/onion-services/advanced/client-auth/ "https://community.torproject.org/onion-services/advanced/client-auth/")
.
\# Install packages
opkg update
opkg install openssl-util coreutils-base32
\# Enable client authorization
openssl genpkey \-algorithm x25519 \-out /etc/tor/hidden\_service.pem
TOR\_KEY\="$(openssl pkey -in /etc/tor/hidden\_service.pem -outform der \\
| tail -c 32 \\
| base32 \\
| sed -e "s/\=//g")"
TOR\_PUB\="$(openssl pkey -in /etc/tor/hidden\_service.pem -outform der -pubout \\
| tail -c 32 \\
| base32 \\
| sed -e "s/\=//g")"
TOR\_HOST\="$(cat /etc/tor/hidden\_service/ssh/hostname)"
cat << EOF \> client.auth\_private
${TOR\_HOST%.onion}:descriptor:x25519:${TOR\_KEY}
EOF
cat << EOF \> /etc/tor/hidden\_service/ssh/authorized\_clients/client.auth
descriptor:x25519:${TOR\_PUB}
EOF
chown \-R tor:tor /etc/tor/hidden\_service
service tor restart
Configure authorization on the client using the private key.
\# Configure client authorization
cat << EOF \>> /etc/tor/custom
ClientOnionAuthDir /etc/tor/onion\_auth
EOF
umask go\=
TOR\_AUTH\="$(cat client.auth\_private)"
TOR\_HOST\="${TOR\_AUTH%%:\*}.onion"
mkdir \-p /etc/tor/onion\_auth
cat << EOF \> /etc/tor/onion\_auth/client.auth\_private
${TOR\_AUTH}
EOF
chown \-R tor:tor /etc/tor/onion\_auth
service tor restart
### Running service
To enable tor-hs service run:
service tor-hs enable
service tor-hs start
In case you enabled option `RestartTor` and `UpdateTorConf` hidden service should be running. Otherwise, you should also restart tor daemon.
service tor restart
After that you should also restart rpcd daemon, so you can use tor-hs RPCD service.
service rpcd restart
### RPCD
The RPCD service helps users to access basic information about hidden services on the router. After running HS, it contains an onion URL for a given hidden service in hostname value.
$ ubus call tor-hs-rpc list-hs
{
"hs-list": \[\
{\
"name": "sshd",\
"description": "Hidden service for SSH",\
"enabled": "1",\
"ipv4": "127.0.0.1",\
"hostname": ".onion",\
"ports": \[\
"22;22"\
\]\
}\
\]
}
Client authorization
--------------------
Secure access with [client authorization](https://community.torproject.org/onion-services/advanced/client-auth/ "https://community.torproject.org/onion-services/advanced/client-auth/")
.
1. Generate public-private key pair using instructions from [Tor client authorization](https://community.torproject.org/onion-services/advanced/client-auth/ "https://community.torproject.org/onion-services/advanced/client-auth/")
.
2. Place the generated public key in `//authorized_clients/.auth`.
* For the example above (ssh server), and a client named `someone`, that will be `/etc/tor/hidden_service/sshd/authorized_clients/someone.auth`.
3. Use the private key in your browser when visiting the hidden service.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/10/17 18:51
* by systemcrash
[](https://openwrt.org/docs/guide-user/services/tor/hs#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Installing and trusting a root CA certificate in a PKI
Installing and trusting a root CA certificate in a PKI
======================================================
As stated above:
> For enabling HTTPS for a website's domain we need a private key and it's TLS certificate that was signed by a Certificate Authority (CA).
But what if you have your private Certificate Authority in your infrastructure? In that case, your CA will sign your certificate but the root certificate (the one from the private CA) won't be trusted by your system. It needs to be installed and added to the system's trust store.
Steps are as follow:
1. Get the root CA certificate
2. Install the root CA certificate
3. Add the root CA certificate to the system's trust store
4. A helper script
For this documentation we will assume:
* The CA name is `ca.private-domain.tld`
* The CA server is accessible at `ca.private-domain.tld`, port `443`
* The CA cert filename is `ca.private-domain.tld.cert`
### 1\. Get the root CA certificate
Let's get the root CA cert.
openssl s\_client \-connect ca.private-domain.tld:443 < /dev/null \> /tmp/temporary.out
openssl x509 \-outform PEM < /tmp/temporary.out \> /tmp/ca.private-domain.tld.cert
rm /tmp/temporary.out
Note: Don't forget to remove the temporary file `/tmp/temporary.out`
### 2\. Install the root CA certificate
Trusted certificates are installed in `/etc/ssl/certs`. However, it is a good practice to follow the [FHS 3](https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html "https://refspecs.linuxfoundation.org/FHS_3.0/fhs/ch04s09.html")
and use `/usr/local/share` for architecture-independant files.
mkdir \-p /usr/local/share/ca-certificates
mv /tmp/ca.private-domain.tld.cert /usr/local/share/ca-certificates/
ln \-s /usr/local/share/ca-certificates/ca.private-domain.tld.cert /etc/ssl/certs/ca.private-domain.tld.cert
chmod ugo-x /usr/local/share/ca-certificates/ca.private-domain.tld.cert
### 3\. Add the root CA certificate to the system's trust store
The certificate is installed but not yet trusted. You need to provide its hash.
\# Generate the hash
HASH\="$(openssl x509 -hash -noout -in /etc/ssl/certs/ca.private-domain.tld.cert).0"
\# Display the hash value
echo "$HASH"
\# Link the hash to the certificate
ln \-s "/etc/ssl/certs/ca.private-domain.tld.cert" "/etc/ssl/certs/$HASH"
Note: If another cert has the same hash use suffix `.1` or `.2` instead of `.0`.
Congratulations, you've installed and trusted your root CA certificate.
### 4\. A helper script
CA\_NAME\="ca.private-domain.tld"
CERT\_FILE\="$CA\_NAME.cert"
CERT\_INSTALL\_DIR\="/usr/local/share/ca-certificates"
CERT\_PATH\="${CERT\_INSTALL\_DIR}/${CERT\_FILE}"
openssl s\_client \-connect ${CA\_NAME}:443 < /dev/null \> /tmp/temporary.out
mkdir \-p "$CERT\_INSTALL\_DIR"
openssl x509 \-outform PEM < /tmp/temporary.out \> "$CERT\_PATH"
HASH\="$(openssl x509 -hash -noout -in $CERT\_PATH).0"
echo "$HASH"
ln \-s "$CERT\_PATH" "/etc/ssl/certs/$CERT\_FILE"
ln \-s "/etc/ssl/certs/$CERT\_FILE" "/etc/ssl/certs/$HASH"
ls \-al "/etc/ssl/certs/$HASH"
rm /tmp/temporary.out
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/07/26 09:30
* by tu1h
[](https://openwrt.org/docs/guide-user/services/tls/pki#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] chan-lantiq for Asterisk
chan-lantiq for Asterisk
========================
**Note: This wiki entry is not finished and not complete yet.**
The Asterisk channel chan-lantiq provides support for FXS ports from routers using lantiq based SoCs. The channel should usable with most routers using DANUBE, VRX200 (VR9) SoC and probably ARX100 (AR9). VRX200 (VR9) devices need a special firmware using a reserved CPU core and reserved RAM (see section 2.)
1\. Install chan-lantiq
-----------------------
To install chan-lantiq for usage with a SIP carrier like sipgate.de the following packages are recommended to install.
opkg install asterisk asterisk-chan-lantiq asterisk-chan-sip asterisk-codec-a-mu asterisk-codec-alaw asterisk-codec-resample asterisk-codec-ulaw asterisk-res-rtp-asterisk
Before release of openwrt-18.06 you could build OpenWrt manually and select the listed packages manually. Self building is supported since OpenWrt master commit 49acec5b5f4b2040c307aebb1a258cf8c1ade278 at 2017-03-24.
2\. Compatible SoCs and routers
-------------------------------
To use chan-lantiq with DANUBE SoC based routers only chan-lantiq needs to be installed. A special easy-to-use firmware should installed automatically by ltq-vmmc and ltq-tapi packages. For VRX200 (VR9) based routers a special lantiq firmware must be loaded to a reserved CPU core that is able to access a amount of 2MB reserved RAM. Reserved core and RAM is not needed with DANUBE based devices.
The channel was tested on the following DANUBE SoC based devices:
* ARV752DPW22 (EasyBox 803A)
The channel should run out of the box with the following VRX200 (VR9) SoC based devices:
* VGV7510KW22 (o2 Box 6431)
* VGV7519 (KPN Experia Box v8)
3\. Add support for new devices
-------------------------------
If chan-lantiq is not working with a specific DANUBE based SoC router, check if the routers DTS file have specified GPIOs within a vmmc section. Give a look to ARV752DPW22 DTS file. To support a new VRX200 (VR9) based router give a look to VGV7519 DTSI file ([https://github.com/openwrt/openwrt/commit/0ce929228a63cc23f0deb52a72cc99b21c1c9bf9#diff-6c090f56b029513115c56a335129a3e2](https://github.com/openwrt/openwrt/commit/0ce929228a63cc23f0deb52a72cc99b21c1c9bf9#diff-6c090f56b029513115c56a335129a3e2 "https://github.com/openwrt/openwrt/commit/0ce929228a63cc23f0deb52a72cc99b21c1c9bf9#diff-6c090f56b029513115c56a335129a3e2")
).
Most important part is to add the following arguments to the kernel command line (bootargs). This line is valid for VGV7519 with 64 MB RAM.
mem=62M vpe1\_load\_addr=0x83e00000 vpe1\_mem=2M maxvpes=1 maxtcs=1 nosmp
You may need to change the mem parameter and vpe1\_load\_addr. The reserved memory for firmware (vpe1\_mem) uses 2M, that means remaining memory is 64M-2M=62M. So the parameter mem=62M is valid. The vpe1\_load\_addr should point to begin of 62th MB of RAM. You should adopt parameters maxvpes and maxtcs unchanged. The parameter nosmp is needed to disable SMP. That means if you want using chan-lantiq you can only use one CPU core. The second CPU core is reserved for the special firmware for supporting FXS. The firmware might support DECT devices, too. But actually there is no utility/service that does maintain DECT telephones (e. g. register, key management).
To use FXS ports with e. g. Archer VR200v the kernel command line (bootargs) needs to be edited and a vmmc section must added to DTS file. Then FXS might probably work with chan-lantiq (not tested).
4\. Example minimal configuration for Asterisk
----------------------------------------------
The minimal configuration allows to take and receive calls via a SIP carrier like sipgate.de
**asterisk/lantiq.conf**
\[interfaces\]
channels = 2
per\_channel\_context = on
**asterisk/sip.conf**
nat=yes
directmedia=no
qualify=yes
register => SIPID:PASSWORD@sipgate.de/SIPID
\[sipgate\]
type=peer
host=sipgate.de
fromdomain=sipgate.de
dtmfmode=rfc2833
insecure=port,invite
directmedia=no
transport=udp,tcp
context=in\_sipgate
disallow=all
allow=alaw,ulaw
username=SIPID
fromuser=SIPID
secret=PASSWORD
add to \[sipgate\] context
context=in\_sipgate
**asterisk/extensions.conf**
\[out\_sipgate\]
exten => \_\[+0-9\].,1,Set(CALLERID(num)=NUMBER)
exten => \_\[+0-9\].,2,Dial(SIP/sipgate/${EXTEN},30,Trg)
exten => \_\[+0-9\].,3,Hangup
\[in\_sipgate\]
exten => SIPID,1,Goto(tel1\_in,s,1)
\[tel1\_out\]
exten => \_Z,1,Goto(out\_internal,${EXTEN},1)
exten => \_\[+0-9\].,1,Gosub(out\_sipgate,${EXTEN})
\[tel2\_out\]
exten => \_Z,1,Goto(out\_internal,${EXTEN},1)
exten => \_\[+0-9\].,1,Gosub(out\_sipgate,${EXTEN})
\[ltq1\_out\]
;exten => \_\[+0-9\]!,1,Goto(tel1\_out,${EXTEN},1)
exten => \_\[+0-9\]!,1,Dial(local/${EXTEN}@tel1\_out/n)
\[ltq2\_out\]
;exten => \_\[+0-9\]!,1,Goto(tel2\_out,${EXTEN},1)
exten => \_\[+0-9\]!,1,Dial(local/${EXTEN}@tel2\_out/n)
\[ltq1\_in\]
exten => s,1,Dial(TAPI/1,30,t)
\[ltq2\_in\]
exten => s,1,Dial(TAPI/2,30,t)
\[tel1\_in\]
;exten => s,1,Goto(ltq1\_in,s,1)
exten => s,1,Dial(local/s@ltq1\_in/n)
\[tel2\_in\]
;exten => s,1,Goto(ltq2\_in,s,1)
exten => s,1,Dial(local/s@ltq2\_in/n)
\[lantiq1\]
include => ltq1\_out
\[lantiq2\]
include => ltq2\_out
5\. See also
------------
[https://forum.openwrt.org/viewtopic.php?id=62696](https://forum.openwrt.org/viewtopic.php?id=62696 "https://forum.openwrt.org/viewtopic.php?id=62696")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/10/06 17:04
* by agriveaux
[](https://openwrt.org/docs/guide-user/services/voip/chan-lantiq#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] NUT (Network UPS Tools)
NUT (Network UPS Tools)
=======================
The [NUT](http://www.networkupstools.org/ "http://www.networkupstools.org/")
package can be useful if you have an UPS connected to the router. For example, you have multiple devices connected to the UPS (PC, NAS ...), but your router is the only device that runs 24/7 (or at least it runs most of the time). In this case you run NUT in _netserver_ mode, where other devices connect to router to see UPS status and be able to shut down correctly if power fails. NUT must be installed on every machine using this feature.
NUT can be installed from packages feed.
NUT was updated with more UCI in commit [a23c4e85](https://github.com/openwrt/packages/commit/a23c4e85c5f6c9f9dcf67743b93c492ba833e365 "https://github.com/openwrt/packages/commit/a23c4e85c5f6c9f9dcf67743b93c492ba833e365")
, which appears in the 18.06 release.
18.06 and beyond
----------------
NOTE: configuration has **changed**: It's now all done through UCI (see below) (and the UCI is changed).
If you wish to use a 'standard' NUT config just remove the symlinks in /etc/nut and replace them with regular NUT configuration files.
### 18.06 / Commit a23c4e85
Due to changes in procd (or the OpenWrt shell wrapper around starting and stopping services with procd) stopping/restarting NUT stopped working properly. Work is underway to remedy this. Unfortunately issues were not reported before the 18.06 release. 18.06.1 has fixes for the most troublesome of the issues, and 18.06.2 should resolve the rest.
[PR #7638](https://github.com/openwrt/packages/pull/7638 "https://github.com/openwrt/packages/pull/7638")
/ [Commmit c95a1d3](https://github.com/openwrt/packages/commit/c95a1d3da89cb62eacc1d8217b861b36194d8838 "https://github.com/openwrt/packages/commit/c95a1d3da89cb62eacc1d8217b861b36194d8838")
Resolves these issues in the 18.06 branch. This should be in the next 18.06.x point release (18.06.2).
See ~[PR #6987](https://github.com/openwrt/packages/pull/6897 "https://github.com/openwrt/packages/pull/6897")
, [Issue #6997](https://github.com/openwrt/packages/issues/6997 "https://github.com/openwrt/packages/issues/6997")
, [Issue #6966](https://github.com/openwrt/packages/issues/6966 "https://github.com/openwrt/packages/issues/6966")
, and [Issue #6843](https://github.com/openwrt/packages/issues/6843 "https://github.com/openwrt/packages/issues/6843")
~
### Commit f48b060 on master
With [Commit f48b060 on master](https://github.com/openwrt/packages/commit/f48b060fa752fdf6556080dc1af221363f9b1ef4 "https://github.com/openwrt/packages/commit/f48b060fa752fdf6556080dc1af221363f9b1ef4")
all known issues are resolved.
[Commit 8ff6a83](https://github.com/openwrt/packages/pull/7167/commits/8ff6a83a541b114437eab170a0760c1c04263aa2 "https://github.com/openwrt/packages/pull/7167/commits/8ff6a83a541b114437eab170a0760c1c04263aa2")
adds building of serial drivers by default.
[Commit daa974c](https://github.com/openwrt/packages/pull/7167/commits/daa974cff0bef94c71277e703c32b3fd36f1411b "https://github.com/openwrt/packages/pull/7167/commits/daa974cff0bef94c71277e703c32b3fd36f1411b")
completes the USB UPS hotplugging in which a USB UPS driver can be run as non-root and the USB device will be given the right permissions.
[Commit a5d06ce](https://github.com/openwrt/packages/pull/7592/commits/a5d06ce1106644b26a1b9d0ad87220d772d6b862 "https://github.com/openwrt/packages/pull/7592/commits/a5d06ce1106644b26a1b9d0ad87220d772d6b862")
adds hotplug support for serial UPSes when using a standare serial-to-USB cable.
### Package Selection
| Package | Purpose |
| --- | --- |
| nut | Required to enable the 'real' packages |
| nut-common | Required for all NUT packages |
| nut-server | NUT server or standalone; only for the host attached directly to the UPS. Note will require a 'nut-dirver-xxx' driver to actually connect to the UPS. |
| nut-upsmon | Monitoring and/or triggering shutdown (e.g. client mode; can be on a server too and is in fact recommended on all hosts). |
| nut-upsc | Command line client for querying UPS status |
| nut-upscmd | Perform 'instant commands' on UPS (e.g. remote shutdown) if supported by UPS |
| nut-upslog | Read UPS log variables and write them to a file |
| nut-upsrw | Set variables on UPS (e.g. buzzer status) if supported by UPS |
| nut-upssched | Schedule script actions from some time after a UPS event |
| nut-upsmon-sendmail-notify | Send an email via sendmail command on a UPS event. In 18.06, added in commit [c94e334c4](https://github.com/openwrt/packages/commit/c94e334c4e5251d09995e3f6c8b80d61928a451c#diff-4ea671be370e4ab06ffeb50e1312d11e "https://github.com/openwrt/packages/commit/c94e334c4e5251d09995e3f6c8b80d61928a451c#diff-4ea671be370e4ab06ffeb50e1312d11e") |
| nut-web-cgi | A 'web' (e.g. uhttpd) GUI for monitoring the UPS |
| nut-avahi-service | Advertise the UPS server via mDNS (avahi-daemon only) |
| nut-driver-xxx | Where xxx is a driver from the list below |
#### UPS Drivers
See [NUT Stable Hardware Compatibility List](https://networkupstools.org/stable-hcl.html "https://networkupstools.org/stable-hcl.html")
to match your UPS model to a driver.
##### Serial
* al175
* bcmxcp
* belkin
* belkinunv
* bestfcom
* bestfortress
* bestuferrups
* bestups
* dummy-ups
* etapro
* everups
* gamatronic
* genericups
* isbmex
* liebert
* liebert-esp2
* masterguard
* metasys
* oldm
* e-shut
* mge-utalk
* microdowell
* mge-shut
* oneac
* optiups
* powercom
* rhino
* safenet
* solis
* tripplite
* tripplitesu
* upscode2
* victronups
* powerpanel
* blazer\_ser
* clone
* ivtscd
* apcsmart
* apcsmart-old
* apcupsd-ups
* riello\_ser
##### SNMP
* snmp-ups
##### USB
* usbhid-ups
* bcmxcp\_usb
* tripplite\_usb
* blazer\_usb
* richcomm\_usb
* riello\_usb
* nutdrv\_atcl\_
* usb nutdrv\_qx
LuCI app
--------
There was a Pull Request ([#936](https://github.com/openwrt/luci/pull/936 "https://github.com/openwrt/luci/pull/936")
) for a LuCI app for the new configuration that sadly never made into 18.06, for complicated reasons that are non-technical, but is merged in a modified form into master.
18.06.x+ UCI files
------------------
| File | Purpose |
| --- | --- |
| [nut\_cgi](https://openwrt.org/docs/guide-user/services/ups/software.nut#nut_cgi "docs:guide-user:services:ups:software.nut") | configure nut-cgi |
| [nut\_monitor](https://openwrt.org/docs/guide-user/services/ups/software.nut#nut_monitor "docs:guide-user:services:ups:software.nut") | configure nut-monitor |
| [nut\_server](https://openwrt.org/docs/guide-user/services/ups/software.nut#nut_server "docs:guide-user:services:ups:software.nut") | configure nut-server |
UCI Configuration (18.06.x+)
----------------------------
### nut\_server
There can be more than one of each section (as appropriate)
#### config driver\_global
[Commit 44e57d4](https://github.com/openwrt/packages/commit/44e57d4bdfe93214e9c031f181533bb0e4ef25ca "https://github.com/openwrt/packages/commit/44e57d4bdfe93214e9c031f181533bb0e4ef25ca")
(adds the following variables) and [Commit f48b060](https://github.com/openwrt/packages/commit/f48b060fa752fdf6556080dc1af221363f9b1ef4 "https://github.com/openwrt/packages/commit/f48b060fa752fdf6556080dc1af221363f9b1ef4")
(fixes synchronous setting)
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| chroot | string | no | _none_ | chroot directory |
| driverpath | string | no | /lib/nut | Where to search for drivers |
| maxstartdelay | integer | no | _none_ | Override default for UPSes not specifying this field |
| maxretry | integer | no | 1 | Number of time to retry loading driver (apart from procd's respawn) initially |
| retrydelay | integer | no | 5 | Number of seconds between retries |
| pollinterval | integer | no | 2 | Maximum number of seconds between UPS status refresh |
| synchronous | boolean string | no | no | Whether reading from UPS has to empty pipe before more data written |
| user | string | no | nut | If run as root, user to which to drop privileges |
#### config driver 'upsname'
**NB**: From 18.06
The config section name (e.g. 'upsname' above) will be used a the ups name.
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| driver | string | yes | _none_ | Driver for the model of UPS (see list above and [NUT HCL for stable release](https://networkupstools.org/stable-hcl.html "https://networkupstools.org/stable-hcl.html") ) |
| port | string | yes | ? (shouldn't rely on anyway) | Port on which the UPS is attached (or auto for auto-detection with USB) |
| other | string | varies | _none_ | see HCL above |
| runas | string | no | _none_ | User as which to run the daemon (note that means the USB device has in /dev/bus/usb/xxxx has to be _writable_ by this user) |
As of [ceff6883](https://github.com/openwrt/packages/commit/ceff68837d4b8d5a9bd8bf1962e913b5203d95e5 "https://github.com/openwrt/packages/commit/ceff68837d4b8d5a9bd8bf1962e913b5203d95e5")
adding random parameters was removed and only pre-defined parameters are allowed.
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| mfr | string | no | _none_ | Manufacturer description string |
| model | string | no | _none_ | Model description string |
| serial | string | no | _none_ | Serial number description string or regex match for serial number (depends on driver) |
| sdtime | integer | no | _none_ | Number of seconds for driver to sleep after sending shutdown signal |
| offdelay | integer | no | 20 | Number of seconds UPS will wait before shutting down after receiving shutdown signal |
| ondelay | integer | no | 30 | Number of seconds UPS will wait before powering up if still on mains after shutdown (must be less than ondelay) |
| pollfreq | integer | no | 30 | How often driver will poll UPS for data |
| vendor | string | no | _none_ | regex to match USB vendor string |
| product | string | no | _none_ | regex to match USB product string |
| bus | string | no | _none_ | regex to match a specific USB bus or group of busses |
| interruptonly | boolean | no | false | flag to driver to do no polling, only get data by interrupts (push) from UPS |
| interruptsize | integer | no | _none_ | limit interrupt data to given number of bytes; e.g. for some PowerCom units |
| maxreport | boolean | no | false | With this option, the driver activates a tweak to workaround buggy firmware returning invalid HID report length. Some APC Back-UPS units are known to have this bug. |
| vendorid | string | no | _none_ | regex: Match only UPSes with this USB vendorid |
| productid | string | no | _none_ | regex: Match only UPSes with this USB productid |
| community | string | no | public | For snmp-ups: community to poll UPS |
| snmp\_version | v1, v2c, or v3 | no | v1 | For snmp-ups: SNMP version |
| snmp\_retries | integer | no | 5 | Number of Net-SNMP tries |
| snmp\_timeout | integer | no | 1 | Number of seconds between Net-SNMP retries |
| notransferoids | boolean | no | false | Disable the monitoring of the low and high voltage transfer OIDs in the hardware. This will remove input.transfer.low and input.transfer.high from the list of variables. This should only be used on APCC Symmetra equipment which has strangeness in the three-phase power reporting. |
[Commit 44e57d4](https://github.com/openwrt/packages/commit/44e57d4bdfe93214e9c031f181533bb0e4ef25ca "https://github.com/openwrt/packages/commit/44e57d4bdfe93214e9c031f181533bb0e4ef25ca")
(adds the following variables)
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| synchronous | yes or no | no | no | Whether UPS must read all data from UPS before getting new data |
| maxstartdelay | integer | no | 45 | How long NUT waits for driver to start before giving up |
| retrydelay | integer | no | 5 | How long NUT waits to retry starting driver |
| override | list of strings | no | _none_ | names of 'override' config sections (below) |
| default | list of strings | no | _none_ | names of 'default' config sections (below) |
| other | list of strings | no | _none_ | names of 'other' config sections (below) |
| otherflags | list of strings | no | _none_ | names of 'otherflag' config sections (below) |
config override 'override\_\[variable\_name\]'
e.g. `config override 'override_battery_charge_low`' creates ups.conf entry for `override.battery.charge.low =`
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| value | varies | yes | _none_ | Value driver 'pretends' UPS sent |
config default 'default\_\[variable\_name\]'
e.g. `config default 'default_battery_charge_low`' creates ups.conf entry for `default.battery.charge.low =`
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| value | varies | yes | _none_ | Value driver 'pretends' UPS sent unless UPS actually sends a value |
config override 'other\_\[parameter\]'
e.g. `config other 'other_parameter`' creates ups.conf entry for `parameter =`
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| value | varies | yes | _none_ | A way to handle currently unknown (to UCI) parameters |
config override 'otherflag\_\[parameter\]'
e.g. `config override 'otherflag_extraflag`' creates ups.conf entry for `extraflag`
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| value | boolean | yes | false | A way to handle currently unknown (to UCI) flags |
#### config user
**NB** From 18.06
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| username | string | yes | ? (probably not) | 'username' (NUT only) for accessing a this server with e.g. upsmon (local or remote) |
| password | password | yes | _none_ | password for the above user |
| actions | string | no | _none_ | optional action (only listed allowed) |
| instcmd | list of strings | no | _none_ | |
| upsmon | ('slave' or 'master') | yes | ? | Whether client is a 'slave' for 'master'. slaves are dependent on masters and can't shutdown the UPS on low UPS power; used for multiple hosts on the same UPS |
#### config listen\_address
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| address | IPv4 or IPv6 address | yes | ::1 | Address to which to bind server (can be a wildcard address such as 0.0.0.0) |
| port | tcp port | yes | 3493 | Port on which to listen |
#### config upsd 'upsd'
There should only be on 'upsd' section and it should be named 'upsd'
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| maxage | integer | yes | 15 | Maximum number of seconds before data is considered 'stale' |
| statepath | string | yes | /var/run/nut | Where to store runtime data |
| maxconn | integer | yes | 102 | Maximum number of connections to accept at once |
| certfile | path | no | _none_ | Only for SSL\-enabled builds; path to SSL certificate |
### nut\_server default file
#config driver 'upsname'
# option driver usbhid-ups
# option port auto
# option other other-value
# option runas root
#config user
# option username upsuser
# option password upspassword
# option actions optional-action
# list instcmd optional-instant-command
# option upsmon slave|master
#config listen\_address
# option address ::1
# option port 3493
#config upsd 'upsd'
# option maxage 15
# option statepath /var/run/nut
# option maxconn 1024
# NB: certificates only apply to SSL-enabled version
# option certfile /usr/local/etc/upsd.pem
### nut\_server working example
config driver 'eaton5p'
option driver usbhid-ups
option port auto
config user
option username upsuser
option password somepassword
option upsmon master
# For a netserver, otherwise the default ::1 (localhost) is fine
config listen\_address
option 0.0.0.0
config upsd upsd
### nut\_monitor
#### config upsmon 'upsmon'
There should be only one upsmon section and should be named 'upsmon'
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| runas | string | yes | nut | User as which to execute upsmon |
| minsupplies | integer | yes | 1 | Not OpenWrt relevent (Datacentre use) minimum number of UPSes that have to be supplying power to host |
| shutdowncmd | path | yes | /sbin/halt | Command to run on UPS clean shutdown (either due to lower power, or NUT action |
| notifycmd | path | no | _none_ | Command to execute if 'notify' type EXEC is set |
| defaultnotify | list of SYSLOG or EXEC or IGNORE or WALL | yes | SYSLOG | How to notify of UPS monitoring events. Note that nut-upsmond-sendmail-notify sets _notifycmd_ to a script which emits a message via email (using 'sendmail' command in standard location) and adds EXEC to _defaultnotify_ |
| pollfreq | integer | yes | 5 | Time in seconds to query the NUT server |
| pollfreqalert | integer | yes | 5 | Time in seconds to query the NUT server while on battery |
| hostsync | integer | yes | 15 | From [upsmon.conf man page (official)](https://networkupstools.org/docs/man/upsmon.conf.html "https://networkupstools.org/docs/man/upsmon.conf.html") upsmon will wait up to this many seconds in master mode for the slaves to disconnect during a shutdown situation. By default, this is 15 seconds. When a UPS goes critical (on battery + low battery, or “FSD”: forced shutdown), the slaves are supposed to disconnect and shut down right away. The HOSTSYNC timer keeps the master upsmon from sitting there forever if one of the slaves gets stuck. This value is also used to keep slave systems from getting stuck if the master fails to respond in time. After a UPS becomes critical, the slave will wait up to HOSTSYNC seconds for the master to set the FSD flag. If that timer expires, the slave will assume that the master is broken and will shut down anyway. This keeps the slaves from shutting down during a short-lived status change to “OB LB” that the slaves see but the master misses. |
| deadtime | integer | yes | 15 | How long a server can go missing before declaring it 'dead' |
| powerdownflags | path | no | /var/run/killpower | If NUT sees this file it will powerdown the UPS(es) |
| finaldelay | integer | yes | 15 | From [upsmon.conf man page (official)](https://networkupstools.org/docs/man/upsmon.conf.html "https://networkupstools.org/docs/man/upsmon.conf.html") When running in master mode, upsmon waits this long after sending the NOTIFY\_SHUTDOWN to warn the users. After the timer elapses, it then runs your SHUTDOWNCMD. By default this is set to 5 seconds. If you need to let your users do something in between those events, increase this number. Remember, at this point your UPS battery is almost depleted, so don’t make this too big. Alternatively, you can set this very low so you don’t wait around when it’s time to shut down. Some UPSes don’t give much warning for low battery and will require a value of 0 here for a safe shutdown. |
| certpath | path | no | /etc/ssl/certs | Only for SSL\-enabled builds: Path to directory containing CA certificates for validating SSL certificates |
| certverify | boolean | no | false | Only for SSL\-enabled builds: server CommonName must match DNS name we are using |
| forcessl | boolean | no | false | Only for SSL\-enabled builds: implied by certverify; without certverfy requires the connection is at least encrypted |
For each of (lowercased):
* COMOK
* COMBAD
* SHUTDOWN
* REPLBATTERY
* NOCOMMS
* NOPARENT
* ONLINE
* ONBATT
* LOWBATT
* FSD
There are 'XXXmsg' and 'XXXnotifyflag' options (e.g. 'comokmsg' and 'comoknotifyflag').
This are all optional. The 'msg' options are strings and are messages to emit instead of the default on one of the above conditions (see [upsmon.conf man page (official)](https://networkupstools.org/docs/man/upsmon.conf.html "https://networkupstools.org/docs/man/upsmon.conf.html")
).
The 'notifyflag' options are boolean (default true) and indicate whether to emit the message using the 'defaultnotify' setting or to not emit a message (IGNORE) setting for that message.
#### config master and config slave
##### Slave vs. Master
From 'UPS TYPES' in [upsmon manpage (official)](https://networkupstools.org/docs/man/upsmon.html "https://networkupstools.org/docs/man/upsmon.html")
upsmon and upsd(8) don’t always run on the same system. When they do, any UPSes that are directly attached to the upsmon host should be monitored in “master” mode. This makes upsmon take charge of that equipment, and it will wait for slaves to disconnect before shutting down the local system. This allows the distant systems (monitoring over the network) to shut down cleanly before upsdrvctl shutdown runs and turns them all off.
When upsmon runs as a slave, it is relying on the distant system to tell it about the state of the UPS. When that UPS goes critical (on battery and low battery), it immediately invokes the local shutdown command. This needs to happen quickly. Once it disconnects from the distant upsd(8) server, the master upsmon will start its own shutdown process. Your slaves must all shut down before the master turns off the power or filesystem damage may result.
upsmon deals with slaves that get wedged, hang, or otherwise fail to disconnect from upsd(8) in a timely manner with the HOSTSYNC timer. During a shutdown situation, the master upsmon will give up after this interval and it will shut down anyway. This keeps the master from sitting there forever (which would endanger that host) if a slave should break somehow. This defaults to 15 seconds.
If your master system is shutting down too quickly, set the FINALDELAY interval to something greater than the default 15 seconds. Don’t set this too high, or your UPS battery may run out of power before the master upsmon process shuts down that system
##### options
| Option | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| upsname | string | yes | _none_ | name assigned to the UPS by the server |
| hostname | string | yes | _none_ | host with the UPS server (dns name or ip) |
| port | tcp port | no | 3493 | port on which to connect to server |
| powervalue | integer | yes | 1 | Number of UPSes supplying this host from the server |
| username | string | yes | _none_ | NUT username for connecting to the server |
| password | password | yes | _none_ | NUT password for the user for connecting to the server |
### nut\_monitor default file
#config upsmon 'upsmon'
# option runas run-as-user
# option minsupplies 1
# option shutdowncmd /sbin/halt
# option notifycmd /path/to/cmd
# list defaultnotify SYSLOG
# option pollfreq 5
# option pollfreqalert 5
# option hostsync 15
# option deadtime 15
# option powerdownflags /var/run/killpower
# option onlinemsg "online message"
# option onbattmsg "on battery message"
# option lowbattmsg "low battery message"
# option fsdmsg "forced shutdown message"
# option comokmsg "communications restored message"
# option combadmsg "communications bad message"
# option shutdowmsg "shutdown message"
# option replbattmsg "replace battery message"
# option nocommmsg "no communications message"
# option noparentmsg "no parent message"
# option onlinenotify "online notify flag 1|0"
# option onbattnotify "on battery notify flag 1|0"
# option lowbattnotify "low battery notify flag 1|0"
# option fsdnotify "forced shutdown notify flag 1|0"
# option comoknotify "communications restored notify flag 1|0"
# option combadnotify "communications bad notify flag 1|0"
# option shutdownotify "shutdown notify flag 1|0"
# option replbattnotify "replace battery notify flag 1|0"
# option nocommnotify "no communications notify flag 1|0"
# option noparentnotify "no parent notify flag 1|0"
# option rbwarntime 4200 # replace battery warn time
# option nocommwarntime 300 # no communications warn time
# option finaldelay 5 # final delay
# option certpath /path/to/ca/dir
# option certverify 0
# option forcessl 0
#config master
# option upsname upsname
# option hostname localhost
# option port # optional port number
# option powervalue 1
# option username upsuser
# option password upspassword
#config slave
# option upsname upsname
# option hostname localhost
# option port # optional port number
# option powervalue 1
# option username upsuser
# option password upspassword
### nut\_monitor working example
config 'upsmon' upsmon
config master
option upsname eaton5p
option hostname localhost
option username upsuser
option password somepassword
### nut\_cgi
The NUT CGI doensn't have to be on the same server as nut-monitor or nut-server.
It does however require a webserver installed (default configuration is for uhttpd).
| Option | Type | Required | Default | |
| --- | --- | --- | --- | --- |
| upsname | upsname | yes | _none_ | Name of UPS to monitor (as configured in nut\_server) |
| hostname | hostname | yes | _none_ | Name or IP of NUT server |
| port | tcp port | no | 3493 | Port on which to connect to NUT server |
| displayname | string | yes | none | What to show in Web UI as the UPS name |
### nut\_cgi default config file
#config host
# option upsname upsname
# option hostname localhost
# option port # optional port number
# option displayname "Display Name"
### nut\_cgi working example
config host
option uspsname eaton5p
option hostname localhost
option displayname "Eaton 5P"
Pre 18.06
---------
In _older release(s)_ there's problem with some USB UPSes (e.g. EATON) that are not recognized by usbhid-ups. This is apparently a bug in libusb-compat, since libusb (0.1.4) can recognize them. You can work around this by installing Attitude Adjustment, manually installing packages _libusb-compat_ and **nut-driver-usbhid-ups**, then manualy remove _libusb-compat_ and install **libusb** istead (packages in trunk may break on having manually installed libusb)
You will want to have packages **nut**, **nut-server** and **nut-client** packages installed to have main functionality.
**NOTE** UCI configuration has changed for 18.06 (as of the commit above).
You may want to have nut-monitor installed, if you want to shutdown your router when UPS power goes critical and your device can turn itself off. Otherwise, the UPS will only provide information for you and clients.
NUT expects configuration by [UCI](https://openwrt.org/docs/techref/uci "docs:techref:uci")
, by putting the following into **/etc/config/ups**:
config driver 'eaton'
option driver 'usbhid-ups'
option port 'auto'
config user
option username 'guest'
option password 'guest'
option upsmon 'slave'
For the NUT to run at all, you must change the MODE in **/etc/nut/nut.conf** to e.g. netserver:
MODE=netserver
If you want the upsd be acccessible from network (why otherwise would you want to run nut on router?), you must put a LISTEN directive to **/etc/nut/upsd.conf**:
LISTEN 0.0.0.0
You may want to change options according to the type of UPS you have and options you want to use.
### Configuring upsmon
After you installed and configured NUT, you may want to setup your router for monitoring UPS. You need to install _nut-monitor_ package and add your config to **/etc/config/upsmon**
Sample upsmon config
config upsmon
option 'shutdowncmd' '/lib/nut/upsdrvctl shutdown'
option 'notifycmd' '/etc/nut/notify.sh'
option 'onlinemsg' 'UPS %s on line power'
option 'onbattmsg' 'UPS %s on battery'
option 'lowbattmsg' 'UPS %s battery is low'
option 'fsdmsg' 'UPS %s: forced shutdown in progress'
option 'commokmsg' 'Communications with UPS %s established'
option 'commbadmsg' 'Communications with UPS %s lost'
option 'shutdownmsg' 'Auto logout and shutdown proceeding'
option 'replbattmsg' 'UPS %s battery needs to be replaced'
option 'nocommmsg' 'UPS %s is unavailable'
option 'noparentmsg' 'upsmon parent process died - shutdown impossible'
option 'onlinenotify' 'EXEC+SYSLOG'
option 'onbattnotify' 'EXEC+SYSLOG'
option 'lowbattnotify' 'EXEC+SYSLOG'
option 'fsdnotify' 'EXEC+SYSLOG'
option 'commoknotify' 'EXEC+SYSLOG'
option 'commbadnotify' 'EXEC+SYSLOG'
option 'shutdownnotify' 'EXEC+SYSLOG'
option 'replbattnotify' 'EXEC+SYSLOG'
option 'nocommnotify' 'EXEC+SYSLOG'
option 'noparentnotify' 'EXEC+SYSLOG'
config master
option 'upsname' 'UPS'
option 'user' 'guest'
option 'password' 'guest'
Upsmon will send to _notifycmd_ script some environment strings:
$UPSNAME - will contain the name of UPS specified in /etc/config/ups
$NOTIFYTYPE - will contain the type string of whatever caused this event to happen.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/08/31 07:08
* by tmomas
[](https://openwrt.org/docs/guide-user/services/ups/software.nut#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Cloudflare tunnel
Cloudflare tunnel
=================
> [Cloudflare Tunnel](https://www.cloudflare.com/products/tunnel/ "https://www.cloudflare.com/products/tunnel/")
> provides you with a secure way to connect your resources to [Cloudflare](https://www.cloudflare.com/ "https://www.cloudflare.com/")
> without a publicly routable IP address. With Tunnel, you do not send traffic to an external IP — instead, a lightweight daemon in your infrastructure `cloudflared` creates outbound-only connections to Cloudflare’s global network. [Cloudflare Tunnel](https://www.cloudflare.com/products/tunnel/ "https://www.cloudflare.com/products/tunnel/")
> can connect HTTP web servers, SSH servers, remote desktops, and other protocols safely to [Cloudflare](https://www.cloudflare.com/ "https://www.cloudflare.com/")
> . This way, your origins can serve traffic through [Cloudflare](https://www.cloudflare.com/ "https://www.cloudflare.com/")
> without being vulnerable to attacks that bypass [Cloudflare](https://www.cloudflare.com/ "https://www.cloudflare.com/")
> .
Beyond enhancing security and privacy, Cloudflare Zero Trust Tunnel is frequently used for NAT traversal, especially in environments with [CGN](https://en.wikipedia.org/wiki/Carrier-grade_NAT "https://en.wikipedia.org/wiki/Carrier-grade_NAT")
.
Site
----
Start by creating an account at [https://www.cloudflare.com/plans/](https://www.cloudflare.com/plans/ "https://www.cloudflare.com/plans/")
. The _free plan_ is sufficient for most users.
You require a domain to add as a site to Cloudflare's service. You receive instructions on how to point the domain to selected Cloudflare DNS servers Sometimes it takes a while for DNS to propagate. In the meantime set up the rest of your settings. I registered a cheap domain specific for this purpose and have no plans to host anything there for an audience. Finally, once DNS has propagated and your site's status says active, we can proceed.
### Zero trust
Select _Zero Trust_ from the sidebar; this is where tunnels are managed. Set up things as you like. For example, under _Gateway_ you find DNS and Firewall policies; there is no need to touch them at all to get tunnel(s) working. Under _Settings_ → _General settings_ you can find your **Team domain**. The sub-domain/hostname part, meaning that part before _.cloudflareaccess.com_ is something that you should remember. When you log in with **WARP** (available for desktop OSs and phones) to establish a client connection, this Team ID is asked upon logon. So write it down if it is difficult to remember.
### Important note
Under _Settings_ → _Network_ are settings for the proxy. To get tunnels working, you **must** enable the proxy. By default, it seems to be disabled. When you enable it, you can select either TCP or UDP, or both. This part is rarely mentioned in other guides.
Other settings on that page are not important for tunneling, except _Split tunnels and local domain fallback_ - so select **manage**. There, are settings for **device enrolments**. Make necessary changes there for login requirements. For example, _\*.yourmaildomain.com_.
Edit also the _default profile_ - there you find the section _Split tunnels_. Select what you prefer. In this example, we choose to **Exclude IPs and domains**. Click _manage_ then find a list of subnets, IP addresses, and domain names. Make sure that the network you want to connect to is not on the list. For example, if your LAN is 192.168.0.1/24, make sure none of the subnets on the list include your used IP range.
For service mode, I chose _Gateway with WARP_. Unsure whether other modes work. It should be chosen as default.
If you want local DNS to resolve to IP addresses, set this under _Local Domain Fallback_. As I did not use it, I cannot comment.
On _Device posture_, as _WARP Client checks_, I added **Gateway** with name _Gateway_ - but that is possibly not a requirement. Other settings on that page can be left as-is.
Finally, basic setup is complete. **Keep your browser open and make sure you stay logged in to Cloudflare**.
OpenWrt shell
-------------
Login to your router and install _cloudflared_ package:
opkg update
opkg install cloudflared
Settings are in `/etc/config/cloudflared`, but the only setting that should be changed is the `enabled` boolean. It is `false` by default.
Another location is at `/etc/cloudflared`, some changes there are necessary but at this moment, we won't touch anything there.
Let's create our tunnel
-----------------------
You can create a tunnel in the Cloudflare dashboard or via command line on your machine (“locally managed”).
Go to Zero Trust Dashboard at [https://one.dash.cloudflare.com/](https://one.dash.cloudflare.com/ "https://one.dash.cloudflare.com/")
Open _Networks_ → _Tunnels_ and click on _Create a tunnel_.
You can copy the token from “4. Run the following command:” and put it into `/etc/config/cloudflared` option `token`.
Then you need to specify a Public Hostname with type HTTP and URL `[http://localhost:80](http://localhost/ "http://localhost:80") ` where your Luci or website is running.
Then restart daemon with `/etc/init.d/cloudflared restart`. It may take up to 3 minutes while the tunnel will be established. Once you see in logs `Updated to new configuration config=“{\”ingress\` then your local tunnel was established and received its config.
Since a tunnel is configured remotely you may need to open `/etc/cloudflared/config.yml` and comment all lines there.
Create tunnel from a command line
---------------------------------
First you'll need to run `cloudflared tunnel login`:
root@openwrt:/etc/cloudflared# cloudflared tunnel login
Please open the following URL and log in with your Cloudflare account:
https://dash.cloudflare.com/argotunnel?callback=https%3A%2F%2Flogin.cloudflareaccess.org%2FXXXXXXXXXX
Leave cloudflared running to download the cert automatically.
Copy the link and open it in your **browser** to proceed. If you were still logged in, you will get a view where you see the site as option that we added in the beginning. Select your site and click **Authorize**.
Go back to your OpenWrt shell, and you see a notification that **cert.pem** has been created. We copy it to `cloudflared`s **config path**.
You have successfully logged in.
If you wish to copy your credentials to a server, they have been saved to:
/root/.cloudflared/cert.pem
root@openwrt:/etc/cloudflared# cp /root/.cloudflared/cert.pem /etc/cloudflared/
Next we create the tunnel named `TUNNELNAME`. Copy the generated `json` config file to the `/etc/cloudflared/` config path. `XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX` is the generated id.
root@openwrt:/etc/cloudflared# cloudflared tunnel create TUNNELNAME
Tunnel credentials written to /root/.cloudflared/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX.json. cloudflared chose this file based on where your origin certificate was found. Keep this file secret. To revoke these credentials, delete the tunnel.
Created tunnel TUNNELNAME with id XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
root@openwrt:/etc/cloudflared# cp /root/.cloudflared/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX.json /etc/cloudflared/
#### Get JSON file from configured tunnel token
**I already created my tunnel from CF dashboard, how can i get json file?**
Token and JSON actually contain the same information, just in slightly different formats.
**How to convert token to JSON**
1. Decode token from base64. It will become a JSON data with one-letter keys.
2. Replace keys with longer versions: a → AccountTag, t → TunnelID, s → TunnelSecret.
**How to convert JSON to token**
Just the opposite:
1. Convert keys to short versions: AccountTag → a, TunnelID → t, TunnelSecret → s
2. Remove whitespaces and line ends, if any
3. Encode to base64, probably removing trailing = if any.
Edit `/etc/cloudflared/config.yml`: I commented out the first line about the URL which is superfluous:
[/etc/cloudflared/config.yml](https://openwrt.org/_export/code/docs/guide-user/services/vpn/cloudfare_tunnel?codeblock=4 "Download Snippet")
#url: http://localhost:8000
tunnel: XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX
credentials-file: /etc/cloudflared/XXXXXXXX-XXXX-XXXX-XXXX-XXXXXXXXXXXX.json
I got errors logged about wrong `sysctl` values so put the settings to I created the `/etc/sysctl.d/30-cloudflared-conf` file:
[/etc/sysctl.d/30-cloudflared-conf](https://openwrt.org/_export/code/docs/guide-user/services/vpn/cloudfare_tunnel?codeblock=5 "Download Snippet")
net.ipv4.ping\_group\_range="0 429296729"
net.core.rmem\_max=2500000
After this, restart the service: `/etc/init.d/cloudflared restart`
Return to the browser and at _Cloudflare Zero Trust_, open _Access_ → _Tunnels_. In the list should be our freshly created `TUNNELNAME`.
Choose to configure it and you are prompted that `TUNNELNAME` must be irreversibly migrated. Go ahead and migrate it, confirm all queries. Now, re-configure it. Choose _Private Network_ tab and add new network. On the CIDR prompt add your LAN subnet. In this example it was 192.168.0.0/24.
After this we enable, and restart `cloudflared`:
/etc/init.d/cloudflared stop
/etc/init.d/cloudflared enable
/etc/init.d/cloudflared start
Test network
------------
Install **Cloudflare WARP** to your phone, **disable wi-fi** staying on the mobile network and start **WARP**. In _Settings_ → _Account_, enter your **team name**. This is in Cloudflare _General Settings_. If you added suitable rules to _Settings_ → _Warp settings_ → _Device enrollment_ you will be asked your credentials, i.e. email address. You are emailed a verification code which you need to enter there.
Under _WARP's Settings_ → _Advanced_ → _Connection options_ → _Excluded routes_ verify that your LAN subnet is absent from the list - we previously excluded it. Under _Virtual Networks_, verify that the profile you chose is checked. I edited the default profile without creating a new one. Finally, exit settings. The front page should say Zero Trust, Connected and Your internet is protected. Open your web browser and point it to your **router's IP** at 192.168.0.1 and if all went well, LuCi opens (in case you have it installed).
One final note
--------------
You may notice that ICMP **ping** doesn't work. This is normal and you cannot do anything about it because we enabled TCP and UDP, while **ICMP** used by ping is unavailable as a feature on `cloudflared`.
If you see a message “failed to dial to edge with quic” this is a known issue [https://github.com/openwrt/packages/issues/23596](https://github.com/openwrt/packages/issues/23596 "https://github.com/openwrt/packages/issues/23596")
. The UDP and QUIC are not so important unless you are on mobile internet with many packet loses.
See also
--------
* [Support forum](https://community.cloudflare.com/t/openwrt-support/610306 "https://community.cloudflare.com/t/openwrt-support/610306")
* [Tunnel general-purpose parameters](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/tunnel-run-parameters/ "https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/tunnel-run-parameters/")
* [config.yml file parameters](https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/local-management/configuration-file/ "https://developers.cloudflare.com/cloudflare-one/connections/connect-networks/configure-tunnels/local-management/configuration-file/")
* [install-cloudflared.sh](https://github.com/Coralesoft/OpenwrtCloudflare "https://github.com/Coralesoft/OpenwrtCloudflare")
Install wizard script
* [How to convert token to JSON](https://github.com/cloudflare/cloudflared/issues/929#issuecomment-2078157277 "https://github.com/cloudflare/cloudflared/issues/929#issuecomment-2078157277")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/12/30 07:12
* by stokito
[](https://openwrt.org/docs/guide-user/services/vpn/cloudfare_tunnel#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Netbird
Netbird
=======
NetBird is a modern, fully open-source Zero Trust VPN that provides a simple and secure way to connect users, devices, and services. It is built on WireGuard®, offering fast, encrypted peer-to-peer networking without the complexity of traditional VPN setups.
Unlike some alternatives, NetBird is fully open source and allows the entire control plane to be self-hosted. This can give full control over your networking infrastructure and data, and avoids dependency.
A free tier is available which is sufficient for small to medium sized networks with up to 5 users (admins) and 100 peers (routers, VPS, client PC, phone, etc.).
See the [Netbird website](https://netbird.io/ "https://netbird.io/")
for further information.
Installation
------------
For Installation and Setup instructions see: [Netbird](https://raw.githubusercontent.com/egc112/OpenWRT-egc-add-on/main/notes/OpenWRT%20Netbird.pdf "https://raw.githubusercontent.com/egc112/OpenWRT-egc-add-on/main/notes/OpenWRT%20Netbird.pdf")
for the latest instructions.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/12/20 11:03
* by egc112
[](https://openwrt.org/docs/guide-user/services/vpn/netbird#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Siproxd on OpenWrt intro
Siproxd on OpenWrt intro
========================
[Siproxd](http://siproxd.sourceforge.net/ "http://siproxd.sourceforge.net/")
is a proxy/masquerading daemon for the SIP protocol. It handles registrations of SIP clients on a private IP network and performs rewriting of the SIP message bodies to make SIP connections work via an masquerading firewall (NAT). It allows SIP software clients (like kphone, linphone) or SIP hardware clients (Voice over IP phones which are SIP-compatible) to work behind an IP masquerading firewall or NAT router.
Siproxd configuration
---------------------
In `/etc/config/siproxd` you can configure Siproxd. You can add to the default configuration to setup the plugins that you'd like to use. For example to load and configure the regex plugin something along the following lines would be appropriate:
\# Load regex plugin and define some replacement rules to ensure that
# local and domestic numbers without area/country code are dialled
# properly:
list load\_plugin 'plugin\_regex.so'
# International calls, prefix 00 converted to +:
# 00 385 1 123456 -> +385 1 123456
list plugin\_regex\_desc = 'Intl'
list plugin\_regex\_pattern = '^(sips?:)00'
list plugin\_regex\_replace = '\\1+'
# Domestic calls to a different area code, drop the 0 and prefix with
# country code added:
# 01 123456 -> +385 1 123456
list plugin\_regex\_desc = 'Domestic'
list plugin\_regex\_pattern = '^(sips?:)0'
list plugin\_regex\_replace = '\\1+385'
# Local calls without an area code - prefix with country code + local
# area code:
# 123456 -> +385 1 123456
list plugin\_regex\_desc = 'Local'
list plugin\_regex\_pattern = '^(sips?:)'
list plugin\_regex\_replace = '\\1+3851'
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/12/16 09:06
* by micmac1
[](https://openwrt.org/docs/guide-user/services/voip/siproxd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Hiawatha webserver
Hiawatha webserver
==================
* [Project Homepage](http://www.hiawatha-webserver.org/about "http://www.hiawatha-webserver.org/about")
and a [Request for Help with documentation](http://www.hiawatha-webserver.org/weblog/19 "http://www.hiawatha-webserver.org/weblog/19")
Package: hiawatha
Version: 7.3-1
Depends: libpthread
Provides:
Status: unknown ok not-installed
Section: net
Architecture: ar71xx
Maintainer: Raphaël HUCK
MD5Sum: 013b802807bc9ee359f09f693a55ea60
Size: 51090
Filename: hiawatha\_7.3-1\_ar71xx.ipk
Source: feeds/packages/net/hiawatha
Description: Hiawatha is an GPLv2 webserver with a focus on security written in C.
The documentation is pretty clearly arranged, so we do not have to provide redundant documentation, see:
* [Howto](http://www.hiawatha-webserver.org/howto "http://www.hiawatha-webserver.org/howto")
* _[manual page](http://www.hiawatha-webserver.org/manpages "http://www.hiawatha-webserver.org/manpages")
_ for `hiawatha`
Configuration
-------------
Example `[/etc/hiawatha/hiawatha.conf](http://www.hiawatha-webserver.org/howto/example_configuration "http://www.hiawatha-webserver.org/howto/example_configuration") `
Configuring Hiawatha and PHP5
-----------------------------
TODO
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/03/03 20:30
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/webserver/http.hiawatha#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Zerotier
Zerotier
========
Zerotier creates a virtual network between hosts. You may refer to [zerotier-openwrt's official Wiki](https://github.com/mwarning/zerotier-openwrt/wiki "https://github.com/mwarning/zerotier-openwrt/wiki")
for the latest instructions.
Installation
------------
apk add zerotier
Basic Configuration
-------------------
* Create virtual network on [Zerotier Central](https://my.zerotier.com/ "https://my.zerotier.com")
. Note the 16-digit _Network ID_.
* Add virtual network to the OpenWrt Zerotier config (the section name `mynet` is arbitrary, you can consistently replace it with whatever label you want)
For ZeroTier version 1.14.0 or older:
uci delete zerotier.sample\_config
uci add zerotier mynet
uci add\_list zerotier.mynet.join=
uci set zerotier.mynet.enabled='1'
uci commit zerotier
service zerotier restart
For ZeroTier version 1.14.1 or newer:
uci set zerotier.global.enabled='1'
uci delete zerotier.earth
uci set zerotier.mynet=network
uci set zerotier.mynet.id=
uci commit zerotier
service zerotier restart
The same defined in the configuration file (`/etc/config/zerotier`):
config zerotier 'global'
option enabled '1'
option secret ''
config network 'mynet'
option id 'put your network id here'
option allow\_managed '1'
option allow\_global '0'
option allow\_default '0'
option allow\_dns '0'
* When a new virtual network is joined, a new _secret_ will be generated, which may take a while. When it's finished, the _secret_ will be saved in `/etc/config/zerotier`, and router will make an attempt to attach to the virtual network.
* To use the virtual network, the device must be first authorized on Zerotier Central portal by clicking “Auth?” box next to the device under Members.
* Communication with other Zerotier nodes is usually done through port 9993/udp (it can be changed), and no additional configuration is needed for an out-of-the-box router configuration.
* Device connectivity (or online status) can be seen by using the “info” command, it will also show your 10-digit node address:
root@OpenWrt# zerotier-cli info
200 info xxxxxxxxxx 1.14.1 ONLINE
* Some services (eg dropbear, Luci) may need to be reconfigured to allow access from the new Zerotier virtual interface. The easy way is to un-restrict them from specific networks/interfaces.
* For dropbear (allow access from anywhere, potentially unsafe):
root@OpenWrt# cat /etc/config/dropbear
config dropbear
option PasswordAuth 'on'
option Port '22'
 You must reboot OpenWrt router at this point otherwise `ztXXXXXXXX` network device won't be created.
After reboot get the device name using your 16-digit Network ID:
root@OpenWrt# zerotier-cli get {network\_id} portDeviceName
ztXXXXXXXX
Alternatively run `zerotier-cli listnetworks`, that will give you the same name plus more details.
\# Create interface
uci \-q delete network.ZeroTier
uci set network.ZeroTier=interface
uci set network.ZeroTier.proto='none'
uci set network.ZeroTier.device='ztXXXXXXXX' \# Replace ztXXXXXXXX with your own ZeroTier device name
\# Configure firewall zone
uci add firewall zone
uci set firewall.@zone\[\-1\].name='vpn'
uci set firewall.@zone\[\-1\].input='ACCEPT'
uci set firewall.@zone\[\-1\].output='ACCEPT'
uci set firewall.@zone\[\-1\].forward='ACCEPT'
uci set firewall.@zone\[\-1\].masq='1'
uci add\_list firewall.@zone\[\-1\].network='ZeroTier'
uci add firewall forwarding
uci set firewall.@forwarding\[\-1\].src='vpn'
uci set firewall.@forwarding\[\-1\].dest='lan'
uci add firewall forwarding
uci set firewall.@forwarding\[\-1\].src='vpn'
uci set firewall.@forwarding\[\-1\].dest='wan'
uci add firewall forwarding
uci set firewall.@forwarding\[\-1\].src='lan'
uci set firewall.@forwarding\[\-1\].dest='vpn'
\# Commit changes
uci commit
\# Reboot
reboot
Advanced Configuration
----------------------
The [sample configuration](https://github.com/openwrt/packages/blob/master/net/zerotier/files/etc/config/zerotier "https://github.com/openwrt/packages/blob/master/net/zerotier/files/etc/config/zerotier")
is helpful to see which uci options are available for configuring the ZeroTier client.
While basic uci configuration of ZeroTier as shown above is supported, almost no advanced configuration support via uci has yet been added. The ZeroTier documentation requires manipulation of the configuration files for many advanced features. However, ZeroTier configurations are stored by default under /var/lib in Linux-based systems, which is a temporary filesystem in OpenWrt, where changes are not persistent. Instead, ordinarily OpenWrt writes a new configuration folder in that location based on the uci configuration above each time the service is started. These configuration files are lost on reboot or service restart, and rewritten each time the service starts again. For a basic configuration which will suit most users, this is not an issue.
In order to configure advanced features, two uci directives may be used to configure OpenWrt to load a copy of a persistent configuration folder from another location when starting the service, such as /etc/zerotier, which the user must first create and populate based on the simple copy made upon first joining a network. Once this persistent location is configured, the user may make persistent changes according to the ZeroTier documentation, with support for all current features otherwise enabled.
* Complete the basic configuration steps above to joint a working network, which will create a temporary copy of the configuration folder with which to start.
* Create the persistent folder in any permanent location (/etc/zerotier will be used for this example), and copy the contents of the temporary folder to the permanent location:
mkdir /etc/zerotier
cp \-r /var/lib/zerotier-one/\* /etc/zerotier/
* Add the directives to use the new persistent folder. The network name _deadbeef00_ will be used, similar to most ZeroTier documentation examples:
uci set zerotier.deadbeef00.config\_path='/etc/zerotier'
uci set zerotier.deadbeef00.copy\_config\_path='1'
uci commit zerotier
service zerotier restart
The router will now refer to the configuration in /etc/zerotier for persistent advanced changes. Restarting the service after any configuration changes using the last line above will reset and apply any changes made. Do not attempt to edit the configuration in the /var/lib/zerotier-one location, as this temporary location will still be overwritten on restart by the configuration in the new persistent directory.
### Local Configuration Options
ZeroTier client in OpenWrt also supports the use of “Local Configuration Options” described in the official [ZeroTier Documentation](https://docs.zerotier.com/config/#local-configuration-options "https://docs.zerotier.com/config/#local-configuration-options")
. What is called `local.conf` in the documentation can be used in OpenWrt by adding a line like this into “global” section of the main configuration file (`/etc/config/zerotier`):
option local\_conf\_path '/etc/zerotier.conf'
The configuration file referenced there should be in JSON format. The following example will instruct the local instance of ZeroTier to not use LAN and WireGuard interfaces to build the connections:
{
"settings": {
"interfacePrefixBlacklist": \[ "br","wg" \]
}
}
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/04/20 05:51
* by bartprokop
[](https://openwrt.org/docs/guide-user/services/vpn/zerotier#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Netcat as Webserver
Netcat as Webserver
===================
[Netcat](https://en.wikipedia.org/wiki/Netcat "https://en.wikipedia.org/wiki/Netcat")
is ...; manpage: [netcat](http://man.cx/netcat "http://man.cx/netcat")
As default OpenWrt installs
* `busybox-ash` (that is the Busybox-fork of the Debian implementation of the [Almquist shell](https://en.wikipedia.org/wiki/Almquist%20shell "https://en.wikipedia.org/wiki/Almquist shell")
(see → [http://www.in-ulm.de/~mascheck/various/ash/#busybox](http://www.in-ulm.de/~mascheck/various/ash/#busybox "http://www.in-ulm.de/~mascheck/various/ash/#busybox")
). In case you want to read about it.)
* `busybox-nc` (= the busybox implementation of netcat) does not support server mode.
You can anytime replace those packages by they original counterparts:
opkg install bash netcat
Examples:
* [https://forum.openwrt.org/viewtopic.php?pid=210001#p210001](https://forum.openwrt.org/viewtopic.php?pid=210001#p210001 "https://forum.openwrt.org/viewtopic.php?pid=210001#p210001")
* [http://www.razvantudorica.com/08/web-server-in-one-line-of-bash/](http://www.razvantudorica.com/08/web-server-in-one-line-of-bash/ "http://www.razvantudorica.com/08/web-server-in-one-line-of-bash/")
while true; do { echo \-e 'HTTP/1.1 200 OK\\r\\n'; cat /tmp/index.html; } | netcat \-l \-p 8080; done
* [https://github.com/TooTallNate/bashttpd](https://github.com/TooTallNate/bashttpd "https://github.com/TooTallNate/bashttpd")
- A web server written in bash , implementation that “Simplify things by using pipes”
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/01/27 12:30
* by dscr
[](https://openwrt.org/docs/guide-user/services/webserver/http.netcat#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] SSH tunnel
SSH tunnel
==========
The `ssh` command allows to create tunnels and forward a port which is useful to bypass NAT. E.g. when you don't have a public IP but have a server or router that have it. This is simplest and popular way of tunneling because not need for a dedicated client. As a downside an encrypted TLS (HTTPS) traffic will be additionally encrypted by SSH. But it's really not a big slowdown. Alternatively you can use [pppossh](https://openwrt.org/docs/guide-user/services/vpn/pppossh/start "docs:guide-user:services:vpn:pppossh:start")
for a full VPN tunneling over SSH.
The simplest tunnel for port forward can be created with a command like `ssh -R *:80:127.0.0.1:80 jonh@myhome.jonh.me`.
In order to keep tunnel reconnecting after disconnect you need to install and configure the additional service [sshtunnel](https://openwrt.org/packages/pkgdata/sshtunnel "https://openwrt.org/packages/pkgdata/sshtunnel")
. The service also provides an easy UCI configuration file and has LUCI app to configure from GUI.
Install
-------
To install from a command line use `opkg install sshtunnel`.
The SSH client included by default on OpenWrt is [DropBear dbclient](https://manpages.debian.org/testing/dropbear-bin/dbclient.1 "https://manpages.debian.org/testing/dropbear-bin/dbclient.1")
. It's small and supports remote and local tunnels but has limited options. Previously, before the sshtunnel version 5.1 it's package installed as a dependency the full [openssh-client](https://openwrt.org/packages/pkgdata/openssh-client "https://openwrt.org/packages/pkgdata/openssh-client")
. If you have enough of space it's generally recommended to install it with a command `opkg install openssh-client`.
There is a LUCI app [luci-app-sshtunnel](https://openwrt.org/packages/pkgdata/luci-app-sshtunnel "https://openwrt.org/packages/pkgdata/luci-app-sshtunnel")
that provides a GUI for the `sshtunnel`. You may install it with `opkg install luci-app-sshtunnel`. It may be not yet available in the main packages feed.
Configuration
-------------
The UCI configuration is located in `/etc/config/sshtunnel`. This file is responsible for defining _ssh servers_ and _tunnels_.
A typical sshtunnel config file contains at least one `server` specifying the connection to an ssh server and one or more `tunnelL`, `tunnelR` or `tunnelD` defining Local, Remote or Dynamic tunnels.
### Server
In most cases there will be only one server defined, but possibly several tunnels to this server.
A minimal `server` declaration may look like the example below.
config server 'home'
option user 'jonh'
option hostname 'myhome.jonh.me'
option port '22'
\* `home` will identify this server on the tunnels sections \* `jonh` specifies the username on the remote machine \* `myhome.jonh.me` is the hostname of a remote machine running an SSH server.
The possible options for server sections are listed in the table below:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `user` | string | yes | `root` | remote host username. |
| `hostname` | string | yes | | remote host hostname. |
| `port` | integer | yes | 22 | Port to connect to on the remote host. |
| `IdentityFile` | string | no | | Specifies a file from which the user's RSA, ed25519 or ECDSA authentication identity is read. The default is `/root/.ssh/id_rsa`, `/root/.ssh/id_ed25519`, `/root/.ssh/id_ecdsa` or `/root/.ssh/id_dropbear` |
| `retrydelay` | integer | no | 60 | Delay after a connection failure before trying to reconnect. |
| `StrictHostKeyChecking` | string | no | `accept-new` | If this flag is set to `yes`, ssh will never automatically add host keys to the `~/.ssh/known_hosts` file, and refuses to connect to hosts whose host key has changed. This provides maximum protection against trojan horse attacks, though it can be annoying when the `/root/.ssh/known_hosts` file is poorly maintained or when connections to new hosts are frequently made. This option forces the user to manually add all new hosts. If this flag is set to `no`, ssh will automatically add new host keys to the user known hosts files. If this flag is set to `accept-new`, new host keys will be added to the known host files and ssh will refuse to connect to hosts whose host key has changed. |
If you have the `openssh-client` then you can specify advanced options:
| Name | Type | Default | Description |
| --- | --- | --- | --- |
| `LogLevel` | string | `INFO` | Gives the verbosity level that is used when logging messages from ssh. The possible values are: `QUIET`, `FATAL`, `ERROR`, `INFO`, `VERBOSE`, `DEBUG`, `DEBUG1`, `DEBUG2`, and `DEBUG3`. The DEBUG and DEBUG1 are equivalent, DEBUG2 and DEBUG3 each specify higher levels of verbose output. |
| `CheckHostIP` | string | `yes` | Enable check the host IP address in the `known_hosts` file. This allows ssh to detect if a host key changed due to DNS spoofing. |
| `Compression` | string | `no` | Enable gzip compression. It may be useful on slow connections but increases CPU usage and adds a small latency. |
| `ServerAliveCountMax` | string | 3 | Sets the number of server alive messages (see below) which may be sent without ssh receiving any messages back from the server. If this threshold is reached while server alive messages are being sent, ssh will disconnect from the server, terminating the session. It is important to note that the use of server alive messages is very different from TCPKeepAlive (below). The server alive messages are sent through the encrypted channel and therefore will not be spoofable. The TCP keepalive option enabled by TCPKeepAlive is spoofable. The server alive mechanism is valuable when the client or server depend on knowing when a connection has become inactive. If, for example, ServerAliveInterval (see below) is set to 15 and ServerAliveCountMax is left at the default, if the server becomes unresponsive, ssh will disconnect after approximately 45 seconds. |
| `ServerAliveInterval` | string | 0 | Sets a timeout interval in seconds after which if no data has been received from the server, ssh will send a message through the encrypted channel to request a response from the server. The default is 0, indicating that these messages will not be sent to the server. |
| `TCPKeepAlive` | string | `yes` | Specifies whether the system should send TCP keep-alive messages to the other side. If they are sent, death of the connection or crash of one of the machines will be properly noticed. However, this means that connections will die if the route is down temporarily, and some people find it annoying. The default is `yes` (to send TCP keepalive messages), and the client will notice if the network goes down or the remote host dies. |
| `VerifyHostKeyDNS` | string | `no` | Specifies whether to verify the remote key using DNS and SSHFP resource records. If this option is set to `yes`, the client will implicitly trust keys that match a secure fingerprint from DNS. |
| `ProxyCommand` | string | | Proxy tunnel command. The command to use to connect to the server. For example, the following command would connect via an HTTP proxy: `ncat --proxy-type http --proxy-auth alice:secret --proxy 192.168.1.2:8080 %h %p` |
For the `openssh-client` you can also configure the server options in the `/root/.ssh/config` file:
Host home
HostName myhome.jonh.me
Port 22
User jonh
\# Allow old DSA keys used by old OpenWrt router
PubkeyAcceptedKeyTypes +ssh-dss
HostkeyAlgorithms +ssh-rsa
But you still need to create a corresponding `server` section and use the `Host` as `hostname`'.
See OpenSSH [man ssh\_config](https://manpages.debian.org/testing/openssh-client/ssh_config.5 "https://manpages.debian.org/testing/openssh-client/ssh_config.5")
### Tunnels
A complete sshtunnel configuration contains at least one section:
* `tunnelR` a remote tunnel: Forward a port on the remote host to a service on the local host.
* `tunnelL` a local tunnel: Forward a port on the local host to a service on the remote host.
* `tunnelD` a Dynamic Tunnel e.g. SOCKS4/SOCKS5 proxy via remote host.
* `tunnelW` TUN/TAP VPN. Requires `openssh-client`.
If no any tunnel were specified for the server then the sshtunnel won't connect to it.
#### tunnelR
A example for a `tunnelR` declaration is given below:
config tunnelR local\_ssh
option server 'home'
option remoteaddress '\*'
option remoteport '2222'
option localaddress '127.0.0.1'
option localport '22'
* **`*`** means to accept a connection from any interface on the **Server side**
` Specifying a remote bind_address will only succeed if the server's GatewayPorts option is enabled. See “SSH Server configuration” bellow`
* **`2222`** is the TCP port to bind on the **Server side**
* **`127.0.0.1`** is the **OpenWrt side** address to where the remote connection will be forwarded
* **`22`** is the **OpenWrt side** TCP port where to the remote connection will be forwarded
The equivalent `ssh` command would be `ssh -R *:2222:127.0.0.1:22 jonh@myhome.jonh.me`
The possible options for `tunnelR` sections are listed in the table below:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | no | `1` | Enable or disable with `0` the auto establishment of the tunnel on service start |
| `server` | string | yes | _(none)_ | Specifies the used server, must refer to one of the defined server sections |
| `remoteaddress` | string | no | `*` | Server side address |
| `remoteport` | integer | yes | _(none)_ | Server side TCP port |
| `localaddress` | string | yes | _(none)_ | OpenWrt side address |
| `localport` | integer | yes | _(none)_ | OpenWrt side TCP port |
#### tunnelL
For a `tunnelL` the declaration is similar:
config tunnelL server\_http
option server 'home'
option remoteaddress '127.0.0.1'
option remoteport '8080'
option localaddress '\*'
option localport '80'
* **`127.0.0.1`** is the **Server side** address to where the connection will be forwarded
* **`8080`** is the **Server side** TCP port to where the local connection will be forwarded
* **`*`** means to accept a connection from any interface on the **OpenWrt side**
* **`80`** is the local TCP port to bind on the **OpenWrt side**
The equivalent `ssh` command would be `ssh -L *:80:127.0.0.1:8080 jonh@myhome.jonh.me`
The possible options for `tunnelL` sections are listed in the table below:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | no | `1` | Enable or disable with `0` the auto establishment of the tunnel on service start |
| `server` | string | yes | _(none)_ | Specifies the used server, must refer to one of the defined server sections |
| `remoteaddress` | string | yes | _(none)_ | Server side address |
| `remoteport` | integer | yes | _(none)_ | Server side TCP port |
| `localaddress` | string | no | `*` | OpenWrt side address |
| `localport` | integer | yes | _(none)_ | OpenWrt side TCP port |
#### tunnelD
A `tunnelD` declaration will create a SOCKS proxy accessible on the defined local port. This is supported only with the `openssh-client`.
config tunnelD proxy
option server 'home'
option localaddress '\*'
option localport '1080'
* **`*`** means to accept a connection from any interface on the **OpenWrt side**
* **`1080`** is the local TCP port to bind on the **OpenWrt side**
The equivalent `ssh` command would be `ssh -D *:1080 jonh@myhome.jonh.me`
The possible options for `tunnelD` sections are listed in the table below:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | no | `1` | Enable or disable with `0` the auto establishment of the tunnel on service start |
| `server` | string | yes | _(none)_ | Specifies the used server, must refer to one of the defined server sections |
| `localaddress` | string | no | `*` | OpenWrt side address |
| `localport` | integer | yes | _(none)_ | OpenWrt side TCP port |
#### tunnelW
A `tunnelW` declaration will TUN/TAP devices on client and server to establish a VPN tunnel between them. This is supported only with the `openssh-client`. You better to use the [PPPoSSH](https://openwrt.org/docs/guide-user/services/vpn/pppossh/start "docs:guide-user:services:vpn:pppossh:start")
.
config tunnelW vpn
option server 'home'
option vpntype 'point-to-point'
option localdev 'any'
option remotedev 'any'
The equivalent `ssh` command would be `ssh -o Tunnel=point-to-point -w any:any jonh@myhome.jonh.me`
The possible options for `tunnelW` sections are listed in the table below:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | no | `1` | Enable or disable with `0` the auto establishment of the tunnel on service start |
| `server` | string | yes | _(none)_ | Specifies the used server, must refer to one of the defined server sections |
| `vpntype` | string | no | `point-to-point` | `point-to-point` or `ethernet` |
| `remotedev` | string | yes | `any` | tun device numerical ID or the keyword `any`, which uses the next available tunnel device |
| `localdev` | string | yes | `any` | remote device ID |
See [Arch Wiki VPN over SSH](https://wiki.archlinux.org/title/VPN_over_SSH "https://wiki.archlinux.org/title/VPN_over_SSH")
### SSH tunnel providers
* [srv.us](https://docs.srv.us/ "https://docs.srv.us/")
works with empty RemoteAddress or set to '\*'. You can also set a custom domain as a number 1, 2 etc.
* [localhost.run](https://localhost.run/ "https://localhost.run")
works with empty RemoteAddress or set to '\*' but the generated domain will be rotated and changed on next restart. You need a custom domain (paid feature).
* [remote.moe](https://github.com/fasmide/remotemoe "https://github.com/fasmide/remotemoe")
works only if a custom domain but this needs for some manual configuration.
See other options in the [Awesome tunneling: SSH services](https://github.com/yurt-page/awesome-tunneling#ssh-services "https://github.com/yurt-page/awesome-tunneling#ssh-services")
### SSH server configuration
To access an SSH server you need to add your public key to a list of authorized keys. So add your pub key (`id_ed25519.pub`, `id_rsa.pub`) to the `/root/.ssh/authorized_keys` or to the `/etc/dropbear/authorized_keys`. In LuCI you can do that with `System / Administration / SSH-Keys`.
For a remote tunnel you also should allow `GatewayPorts` on the server. For the Dropbear you can edit its config `vi /etc/config/dropbear`, add the `option GatewayPorts 1`, reload it with `service dropbear reload`.
Or by using UCI:
uci set dropbear.@dropbear\[0\].GatewayPorts=1
uci commit
For the OpenSSHd you need to edit the `/etc/ssh/sshd_config`, add the `GatewayPorts yes`, reload with `service sshd reload`.
mak
### See also
* [Video: Setup SSH tunnel on router](https://www.youtube.com/watch?v=xrtqq9fVq34 "https://www.youtube.com/watch?v=xrtqq9fVq34")
* [OpenWrt - Reverse SSH tunnel](https://eko.one.pl/?p=openwrt-sshtunnel "https://eko.one.pl/?p=openwrt-sshtunnel")
in Polish
* [OpenWrt SSH tunnel](https://gist.github.com/ssalonen/9755dfd631a60951a369d563bb20cd71 "https://gist.github.com/ssalonen/9755dfd631a60951a369d563bb20cd71")
* [howto: SOCKS Proxy SSH Tunnels on OpenWRT](https://blog.thestateofme.com/2022/10/26/socks-proxy-ssh-tunnels-on-openwrt/ "https://blog.thestateofme.com/2022/10/26/socks-proxy-ssh-tunnels-on-openwrt/")
* [howto: OpenWrt SSH Tunneling](https://github.com/DerekGn/OpenWrt/wiki/OpenWrt-SSH-Tunneling "https://github.com/DerekGn/OpenWrt/wiki/OpenWrt-SSH-Tunneling")
* [sshtunnel SystemD](https://github.com/yurt-page/sshtunnel "https://github.com/yurt-page/sshtunnel")
port of the sshtunnel to other SystemD based Linux distros (Ubuntu, Debian etc).
* [pppossh](https://openwrt.org/docs/guide-user/services/vpn/pppossh/start "docs:guide-user:services:vpn:pppossh:start")
an L3 tunnel over SSH
* [sshuttle](https://gist.github.com/kylekyle/fcbb7b93ad9816915b31022a17f19cea "https://gist.github.com/kylekyle/fcbb7b93ad9816915b31022a17f19cea")
- a Python based SSH VPN.
* [autossh](https://openwrt.org/docs/guide-user/services/ssh/autossh "docs:guide-user:services:ssh:autossh")
- an older SSH re-connection tool
* [man ssh\_config — OpenSSH client configuration file. Manual](https://manpages.debian.org/testing/openssh-client/ssh_config.5.html "https://manpages.debian.org/testing/openssh-client/ssh_config.5.html")
* [man ssh — OpenSSH client. Manual](https://manpages.debian.org/testing/openssh-client/ssh.1.html "https://manpages.debian.org/testing/openssh-client/ssh.1.html")
* [sslh](https://github.com/yrutschle/sslh "https://github.com/yrutschle/sslh")
- multiplexer proxy (e.g. share SSH and HTTPS)
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/03/07 17:40
* by stokito
[](https://openwrt.org/docs/guide-user/services/ssh/sshtunnel#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] µMurmur
µMurmur
=======
µMurmur or uMurmur is a minimalistic [Mumble (software)](https://en.wikipedia.org/wiki/Mumble%20(software) "https://en.wikipedia.org/wiki/Mumble (software)")
server primarily targeted to run on embedded devices with an open OS like OpenWrt.
Project page for more info and most up-to-date documentation at [https://github.com/umurmur/umurmur](https://github.com/umurmur/umurmur "https://github.com/umurmur/umurmur")
Preparation
-----------
### Prerequisites
So far there are two uMurmur packages available in the repos, one compiled against the Mbed-TLS library and one against the OpenSSL library.
opkg info umurmur-mbedtls
opkg info umurmur-openssl
_**Note**_ that currently, the Mbed-TLS version does not auto-generate a certificate, causing it to not startup correctly. It is therefor suggested to use the OpenSSL version for the time being.
See this GitHub issue: [https://github.com/openwrt/packages/issues/22188](https://github.com/openwrt/packages/issues/22188 "https://github.com/openwrt/packages/issues/22188")
_Firewall:_ The default ports are 64738 tcp and 64738 udp. [open](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_examples#opening_ports_on_the_openwrt_router "docs:guide-user:firewall:fw3_configurations:fw3_config_examples")
them up in `[/etc/config/firewall](https://openwrt.org/docs/guide-user/firewall/start "docs:guide-user:firewall:start") `.
### Required Packages
The following list specifies package versions for latest stable release of OpenWrt. At time of writing, 23.05.
#### Server (OpenWrt)
| Name | Version | Size | Description |
| --- | --- | --- | --- |
| umurmur-openssl | 0.2.20-2 | 36762 | Minimalistic Mumble server daemon. Uses OpenSSL library for SSL and crypto. |
| libopenssl3 | 3.0.12-1 | 1394609 | The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, full-featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) protocols as well as a full-strength general purpose cryptography library. This package contains the OpenSSL shared libraries, needed by other programs. |
| libconfig11 | 1.7.3-1 | 15719 | Libconfig is a simple library for manipulating structured configuration files. This file format is more compact and more readable than XML. And unlike XML, it is type-aware, so it is not necessary to do string parsing in application code. Libconfig is very compact -- just 38K for the stripped C shared library (less than one-fourth the size of the expat XML parser library) and 66K for the stripped C++ shared library. This makes it well-suited for memory-constrained systems like handheld devices. |
| libprotobuf-c | 1.4.1-1 | 9922 | Runtime library to use Google Protocol Buffers from C applications. Protocol Buffers are a way of encoding structured data in an efficient yet extensible format. Google uses Protocol Buffers for almost all of its internal RPC protocols and file formats. |
#### Client (your PC)
On Linux you need to install the `mumble` package, like [this one](http://packages.debian.org/squeeze/mumble "http://packages.debian.org/squeeze/mumble")
. On Windows or MacOSX you have to download it: [http://mumble.sourceforge.net/](http://mumble.sourceforge.net/ "http://mumble.sourceforge.net/")
.
_**Note**_ that uMurmur version 0.2.x is compatible with Mumble version 1.2.x series. Mumble version 1.1.x series is **not** compatible.
Installation
------------
Example using shell access:
opkg install umurmur-openssl
vi /etc/umurmur.conf
/etc/init.d/umurmur enable
/etc/init.d/umurmur start
logread
Check log output that the `uMurmurd` started up OK.
[open](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_config_examples#opening_ports_on_the_openwrt_router "docs:guide-user:firewall:fw3_configurations:fw3_config_examples")
port 64738 for TCP and UDP in `[/etc/config/firewall](https://openwrt.org/docs/guide-user/firewall/start "docs:guide-user:firewall:start") `.
vi /etc/config/firewall
/etc/init.d/firewall reload
You should now be able to connect via the mumble protocol.
Configuration
-------------
`cat /etc/umurmur.conf`
`max_bandwidth = 48000; welcometext = “Welcome to uMurmur!”; certificate = “/etc/umurmur/cert.crt”; private_key = “/etc/umurmur/key.key”; password = “”; max_users = 10; # Root channel must always be defined first. # If a channel has a parent, the parent must be defined before the child channel(s). channels = ( { name = “Root”; parent = “”; description = “The Root of all channels”; }, { name = “Lobby”; parent = “Root”; description = “Lobby channel”; }, { name = “Red team”; parent = “Lobby”; description = “The Red team channel”; }, { name = “Blue team”; parent = “Lobby”; description = “The Blue team channel”; } ); # Channel links configuration. channel_links = ( { source = “Lobby”; destination = “Red team”; }, { source = “Lobby”; destination = “Blue team”; } ); default_channel = “Lobby”;`
Start on boot
-------------
To enable/disable start on boot: `/etc/init.d/umurmur enable` this simply creates a symlink to umurmur in “`/etc/rc.d/`” `/etc/init.d/umurmur disable` this removes the symlink again
Administration
--------------
There is no privilege system implemented in uMurmur version < 0.2.10 meaning that users cannot be kicked, banned or muted by other users. If you have a need for this kind of functionality the options are:
* Set a server password
* Add the IP of misbehaving users to your firewall.
Since uMurmur 0.2.10 there is a password based administration scheme. A package is available in OpenWRT trunk. For this to work you'd need to install the dependencies from trunk as well if you are running Backfire.
Troubleshooting
---------------
The most common error is the firewall. Double check connection problems with
iptables -n -v
and check those counters.
If users cannot connect and you get this error in the log
WARN: SSL handshake failed: -28672
you're probably running Backfire 10.03.1-rc4 with Polarssl 0.14. Upgrade to Backfire 10.03.1-RC5 or later.
Notes
-----
1. Read about certificates in general. Do it! [Public key certificate](https://en.wikipedia.org/wiki/Public%20key%20certificate "https://en.wikipedia.org/wiki/Public key certificate")
2. enlighten your friends, there is no point in security if not all users understand the principle of operation
* Project Homepage: [https://github.com/umurmur/umurmur](https://github.com/umurmur/umurmur "https://github.com/umurmur/umurmur")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/12 12:20
* by iguanajuice
[](https://openwrt.org/docs/guide-user/services/voip/umurmur#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] FreeSWITCH on OpenWrt intro
FreeSWITCH on OpenWrt intro
===========================
This page is meant to provide some basic information about FreeSWITCH on OpenWrt. Visit the official [FreeSWITCH wiki](https://freeswitch.org/confluence/display/FREESWITCH/FreeSWITCH+Explained "https://freeswitch.org/confluence/display/FREESWITCH/FreeSWITCH+Explained")
to find out more about FreeSWITCH in particular.
**Telephony systems like FreeSWITCH are targeted by criminals to commit toll fraud. If you fall victim to toll fraud this can cost you a lot of money. You are responsible for the security of your sytem. Make sure all security measures are in place before bringing FreeSWITCH online.**
freeswitch init configuration
-----------------------------
The file `/etc/config/freeswitch` contains the general on/off switch - FreeSWITCH is disabled by default. Here you can also change the command line switches that are used when starting FreeSWITCH. E.g. you can set the directories for recordings and logs etc.
**WARNING: FreeSWITCH writes to its databases constantly. Constant writes will quickly kill your device's integrated flash memory.**
It's recommended to keep the databases on external storage (see [Using storage devices](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
).
If that is not possible they can also be kept in the device's RAM (working memory), on a _tmpfs_ filesystem (`/tmp` is mounted as a _tmpfs_ file system on OpenWrt devices). RAM memory is not subject to constant writing wear like flash memory.
The downside of the _tmpfs_ approach is that the databases will be lost when the device loses power or is restarted, also the RAM used by these databases will decrease the amount of available RAM of the system by a few MB. Please consider your options and requirements.
Last but not least, you can select whether the output streams (_STDOUT_ and _STDERR_) that are sent to the init process (`procd`), shall be forwarded to the system logger. Defaults to yes for both.
freeswitch packages
-------------------
### Modules
FreeSWITCH has a multitude of modules. OpenWrt typically runs on hardware that is somewhat restricted, i.e. memory, storage and processing power are limited. Luckily only a few packages are needed for basic functionality (depending on what you want it to do). Here is a list of modules you might be interested in:
* [freeswitch-mod-commands](https://freeswitch.org/confluence/display/FREESWITCH/mod_commands "https://freeswitch.org/confluence/display/FREESWITCH/mod_commands")
: various API commands, for instance `fsctl`
* [freeswitch-mod-dialplan-xml](https://freeswitch.org/confluence/display/FREESWITCH/XML+Dialplan "https://freeswitch.org/confluence/display/FREESWITCH/XML+Dialplan")
: adds support for dialplans written in XML
* [freeswitch-mod-dptools](https://freeswitch.org/confluence/display/FREESWITCH/mod_dptools "https://freeswitch.org/confluence/display/FREESWITCH/mod_dptools")
: dialplan tools (`answer`, `blind_transfer` etc.)
* [freeswitch-mod-event-socket](https://freeswitch.org/confluence/display/FREESWITCH/mod_event_socket "https://freeswitch.org/confluence/display/FREESWITCH/mod_event_socket")
: provides a socket interface to FreeSWITCH which is used, for example, by `fs_cli`
* [freeswitch-mod-hash](https://freeswitch.org/confluence/display/FREESWITCH/mod_hash "https://freeswitch.org/confluence/display/FREESWITCH/mod_hash")
: can be used to limit the amount of calls and other things
* [freeswitch-mod-logfile](https://freeswitch.org/confluence/display/FREESWITCH/mod_logfile "https://freeswitch.org/confluence/display/FREESWITCH/mod_logfile")
: allows saving logs of the running application
* [freeswitch-mod-sofia](https://freeswitch.org/confluence/display/FREESWITCH/mod_sofia "https://freeswitch.org/confluence/display/FREESWITCH/mod_sofia")
: the SIP stack used by FreeSWITCH
* [freeswitch-mod-spandsp](https://freeswitch.org/confluence/display/FREESWITCH/mod_spandsp "https://freeswitch.org/confluence/display/FREESWITCH/mod_spandsp")
: adds fax capabilities, also includes additional audio codecs, e.g. G722 (“HD Voice”)
* [freeswitch-mod-xml-cdr](https://freeswitch.org/confluence/display/FREESWITCH/mod_xml_cdr "https://freeswitch.org/confluence/display/FREESWITCH/mod_xml_cdr")
: can save call data records, also useful for troubleshooting
### FreeTDM modules
FreeSWITCH supports select TDM hardware. At the heart of this sits [libfreetdm](https://freeswitch.org/confluence/display/FREESWITCH/FreeTDM "https://freeswitch.org/confluence/display/FREESWITCH/FreeTDM")
. It will be pulled in automatically when you install the endpoint driver _freeswitch-mod-freetdm_, which is used by FreeSWITCH to interconnect with all protocols supported by FreeTDM.
FreeTDM itself is modular as well. OpenWrt packages the following FreeTDM modules:
* libfreetdm-ftmod-analog: signaling module; provides support for FXS/FXO
* libfreetdm-ftmod-analog-em: signaling module; not solely for analog, supports E1/T1 analog and digital cards using CASE&M signaling
* libfreetdm-ftmod-libpri: signaling module; provides support for ISDN over PRI/BRI
* libfreetdm-ftmod-pritap: PRI tapping
* libfreetdm-ftmod-skel: example module
* libfreetdm-ftmod-zt: I/O module; takes care of reading and writing raw data bytes and executing low level control commands on the telephony hardware
Don't forget to install _kmod-dahdi_. It provides the kernel driver for the TDM hardware.
### Utilities
There are also a number of utilities available. Let's just mention the one that is probably the most important:
* [freeswitch-util-fs-cli](https://freeswitch.org/confluence/display/FREESWITCH/Command-Line+Interface+fs_cli "https://freeswitch.org/confluence/display/FREESWITCH/Command-Line+Interface+fs_cli")
: allows CLI access to a FreeSWITCH server, either local or remote (uses the event socket interface mentioned above)
### Examples
The FreeSWITCH source contains a number of folders with configuration examples. These are packaged as well:
* freeswitch-example-curl
* freeswitch-example-insideout
* ...
Any of these will install the corresponding sample configuration to `/usr/share/freeswitch/examples`.
Hotplug
-------
The _freeswitch_ package includes a hotplug script. You can set a hotplug interface in `/etc/config/freeswitch` to enable it.
Note: It may be advisable to disable the init autostart, to avoid FreeSWITCH beeing started twice when booting:
/etc/init.d/freeswitch disable
The hotplug script can check the following extra conditions:
* a device (perhaps a USB stick) is connected at a given mount point (for instance `/mnt/usb`)
* the system clock is accurate (needs `ntpd` to be installed)
If you add any of these conditions the hotplug script will only start FreeSWITCH if the condition is met. You can also specify the timeout after which it considers a condition failed (defaults to 60 seconds).
Below a log excerpt from the hotplug script in action:
Sat Nov 17 11:24:43 2018 user.notice freeswitch-hotplug: /mnt/usb mounted
Sat Nov 17 11:24:43 2018 user.notice freeswitch-hotplug: ntpd stratum 16
Sat Nov 17 11:24:43 2018 user.notice freeswitch-hotplug: system time not in sync yet, timeout in 60 s
Sat Nov 17 11:24:48 2018 user.notice freeswitch-hotplug: ntpd stratum 16
Sat Nov 17 11:24:48 2018 user.notice freeswitch-hotplug: system time not in sync yet, timeout in 55 s
Sat Nov 17 11:24:53 2018 user.notice freeswitch-hotplug: ntpd stratum 3
Sat Nov 17 11:24:53 2018 user.notice freeswitch-hotplug: ntpd to system time offset +/- 4 ms
Sat Nov 17 11:24:53 2018 user.notice freeswitch-hotplug: system time in sync
Sat Nov 17 11:24:54 2018 user.notice freeswitch-hotplug: started freeswitch due to "ifup wan" event
Both extra conditions were configured. A device was already mounted at `/mnt/usb`. The system time was initially not accurate, so the hotplug script waited a bit before starting FreeSWITCH.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2022/05/31 20:33
* by micmac1
[](https://openwrt.org/docs/guide-user/services/voip/freeswitch#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Pseudowire
Pseudowire
==========
This article may contain network configuration that depends on migration to DSA in OpenWrt 21.02
* Check if your device uses DSA or swconfig as not all devices have been migrated
* ifname@interface has been moved to device sections
* [DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Mini tutorial for DSA network config](https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998 "https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998")
on the forum
* [DSA in the 21.02 release notes](https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change "https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change")
[Pseudo-wire](https://en.wikipedia.org/wiki/Pseudo-wire "https://en.wikipedia.org/wiki/Pseudo-wire")
In today's data center an important question is: How to react on server outages? One of the possible answer to this question is a second data center in another location with a symmetric internet connection. This second data center can be run on cheap servers. With this setup, data from the primary data center can continuously be transmitted to the secondary one. If one or more server in the primary data center fail (e.g. because of hardware defect) the second data center can be used as fallback. This would be possible, if both of the data centers could be connected on layer 2 so they both share the same address range simultaneously. With expensive, proprietary hardware (e.g. Cisco) this is easily possible. For exactly this problem pseudowire switching can be used as seen in the following picture.
Proprietary setup: [](http://isc.sans.edu/diary.html?storyid=8704 "http://isc.sans.edu/diary.html?storyid=8704")
Linux also supports Layer 2 coupling with VPN1 or unencrypted via the Internet. Examples therefor are:
OpenVPN in bridged to bridged mode. To achieve this the following options are used on the server side:
server-bridge ....
up "/etc/openvpn/bridge-start"
dev tap0
In the remote data center one client is provided with two VLANs. The first is used to connect to the vpn server. The second one is used later on when routing the layer 2 traffic of the first data center. In this example this is VLAN 111, which is available on the client as bridge.
up "/etc/openvpn/bridge-start"
client
#
/etc/openvpn/bridge-start
#!/bin/bash
#################################
\# Set up Ethernet bridge on Linux
\# Requires: bridge-utils
#################################
\# Define Bridge Interface
br\="vlan111"
\# Define list of TAP interfaces to be bridged,
\# for example tap="tap0 tap1 tap2".
tap\="$1"
for t in $tap; do
/usr/sbin/openvpn \--mktun \--dev $t
done
for t in $tap; do
/usr/sbin/brctl addif $br $t
done
for t in $tap; do
/sbin/ifconfig $t 0.0.0.0 promisc up
done
The advantage of routing the layer 2 traffic in the unused VLAN 111 has the advantage that local traffic does not mix with the traffic of the remote data center. A disadvantage hereby is the somewhat smaller throughput due to the architecture of openvpn, as to many interrupts are required to copy the data vom kernel space to user space and back. This has a significant role when working with embedded hardware.
[](https://openwrt.org/_detail/doc/howto/rbridge.jpg?id=docs%3Aguide-user%3Aservices%3Avpn%3Apseudowire "doc:howto:rbridge.jpg")
See [rbridge](http://www.inlab.de/rbridge/index.html "http://www.inlab.de/rbridge/index.html")
and [etherip](http://lwn.net/Articles/119535/ "http://lwn.net/Articles/119535/")
.
Here an UDP tunnel in both directions is created to connect two Ethernet segments. An encryption of this tunnel can be implemented by using IPsec on top of this tunnel. This program, however, is not available as source code and therefor its usage is limited.
L2TPv3 with OpenWrt
-------------------
L2TPv3 is [available](http://kerneltrap.org/mailarchive/linux-netdev/2010/4/2/6273948 "http://kerneltrap.org/mailarchive/linux-netdev/2010/4/2/6273948")
since Kernel 2.6.35.
So what else is to be done to get this working:
* install Linux
* confgiure the firewall
* set up the IPSEC Tunnel
* monitor the IPSEC Tunnel
* start the L2TPv3 Tunnel and bridge it on both ends
No Linux distribution has included L2TPv3 in their network setup - but OpenWrt. With OpenWrt it can be configured in the network configuration in `/etc/config/network`. Have a look at [L2TPv3 Pseudowire bridged to LAN](https://openwrt.org/docs/guide-user/network/tunneling_interface_protocols#l2tpv3_pseudowire_bridged_to_lan "docs:guide-user:network:tunneling_interface_protocols")
.
Openwrt can be used on many other hardware besides routers from Linksys. Even para virtual network devices are available to achieve performant network operations in virtualised environments:
* KVM - Kernel Based Virtual Machine
* XEN - [http://de.wikipedia.org/wiki/Xen](http://de.wikipedia.org/wiki/Xen "http://de.wikipedia.org/wiki/Xen")
* ESX/ESXI - VMware
* Virtual Box - Oracle
Openwrt is small, can be easily adopted and has an excellent buildchain. With this buildchain personal modifications are simple to include.
Implementation
--------------
After the theoretical depiction follows a practical implementation using an example network environment. The used network ranges are:
* external IP address in the primary data center (141.64.161.74), gateway (141.64.161.1), netmask (Class C)
* internal IP range 10.1.0.0/24
* external IP address in the secondary data center (192.166.120.139), gateway (192.166.120.1), netmask (Class C)
* unused VLAN 111 in the secondary data center
[](https://openwrt.org/_detail/doc/howto/pseudowire-practical.jpeg?id=docs%3Aguide-user%3Aservices%3Avpn%3Apseudowire "doc:howto:pseudowire-practical.jpeg")
This shows the implementation of the Layer 2 coupling. First, the IPSEC tunnel between 141.64.161.75 to 192.166.120.139 is established. After succeeding, the IPs 192.168.202.5/32 and 192.168.202.9/32 are assigned to the tunnel endpoints. On top of this tunnel the L2TPv3 tunnel can be initialized. The IPSEC tunnel is needed as the connection between the data centers has to be cryptographically secure. This encryption is implemented in the kernel and can be implemented in hardware so latencies should be small and throughput should be huge. L2TPv3 is kernel based, too, which is one of the features that make it appealing in using to achieve the aspired goals.
Implementation using OpenWrt
----------------------------
To implement this setup with OpenWrt in both data centers an instance (l-01 in the primary, l-02 in the secondary) has to be configured as follows.
### l-01
\# /etc/config/network
config interface wan
option ifname eth0
option type bridge
option proto static
option ipaddr 141.64.161.74
option netmask 255.255.255.0
option gateway 141.64.161.1
config interface lan
option ifname eth1
option type bridge
option proto l2tp
option ipaddr 10.1.0.1
option netmask 255.255.255.0
option encap udp
option sport 1701
option dport 1702
option localaddr 172.30.201.5
option peeraddr
172.30.201.9
\# /etc/config/firewall
config rule
option src wan
option proto gre
option target ACCEPT
config rule
option src wan
option proto esp
option target ACCEPT
config rule
option src wan
option proto ah
option target ACCEPT
config rule
option src wan
option dest\_port 500
option proto udp
option target ACCEPT
config rule
option src wan
option dest\_port 4500
option proto udp
option target ACCEPT
\# /etc/ipsec.conf
\# OpenSwan is being used
conn to-secondary
type\=tunnel
left\=141.64.161.74
leftnexthop\=141.64.161.1
leftsourceip\=192.168.201.5
leftsubnet\=172.30.201.5/32
leftid\="primary@rz"
right\=192.166.120.139
rightnexthop\=192.166.120.1
rightsourceip\=192.168.201.9
rightsubnet\=192.168.201.9/32
authby\=secret
auto\=start
ike\=aes128-sha-modp1024
esp\=aes128-sha1
\# /etc/monitrc
check process pluto with pidfile /var/run/pluto/pluto.pid
start program = "/etc/init.d/ipsec restart"
stop program = "/etc/init.d/ipsec restart"
#
check host secondary with address 10.1.0.2
if failed icmp type echo count 5 with timeout 30 seconds
then exec "/sbin/ifup lan"
### l-02
\# /etc/config/network
config interface wan
option ifname eth0
option type bridge
option proto static
option ipaddr 192.166.120.139
option netmask 255.255.255.0
option gateway 192.166.120.1
config interface lan
option ifname eth1
option type bridge
option proto l2tp
option ipaddr 10.1.0.2
option netmask 255.255.255.0
option encap udp
option sport 1702
option dport 1701
option localaddr 172.30.201.9
option peeraddr 172.30.201.5
\# /etc/config/firewall
\# same as l-01
\# /etc/ipsec.conf
\# OpenSwan is being used
conn to-primary
type\=tunnel
left\=141.64.161.74
leftnexthop\=141.64.161.1
leftsourceip\=192.168.201.5
leftsubnet\=172.30.201.5/32
rightid\="secondary@rz"
right\=192.166.120.139
rightnexthop\=192.166.120.1
rightsourceip\=192.168.201.9
rightsubnet\=192.168.201.9/32
authby\=secret
auto\=start
ike\=aes128-sha-modp1024
esp\=aes128-sha1
\# /etc/monitrc
check process pluto with pidfile /var/run/pluto/pluto.pid
start program = "/etc/init.d/ipsec restart"
stop program = "/etc/init.d/ipsec restart"
#
check host secondary with address 10.1.0.1
if failed icmp type echo count 5 with timeout 30 seconds
then exec "/sbin/ifup lan"
Explanations
------------
The functionality of both the IPSEC and the L2TPv3 tunnel are assured by the use of the daemon monit on both ends. If one of the tunnels is destroyed an ifup lan is triggered to restart the connection. In the secondary data center eth1 has to be in VLAN 111. Because of this, the internal network of the primary data center can be used without the interference of layer 2 noise. This means the internal network of the primary data center is bridged in the VLAN 111 in the secondary data center.
Bridging of devices with varying MTUs
-------------------------------------
For now the setup works so both sides can ping each other. An ssh connection, however, is either not possible or freezes after a few seconds.
The reason: The bridge for the L2TPv3 contains devices with different MTUs. Furthermore, as the connection is bridged no routing happens, the MTU is not automatically adjusted by the router. All devices in the LAN usually use an MTU of 1500. The MTU of the L2TPv3 devices is about 1400. As the tunnel itself can not fragment packets all packets bigger than the MTU are lost. This happens at longer HTTP request, too.
To solve the problem bridge firewalling and TCP MSS Clamping is used. Bridge firewalling means the iptables rules are used when a packet passes a bridge. Normally this should not work, as a bridge only works in Layer 2. However, if bridge firewalling is enabled in the kernel a bridge can work in Layer 2 as well as Layer 3.
The following sysctl keys are used for this:
* net.bridge.bridge-nf-call-iptables
* 0 - do not send IPv4 traffic through iptables
* 1 - do send IPv4 traffic through iptables
* net.bridge.bridge-nf-filter-vlan-tagged
* 0 - do not send vlan tagged Ipv4 traffic through iptables
* 1 - send vlan tagged Ipv4 traffic through iptables
IPv6 have to be configured separately.
For the example setup the rules should be like this:
iptables \-I FORWARD \-s 10.1.0.0/24 \-p tcp \--tcp-flags SYN,RST SYN \-j TCPMSS \--set-mss 1400
iptables \-I FORWARD \-d 10.1.0.0/24 \-p tcp \--tcp-flags SYN,RST SYN \-j TCPMSS \--set-mss 1400
iptables \-I FORWARD \-s 10.1.0.0/24 \-p tcp \--tcp-flags SYN,RST SYN \-j TCPMSS \--clamp-mss-to-pmtu
iptables \-I FORWARD \-d 10.1.0.0/24 \-p tcp \--tcp-flags SYN,RST SYN \-j TCPMSS \--clamp-mss-to-pmtu
These rules should be narrowed as good as possible to avoid unpleasant side affects.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/05/27 11:39
* by sur5r
[](https://openwrt.org/docs/guide-user/services/vpn/pseudowire#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Wake on LAN configuration
Wake on LAN configuration
=========================
The configuration file `/etc/config/wol` is provided by the _wol_ package and defines hosts to wake when starting the `/etc/init.d/wol` init script. An alternative opkg-package is `[etherwake](https://openwrt.org/docs/guide-user/services/w_o_l/etherwake "docs:guide-user:services:w_o_l:etherwake") `
Please see `[/etc/crontabs/root](https://openwrt.org/docs/guide-user/base-system/notuci.config#etccrontabsroot "docs:guide-user:base-system:notuci.config") ` to configure `crond`.
Sections
--------
There is only one section type `wol-target` defined for the configuration. Multiple _wake on lan targets_ may exist in the file.
### Wake on LAN targets
A `wol-target` section defines the parameters the _wol_ utility is started with. The init script will start one instance of _wol_ for each section of this type.
Below is a listing of the parameters defined for this section.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `mac` | MAC address | yes | _(none)_ | Specifies the MAC address of the host to wake |
| `broadcast` | IPv4 address or hostname | no | `255.255.255.255` | Specifies the target address magic packets are broadcasted to |
| `port` | integer | no | `40000` | Specifies the UDP destination port for magic packets |
| `password` | string | no | _(none)_ | Send given _SecureON_ password when waking the host |
| `enabled` | boolean | no | `1` | Don't start _wol_ for this section if set to `0` |
Example
-------
Example entry to wake a host with the MAC address `00:06:29:4f:e4:b6` in the `192.168.0.0/24` subnet:
config wol-target
option mac '00:06:29:4f:e4:b6'
option broadcast '192.168.0.255'
option enabled '1'
Notes
-----
If _wol_ does not work, the _etherwake_ package can be used instead. To wake a host on boot, and put the following command into `/etc/rc.local`:
etherwake 00:0f:3d:ce:ef:ee
This would wake the host with the MAC address `00:0f:3d:ce:ef:ee`.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/08/26 08:38
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/w_o_l/wol#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] mini-httpd webserver
mini-httpd webserver
====================
Installation
------------
See →`[opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg") ` on its usage.
First update, then install mini-httpd, openssl-util, and libopenssl.
opkg update
opkg install mini-httpd
opkg install mini-httpd-openssl
opkg install openssl-util
Configuration
-------------
### Get mini-httpd-openssl working without SSL Certificate errors
Quick guide for Chaos Calmer and later (using self-signed certs):
1. The certificate's 'common-name' must match the host part of the URL which you use to access your router. OpenWRT defaults to 'OpenWRT', as the common name, so if you don't plan to use [https://OpenWRT/](https://openwrt/ "https://OpenWRT/")
, then edit /etc/config/uhttpd so that the commonname reflects the host part of the URL you'll be using. You'll then need to rm (or backup) /etc/uhttpd.key and /etc/uhttpd.crt, and regenerate them with: /etc/init.d/uhttpd restart
2. Set your web browser to recognise the self-signed key without lots of scary warnings etc. This is very platform specific but the following guides may be useful (please add to this list):
* Chrome / Linux [https://chromium.googlesource.com/chromium/src/+/master/docs/linux\_cert\_management.md](https://chromium.googlesource.com/chromium/src/+/master/docs/linux_cert_management.md "https://chromium.googlesource.com/chromium/src/+/master/docs/linux_cert_management.md")
* Chrome (and other browsers, since Chrome uses the OS's native cert management) on various desktop platforms [http://stackoverflow.com/questions/7580508/getting-chrome-to-accept-self-signed-localhost-certificate](http://stackoverflow.com/questions/7580508/getting-chrome-to-accept-self-signed-localhost-certificate "http://stackoverflow.com/questions/7580508/getting-chrome-to-accept-self-signed-localhost-certificate")
### Get mini-httpd-openssl working without SSL Certificate errors
As with Telnet, HTTP will transmit your usernames, passwords, and all data in clear text across the network. This means that anyone on the same subnet on either the client or the server networks could intercept the traffic and steal your credentials. Using packages from Backports, you can install an HTTPS\-only Web server.
This guide will show you how to turn on SSL access to your OpenWrt running LuCI. Enabling https access to your router, and disabling http access, will provide greater security. This guide will also show you how to install your certificate in Windows 7, which will get rid of browser errors stating the certificate is not valid.
**`Note:`** My build at the time of this article trunk (r32793)
### Process Breakdown
1. Create keys and certs
2. Create mini\_httpd.pem
3. Install cert to Windows 7
4. Upload mini\_httpd.pem
5. Enable / Start mini\_httpd
6. Test
7. Disable http access
#### Backup your mini-httpd.pem
[](https://openwrt.org/_detail/doc/howto/winscp-ss1.png?id=docs%3Aguide-user%3Aservices%3Awebserver%3Ahttp.mini-httpd "doc:howto:winscp-ss1.png")
Next, get into the router using WinSCP (don't forget to change the protocol) and navigate to /etc Make a backup of `mini_httpd.pem` and stick it in a secure place, just in case you need to revert back to this original key at some point. What I did was copy the file to my desktop and renamed it to `mini_httpd-ORG.pem`
#### A Simple Understanding of TLS and SSL
After much discussion with mancha in the #openssl IRC channel, he explained some basics about the underlying encrypted network connections that I feel are important for those of you who are doing this. Without knowing some of what this guide will teaching, changing it to suit your situation will be more difficult. Creating a certificate is for your router to say to a browser, “Hey this is me and you can trust it is me.” The webserver on the router and your browser will use transport protocol SSL or TLS to negotiate a cipher. Your browser client says “Here are the ciphers I understand”. The server will reply “Good, I understand this subset of ciphers, now pick this one.” This all goes on without our interaction. We just see a browser connecting via HTTPS. This process has nothing to do with the certificate we are creating. This is important to understand, as creating a strong certificate does _not_ mean mini\_httpd and your browser will use the _maximum_ available cipher. So you can generate a 4096-bit RSA certificate, only to have your browser and the server decide to use DES-CBC-SHA (Kx=RSA Au=RSA Enc=DES(56) Mac=SHA1) which is considered a Medium Strength Cipher (>= 56-bit and < 112-bit key). Fortunately, we can force mini-httpd to always use a stronger one. This is detailed below in the section _Forcing a strong SSL/TLS Cipher_.
#### Creating the 1024-bit key and certificate
Step 1: Using PuTTY to access the router over SSH, we then make our keys using openssl by issuing these commands:
openssl req -nodes -new > cert.csr
This requests the key and certificate creation. `-nodes` creates a key which will not be encrypted with a DES pass phrase. More info [here](http://www.madboa.com/geek/openssl/#cert-self "http://www.madboa.com/geek/openssl/#cert-self")
#### Optional: Create a 2048-bit key and certificate instead
If you prefer to have stronger than 1024-bit encryption, use this command _instead_ to get 2048-bit encryption:
openssl req -nodes -newkey rsa:2048 -new > cert.csr
#### Fill in the certificate
Step 2: Next enter this stuff based on your own info:
`Country Name: US State/Province: CA Locality Name: Los Angeles Organization Name: You may hit enter to leave blank. Organization Unit Name: You may hit enter to leave blank. Common Name: 192.168.1.1 Email Address: You may hit enter to leave blank. A Challenge Password: You may hit enter to leave blank. Optional company name: You may hit enter to leave blank.`
Note that `Common Name:` is VERY important. Without this entered properly, it will always error out. Make this the IP of the router, and _do not_ suffix it with the cgi-bin/luci.
#### Convert and sign the certificate
Step 3: Lastly, issue this command:
openssl x509 -in cert.csr -out cert.pem -req -signkey privkey.pem -days 365
x509 option converts the certificate (.csr) to .pem certificate. It then signs the privkey.pem and makes it valid for 1 year. For more info [see this page](http://en.wikipedia.org/wiki/X.509#Certificate_filename_extensions "http://en.wikipedia.org/wiki/X.509#Certificate_filename_extensions")
#### Grabbing the key and certificate
Use WinSCP to login and navigate to /root Copy these 2 files to your OS, as you will be manipulating them (I threw mine on my desktop):
cert.pem (copy to OS, then delete)
privkey.pem (copy to OS, then delete)
cert.csr (Just delete)
#### Creating a new mini-httpd.pem
Open `cert.pem` with a text editor and copy the contents from the top starting with:
\-----BEGIN CERTIFICATE-----
all the way to the end and including the line
\-----END CERTIFICATE-----
Open `privkey.pem`, and right after
\-----END RSA PRIVATE KEY-----
Paste onto the line below it, the contents of cert.pem that you copied.
It should look like this:
\-----BEGIN PRIVATE KEY-----
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
-----END PRIVATE KEY-----
-----BEGIN CERTIFICATE-----
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
RANDOM GARBLED ENCRYPTION RANDOM GARBLED ENCRYPTION
-----END CERTIFICATE-----
Save `privkey.pem`. Then rename it to: `mini_httpd.pem`
Installing the certificate to Windows 7
---------------------------------------
[](https://openwrt.org/_detail/doc/howto/chromeerror.png?id=docs%3Aguide-user%3Aservices%3Awebserver%3Ahttp.mini-httpd "doc:howto:chromeerror.png")
[](https://openwrt.org/_detail/doc/howto/ie-cert-error.jpg?id=docs%3Aguide-user%3Aservices%3Awebserver%3Ahttp.mini-httpd "doc:howto:ie-cert-error.jpg")
To avoid issues with your browser whining that the SSL connection is not secure, we will install the certificate we made to the OS, so that it knows it is indeed safe. Note: At this point in the guide you won't see the above erros in your browser, as the service is not started. They are to demonstrate what it will whine about after you have the service running, but have not yet installed the certificate to your OS.
To accomplish this, we need to install `cert.pem` on the computer(s) accessing the WebGUI. On Windows 7 execute:
certmgr.msc
Next, on the left pane click on Trusted Root Certification Authorities, expand it, or double click on Certificates in the right pane. You should now see a bunch of other certificates.
[](https://openwrt.org/_detail/doc/howto/certmgr-ss.jpg?id=docs%3Aguide-user%3Aservices%3Awebserver%3Ahttp.mini-httpd "doc:howto:certmgr-ss.jpg")
Now, Right-click in the right pane (or click Action in the toolbar) and choose 'All Tasks' then 'Import...' Click on next. Click Browse, in the explorer window that pops up, change the extension (bottom right) from 'X.509 Certificate (\*.cer,\*.crt) to All Files (\*.\*) then select `cert.pem` from your Desktop.
[](https://openwrt.org/_detail/doc/howto/cert-ext-window-ss.png?id=docs%3Aguide-user%3Aservices%3Awebserver%3Ahttp.mini-httpd "doc:howto:cert-ext-window-ss.png")
Then click on next. Choose 'Place all certificates in the following store. If 'Trusted Root Certification Authorities' _is_ select already, click next, then Finish. If it _is not_ already selected, click browse and then click on 'Trusted Root Certification Authorities' and click ok. Then click next, and Finish.
Now, it will issue a security warning. It warns you that it cannot validate the certificate is actually from your router IP address. As this is a self-signed certificate, you know it's from you, so click on YES to install the certificate. It will then successfully install to the Trusted Root Certification Authorities. If you do not see it in the list, simply hit right-click in the right pane, and choose 'Refresh'. Ta-da!
Upload mini\_httpd.pem and starting the service
-----------------------------------------------
Now, before you can access the router by HTTPS, you will need to do a couple more things: giving the router the private key and cert in the form of the `mini_httpd.pem`, and enabling then starting the service.
Now, we already created `mini_httpd.pem` above, so let's place it on the router where it belongs. Using WinSCP, login and navigate to /etc. Delete the existing`mini_httpd.pem` from the router (If you have been following this word for word, then you should already have a backup named `mini_httpd-ORG.pem` on the desktop or wherever) and copy your created `mini_httpd.pem` over to /etc.
Once that is completed, you can close WinSCP.
Starting the service
--------------------
/etc/init.d/mini\_httpd enable
/etc/init.d/mini\_httpd start
### Testing
Try opening a browser and navigate to: [https://192.168.1.1](https://192.168.1.1/ "https://192.168.1.1")
If you have trouble, try: Clearing the cookies/cache in your browser. Trying Incognito mode (Chrome) or InPrivate (Internet Explorer) Try navigating to the full url: `[https://192.168.1.1/cgi-bin/luci](https://192.168.1.1/cgi-bin/luci "https://192.168.1.1/cgi-bin/luci") `
You should get NO error regarding the certificate. :)
### Shutting Down regular HTTP access (uhttpd)
Before Chaos Calmer:
/etc/init.d/uhttpd stop
/etc/init.d/uhttpd disable
To test it's down, navigate to your [http://192.168.1.1](http://192.168.1.1/ "http://192.168.1.1")
and it should error out.
You can also stop and disable this through Luci. Log into Luci (HTTPS), go to the System tab, then to the Startup sub tab. Find uhttpd and choose STOP. Then DISABLE.
Chaos Calmer and later:
uhttpd listens on both http and https, so stopping / disabling uhttpd will turn off both. Instead, tell uhttpd not to listen on http - edit /etc/config/uhttpd and remove the 'listen\_http' lines stop listening on port 80. Then:
/etc/init.d/uhttpd restart
and use:
netstat -l
to verify that nothing is listening on http / TCP port 80.
Forcing a strong SSL/TLS Cipher
-------------------------------
As written above, creating a strong certificate does not mean mini\_httpd and your browser will use the maximum available cipher.
Following [information that I found here](http://www.skytale.net/blog/archives/22-SSL-cipher-settings.html "http://www.skytale.net/blog/archives/22-SSL-cipher-settings.html")
, I found some strong SSL ciphers and plugged them into mini-httpd.
You will need to find which cipher you prefer, or you should be able to use one of the following:
**SSL v3**
DES-CBC3-SHA
RC4-MD5
RC4-SHA
**TLSv1**
DES-CBC3-SHA
AES128-SHA
AES256-SHA
RC4-MD5
RC4-SHA
SEED-SHA
You can find out more about the different ciphers by running:
openssl ciphers -v
The format being Cipher name, Key eXchange, Authentication, Encryption method, and Message Authentication Code
Now, if you run [mini\_httpd --help](http://www.digipedia.pl/man/doc/view/mini-httpd.8/ "http://www.digipedia.pl/man/doc/view/mini-httpd.8/")
you will see that there is a \[-Y cipher\] option. To utilize this, edit your mini\_httpd.conf
vi /etc/mini\_httpd.conf
At the bottom, insert a new line:
cipher=
Obviously replacing with one of those from above. For example:
cipher=AES128-SHA
Save the file. Restart mini\_httpd.
Using a different port
----------------------
By using an un-standard port to run mini-httpd, you add one more layer to the onion of security. Security by obscurity may not be an end-all-be-all, but it never hurts.
Dynamic/Private ports exist in this range: 49152-65535.
If you run [mini\_httpd --help](http://www.digipedia.pl/man/doc/view/mini-httpd.8/ "http://www.digipedia.pl/man/doc/view/mini-httpd.8/")
you will see that there is a \[-p port\] option. To utilize this, edit your mini\_httpd.conf
vi /etc/mini\_httpd.conf
At the bottom, insert a new line:
port=
Obviously replacing with something other than 80 or 443. For example:
port=51529
Save the file. Restart mini\_httpd.
Troubleshooting
---------------
**Help! I need my http back!**
Now, if something happened and need to get back into your router through the normal HTTP GUI. It’s easy to bring it back using SSH.
Login to your router by SSH. Issue the following 2 commands:
/etc/init.d/uhttpd enable
/etc/init.d/uhttpd start
Now, try accessing your 192.168.1.1 via regular http and not https. It should be back up and running.
Notes
-----
I found that a couple of times, I needed to run the commands to shut down and disable uhttpd and restart mini\_httpd like this
/etc/init.d/uhttpd stop
/etc/init.d/uhttpd disable
/etc/init.d/mini\_httpd stop
/etc/init.d/mini\_httpd disable
/etc/init.d/mini\_httpd enable
/etc/init.d/mini\_httpd start
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/03/03 20:30
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/webserver/http.mini-httpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Wake on LAN (sending Ethernet messages to power up network devices)
Wake on LAN (sending Ethernet messages to power up network devices)
===================================================================
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
============================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/services/w_o_l/start#top-2057427842 "Continue with the « docs » section at the top...")
[Wake on LAN (sending Ethernet messages to power up network devices)](https://openwrt.org/docs/guide-user/services/w_o_l/start "docs:guide-user:services:w_o_l:start")
* [Etherwake configuration](https://openwrt.org/docs/guide-user/services/w_o_l/etherwake "docs:guide-user:services:w_o_l:etherwake")
* [Wake on LAN configuration](https://openwrt.org/docs/guide-user/services/w_o_l/wol "docs:guide-user:services:w_o_l:wol")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/16 20:48
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/w_o_l/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] TLS/SSL certificates for a server
TLS/SSL certificates for a server
=================================
[Transport\_Layer\_Security](https://en.wikipedia.org/wiki/Transport_Layer_Security "https://en.wikipedia.org/wiki/Transport_Layer_Security")
(TLS, formerly called SSL) is used to encrypt and protect communication. When a webserver works with regular HTTP protocol i.e. its address starts with `http` but over the encrypted TLS this called HTTPS and a site address starts with `https`.
For all HTTPS sites a web browser shows a lock icon in an address bar.
To enable HTTPS for a website's domain we need a private key and its TLS certificate that was signed by a Certificate Authority (CA).
The OpenWrt admin site LuCI by default supports the HTTPS so you can open it with [httpS://192.168.1.1/](https://192.168.1.1/ "https://192.168.1.1/")
. But it's certificate is self signed and not verified by a CA so your browser will show a warning.
You can buy a TLS cert but nowadays the [Let's Encrypt](https://letsencrypt.org/how-it-works/ "https://letsencrypt.org/how-it-works/")
CA allows to sign and verify certificates for free with a **certbot** program that uses [ACME protocol](https://www.rfc-editor.org/rfc/rfc8555.html "https://www.rfc-editor.org/rfc/rfc8555.html")
. The only problem is that the certificate will have a short period of validity and you have to configure certificate renewal.
There is few ACME clients that automates the cert issuing:
* [certbot](https://certbot.eff.org/ "https://certbot.eff.org/")
is an official ACME client that is feature rich but is too heavy for small OpenWrt routers.
* [acme.sh](https://github.com/acmesh-official/acme.sh "https://github.com/acmesh-official/acme.sh")
is small ACME client that uses shell script and has a LUCI app to configure. This is a recommended for OpenWrt.
* [uacme](https://github.com/ndilieto/uacme "https://github.com/ndilieto/uacme")
lightweight ACME client written in plain C with minimal dependencies: libcurl and one of MbedTLS, OpenSSL or GnuTLS.
* Many others [ACME Client Implementations](https://letsencrypt.org/docs/client-options/ "https://letsencrypt.org/docs/client-options/")
If you have already taken care of certificate automation see also [Installing a publicly trusted certificate](https://openwrt.org/docs/guide-user/luci/getting_rid_of_luci_https_certificate_warnings#option_ainstalling_a_publicly_trusted_certificate "docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings")
.
ACME.sh
-------
See [acme.sh](https://openwrt.org/docs/guide-user/services/tls/acmesh "docs:guide-user:services:tls:acmesh")
Self signed certs
-----------------
See [HTTPS Enable and Certificate Settings and Creation](https://openwrt.org/docs/guide-user/services/webserver/uhttpd#https_enable_and_certificate_settings_and_creation "docs:guide-user:services:webserver:uhttpd")
or [Getting rid of LuCI HTTPS warnings](https://openwrt.org/docs/guide-user/luci/getting_rid_of_luci_https_certificate_warnings#option_bcreating_installing_trusting_a_self-signed_certificate "docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings")
.
Own Certificate Authority with PKI
----------------------------------
See [Installing and trusting a root CA certificate in a PKI](https://openwrt.org/docs/guide-user/services/tls/pki "docs:guide-user:services:tls:pki")
External services
-----------------
You can use CloudFlare.com as a proxy that will terminate TLS and forward requests to your router with HTTP or HTTPS with a self signed certificate. Some tunnels like PageKite or localhost.run are working through HTTPS.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/10/30 05:11
* by ziqin1
[](https://openwrt.org/docs/guide-user/services/tls/certs#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Etherwake configuration
Etherwake configuration
=======================
See also: [Wake on LAN configuration](https://openwrt.org/docs/guide-user/services/w_o_l/wol "docs:guide-user:services:w_o_l:wol")
, [Scheduling tasks](https://openwrt.org/docs/guide-user/base-system/cron "docs:guide-user:base-system:cron")
The configuration file `/etc/config/etherwake` is provided by the _etherwake_ package and defines hosts to wake up when starting the `/etc/init.d/etherwake` script. Install package [luci-app-wol](https://openwrt.org/packages/pkgdata/luci-app-wol "packages:pkgdata:luci-app-wol")
for a web interface.
Sections
--------
There are two sections `setup` and `target` defined for the configuration. Multiple _wake on lan targets_ may exist in the file.
### Setup
config 'etherwake' 'setup'
option 'pathes' '/usr/bin/etherwake /usr/bin/ether-wake'
option 'sudo' 'off'
option 'interface' 'eth0'
option 'broadcast' 'off'
Below is a listing of the parameters defined for this section.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `pathes` | path | yes | _(none)_ | path to etherwake binary (typo is normal) |
| `sudo` | boolean | no | `off` | Should Etherwake invoke sudo for superuser privileges? |
| `interface` | string | no | `eth0` | On which interface to send the WOL packages |
| `broadcast` | boolean | no | `off` | Send WOL packets to the broadcast ethernet address instead of the host's |
### Target
config 'target'
option 'name' 'example' # name for the target
option 'mac' '11:22:33:44:55:66' # mac address of the machine to wake up
option 'password' 'AABBCCDDEEFF' # password in hex without any delimiters
option 'wakeonboot' 'off' # wake up on system start, defaults to off
Below is a listing of the parameters defined for this section.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `name` | string | no | _(none)_ | name of the target |
| `mac` | MAC address | yes | _(none)_ | Specifies the MAC address of the host to wake up |
| `password` | string | no | _(none)_ | Send given _SecureON_ password when waking up the host |
| `wakeonboot` | boolean | no | `off` | Don't send WOL packet when booting OpenWrt |
Example
-------
config 'etherwake' 'setup'
option 'pathes' '/usr/bin/etherwake'
option 'sudo' 'off'
option 'interface' 'eth0.2'
option 'broadcast' 'on'
config 'target'
option 'name' 'popeye'
option 'mac' '00:22:33:44:55:66'
option 'password' 'AABBCCDDEEFF' # password in hex without any delimiters
option 'wakeonboot' 'off'
Wake target
-----------
\# Syntax
/etc/init.d/etherwake start
\# Wake up "popeye"
/etc/init.d/etherwake start popeye
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/06/22 05:17
* by kontaxis
[](https://openwrt.org/docs/guide-user/services/w_o_l/etherwake#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Tinydns
Tinydns
=======
`Tinydns is a DNS server. It accepts iterative DNS queries from hosts around the Internet, and responds with locally configured information. D. J. Bernstein : [http://cr.yp.to/djbdns/tinydns.html](http://cr.yp.to/djbdns/tinydns.html "http://cr.yp.to/djbdns/tinydns.html") `
* * *
That a very good choice for makeing a dns server, the openwrt package is amazing, and have really integrate tinydns on openwrt. Tinydns is very nice for make small domain, and have capability to grow without major change. Compare to Bind design deployment that the day and the night. You should consider djbdns tools and the amazing work done by the packager of Djbdns
[https://dev.openwrt.org/browser/packages/net/djbdns/README](https://dev.openwrt.org/browser/packages/net/djbdns/README "https://dev.openwrt.org/browser/packages/net/djbdns/README")
Install tinydns
---------------
Tinydns is all ready aviable on OpenWrt, you can use opkg tool for install it:
opkg update
opkg install djbdns-base djbdns-tinydns
Configuration file
------------------
**/etc/tinydns/data**
It file contain informations about you Domain Name store in **tinydns-data** format, it format is describ by the author here [http://cr.yp.to/djbdns/tinydns-data.html](http://cr.yp.to/djbdns/tinydns-data.html "http://cr.yp.to/djbdns/tinydns-data.html")
The logic is simple the each line define a thing, and the frist letter of each line is a Flag it define the Type.
* The djbdns-tinydns package provide it file as exemple for make you first tests. You have to edit it file for put you own setting as describ on it document.
* On tipical djbdns deploiement it file is convert to binary cdb format and store in memory, all that work is done via /etc/init.d/tinydns script on OpenWrt.
* Take care about you SOA serial number, each time you change something you have to increase it number. It is not done by the /etc/init.d/tinydns script.
### SOA Serial notes:
`Few admins system like put Epoch (reference date) as SOA serial number, and that a good practice. An other practice can be add +1 each to the SOA Serial number, that work too. That a arbitral value the DNS standard require to add +1 as minimum, that because lot of dns servers will ignore and nor relay you new data file. You can choose to never update it serial if you have only one DNS server at home, but that a bad pratice name “poor design” That the frist cause of mistake increase you SOA manually at all`
UCI integration
---------------
The entire djbdns tools have true UCI integration, here what uci store for tinydns
root@openwrt:/# uci show djbdns | grep 'tinydns\\|global'
djbdns.@global\[0\]=global
djbdns.@global\[0\].runasuser=djbdns
djbdns.@global\[0\].runasgroup=djbdns
djbdns.@tinydns\[0\]=tinydns
djbdns.@tinydns\[0\].logging=0
djbdns.@tinydns\[0\].interface=lan
**djbdns.@global\[0\].runasuser** define with which user the /etc/init.d/tinydns script will execute all djbdns tools.
**djbdns.@global\[0\].runasgroup** define with which group the /etc/init.d/tinydns script will execute all djbdns tools.
**djbdns.@tinydns\[0\].logging** it's the same as export the environement Variable DEBUG before start /etc/init.d/tinydns script. It enable a a mode where init tinydns write it activity.
**djbdns.@tinydns\[0\].interface** init script will determine the ip of the interface set here.
For the entire list of what djbdns uci store:
root@openwrt:/# uci show djbdns
Script provide by djbdns
------------------------
tinydns come with several script it can help you to configure your /etc/tinydns/data file.
Usage of they script will be describe later on it document, for the complet howto follow it link: [http://cr.yp.to/djbdns/run-server.html](http://cr.yp.to/djbdns/run-server.html "http://cr.yp.to/djbdns/run-server.html")
/etc/tinydns/add-alias
/etc/tinydns/add-childns
/etc/tinydns/add-host
/etc/tinydns/add-mx
/etc/tinydns/add-ns
What a tipical conf can be
--------------------------
All IP use for they exemples should be change for you own IP
They docs declare each time the last MX to a antispam black list, that a good practice, same for spf txt entry.
The Reverse address xxx.xxx.xxx.xxx.in-addr.arpa is declare like that for a Local Area Network, in case you use IP public to a Wide Area Network the reverse entry should be done via an ISP (Internet Provider) tool, general a web interface, or a Incident Ticket.
_Minimal setting for a personal usage_:
#SOA
Zexemple.net:ns1.exemple.net:hostmaster.exemple.net:1330551249:16384:2048:1048576:2560:::
#NS
.exemple.net:192.168.31.215:ns1.exemple.net:259200:
.215.31.168.192.in-addr.arpa::ns1.exemple.net:259200:
#Domain
+exemple.net:192.168.31.215:86400
#MX
@exemple.net:192.168.31.215:mx1.exemple.net:10:86400
@exemple.net:tarbaby.junkemailfilter.com:tarbaby.junkemailfilter.com:30:86400
:exemple.net:16:\\016v=spf1\\040mx\\040-all:86400
#Exemple Web servers
=www.exemple.net:192.168.31.215:86400
#Mail Server
=mail.exemple.net:192.168.31.215:86400
_Multi NS , Multi MX exemple_:
#SOA
Zexemple.net:ns1.exemple.net:hostmaster.exemple.net:1330551249:16384:2048:1048576:2560:::
#NS1
.exemple.net:192.168.31.215:ns1.exemple.net:259200:
.215.31.168.192.in-addr.arpa::ns1.exemple.net:259200:
#NS2
.exemple.net:192.168.185.63:ns2.exemple.net:259200:
.63.185.168.192.in-addr.arpa::ns2.exemple.net:259200:
#NS3
.exemple.net:192.168.114.57:ns3.exemple.net:259200:
.57.114.168.192.in-addr.arpa::ns3.exemple.net:259200
#Domain
+exemple.net:192.168.31.215:86400
#MX
@exemple.net:192.168.31.215:mx1.exemple.net:10:86400
@exemple.net:192.168.114.57:mx2.exemple.net:20:86400
@exemple.net:tarbaby.junkemailfilter.com:tarbaby.junkemailfilter.com:30:86400
:exemple.net:16:\\016v=spf1\\040mx\\040-all:86400
#Web servers
=www.exemple.net:192.168.31.215:86400
=www1.exemple.net:192.168.31.215:86400
=www2.exemple.net:192.168.114.57:86400
#Ntp servers
=ntp1.exemple.net:192.168.31.215:86400
=ntp2.exemple.net:192.168.114.57:86400
#Mail Server
=mail.exemple.net:192.168.31.215:86400
#Other
+friends.exemple.net:192.168.72.94:86400
Test you installation
---------------------
Open a terminal session on you machine, export a env variable name DEBUG, then start/restart the tinydns init script.
export DEBUG="1"; /etc/init.d/tinydns restart
Restarting Authoritative nameserver: tinydns...
Stopping Authoritative nameserver: tinydns .
Starting Authoritative nameserver: tinydns
starting tinydns
The tinydns server restart, but keep the hand, now you can test from an other machine or a other terminal session.
The exemple for make the test is done with djbdns “dnsq” tool but it work with “dig”,“nslookup”, or all other resolver you like.
dnsq a mail.exemple.net $YOU\_TINYDNS\_IP\_ADDRESS
1 mail.exemple.net:
155 bytes, 1+1+3+3 records, response, authoritative, noerror
query: 1 mail.exemple.net
answer: mail.exemple.net 86400 A $IP\_ADRESS\_MAIL
authority: exemple.net 259200 NS ns1.exemple.net
authority: exemple.net 259200 NS ns2.exemple.net
authority: exemple.net 259200 NS ns3.exemple.net
additional: ns1.exemple.net 259200 A $IP\_ADRESS\_NS1
additional: ns2.exemple.net 259200 A $IP\_ADRESS\_NS2
additional: ns3.exemple.net 259200 A $IP\_ADRESS\_NS3
From you frist terminal, you should see tinydns recive and reply to the request
c0a8010f:bc4b:3a0c + 0001 mail.exemple.net
stats 1 1 0 0 0 0 0
That mean it work, but remenber to back to the normal, because when you'll leave you terminal session tinydns will die with it.
On you first terminal session use the combinaison key “Control + C” for close tinydns then:
^C
root@openwrt:/root# unset DEBUG; /etc/init.d/tinydns restart
Restarting Authoritative nameserver: tinydns...
Stopping Authoritative nameserver: tinydns .
Starting Authoritative nameserver: tinydns
root@openwrt:/root#
The tinydns restart and give back the hand, if you have enable the service at startup you'll be a enjoy guy :)
### Have you own domain name :
It's possible to have you own domain for free by exemple with : [http://www.eu.org](http://www.eu.org/ "http://www.eu.org")
, but generally you have to pay to a registar a lease for you domain.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/03/03 20:15
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/dns/tinydns#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] DLNA Media Server
DLNA Media Server
=================
Based on the official DLNA standard, this service streams pictures, videos and music of a given media folder to DLNA-capable entertainment devices on the same network (e.g. modern Smart-TVs)
* The DLNA service is based on an up to date version of [Minidlna (Readymedia)](https://sourceforge.net/projects/minidlna "https://sourceforge.net/projects/minidlna")
.
* A LuCi web admin GUI package is available, to be found in the Luci “Services” menu, if installed
**Device requirements:**
* Device flash size: >8MB or using extroot recommended (The package and its dependencies take about 3-3.5 MB of total flash space)
* Device memory size: >=64MB RAM recommended (older OpenWrt documentations claim it may run with 32MB as well)
**Possible usage limitations:**
As LEDE devices usually do not have multimedia-CPUs, it may be recommended, to disable index picture creation on small scale LEDE devices, to avoid doing (J/M)PEG decoding on the device CPU. The streaming itself takes very little to no CPU-cycles on the LEDE device, as the media file decoding is not handled by DLNA on the LEDE device, but by the receiving device.
Config file location and documentation
--------------------------------------
* LEDE config file location: `/etc/config/minidlna`
* External link to extensive Ubuntu documentation: [minidlna.conf](http://manpages.ubuntu.com/manpages/cosmic/en/man5/minidlna.conf.5.html "http://manpages.ubuntu.com/manpages/cosmic/en/man5/minidlna.conf.5.html")
* More reading and useful commands: [MiniDLNA Ubuntu community](https://help.ubuntu.com/community/MiniDLNA "https://help.ubuntu.com/community/MiniDLNA")
Installation
------------
opkg update
opkg install minidlna
opkg install luci-app-minidlna
* A SmartTV to access the DLNA service has to be in the same network, as SmartTVs automatically issue broadcast messages from time to time, to find DLNA data providers in the same network (if the SmartTV supports DLNA).
* The files available for streaming by this DLNA service will then be visible in the TV specific media browser / TV source selector for viewing.
* It depends on the supported media types of the SmartTV software, whether the SmartTV can decode and show the media files
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/03/29 16:11
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/media_server/dlna#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:services:network_monitoring:collectd.rrdtool
* Install all needed packages
* opkg install collectd collectd-mod-cpu collectd-mod-disk collectd-mod-iptables collectd-mod-load collectd-mod-memory collectd-mod-ping collectd-mod-rrdtool collectd-mod-uptime rrdtool uhttpd nano # 1.6 MB of space needed
* Configure collectd.conf file
* nano /etc/collectd.conf
* Enable and start collectd service
* /etc/init.d/collectd enable
* /etc/init.d/collectd start
* Enable uhttpd web server
* /etc/init.d/uhttpd enable
* /etc/init.d/uhttpd start
* Enable traffic monitoring
* echo “iptables -N traffic” >> /etc/rc.local
* echo “iptables -I FORWARD -j traffic” >> /etc/rc.local
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/03/03 20:19
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/network_monitoring/collectd.rrdtool#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Bandwidthd
Bandwidthd
==========
Update 4/19/2026. Bandwidthd is no longer available after OpenWRT 22.03.7. It is removed in September 2023 commit, see details here: [https://github.com/openwrt/packages/pull/22008](https://github.com/openwrt/packages/pull/22008 "https://github.com/openwrt/packages/pull/22008")
[http://bandwidthd.sourceforge.net/](http://bandwidthd.sourceforge.net/ "http://bandwidthd.sourceforge.net/")
(openWRT older than 17)
[https://github.com/NethServer/bandwidthd](https://github.com/NethServer/bandwidthd "https://github.com/NethServer/bandwidthd")
(openWRT 17 or higher)
**Note: bandwidthd in LEDE/OpenWRT 17.01 or higher tracks the SMTP data (ports 25, 465 and 587) while the version in the previous version of OpenWrt (Chaos Calmer and older) tracks the P2P data (Gnutella, eDonkey, etc.). All of the other data (FTP, UDP, TCP, etc.) is tracked the same way in all versions.**
**Bandwidthd is composed of 4 packages:**
1. **bandwidthd**: this package cannot save in a postgresql or sqlite database. This allows the router to generate bandwidth data that is accessible with a browser at [http://192.168.1.1/bandwidthd](http://192.168.1.1/bandwidthd "http://192.168.1.1/bandwidthd")
. **__Use this package if you have no intention of storing the data on a postgresql or sqlite database.__**
2. **bandwidthd-pgsql**: this package can do everything the bandwidthd package can do, but in addition it can save the data to a postgresql database that can reside on the router or on another server. This data can be analyzed by a series of PHP scripts and visualized with a browser. Note that the router, the posgresql database and the graphing of the data by PHP can be on three different systems, one for each task (i.e.: _collecting the data_, _storing the postgresql data_ and _generating the graphs with PHP_). Note that postgresql does not have to be installed on the router if the postgresql data is not stored on the router. **NOTE: install only one of the package: bandwidthd, bandwidthd-pgsql or bandwidthd-sqlite.**
3. **bandwidthd-php**: This package contains the PHP files that are installed in /www/phphtdocs on the router. It is only required if the OpenWrt router serves as the web server to generate the graphs from the data on the postgresql database by pointing the browser to [http://192.168.1.1/phphtdocs](http://192.168.1.1/phphtdocs "http://192.168.1.1/phphtdocs")
. **NOTE: if you installed bandwidthd-sqlite, do not install bandwidthd-php as bandwidthd-sqlite contains the required PHP files to graph the data.**
4. **bandwidthd-sqlite**. This package, in addition to do what the plain bandwidthd package can do, stores the data in a sqlite database on the router and graph the data using PHP. In a way, it is a combination of bandwidthd-pgsql and bandwidthd-php together, but using sqlite instead of postgresql. **NOTE: install only one of the package: bandwidthd, bandwidthd-pgsql or bandwidthd-sqlite.**
The availability of each package varies according to which version of OpenWrt/LEDE you have:
**bandwidthd**
* In Backfire (10.03 or 10.03.1) as a package.
* In Attitude Adjustment (12.09) as a package.
* In Barrier Breaker (14.07) in “oldpackages” as a package.
* In original Chaos Calmer (15.05) _it is not available as a precompiled package_: you have to compile it yourself and install it. See [https://wiki.openwrt.org/doc/howto/build](https://wiki.openwrt.org/doc/howto/build "https://wiki.openwrt.org/doc/howto/build")
to have details on how to compile a package.
* As a package in 15.05.1 or higher.
**bandwidthd-pgsql**
* In the original Chaos Calmer (15.05) _it is not available as a precompiled package_: you have to compile it yourself and install it. See [https://wiki.openwrt.org/doc/howto/build](https://wiki.openwrt.org/doc/howto/build "https://wiki.openwrt.org/doc/howto/build")
to have details on how to compile a package.
* In the minor fix release of Chaos Calmer (15.05.1) it is available as a package.
* As a package in 15.05.1 or higher.
**bandwidthd-php**
* Available in LEDE/OpenWRT 17.01 or higher as a package and uses php7 or php8. The PHP files found in these versions work fine with Chaos Calmer 15.05 or 15.05.1 with php5 (tested).
**bandwidthd-sqlite**
* Available in LEDE/OpenWRT 17.01 or higher.
Installation
------------
For the bandwidthd package:
opkg install bandwidthd uhttpd
/etc/init.d/uhttpd enable
/etc/init.d/uhttpd start
/etc/init.d/bandwidthd enable
/etc/init.d/bandwidthd start
For the bandwidthd-pgsql package (note: do not install uhttpd if you do not plan for the router to perform the graphs):
opkg install bandwidthd-pgsql uhttpd
/etc/init.d/uhttpd enable
/etc/init.d/uhttpd start
/etc/init.d/bandwidthd enable
/etc/init.d/bandwidthd start
With all dependencies it uses around 500 kB of storage space. If you have not changes the IP address of your router (192.168.1.1), then the web page with the bandwidthd data will be available at [http://192.168.1.1/bandwidthd](http://192.168.1.1/bandwidthd "http://192.168.1.1/bandwidthd")
. If you have changed the IP address of your router, then edit the /etc/config/bandwidthd file to correct the address.
Configuration
-------------
Packages **bandwidth**, **bandwidthd-pgsql** and **bandwidthd-sqlite** use basically the same configuration file: _/etc/config/bandwidthd_
Each package installs the proper configuration file, and usually requires very little modifications, if any.
The options are the same for the 3 packages, with two additional for **bandwidthd-pgsql** and two others for **bandwidthd-sqlite**.
Here are the various options:
_option dev_: Device to listen on. The default is _br-lan_.
_option subnets_: Subnets to collect statistics on. Traffic that matches none of these subnets will be ignored. Syntax is either IP Subnet Mask or CIDR. Ex: _“10.0.0.0 255.0.0.0”_, _“192.168.0.0/16”_ or _“172.16.0.0/12”_. The defaults is _“192.168.1.0/24”_.
_option skip\_intervals_: An interval is 2.5 minutes, this is how many intervals to skip before doing a graphing run. The default is _0_.
_option graph\_cutoff_: Graph cutoff is how many k must be transferred by an ip before we bother to graph it. The default is _1024_.
_option promiscuous_: Put interface in promiscuous mode to score to traffic that may not be routing through the host machine. The default is _true_.
_option output\_cdf_: Log data to cdf file _log.cdf_. All packages can log to cdf files. These are only useful if you are using the **bandwidthd** package as the other packages (**bandwidthd-pgsql** and **bandwidthd-sqlite**) can store the data in a database. These files are located on the root of the router (/). The cdf files can be read when bandwidthd is started (see the option recover\_cdf), which is useful if you reboot the router to recover the bandwidth data. The default is _false_.
_option recover\_cdf_: Read back the cdf file on startup. See the comments for _output\_cdf_ above. The default is _false_.
_option filter_: Libpcap format filter string used to control what bandwidthd see's. Please always include “ip” in the string to avoid strange problems. The default is _ip_.
_option graph_: Draw Graphs - This default to true to graph the traffic bandwidthd is recording. Usually set this to false if you only want cdf output or you are using the database output option (**bandwidthd-pgsql** or **bandwidthd-sqlite**). Bandwidthd will use very little ram and cpu if this is set to false. The defaults is _true_.
_option meta\_refresh_: Set META REFRESH seconds (default 150, use 0 to disable). Default is _150_.
_option pgsql\_connect\_string_: Only used for **bandwidthd-pgsql**. Standard postgres connect string. The default is _“user = postgres dbname = bandwidthd host = 192.168.1.1”_.
_option sensor\_id_: Used for **bandwidthd-pgsql** and **bandwidthd-sqlite**. Arbitrary sensor name. It can be anything you want for **bandwidthd-pgsql** but it has to be _“default”_ for **bandwidthd-sqlite**. Default is _“openwrt”_ for **bandwidthd-pgsql**.
_option sqlite\_filename_: Only used for **bandwidthd-sqlite**. This is the sqlite database file. Default is _“/www/bandwidthd/stats.db”_.
The package **bandwidthd-php** uses another configuration file: _/etc/config/bandwidthd-php_. Package **bandwidthd-sqlite** can also use the _bandwidthd-php_ configuration file (**bandwidthd-sqlite** uses two configuration files: _/etc/config/bandwidthd_ and _/etc/config/bandwith-php_).
**NOTE:** the **bandwidthd-sqlite** package does not provide the _/etc/config/bandwidthd-php_ file: it is not needed as the init file (_/etc/init.d/bandwidthd_) will provide the bandwidthd application the default graph sizes (900 and 256) and interval (INT\_DAILY) and the default sqlite database: _/www/bandwidthd/stats.db_. Create a /etc/config/bandwidthd-php file for bandwidthd-sqlite if you need to change the default.
Here are the options of the _/etc/config/bandwidthd-php_ configuration file:
_option dflt\_width_: Widthd of the graphs generated. Default is _'900'_.
_option dflt\_height_: height of the graphs generated. Default is _'256'_.
_option dflt\_interval_: Defaultinterval for the graphs. The default is _'INT\_DAILY'_. Options are: _INT\_DAILY_, _INT\_WEEKLY_, _INT\_MONTHLY_ and _INT\_YEARLY_.
_option host_: This is for the host that has the postgresql database. The default is _'127.0.0.1'_ which is the router.
_option user_: This is the user owning the postgresql database. Default is _'postgres'_.
_option dbname_: This is the name of the postgresql database. Default is _'bandwidthd'_.
A _/etc/config/bandwidthd-php_ for **bandwidthd-sqlite** will have the same structure, but the options _host_, _user_ and _dbname_ are not needed and are replaced by the following:
_option sqlite\_dbname “/www/bandwidthd/stats.db”_
Usage
-----
By default, bandwidthd hosts its statistics at /bandwidthd. All packages (**bandwidthd**, **bandwidthd-pgsql** and **bandwidthd-sqlite**) are set by default to graph and if this is not the behaviour that you want, then change the _option graph_ to _false_ in the configuration file (_/etc/config/bandwidthd_) For example, if the OpenWRT router's IP address is 192.168.1.1, bandwidthd's stats would be available at [http://192.168.1.1/bandwidthd](http://192.168.1.1/bandwidthd "http://192.168.1.1/bandwidthd")
**bandwidthd-pgsql** can store in a postgresql database and PHP has to be used to generate the graphs that are available at [http://192.168.1.1/phphtdocs/index.php](http://192.168.1.1/phphtdocs/index.php "http://192.168.1.1/phphtdocs/index.php")
(see below) (of course, change the IP address to the one of the web server hosting the PHP files (your router or whatever web server you are using to graph the data)).
Storing bandwidthd stats in external permanent storage
------------------------------------------------------
The default bandwidthd installation loses your previous statistics on each reboot and you need more space to save those. To keep statistics it is needed to modify “/etc/config/bandwidthd”.
You need to change “option output\_cdf true” and “option recover\_cdf true” and “option sqlite\_filename 'file.db' ”
config bandwidthd
option dev br-lan
option subnets "192.168.1.0/24"
option skip\_intervals 0
option graph\_cutoff 1024
option promiscuous true
option output\_cdf true
option recover\_cdf true
option filter ip
option graph true
option meta\_refresh 150
option SQLite\_filename "/path/to/file.db" # file gets created automatically and default path works pretty well
After modifying both of the files, restart the service. Afterwards, you will get a file and directory structure on your external mount like this:
root@openwrt:~# ls -la /mnt/usb/bandwidthd/
drwxr-xr-x 3 root root 1024 Aug 25 12:21 .
drwxr-xr-x 6 root root 1024 Aug 25 00:39 ..
-rw-r--r-- 1 root root 158 Aug 25 00:40 bandwidthd.conf
drwxr-xr-x 2 root root 2048 Aug 25 00:40 htdocs
-rw-r--r-- 1 root root 50034 Aug 25 12:21 log.1.0.cdf
-rw-r--r-- 1 root root 22204 Aug 25 12:21 log.2.0.cdf
-rw-r--r-- 1 root root 6698 Aug 25 12:10 log.3.0.cdf
-rw-r--r-- 1 root root 529 Aug 25 00:39 log.4.0.cdf
Storing bandwidthd stats in a postgresql database
-------------------------------------------------
Bandwidthd now has support for external databases: it is provided by the **bandwidthd-pgsql** package: _the **bandwidthd** package does not support this_. This system consists of 3 major parts, and each part can be on a different server:
1. **The bandwidthd binary** which acts as a sensor, recording traffic information and storing it in a database across the network or on the OpenWrt router. In this mode Bandwidthd uses very little ram and CPU. In addition, multiple sensors can record to the same database.
2. **The database system.** Currently Bandwidthd only supports Postgresql. Please note that the postgres-server package on OpenWrt is pretty big (the server and a blank database takes more than 15 MB) and unless you have at lot of memory in your router, you will not be able to install it!
3. **The webserver and php application.** The package **bandwidthd-php** provides the required file if these have to run on the OpenWrt router. In the “/www/phphtdocs” directory is a php application that reports on and graphs the contents of the database. This has been designed to be easy to customize. Everything is passed around on the urls, just tinker with it a little and you'll see how to generate custom graphs pretty easy.
Using Bandwidthd with a database has many advantages, such as much lower overhead, because graphs are only graphed on demand. And much more flexibility, SQL makes building new reports easy, and php+sql greatly improves the interactivity of the reports.
**It is strongly recommended to use the router only to collect the data and store it to another server running postgres.** That same server can also be running the web server and use PHP to generate the graphs, but generating the graphs can take a lot of CPU time for a router and the various packages (postgresql, php) uses a lot of memory space that most router do not have.
**INSTRUCTIONS**
As a prerequisite for these instructions, you must have Postgresql server installed and working for the database, as well as a web server that supports php for the web server that will generate the graphs. Consult [https://forum.openwrt.org/viewtopic.php?id=11812](https://forum.openwrt.org/viewtopic.php?id=11812 "https://forum.openwrt.org/viewtopic.php?id=11812")
to have more information on installing postgresql on OpenWrt. For other OSes (Linux, NetBSD, Unix, etc.) consult the help on the respective OS.
**_Database Setup:_** Note that the database can reside on a remote computer and does not have to be on the OpenWrt router. If not using the router for the database, the required files for the setup can be found at [http://bandwidthd.sourceforge.net/](http://bandwidthd.sourceforge.net/ "http://bandwidthd.sourceforge.net/")
.
1. Create a database for bandwidthd. You will need to create a user that can access the database remotely if you want remote sensors. In OpenWrt, log as the user postgres (su - postgres) and issue the command “createdb bandwidthd”, then go back to be the root user with “exit”.
2. Bandwidthd's schema is in “schema.postgresql” that can be found in /usr/share/postgresql (provided by the bandwidthd-pgsql package). “psql mydb username < schema.postgresql” should load it and create the 2 tables and 4 indexes.
In addition, you should schedule bd\_pgsql\_purge.sh to run every so often. I recommend running it weekly. This script outputs sql statements that aggregate the older data points in your database in order to reduce the amount of data that needs to be slogged through in order to generate yearly, monthly, and weekly graphs.
Example to be run as the postgres user:
bd\_pgsql\_purge.sh | psql bandwidthd postgres
Will connect to the bandwidthd database on local host as the user postgres and summarize the data.
**_Bandwidthd Setup:_** Here is the /etc/config/bandwidthd file in the **bandwidthd-pgsql** package:
config bandwidthd
option dev br-lan
option subnets "192.168.1.0/24"
option skip\_intervals 0
option graph\_cutoff 1024
option promiscuous true
option output\_cdf false
option recover\_cdf false
option filter ip
option graph true
option meta\_refresh 150
option pgsql\_connect\_string "user = postgres dbname = bandwidthd host = 192.168.1.1"
option sensor\_id "openwrt"
The default configuration file may work, but chances are that you will have to modify it. Modify the following lines:
option graph false
By default this is true so you can at least get some graph at http://192.168.1.1/bandwidthd even if the pgsql settings
are not adequate. If you plan to only use PHP to obtain your graphs, then set it at false.
option pgsql\_connect\_string "user = postgres dbname = bandwidthd host = 192.168.1.1"
Change the user variable to the proper username
Change the dbname variable to the database name (by default it is bandwidthd)
Change the host variable to the IP address (or the domain name) of the postghresql server
option sensor\_id "openwrt"
Change the name to the name that you want for your sensor: the name you give is not really critical.
Simply start bandwidthd (/etc/init.d/bandwidthd start), and after a few minutes data should start appearing in your database. If not, check syslog (logread) for error messages. (see [https://wiki.openwrt.org/doc/howto/log.essentials](https://wiki.openwrt.org/doc/howto/log.essentials "https://wiki.openwrt.org/doc/howto/log.essentials")
if you want more information on syslog in OpenWRT)
**_Web Server Setup:_** Note that the web server can be on a remote web server and does not have to reside on the OpenWrt router. Consult [http://wiki.openwrt.org/doc/howto/php](http://wiki.openwrt.org/doc/howto/php "http://wiki.openwrt.org/doc/howto/php")
for installation of PHP on OpenWrt. For other OSes (Linux, NetBSD, Unix, etc.) consult the help on the respective OS. You will also have to configure the web server to work with PHP. Running this on OpenWrt takes about 2 MB of storage space for the various packages.
1. Copy the contents of phphtdocs into your web tree somewhere: these files are available at [http://bandwidthd.sourceforge.net/](http://bandwidthd.sourceforge.net/ "http://bandwidthd.sourceforge.net/")
, [https://github.com/NethServer/bandwidthd](https://github.com/NethServer/bandwidthd "https://github.com/NethServer/bandwidthd")
or in the **bandwidthd-php** package: the package will install them automatically and puts then in /www/phphtdocs.
2. Edit the file bandwidthd-php in /etc/config to set your db connect string (_$db\_connect\_string = “host=192.168.1.1 user=postgres dbname=bandwidthd”_). The variables _host_, _user_ and _dbname_ have to be edited in order to connect to the database.
3. On OpenWrt, the following packages will be installed automatically: **libpcre**; **libxml2**; **php7**; **php7-cgi**; **php7-mod-pgsql** and **php7-mod-gd**. On another system, the corresponding packages should be installed. Note that it also works with php5 which to be used on Chaos Calmer as php7 is not available.
4. Starting at the end of 2021, **php8** maybe installed instead of **php7**.
5. With php5, a zoneinfo package should be installed (ex: **zoneinfo-northamerica** or **zoneinfo-europe**). This is required to set the date.timezone value in php.ini.
6. If you are not using the **bandwidthd-php** package from OpenWrt (i.e. you got the php files on the web at one of the links above), the file /etc/php.ini should be edited to have the following: **short\_open\_tag = On**: the reason is that the php files taken from [http://bandwidthd.sourceforge.net/](http://bandwidthd.sourceforge.net/ "http://bandwidthd.sourceforge.net/")
or [https://github.com/NethServer/bandwidthd](https://github.com/NethServer/bandwidthd "https://github.com/NethServer/bandwidthd")
have the php short tag ( ?>) instead of the normal tag (). If you do not do it, then you will get a bunch of garbage on the screen. If you installed the **bandwidthd-php** package on your router, then this is not necessary to set the **short\_open\_tag =** at **On** as the tags in the php files have been corrected to have .
7. In the /etc/php.ini file a **date.timezone =** whould be present (ex:**date.timezone = “America/Montreal”**). _Without the **date.timezone** set to something valid, the graphs will not be drawn_.
8. In the /etc/php.ini file the **display\_errors** should be set to off as many variables are not defined. If you have **display\_errors = On** the web page will most probably not work.
9. If you are using uhttpd, the following two lines should be added to /etc/config/uhttpd: **list interpreter '.php=/usr/bin/php-cgi'** and **option index\_page 'index.php'**.
You should now be able to access the web application and see you graphs. All graphing is done by graph.php, all parameters are passed to it in it's url. You can create custom urls to pull custom graphs from your own index pages, or use the canned reporting system.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/04/19 07:09
* by jx2014
[](https://openwrt.org/docs/guide-user/services/network_monitoring/bandwidthd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Zabbix network monitoring
Zabbix network monitoring
=========================
There are a number of packages for [Zabbix](https://www.zabbix.com/ "https://www.zabbix.com/")
in OpenWrt, as listed on [administration---zabbix](https://openwrt.org/packages/index/administration---zabbix "packages:index:administration---zabbix")
.
Zabbix Agent
------------
In OpenWrt the zabbix-agentd is a standard Zabbix 7.0.9 agent (for OpenWrt 24.10.0 through 24.10.4, at least) [whose configuration is detailed in the upstream Zabbix documentation](https://www.zabbix.com/documentation/7.0/en/manual/appendix/config/zabbix_agentd "https://www.zabbix.com/documentation/7.0/en/manual/appendix/config/zabbix_agentd")
. In OpenWrt, however, there are three precompiled 'flavors': the base (no SSL) agent, the agent with GnuTLS for SSL, and the agent with OpenSSL for SSL.
In OpenWrt 25.12 the user under which the agent runs has been changed from \`zabbix\` to \`zabbix-agent\` and you have to add \`User=zabbix-agent\` to \`zabbix\_agentd.conf\`, otherwise your system log will be flooded with
`daemon.err: zabbix_agentd[8071]: zabbix_agentd [8071]: user zabbix does not exist daemon.err: zabbix_agentd[8071]: zabbix_agentd [8071]: cannot run as root!`
Zabbix Server
-------------
The Zabbix Server packages (for the same three flavors as the agent) in OpenWrt currently do not have a `procd` initscript, so here is one you can use until one is added to the package (add as `/etc/init.d/zabbix_server` and issue `/etc/init.d/zabbix_server enable`. You will likely also want to add `/etc/init.d/zabbix_server` to `/etc/sysupgrade.conf` in order to preserve the initscript during a sysupgrade).
**Note**: This script expects `/etc/zabbix_server.conf` to contain a directive `PidFile=/etc/zabbix/zabbix_server.pid`
#!/bin/sh /etc/rc.common
# Copyright (C) 2008-2011 OpenWrt.org
START=59
USE\_PROCD=1
PROG=/usr/sbin/zabbix\_server
CONFIG=/etc/zabbix\_server.conf
mkdir -p /run/zabbix
chown zabbix:zabbix /run/zabbix
chown zabbix:zabbix ${CONFIG}
start\_service() {
\[ -f ${CONFIG} \] || return 1
procd\_open\_instance
procd\_set\_param command ${PROG} -c ${CONFIG} -f
procd\_set\_param limits nofile="16384 100000"
procd\_set\_param file ${CONFIG}
procd\_set\_param user zabbix
procd\_set\_param respawn
procd\_set\_param stdout 1
procd\_set\_param stderr 1
procd\_close\_instance
}
Zabbix Server Frontend (Web UI)
-------------------------------
The web interface for Zabbix is in the package `zabbix-server-frontend`. It is not configured by default and takes some work to get setup. For a tutorial on this, see [frontend\_tutorial](https://openwrt.org/docs/guide-user/services/network_monitoring/zabbix/frontend_tutorial "docs:guide-user:services:network_monitoring:zabbix:frontend_tutorial")
.
OpenWrt 'extra' packages for Zabbix
-----------------------------------
There are 3 'extra' packages for zabbix that add userparameters and detections rules for zabbix-agentd:
* zabbix-extra-network: a detection rule with the ifname (eth0.1) and the network name (wan)
* zabbix-extra-wifi: an universal detection rule for wifi (using libuci-lua) and many userparameters (using libiwinfo-lua)
* zabbix-extra-mac80211: a phy (phy0) detection rule and userparameters for mac80211 devices
Here follow Zabbix templates for Openwrt
“Template Openwrt Mac80211” (for zabbix-extra-mac80211): [http://pastebin.com/3iWQq2kc](http://pastebin.com/3iWQq2kc "http://pastebin.com/3iWQq2kc")
“Template Openwrt Network” (for zabbix-extra-network): [http://pastebin.com/5Jcg7w9j](http://pastebin.com/5Jcg7w9j "http://pastebin.com/5Jcg7w9j")
“Template Openwrt Wifi” (for zabbix-extra-wifi): [http://pastebin.com/uWtWT6C8](http://pastebin.com/uWtWT6C8 "http://pastebin.com/uWtWT6C8")
“All in one”: [http://pastebin.com/nQdZM89w](http://pastebin.com/nQdZM89w "http://pastebin.com/nQdZM89w")
Relevant commit: [https://dev.openwrt.org/changeset/36740](https://dev.openwrt.org/changeset/36740 "https://dev.openwrt.org/changeset/36740")
Tips and tricks for Zabbix on OpenWrt
-------------------------------------
### Configure Zabbix Server to monitor flash file systems
By default, Zabbix does not monitor flash filesystems such as ubifs or f2fs. Here is how to monitor them.
In the Zabbix web UI:
1. Select 'Administration|General|Regular expressions'
2. Update 'Filesystems for discovery to include f2fs|ubifs (E.g. update 'Expressions' to `^(btrfs|ext2|ext3|ext4|f2fs|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|ubifs|zfs)$`
3. Select 'Update'
4. Clone 'Data collection|templates|Linux by Zabbix agent' (and/or 'Data collection|templates|Linux by Zabbix agent active') as 'Data collection|Templates|Linux on OpenWrt by Zabbix agent'
5. Select 'Data collection|Templates|Linux on OpenWrt by Zabbix agent'
6. Select 'Macros'
7. Edit `{$VFS.FS.FSTYPE.MATCHES}` to be `^(btrfs|ext2|ext3|ext4|f2fs|reiser|xfs|ffs|ufs|jfs|jfs2|vxfs|hfs|apfs|refs|ntfs|fat32|ubifs|zfs)$`
8. Select 'Update'
9. Optional: Repeat this for host macros
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/03/06 05:32
* by ingoratsdorf
[](https://openwrt.org/docs/guide-user/services/network_monitoring/zabbix#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Bandwith Monitoring with wrtbwmon
Bandwith Monitoring with wrtbwmon
=================================
wrtbwmon is a small and basic shell script designed to run on linux powered routers (OpenWRT, DD-WRT, Tomato, and other routers where shell access is available). It provides per user bandwidth monitoring capabilities and generates usage reports. See the screenshot [here](https://raw.githubusercontent.com/pyrovski/wrtbwmon/master/example.png "https://raw.githubusercontent.com/pyrovski/wrtbwmon/master/example.png")
.
Original wrtbwmon is hosted on [code.google](https://code.google.com/p/wrtbwmon/ "https://code.google.com/p/wrtbwmon/")
, but it has been dead since 2010. We have a fork for OpenWrt which is hosted on [github](https://github.com/pyrovski/wrtbwmon "https://github.com/pyrovski/wrtbwmon")
by pyrovski.
There are many good general descriptions about how to install it:
1. [google code](https://code.google.com/p/wrtbwmon/wiki/Deploying "https://code.google.com/p/wrtbwmon/wiki/Deploying")
2. [kallisti](http://www.kallisti.net.nz/blog/2010/12/per-user-traffic-monitoring-on-openwrt/ "http://www.kallisti.net.nz/blog/2010/12/per-user-traffic-monitoring-on-openwrt/")
3. [pyrovski](https://github.com/pyrovski/wrtbwmon "https://github.com/pyrovski/wrtbwmon")
Installation
------------
Based on these 3 descriptions I've created a step-by-step manual for installing wrtbwmon on OpenWrt:
* download latest tar.gz from [https://github.com/pyrovski/wrtbwmon/releases](https://github.com/pyrovski/wrtbwmon/releases "https://github.com/pyrovski/wrtbwmon/releases")
* tar -zxvf /tmp/wrtbwmon-0.2.tar.gz
* copy that 7 files to any folder, eg /opt/wrtbwmon/
* edit wrtbwmon.sh to set both baseDir and dataDir to point to directory of readDB.awk and usage.htm\* (eg /opt/wrtbwmon/)
Note: If you're looking for an install that will collect data for you in a sqlite3 database
* Download latest tar.gz from [https://github.com/Jcarnage/wrtbwmon.git](https://github.com/Jcarnage/wrtbwmon.git "https://github.com/Jcarnage/wrtbwmon.git")
.
* It's based on the pyrovski base release package but adds a remote scripts for capturing and displaying all the data.
using first time
----------------
Using wrtbwmon consists of three separated steps: setup, update and publish.
Note: The setup below uses pyrovski's version of wrtbwmon. Other versions may differ.
* ./wrtbwmon setup /tmp/usage.db # this will create iptables chains and rules
* to verify 1st step, run: iptables -t mangle -L | grep -i rrd
* ./wrtbwmon update /tmp/usage.db # this will copy usage statistics from iptables to usage.db file
* to verify 2nd step, run: cat /tmp/usage.db
* ./wrtbwmon publish /tmp/usage.db /tmp/usage.htm
* ln -s /tmp/usage.htm /www/usage.htm
* check result at [http://192.168.1.1/usage.htm](http://192.168.1.1/usage.htm "http://192.168.1.1/usage.htm")
schedule the whole process
--------------------------
### Setup
* ./wrtbwmon setup /tmp/usage.db
* it must run once after every boot in order to restore required iptables chains and rules
* one way to do this is to insert this command into /etc/rc.local
* if \[ \-x /opt/wrtbwmon/wrtbwmon \]; then
logger \-t 'rc.local' "Starting wrtbwmon setup..."
/opt/wrtbwmon/wrtbwmon setup /tmp/usage.db
fi
### Update
* ./wrtbwmon update /tmp/usage.db
* it must run regularly, eg every 5 minutes
* one way to do this is cron
* cat << "EOF" \>> /etc/crontabs/root
\*/5 \* \* \* \* /opt/wrtbwmon/wrtbwmon update /tmp/usage.db
EOF
service cron restart
logread \-l 5 \-f
### Publish
* in order to have friendly-names insted of mac-addresses, create a text file
* echo “00:aa:bb:cc:dd:ee,friendlyname1” > /opt/wrtbwmon/macusers.txt
* echo “11:22:33:44:55:66,friendlyname1” >> /opt/wrtbwmon/macusers.txt
* letters in mac address must be lowercase!
* unnecessary to insert devices using static-leases or in /etc/hosts file
* publishing /tmp/usage.htm file can be accomplished by two different ways:
* we can publish it regularly via cron, but this is not necessary
* or
* we can publish it on demand via cgi-bin: create a file to /www/cgi-bin/usage
* #!/bin/sh
echo 'Content-Type: text/html'
echo 'X-Dummy: dummy'
echo
/opt/wrtbwmon/wrtbwmon update /tmp/usage.db
/opt/wrtbwmon/wrtbwmon publish /tmp/usage.db /tmp/usage.htm /opt/wrtbwmon/macusers.txt
cat /tmp/usage.htm
* chmod +x /www/cgi-bin/usage
* check result at [http://192.168.1.1/cgi-bin/usage](http://192.168.1.1/cgi-bin/usage "http://192.168.1.1/cgi-bin/usage")
Extras
------
### Log level
You can change loglevel of cron in order to write only error messages into syslog by:
uci set system.@system\[0\].cronloglevel="9"
uci commit system
service cron restart
logread \-l 5 \-f
### Log rotation
If you are interested in the traffic of the current day, then usage.db file has to be deleted every day at midnight. If we move usage.db file instead of deleting, then it can be used later for publishing via cgi-bin.
0 0 \* \* \* mv /tmp/usage.db /mnt/usbdrive/wrtbwmon/usage-$(date '+%Y.%m.%d').db
### Peak and offpeak times
Note: this only works with kallisti's version. Bandwidth usage can be separated to peak and offpeak times.
In this example the off-peak counters get updated from 4:00 to 8:59, the peak counters the rest of the day.
\*/30 0\-3 \* \* \* /opt/wrtbwmon/wrtbwmon update /tmp/wrtbwmon.db peak
\*/30,59 4\-8 \* \* \* /opt/wrtbwmon/wrtbwmon update /tmp/wrtbwmon.db offpeak
\*/30 9\-23 \* \* \* /opt/wrtbwmon/wrtbwmon update /tmp/wrtbwmon.db peak
### Backup
The /tmp/usage.db file is a database file that contains the accounting records. It will be written to very often, so it is not recommended to put it on flash memory, but should be put in RAM (like in /tmp/ directory). If you put it in RAM, schedule a periodic backup task and restore it if missing, for example:
\# local backup storage
15 \* \* \* \* cp /tmp/usage.db /mnt/usbdrive/wrtbwmon/
\* \* \* \* \* \[ ! \-f /tmp/usage.db \] && cp /mnt/usbdrive/wrtbwmon/usage.db /tmp/
\# online backup storage
15 \* \* \* \* cd /tmp && ftpput \-u username \-p password usage.db . some\_ftp\_server\_url
\* \* \* \* \* \[ ! \-f /tmp/usage.db \] && wget some\_url/usage.db \-O /tmp/usage.db
Enhanced version
----------------
You may use a forked version and is luci companion.
* [wrtbwmon](https://github.com/brvphoenix/wrtbwmon "https://github.com/brvphoenix/wrtbwmon")
- pyrovski's forked enhanced version
* [luci-app-wrtbwmon](https://github.com/brvphoenix/luci-app-wrtbwmon "https://github.com/brvphoenix/luci-app-wrtbwmon")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/02/23 15:35
* by palebloodsky
[](https://openwrt.org/docs/guide-user/services/network_monitoring/wrtbwmon#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Minimal SNMP Daemon (mini_snmpd) configuration
Minimal SNMP Daemon (mini\_snmpd) configuration
===============================================
The _mini\_snmpd_ configuration is located in `/etc/config/mini_snmpd`. This configuration is responsible for defining basic snmp attributes, such as _location_, _contact_, _community_ and snmp tables for _disks_ and _interfaces_. This daemon reports only 32bit counters (Counter32).
Sections
--------
Configuration consists of single section called _mini\_snmpd_.
The default configuration defines following settings:
config mini\_snmpd
option enabled '0'
option ipv6 '0'
option community 'public'
option location ' '
option contact ' '
list disks '/tmp'
list disks '/jffs'
list interfaces 'lo'
list interfaces 'br-lan'
list interfaces 'br-wan' # Max 4
* `enabled` defines if daemon should be started on by rc script
* `ipv6` enables daemon's support of ipv6 sockets - it will listen on :::161 instead of 0.0.0.0:161
* `community` sets SNMP community string
* `location` and `contact` set those base SNMP attributes
* `disks` and `interfaces` specifies which filesystems and interfaces should be referenced by corresponding management tables.
* `sysName` is set automatically from the Hostname on the main System page of the web GUI
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | yes | `0` | Switches daemon on or off in rc (init.d) script |
| `ipv6` | boolean | no | `0` | Enables daemon's support of ipv6 sockets |
| `community` | string | yes | `public` | Sets SNMP Community string to contact this agent |
| `location` | string | no | _(none)_ | If defined, sets _location_ OID which _mini\_snmpd_ reports |
| `contact` | string | no | _(none)_ | If defined, sets _contact_ OID wchi _mini\_snmpd_ reports |
| `disks` | list of filesystems' mountpoints | no | _(none)_ | If defined, _mini\_snmpd_ includes this filesystem in output table |
| `interfaces` | list of network interfaces | no | _(none)_ | If defined, _mini\_snmpd_ includes this interfaces in output table |
Examples
--------
_Simple example:_ enable daemon, excluding ipv6 support, defining other parameters.
config mini\_snmpd
option enabled 1
option ipv6 0
option community public
option location ''
option contact ''
option disks '/tmp,/jffs'
option interfaces 'wlan0,br-lan,eth0.1,eth0' # Max 4
Example of the `snmpwalk`:
$ snmpwalk -m ALL -v 2c -c public 192.168.1.1
SNMPv2-MIB::sysDescr.0 = STRING:
SNMPv2-MIB::sysObjectID.0 = OID: SNMPv2-SMI::enterprises
DISMAN-EVENT-MIB::sysUpTimeInstance = Timeticks: (17915) 0:02:59.15
SNMPv2-MIB::sysContact.0 = STRING:
SNMPv2-MIB::sysName.0 = STRING: OpenWrt
SNMPv2-MIB::sysLocation.0 = STRING:
RFC1213-MIB::ifNumber.0 = INTEGER: 4
RFC1213-MIB::ifIndex.1 = INTEGER: 1
RFC1213-MIB::ifIndex.2 = INTEGER: 2
RFC1213-MIB::ifIndex.3 = INTEGER: 3
RFC1213-MIB::ifIndex.4 = INTEGER: 4
RFC1213-MIB::ifDescr.1 = STRING: "wlan0"
RFC1213-MIB::ifDescr.2 = STRING: "br-lan"
RFC1213-MIB::ifDescr.3 = STRING: "eth0.1"
RFC1213-MIB::ifDescr.4 = STRING: "eth0"
RFC1213-MIB::ifOperStatus.1 = INTEGER: up(1)
RFC1213-MIB::ifOperStatus.2 = INTEGER: up(1)
RFC1213-MIB::ifOperStatus.3 = INTEGER: up(1)
RFC1213-MIB::ifOperStatus.4 = INTEGER: up(1)
RFC1213-MIB::ifInOctets.1 = Counter32: 19574486
RFC1213-MIB::ifInOctets.2 = Counter32: 18252147
RFC1213-MIB::ifInOctets.3 = Counter32: 124204634
RFC1213-MIB::ifInOctets.4 = Counter32: 126247040
RFC1213-MIB::ifInUcastPkts.1 = Counter32: 91002
RFC1213-MIB::ifInUcastPkts.2 = Counter32: 90354
RFC1213-MIB::ifInUcastPkts.3 = Counter32: 113467
RFC1213-MIB::ifInUcastPkts.4 = Counter32: 113467
RFC1213-MIB::ifInDiscards.1 = Counter32: 0
RFC1213-MIB::ifInDiscards.2 = Counter32: 0
RFC1213-MIB::ifInDiscards.3 = Counter32: 0
RFC1213-MIB::ifInDiscards.4 = Counter32: 0
RFC1213-MIB::ifInErrors.1 = Counter32: 0
RFC1213-MIB::ifInErrors.2 = Counter32: 0
RFC1213-MIB::ifInErrors.3 = Counter32: 0
RFC1213-MIB::ifInErrors.4 = Counter32: 0
RFC1213-MIB::ifOutOctets.1 = Counter32: 127834842
RFC1213-MIB::ifOutOctets.2 = Counter32: 125363371
RFC1213-MIB::ifOutOctets.3 = Counter32: 19332841
RFC1213-MIB::ifOutOctets.4 = Counter32: 20197296
RFC1213-MIB::ifOutUcastPkts.1 = Counter32: 112239
RFC1213-MIB::ifOutUcastPkts.2 = Counter32: 111021
RFC1213-MIB::ifOutUcastPkts.3 = Counter32: 85992
RFC1213-MIB::ifOutUcastPkts.4 = Counter32: 88600
RFC1213-MIB::ifOutDiscards.1 = Counter32: 0
RFC1213-MIB::ifOutDiscards.2 = Counter32: 0
RFC1213-MIB::ifOutDiscards.3 = Counter32: 0
RFC1213-MIB::ifOutDiscards.4 = Counter32: 0
RFC1213-MIB::ifOutErrors.1 = Counter32: 0
RFC1213-MIB::ifOutErrors.2 = Counter32: 0
RFC1213-MIB::ifOutErrors.3 = Counter32: 0
RFC1213-MIB::ifOutErrors.4 = Counter32: 0
HOST-RESOURCES-MIB::hrSystemUptime.0 = Timeticks: (1547471) 4:17:54.71"
As you see walk doesn't catch on disks for some reason.
**Under Construction!**
This page is currently under construction. You can edit the article to help completing it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/08/26 11:35
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/snmp/mini_snmpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] daloRADIUS management system
daloRADIUS management system
============================
This page covers installation of DaloRADIUS and extending it. All this should be done on an extroot as it will take too much space for most routers and in the case of mysql poses the risk of wearing down your flash! Warning: all this has been commited from memory!
Basics
------
### Prerequisites
* You need to have a freeradius server up and running.
Unfortunately, this is not documented on this wiki yet, but relatively straightforward. This howto expects that you have one already up and running.
* You should have configured your Wifi to use your radius server.
For this, see [wpa\_enterprise\_access\_point](https://openwrt.org/docs/guide-user/network/wifi/basic#wpa_enterprise_access_point "docs:guide-user:network:wifi:basic")
. Don't forget, that you will need wpad instead of wpad-mini for enterprise WPA!
* It might be a good idea to have [LuCI running on Lighthttpd](https://openwrt.org/doc/howto/luci.on.lighttpd "doc:howto:luci.on.lighttpd")
### Required Packages
#### Server (OpenWrt)
* **`lighttpd`** as webserver
* **`lighttpd-mod-fastcgi`** to run php5
* **`php5-fastcgi`**
* **`php-pear-db`** prerequisite for daloradius
* **`php5-mod-session`** prerequisite for daloradius
* **`php5-mod-gd`** prerequisite for daloradius
* **`php5-mod-mysql`** prerequisite for daloradius
* **`mysql-server`** prerequisite for daloradius
* **`freeradius2-mod-sql-mysql`** to connect freeradius to your DB
* **`samba36-server`** if you want to use the NT-Hash authentification described below
Installation
------------
### Packages
opkg install lighttpd lighttpd-mod-fastcgi php5-fastcgi php-pear-db php5-mod-session php5-mod-gd php5-mod-mysql mysql-server freeradius2-mod-sql-mysql
### Download & unpack daloradius
Download daloradius-XXX.tar.gz from [http://sourceforge.net/projects/daloradius/files/latest/download](http://sourceforge.net/projects/daloradius/files/latest/download "http://sourceforge.net/projects/daloradius/files/latest/download")
gunzip daloradius-XXX.tar.gz
tar xzvf daloradius-XXX.tar
mv daloradius-XXX /www/daloradius
### Necessary configuration
#### lighttpd
In `/etc/lighttpd/lighttpd.conf` (note that bin-path differs from the default in this file!):
\#### fastcgi module
## read fastcgi.txt for more info
fastcgi.server = (
".php" => (
"localhost" => (
"socket" => "/tmp/php-fastcgi.socket",
"bin-path" => "/usr/bin/php-fcgi"
)
)
)
#### php
Create a file `/etc/php5/pear.ini` or edit your `/etc/php.ini`
include\_path = ".:/usr/lib/php/"
#### mysql
Set a `datadir` in `/etc/my.cnf`
datadir = /data/mysql/
and run
mysql\_install\_db \--force
Create a DB 'radius' and a user by the same name. Insert your password.
cat <> /etc/passwd
\# add entry to /etc/samba/smbpasswd
cat <NT-Password
note that at this state you still have to enter your calculated NT-Hash in the password text field!
If you want daloradius to calculate your NT-Hash for you if you select NT-Password, you have to add the following code to `/www/daloradius/mng-new.php` after line 438 (don't forget to copy the above script to /bin/smbencrypt!):
// or calculate an NT hash
} elseif ($passwordtype=="NT-Password"){
$dbPassword = "'".shell\_exec("smbencrypt '".escapeshellcmd($dbPassword)."' | tail -n1 | sed 's/^X\* \*//'")."'";
}
Final warning
-------------
From what I've seen so far, daloradius is cool - but the code looks to me like it's prone to all kinds of injections. As it is an interface that should ony accessed by the administrator (you!): put it behind an HTTP auth - see `lighttpd_mod_auth`
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/06/11 14:24
* by tmomas
[](https://openwrt.org/docs/guide-user/services/remote_control/daloradius#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] ZNC IRC network bouncer
ZNC IRC network bouncer
=======================
[ZNC's](https://en.wikipedia.org/wiki/ZNC "https://en.wikipedia.org/wiki/ZNC")
configuration is located in `/etc/config/znc`. You can use it to configure most common aspects of ZNC. Supplying your own configuration is supported as of 0.998-2.
Notes:
* This configuration is only for ZNC 0.094 or later.
* 10.03.1-rc4's ZNC 0.094 has a hidden dependency to `libstdcpp`. This is fixed in trunk and recent Backfire builds.
* 10.03.1-rc4's ZNC 0.094 takes 30 seconds until it actually works after starting it. This wait time is removed in trunk.
Sections
--------
There are two section types for ZNC, a common one and one or more user sections.
### Common Options
The common section defines where ZNC is supposed to listen, which global modules should be loaded and some other global options. A minimum configuration looks like this:
config 'znc'
list 'listener' '192.168.1.1 1234'
#### Valid Options
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `anoniplimit` | integer | no | `10` | Number of anonymous connections allowed. |
| `connectdelay` | integer | no | `5` | Time in seconds ZNC waits between establishing connections. |
| `listener` | list of strings | Yes | _none_ | One or more directives where ZNC should listen, in the format “ \[+\]”. The “+” forces the port to be SSL. Both IPv4 and IPv6 addresses are valid. **Note:** You need to provide a SSL certificate for using SSL ports. |
| `maxbuffersize` | integer | no | `500` | Sets the global Max Buffer Size a user can have. |
| `module` | list of strings | no | _none_ | Instructs ZNC to load global modules. Uses the format “ \[arguments...\]”. |
| `runas_user` | string | no | _root/nobody_ | Run ZNC as this user instead of the default user (root for external config, nobody for generated config) |
| `runas_group` | string | no | _nogroup_ | Run ZNC as this group. Only used when using a generated config. |
| `runas_shell` | string | no | _none_ | Use this when the _runas\_user_ does not have a shell, i.e. _nobody_ in _passwd_ is _/bin/false_. Only used when using a generated config. |
| `serverthrottle` | integer | no | `30` | Time in seconds ZNC waits between two connection attempts to an IRC server. |
| `znc_config_path` | string | no | _none_ | Use an external configuration at this location instead of the generated one. Any other options except `runas_user` will get ignored. **Note:** Using runas\_user to run ZNC as a different user with an external config requires `'su`' installed. Alternatively, you may make use of [droproot](http://wiki.znc.in/Droproot "http://wiki.znc.in/Droproot") from your external configuration file, as it is always installed with ZNC. |
| `znc_ssl_cert` | string | no | _none_ | Use this certificate for SSL ports. |
**Note:** If you want your ZNC to be reachable from the outside, you can use '0.0.0.0' as the IP address, which makes ZNC listen on all interfaces. You also need to allow connections to its port through the firewall.
### User Definition
For each connection you want to use you need to create a separate user. Each user section corresponds to one user in ZNC. The section name is the user name for authentication to ZNC itself.
A minimal user configuration looks like this:
config 'user' 'sampleUser'
option 'password' 'changeme'
option 'nick' 'sampleUser'
This would create a user with the login `sampleUser`, the password `changeme` and the nick `sampleUser`.
#### Valid Options
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `altnick` | string | no | _none_ | The Alternative Nickname, if the first one is occupied. |
| `buffer` | integer | no | `50` | Specifies the per channel log buffer limit in lines. |
| `chanmodes` | string | no | __ | Overrides the channel modes. |
| `channel` | list of strings | no | _none_ | Specifies one or more channels to join on connect. The required format is “ \[\]”. **Note:** Only ZNC 0.096 or later. |
| `ident` | string | no | __ | Specifies the ident to use. |
| `module` | list of strings | no | _none_ | Instructs ZNC to load user modules. The required format is “modulename> \[\]”. |
| `nick` | string | Yes | _none_ | The Nickname of this user. |
| `realname` | string | no | __ | The real name of this user. |
| `password` | string | Yes | _none_ | Password for this user. Can be either a plain text password, or a generated password hash through `znc -s`. **Note:** ZNC 0.094 supports only plain text. |
Example code for crypted
option 'password' 'sha256#...'
Method = sha256
Hash = 746a8a22b32f22c9dd92e9918b084ac8bcf1c94361d71fd5ee4a7154f86371d4
Salt = 8+1Isl8ewZ+Bai;tx2ML
| | | | | |
| --- | --- | --- | --- | --- |
| `quitmsg` | string | no | __ | Specifies the quit message used when closing the connection to the server. |
| `server` | list of strings | no | _none_ | Specifies the list of servers to connect to. The required format “ \[+\] \[\]”, where the “+” indicates that SSL should be used. Both IPv4 and IPv6 addresses are valid. |
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/05/28 16:36
* by broadcomfail
[](https://openwrt.org/docs/guide-user/services/proxy/znc#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] TLS libraries
TLS libraries
-------------
There is few crypto libraries for TLS that works on OpenWrt:
* [OpenSSL](https://en.wikipedia.org/wiki/OpenSSL "https://en.wikipedia.org/wiki/OpenSSL")
is a de-facto standard. It's libopenssl takes more than a 1Mb of disk space.
* [MbedTLS](https://en.wikipedia.org/wiki/Mbed_TLS "https://en.wikipedia.org/wiki/Mbed_TLS")
is a small library developed for embedded devices. Was used by default in OpenWrt before.
* [WolfSSL](https://en.wikipedia.org/wiki/WolfSSL "https://en.wikipedia.org/wiki/WolfSSL")
is a small library developed for embedded devices. Supports TLS1.3. Installed by default in OpenWrt 21. But in future this may be changed back to MbedTLS.
* [Nettle](https://www.lysator.liu.se/~nisse/nettle/ "https://www.lysator.liu.se/~nisse/nettle/")
just a small crypto library without TLS support.
* [GnuTLS](https://en.wikipedia.org/wiki/GnuTLS "https://en.wikipedia.org/wiki/GnuTLS")
is GNU project but not often used. Internally uses Nettle.
* [LibTomCrypt](https://github.com/libtom/libtomcrypt "https://github.com/libtom/libtomcrypt")
: used internally in Dropbear SSH daemon. It's not a TLS lib that you may use but all routers have it.
When you are installing some program you may check which library you already have and install a specific version to reuse existing dependency. For example rtty daemon has three versions `rtty-mbedtls`, `rtty-openssl`, `rtty-wolfssl`. Some OpenWrt only packages like `kadnode` uses only mbedtls and other libraries aren't supported yet.
See also [Comparison of TLS implementations](https://en.wikipedia.org/wiki/Comparison%20of%20TLS%20implementations "https://en.wikipedia.org/wiki/Comparison of TLS implementations")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2022/07/10 10:52
* by stokito
[](https://openwrt.org/docs/guide-user/services/tls/libs#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] How to add data from a TP9605BT multimeter to apcupsd rrd and graphs.
How to add data from a TP9605BT multimeter to apcupsd rrd and graphs.
=====================================================================
**WARNING: All liability is yours: this procedure involves handling of potentially lethal electrical currents.**
This describes how to add Voltage Output data to the apcupsd RRD database.
I did this because the APC BackUps ES-500 I have does not report a value I was interested in: “OUTPUTV - The voltage the UPS is supplying to your equipment” ( [http://www.apcupsd.org/manual/manual.pdf](http://www.apcupsd.org/manual/manual.pdf "http://www.apcupsd.org/manual/manual.pdf")
).
The plan was simple:
* Get a multimeter that could output voltage readings to my router.
* Add the readings to the apcupsd RRD database.
* Verify the readings appear in the appropriate graph.
I found a multimeter that worked and was cheap enough, the [Tekpower TP9605BT](http://amzn.to/2reiCzk "http://amzn.to/2reiCzk")
( This an affiliate link from Louis Rossmann's work with this meter at: [Multimeter Overlay in OBS](https://mailin.repair/blog/multimeter-overlay-in-obs-making-the-readings-show-on-screen-for-recordings "https://mailin.repair/blog/multimeter-overlay-in-obs-making-the-readings-show-on-screen-for-recordings")
).
The physical attachment of the multimeter involved:
* Connecting the meter's USB cable to the router USB, which further required a small USB hub.
* Experimenting until I found the correct button-press combination that put the meter into always-on mode.
* The documentation had an incorrect sequence.
* The correct sequence is: hold down the \[Range\] button while turning on the meter.
* Switching to probes that would stay in a mains socket
* Cobbling up a 9 volt battery eliminator.
* Making sure I used the same circuit on the battery-backed-up side of the UPS for both the meter probes, and the battery eliminator. This minimizes the chances of a ground loop destroying the multimeter.
The next step was to establish communication between the meter and the router:
* opkg install kmod-usb-serial-ch341
* Make sure the communication worked.
* Write some code that periodically took a value from the meter, and dumped it in the apcupsd RRD database.
From looking at logread, I determined that the meter's port is on /dev/ttyUSB0. So, I did:
\# cat /dev/ttyUSB0
and got some very reasonable results:
+1227 3)�
+1227 3)�
Now, came the analysis part. The “)?” characters tell us what range the meter is set to. This didn't matter to me in this application, because I already knew the settings.
* “+1227” are the numbers on the meter display.
* “3” is where to put the decimal point.
* So, “+1227 3)�” = 122.7 Volts AC.
Below is some code I whipped up. I'm sure it can be improved. Note that it has custom locations for the RRD files, and the port for the meter.
I added these lines to the crontabs/root:
\# get AC Volts from the multimeter once every minute
\*/1 \* \* \* \* /usr/share/bobvolts\_TP9605BT\_usb.sh
This runs the program every minute, and seems to work well when I look at the graph: [](https://openwrt.org/_detail/media/doc/howtos/statistics_apcups_multimeter_graph.png?id=docs%3Aguide-user%3Aservices%3Aups%3Astatistics.apcupsd_multimeter "media:doc:howtos:statistics_apcups_multimeter_graph.png")
Now for some cleanup. Add this line to /etc/sysupgrade.conf, which preserves this new script across upgrades:
/usr/share/bobvolts\_TP9605BT\_usb.sh
And, here is the script, to add to /usr/share/bobvolts\_TP9605BT\_usb.sh:
##!/bin/bash
# bobvolts\_TP9605BT\_usb.sh, Copyright 2017 Bob Meizlik, license: CC Attribution-Noncommercial-Share Alike 3.0.
# All liability is yours: this code presumes handling of dangerous tools and electricity.
#
# Purpose:
# Collect and store AC Voltage Output readings, when your UPS does not.
#
# Usage:
# Connect your meter appropriately, to the output AC of the UPS, and the (USB or RS232 or Bluetooth) of your computer or access point.
# Hold down RANGE button, and turn meter on, to defeat the auto-power-off timer.
# Set meter range to Volts, AC.
# Set meter to RS232 output (this enables, RS232, USB and Bluetooth)
# Install drivers
# Set this script to run periodically, perhaps with a cron script, or a daemon.
#
# Code Process:
# Get AC Voltage readings from a TekPower TP9605BT multimeter, and
# send them to the apcups, collectd RRD file meant for these readings.
#
# get the latest voltage reading from a TekPower TP9605BT multimeter
# set to AC Volts range
# set to RS232 output
#
# We get 4 readings per second.
# each reading is 14 bytes long
# the lines look like this: 2b 31 32 31 38 20 33 29 20 20 80 20 0a 0a 2b 31 |+1218 3) . ..+1|
# if we start in the middle of a line, ignore the line, and go to the next line, which is presumably complete.
# the x0a characters look like new lines in this processing, resulting in a data line that is 12 bytes long.
#
# Known issues:
# The input will hang, when there is no device at /dev/ttyUSB0.
# The input will hang, when the meter is turned off.
inputfile="/dev/ttyUSB0"
rrdfile="/mnt/share/tmp/mydigitemp.rrd"
rrdfile="/mnt/share/stats/rrd/g70outside/apcups/voltage-output.rrd"
# todo: get the rrdfile name from /etc/config/luci-statistics option DataDir '/mnt/share/stats/rrd'
# translate 0 to space, because the length is our checksum
dat=$(dd bs=1 count=50 if=$inputfile | tr \\\\000 \\\\040 )
line1=$(echo -en "$dat" | sed --quiet '1p')
line2=$(echo -en "$dat" | sed --quiet '2p')
line3=$(echo -en "$dat" | sed --quiet '3p')
line1len=${#line1}
line2len=${#line2}
line3len=${#line3}
# todo, this would be nicer if it was a loop
if \[ 12 -eq "$line1len" \]; then
theline=$line1
else
theline=$line3
fi
# extract the data from the line, and convert it to a form that rrd can use.
set -- junk $theline
val=$2 # the value, like +1234
dec=\`expr "$3" : '\\(\[0-9\]\\)'\` # the decimal place, like 3
decp1=\`expr 1 + $dec\` # add 1 to get past the sign
theValue=${val:0:$decp1}.${val:$decp1} # put the value together with the decimal place
# generate and run a line like: rrdtool update .rrd $(date +%s):+122.5
theSeconds=$(date +%s)
rrdcmd='rrdtool update '$rrdfile' ''N:'$theValue
$rrdcmd
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/03/04 07:46
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/ups/statistics.apcupsd_multimeter#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenSSH Multi Factor Authentication
OpenSSH Multi Factor Authentication
===================================
The following tutorial will set up two-factor authentication for OpenSSH on my OpenWrt x86 router (v19.07.06). It comes from a [post in the OpenWrt forums](https://forum.openwrt.org/t/howto-openssh-with-mfa-on-openwrt-19-07-x-using-google-authenticator/88025 "https://forum.openwrt.org/t/howto-openssh-with-mfa-on-openwrt-19-07-x-using-google-authenticator/88025")
Start
-----
In this tutorial the router IP is the default 192.168.1.1.
Configure OpenWrt's built-in Dropbear SSH to work on LAN only and away from port 22 (e.g., 20022). This can be done in Luci at [http://192.168.1.1/cgi-bin/luci/admin/system/admin/dropbear](http://192.168.1.1/cgi-bin/luci/admin/system/admin/dropbear "http://192.168.1.1/cgi-bin/luci/admin/system/admin/dropbear")
. If anything goes wrong with OpenSSH, you still should be able to log in from your local network using Dropbear: [](https://openwrt.org/_media/docs/guide-user/services/ssh/openssh_mfa_auth_1_luci_dropbear.jpeg "docs:guide-user:services:ssh:openssh_mfa_auth_1_luci_dropbear.jpeg")
Log into the router using Dropbear and install the openssh-server-pam and google-authenticator-libpam packages:
ssh -p 20022 root@192.168.1.1
opkg update
opkg install google-authenticator-libpam openssh-server-pam
Set up OpenSSH public/private key authentication. This is no different from a typical non-MFA scenario, I've just followed [this excellent guide](https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys-2 "https://www.digitalocean.com/community/tutorials/how-to-set-up-ssh-keys-2")
.
Restart the OpenSSH service (service sshd restart from the stil-open Dropbear session of step 2) and test that you can connect to OpenSSH as root on port 22, from some other host:
ssh root@192.168.1.1
Run google-authenticator (in the open Dropbear session) and enroll in MFA. Follow [this guide](https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04 "https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04")
precisely, starting from “**Run the initialization app**” and stopping at “**Step 2 — Configuring OpenSSH**”.
You can use Google Authenticator, Microsoft Authenticator or any other MFA app that implements the standard Time-based One-time Password Algorithm [(TOTP - RFC 6238)](https://tools.ietf.org/html/rfc6238 "https://tools.ietf.org/html/rfc6238")
.
Edit /etc/ssh/sshd\_config (with nano /etc/ssh/sshd\_config) to make these scattered changes:
PermitRootLogin yes
PubkeyAuthentication yes
ChallengeResponseAuthentication yes
UsePAM yes
AuthenticationMethods publickey,keyboard-interactive
Here is a working version of /etc/ssh/sshd\_config:
# $OpenBSD: sshd\_config,v 1.103 2018/04/09 20:41:22 tj Exp $
# This is the sshd server system-wide configuration file. See
# sshd\_config(5) for more information.
# This sshd was compiled with PATH=/usr/bin:/bin:/usr/sbin:/sbin
# The strategy used for options in the default sshd\_config shipped with
# OpenSSH is to specify options with their default value where
# possible, but leave them commented. Uncommented options override the
# default value.
Port 22
#AddressFamily any
#ListenAddress 0.0.0.0
#ListenAddress ::
HostKey /etc/ssh/ssh\_host\_rsa\_key
HostKey /etc/ssh/ssh\_host\_ecdsa\_key
HostKey /etc/ssh/ssh\_host\_ed25519\_key
# Ciphers and keying
#RekeyLimit default none
# Logging
#SyslogFacility AUTH
#LogLevel INFO
# Authentication:
#LoginGraceTime 2m
PermitRootLogin yes
#StrictModes yes
#MaxAuthTries 6
#MaxSessions 10
PubkeyAuthentication yes
# The default is to check both .ssh/authorized\_keys and .ssh/authorized\_keys2
# but this is overridden so installations will only check .ssh/authorized\_keys
AuthorizedKeysFile .ssh/authorized\_keys
#AuthorizedPrincipalsFile none
#AuthorizedKeysCommand none
#AuthorizedKeysCommandUser nobody
# For this to work you will also need host keys in /etc/ssh/ssh\_known\_hosts
#HostbasedAuthentication no
# Change to yes if you don't trust ~/.ssh/known\_hosts for
# HostbasedAuthentication
#IgnoreUserKnownHosts no
# Don't read the user's ~/.rhosts and ~/.shosts files
#IgnoreRhosts yes
# To disable tunneled clear text passwords, change to no here!
#PasswordAuthentication yes
#PermitEmptyPasswords no
# Change to no to disable s/key passwords
ChallengeResponseAuthentication yes
# Kerberos options
#KerberosAuthentication no
#KerberosOrLocalPasswd yes
#KerberosTicketCleanup yes
#KerberosGetAFSToken no
# GSSAPI options
#GSSAPIAuthentication no
#GSSAPICleanupCredentials yes
# Set this to 'yes' to enable PAM authentication, account processing,
# and session processing. If this is enabled, PAM authentication will
# be allowed through the ChallengeResponseAuthentication and
# PasswordAuthentication. Depending on your PAM configuration,
# PAM authentication via ChallengeResponseAuthentication may bypass
# the setting of "PermitRootLogin without-password".
# If you just want the PAM account and session checks to run without
# PAM authentication, then enable this but set PasswordAuthentication
# and ChallengeResponseAuthentication to 'no'.
UsePAM yes
AuthenticationMethods publickey,keyboard-interactive
#AllowAgentForwarding yes
#AllowTcpForwarding yes
#GatewayPorts no
#X11Forwarding no
#X11DisplayOffset 10
#X11UseLocalhost yes
#PermitTTY yes
#PrintMotd yes
#PrintLastLog yes
#TCPKeepAlive yes
#PermitUserEnvironment no
#Compression delayed
#ClientAliveInterval 0
#ClientAliveCountMax 3
#UseDNS no
#PidFile /var/run/sshd.pid
#MaxStartups 10:30:100
#PermitTunnel no
#ChrootDirectory none
#VersionAddendum none
# no default banner path
#Banner none
# override default of no subsystems
Subsystem sftp /usr/lib/sftp-server
# Example of overriding settings on a per-user basis
#Match User anoncvs
# X11Forwarding no
# AllowTcpForwarding no
# PermitTTY no
# ForceCommand cvs server
Edit **/etc/pam.d/sshd** (with **nano /etc/pam.d/sshd**) to make these changes:
**#auth include common-auth** (must be commented out)
**auth required /usr/lib/security/pam\_google\_authenticator.so** (append at the very end of the file)
**NOTE:** The above two lines are very important and a difference from all the guides I've linked above. They were suggested using “auth required pam\_google\_authenticator.so”. However, at least in OpenWrt 19.07, pam.d tries to load this plugin from /lib/security and that fails, because the current google-authenticator-libpam package installs pam\_google\_authenticator.so into /usr/lib/security.
Here is a working version of /etc/pam.d/sshd:
# PAM configuration for the Secure Shell service
# Read environment variables from /etc/environment and
# /etc/security/pam\_env.conf.
auth required pam\_env.so
# Skip Google Authenticator if logging in from the local network.
# auth \[success=1 default=ignore\] pam\_access.so accessfile=/etc/security/access-sshd-local.conf
# Google Authenticator 2-step verification.
#auth requisite pam\_google\_authenticator.so
# Standard Un\*x authentication.
#auth include common-auth
# Disallow non-root logins when /etc/nologin exists.
account required pam\_nologin.so
# Uncomment and edit /etc/security/access.conf if you need to set complex
# access limits that are hard to express in sshd\_config.
# account required pam\_access.so
# Standard Un\*x authorization.
account include common-account
# Standard Un\*x session setup and teardown.
session include common-session
# Print the message of the day upon successful login.
session optional pam\_motd.so
# Print the status of the user's mailbox upon successful login.
session optional pam\_mail.so standard noenv
# Set up user limits from /etc/security/limits.conf.
session required pam\_limits.so
# Set up SELinux capabilities (need modified pam)
# session required pam\_selinux.so multiple
# Standard Un\*x password updating.
password include common-password
auth required /usr/lib/security/pam\_google\_authenticator.so
Restart sshd (**service sshd restart**) and try to connect to it from another machine. You should be prompted for a one-time MFA password.
Configure your Firewall trafic rules ([http://192.168.1.1/cgi-bin/luci/admin/network/firewall/rules](http://192.168.1.1/cgi-bin/luci/admin/network/firewall/rules "http://192.168.1.1/cgi-bin/luci/admin/network/firewall/rules")
) if you want to be able to connect to OpenSSH from the Internet.
Congrats, you've hardened your OpenWrt OpenSSH root access with two-factor authentication.
**NOTE:** The OTP codes are time-based. My x86 router has an RTC clock, so the MFA should work even if the router is offline. OpenWrt automatically syncs time using NTP, so as long as the router is online, the MFA still should work. Otherwise, if the router is offline and there's no RTC, you should still have an option to connect from the LAN using Dropbear on port 20022.
### Some helpful resources
* [Installing Google Authenticator for SSH, OpenConnect, OpenVPN? 6](https://forum.openwrt.org/t/installing-google-authenticator-for-ssh-openconnect-openvpn/31439 "https://forum.openwrt.org/t/installing-google-authenticator-for-ssh-openconnect-openvpn/31439")
* [https://forum.archive.openwrt.org/viewtopic.php?id=38905](https://forum.archive.openwrt.org/viewtopic.php?id=38905 "https://forum.archive.openwrt.org/viewtopic.php?id=38905")
* [https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04](https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04 "https://www.digitalocean.com/community/tutorials/how-to-set-up-multi-factor-authentication-for-ssh-on-ubuntu-16-04")
2
* [https://www.vultr.com/docs/how-to-use-twofactor-authentication-with-ubuntu-20-04](https://www.vultr.com/docs/how-to-use-twofactor-authentication-with-ubuntu-20-04 "https://www.vultr.com/docs/how-to-use-twofactor-authentication-with-ubuntu-20-04")
1
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/02/09 18:21
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/services/ssh/ssh.mfa.auth#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] APC SmartUps SU-700 - Linksys EA3500 - LuCI graphs
APC SmartUps SU-700 - Linksys EA3500 - LuCI graphs
==================================================
This describes how to connect an APC SmartUps SU-700 via USB on a Linksys EA3500 router. This includes collecting the data, and displaying graphs.
* Plug in UPS
* Connect a 940-0024 serial cable to the UPS (I'm using a 940-0024c. Other 'smart' cables may work as well. See: [http://www.apcupsd.org/manual/manual.html#cables](http://www.apcupsd.org/manual/manual.html#cables "http://www.apcupsd.org/manual/manual.html#cables")
)
* Connect other end of the cable to a serial-to-usb converter
* Some converters work, some don't. A cable from eBay called “USB to RS232 Serial 9 Pin DB9 PIN PL2303 Cable Adapter” did not end up working for me, due to Linux driver issues. I ended up using a [https://www.iogear.com/product/GUC232A](https://www.iogear.com/product/GUC232A "https://www.iogear.com/product/GUC232A")
.
* Connect the serial-to-usb converter to the router USB port (or a USB hub, if you need multiple things plugged into the port).
* In the router command line or LuCI web pages, install packages: apcupsd, collectd-mod-apcups, and kmod-usb-serial-pl2303
* For the command line, the commands are:
opkg update
opkg install kmod-usb-serial-pl2303
opkg install apcupsd
opkg install collectd-mod-apcups
* On the router command line, verify that the USB driver is installed and working with command and response:
\# ls -la /dev/ttyUSB\*
crw------- 1 root root 188, 0 Dec 1 00:29 /dev/ttyUSB0
* If you don't see a serial port then something is wrong with the driver for the serial-to-usb converter.
* Resolve this, before proceeding.
* The next step is to customize the apcupsd config file. Details of the options can be found at [http://www.apcupsd.org/manual/manual.html](http://www.apcupsd.org/manual/manual.html "http://www.apcupsd.org/manual/manual.html")
, in the section “Configuration Directive Reference”.
* On the router command line, go to the /etc/apcupsd directory, and edit the config file:
\# cd /etc/apcupsd
# vi apcupsd.conf
* use the dd command to delete all the lines in the file
* use the i command to set the VI editor into “insert” mode.
* Copy and paste this text into the editor:
\## apcupsd.conf v1.1 ##
UPSNAME APC700
UPSCABLE smart
UPSTYPE apcsmart
DEVICE /dev/ttyUSB0
LOCKFILE /var/lock
ONBATTERYDELAY 6
BATTERYLEVEL 5
MINUTES 3
TIMEOUT 0
ANNOY 300
ANNOYDELAY 60
NOLOGON disable
KILLDELAY 0
NETSERVER on
NISIP 0.0.0.0
NISPORT 3551
EVENTSFILE /var/log/apcupsd.events
# max kilobytes
EVENTSFILEMAX 10
UPSCLASS standalone
UPSMODE disable
# ===== Configuration statements to control apcupsd system logging ========
# Time interval in seconds between writing the STATUS file; 0 disables
STATTIME 0
# Location of STATUS file (written to only if STATTIME is non-zero)
STATFILE /var/log/apcupsd.status
LOGSTATS off
# Time interval in seconds between writing the DATA records to
# the log file. 0 disables.
DATATIME 0
* type :wq into the editor, to write the new apcupsd.conf, and quit the edit session
* restart the apcupsd deamon process:
# /etc/init.d apcupsd restart
* Enter the apcaccess command into the command line, and you should get output like this:
\# apcaccess
APC : 001,034,0829
DATE : 2017-12-01 18:11:01 -0700
HOSTNAME : myrouter
VERSION : 3.14.14 (31 May 2016) unknown
UPSNAME : APC700
CABLE : Custom Cable Smart
DRIVER : APC Smart UPS (any)
UPSMODE : Stand Alone
STARTTIME: 2017-12-01 18:10:11 -0700
MODEL : Smart-UPS 700 RM
STATUS : ONLINE
...
* Note the STATUS : ONLINE . If you don't have “ONLINE”, then something is wrong
* Reboot the router.
* In the router web interface, go to Statistics, Graphs, APC UPS
* You should see the graphs, with data starting on the right side.
* If not, wait a minute, refresh your browser and you should start to see data being written.
Saving the data across Reboots
------------------------------
* By default the collected data will be lost after a reboot of the router. To save the data, you need to put it on an external device, like a USB flash drive. Connecting both the UPS and a flash drive to a USB hub, which is then connected to the router, works fine for me.
* To put the data on an external device, go to Statistics / Setup / Output plugins / RRDTool ([http://192.168.1.1/cgi-bin/luci/admin/statistics/collectd/output/rrdtool](http://192.168.1.1/cgi-bin/luci/admin/statistics/collectd/output/rrdtool "http://192.168.1.1/cgi-bin/luci/admin/statistics/collectd/output/rrdtool")
), and change the Storage directory to wherever you want to store your data.
Troubleshooting
---------------
If you don't have APC UPS graphs at this point, here are some things to check:
1. Change the data collection interval to 10 seconds. This is a workaround for the issue reported in: [https://github.com/collectd/collectd/issues/617](https://github.com/collectd/collectd/issues/617 "https://github.com/collectd/collectd/issues/617")
.
* Go to Statistics / Setup /
* Change the Data collection interval to 10 seconds
2. Verify that serial communication to the UPS is working - On a PC
* attach usb converter to PC
* startup minicom (or equivalent): minicom -D /dev/ttyUSB0
* ctrl-a, ctrl-z, P,
* change port configuration to 2400,8,n,1
* ctrl-a, ctrl-z, O, Serial Port Setup
* change port configuration to hardware / software flow control: none
* type the uppercase letter: Y , and expect the reply SM
Y
SM
* Note: serial APC UPS commands are documented at: [http://networkupstools.org/protocols/apcsmart.html](http://networkupstools.org/protocols/apcsmart.html "http://networkupstools.org/protocols/apcsmart.html")
)
3. Verify that serial communication to the UPS is working - On the Router
* Detach the usb converter from PC , attach to router
* Install minicom on the router.
* Use the same minicom commands to verify communication with the router.
* type the uppercase letter: Y , and expect the reply SM
Y
SM
4. There should be a tab for APC UPS on the General Plugins page at:
http://192.168.1.1/cgi-bin/luci/admin/statistics/collectd/general
If not, you may not have the patches that added luci-statistics support for the apcups plugin: [https://github.com/openwrt/luci/pull/1227](https://github.com/openwrt/luci/pull/1227 "https://github.com/openwrt/luci/pull/1227")
. The best fix for this is to upgrade to a version that does.
5. /var/etc/collectd.conf should have a section for apcups:
LoadPlugin apcups
Host localhost
Port "3551"
If it does not, you can regenerate /var/etc/collectd.conf with this command:
/usr/bin/stat-genconfig > /var/etc/collectd.conf
* If you still don't have APC UPS graphs, you may not have the patches that added luci-statistics support for the apcups plugin: [https://github.com/openwrt/luci/pull/1227](https://github.com/openwrt/luci/pull/1227 "https://github.com/openwrt/luci/pull/1227")
. The best fix for this is to upgrade to a version that does.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/09/20 20:26
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/ups/apcupsd_su700#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Using OpenWrt to build a LAMP/WordPress server
Using OpenWrt to build a LAMP/WordPress server
==============================================
**NOTE** The article is outdated, see the [Set up a LAMP webserver stack](https://openwrt.org/docs/guide-user/services/webserver/lamp "docs:guide-user:services:webserver:lamp")
instead.
Preamble/Scope
--------------
Pro web developers tend to rely on development servers, because no-one likes to expose a half-built site on the Internet. But if you work from home and build a site, say, every couple of months, it's hard to justify a dedicated server. Even a cheap old PC still takes up a lot of space. Much better to have a little box that you can stash in a drawer when it's not in use, right?
Well, getting a tiny devserver to behave like a commercial host is time consuming and can be expensive. Around 2010 I bought a SheevaPlug and committed several weeks of headscratching to the installation of a LAMP stack and WordPress, only to have the machine burn out within a week of commission.
Things have got better in the last decade and with OpenWrt and a so-called 'travel router' you can have a full-featured devserver with an outlay of less than $50 and a day or so of work. This how-to documents how I got WordPress running on a GL.inet MT300A I bought for £27 on Amazon. Much of my account references sources on this wiki and elsewhere. I will indicate the problems I encountered and how others might improve on my methods. I might have misremembered a few details and I'm afraid I don't know the Windows or Mac equivalents to the Linux commands given here. Sorry!
NOTE: My objective was to build a small, cheap router that I could plug into my home network as needed. I do NOT recommend following this route if you're hosting content to any third party. It goes without saying that you won't be putting sensitive information on the devserver and that you won't be running it outside a firewall.
Hardware
--------
I chose the MT300A in a blind purchase because of its low cost, small footprint and OpenWrt friendliness. Conclusion: it kinda works, with some bodging. I definitely wouldn't recommend trying to make the instructions below work with any of its predecessors, and other, better hardware may be available by the time you read this.
Power up the router as per manufacturer's instructions. I'd suggest connecting its LAN port to one of the spare ports on your broadband router, but of course that assumes that you've got a typical home/small office setup with a broadband router plugged straight into your phone line.
Firmware
--------
Launch a browser and type the IP address of your device (192.168.8.1 for an out-of-the-box MT300A). You can access it using the factory default password.
GL.inet recommend setting a new root password as soon as you connect. You're welcome to do so, but since you'll need to replace the firmware on the router there's little point. I used lede-17.01.4-ramips-mt7620-gl-mt300a-squashfs-sysupgrade.bin from this site and followed these instructions: [factory\_installation](https://openwrt.org/docs/guide-quick-start/factory_installation "docs:guide-quick-start:factory_installation")
The new firmware changes the default IP address from `192.168.8.1` to `192.168.1.1`. For access via OpenWrt's LuCI GUI, point your browser at the new address. Now's the time to set that new password!
NOTE: GL.inet state that you can use the reset button to return the device to factory defaults in the event of a meltdown, but that isn't strictly accurate. The reset button simply returns the installed firmware to its default state. Thus, once you've uploaded OpenWrt firmware, resetting the device will take you back to a clean OpenWrt install rather than factory settings.
Software prerequisites?
-----------------------
There are loads of packages to install, so I'm not listing prerequisites. However, I will state at the outset that, since you'll need to use CLI/terminal programs, you might want to get up to speed on PuTTY and scp (secure copy). It's no fun wrestling with unfamiliar software on your own computer while trying to wrangle a remote machine.
LAN
---
TCP/IP is widely documented but still causes confusion. A brutally quick account: your broadband router has a fixed IP address on the local network (LAN). It dynamically assigns IP addresses to the devices which connect to it. Your new router will need a fixed IP address so that you will be able to find it easily on the LAN, but that address has to align with the stuff the broadband router is doing.
To find exactly what the broadband router is up to, launch a terminal on your own computer and do:
`route -n`
The response will look like this:
Kernel IP routing table
Destination Gateway Genmask Flags Metric Ref Use Iface
0.0.0.0 192.168.1.254 0.0.0.0 UG 1024 0 0 wlan0
169.244.0.0 0.0.0.0 255.255.0.0 U 1000 0 0 wlan0
192.158.1.0 0.0.0.0 255.255.255.0 U 0 0 0 wlan0
Special bonus for UK readers: BT broadband routers mostly use the IP address 192.168.1.254. Either way, make a note of that gateway IP address.
Launch PuTTY from the terminal and start a new session with the ip address of the new router. Log in as 'root' using whatever password you set via LuCI. If the login is successful, you'll see an OpenWrt logo in text and a command prompt. Update the gateway address by typing a uci command:
uci set network.lan.gateway 192.168.1.254
Depending on setup you may also need to type:
uci set network.lan.dns 192.168.1.254
...then:
uci commit network
reboot
The new router \*should\* now be set up for your existing LAN. Check by using OpenWrt's package manager to install nano, thus:
opkg update
opkg install nano
If you get errors, there is a network configuration problem. Google is your friend!
However, assuming you've got nano running, you'll be able to review all your network config options at one pass by doing:
`nano /etc/config/network`
BTW, when you've finished with nano, it will be faster to reload the network than to reboot the router:
`/etc/init.d/network reload`
Extending the ROM
-----------------
OpenWrt is tiny, and so are its numerous packages. This enables the system to operate from the meagre storage provided by the average router. The MT300A offers only 16Mb, but that's enough for a LAMP stack.
Unfortunately, it isn't enough for WordPress, which presently runs to about 20Mb.
A full solution to this problem is to dedicate an external USB stick to the router using a technique called overlaying, documented here: [extroot](https://openwrt.org/docs/guide-user/additional-software/extroot_configuration "docs:guide-user:additional-software:extroot_configuration")
NOTES: \* I found that, after following these instructions, I still needed to access the LuCI GUI tool, select 'System/Mount Points', check the 'Enabled' option and reboot the new router to gain access to the extended storage. \* I used extroot/overlay because I didn't want to wrangle multiple storage devices on the router. However, the technique has a downside: the USB stick can't easily be moved between devices, so you can't, for instance, re-plug it into your own machine to copy files. You might prefer to mount the USB stick on the router and access it as /dev/sda1 or whatever without bothering to overlay it. Useful pointers here: [https://snippets.khromov.se/installing-wordpress-on-a-tiny-wireless-router/](https://snippets.khromov.se/installing-wordpress-on-a-tiny-wireless-router/ "https://snippets.khromov.se/installing-wordpress-on-a-tiny-wireless-router/")
Configuring the web server
--------------------------
You already have a working web server -- OpenWrt ships with uhttpd preinstalled. Result! The drawback is that uhttpd is tied up in providing the LuCI GUI.
The simplest way around this is to activate another instance of uhttpd on port 81 pointing to a distinct directory (where your dev website will live). This will slightly complicate the business of accessing your development site, but that's better than messing up LuCI. Instructions here: [lamp](https://openwrt.org/docs/guide-user/services/webserver/lamp "docs:guide-user:services:webserver:lamp")
\[scroll down to 'Installing and configuring a web server/uHTTPd'\]
Installing MySQL
----------------
I chose MySQL over SQLite. I imagine you'd get faster performance with the SQLite.
The MySQL install itself is pretty easy:
opkg update
opkg install mysql-server
Installing PHP
--------------
PHP is available via opkg so you might think this would be easy. But you have to choose PHP5 or PHP7, and then you'll find that this is one of those times when OpenWrt's parsimonious approach to memory usage complicates matters -- the package is split across multiple components.
The following worked for me:
opkg update
opkg install php7 php7-cgi php7-cli php7-mod-gd php7-mod-hash php7-mod-json php7-mod-mbstring php7-modmysqli php7-mod-opcache php7-mod-pdo php7-mod-pdo-mysql php7-mod-session
Use the configuration instructions here: [uhttpd](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
\[scroll down to 'Using PHP5' section, still seems to apply.\]
Installing WordPress
--------------------
You'll need to install WordPress the hard way.
Go to wordpress.org and download a copy of the latest version to your own machine. Unzip it and, while you're at it, rename 'wp-config-sample.php' to 'wp-config.php'.
Using Putty, make a new `wordpress` directory in `/srv/www` on the router:
cd /srv/www
mkdir wordpress
Now launch a terminal (not a PuTTY session!) and use scp to copy the unzipped archive to the new directory:
scp -r /home/\[yermamaspc\]/Downloads/wordpress/ root@192.168.1.1:/srv/www/wordpress/
Tying it all together (but don't install PHPMyAdmin)
----------------------------------------------------
If you've run WordPress in a commercial environment, you've almost certainly used PHPMyAdmin to set up your MySQL databases. On OpenWrt, that's a bad move, since the available MySQL daemon isn't fully compatible with the latest PHP. Fortunately, manually configuring a suitable MySQL database is a piece of cake. Good instructions here: [websiteforstudents.com/creating-new-mysql-user-database-wordpress/](https://websiteforstudents.com/creating-new-mysql-user-database-wordpress/ "https://websiteforstudents.com/creating-new-mysql-user-database-wordpress/")
For our purposes I recommend standardizing thus: wordpress\_db / wordpress\_user / wordpress\_pw. Of course that's at your own risk. (You're not going to put your credit card details or Google password on there, are you?)
Once you've set up the MySQL database, you can run the WordPress installer script from:
`192.168.1.1:81/wordpress/`
From now on, you're on your own...
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/12/14 19:33
* by stokito
[](https://openwrt.org/docs/guide-user/services/webserver/install_wordpress#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] uHTTPd webserver
uHTTPd webserver
================
uHTTPd is OpenWrt's default web server and is used to provide the [LuCI](https://openwrt.org/docs/techref/luci "docs:techref:luci")
web interface.
Its source code is available in the following git repository:
* [https://git.openwrt.org/project/uhttpd.git](https://git.openwrt.org/project/uhttpd.git "https://git.openwrt.org/project/uhttpd.git")
* [https://github.com/openwrt/uhttpd](https://github.com/openwrt/uhttpd "https://github.com/openwrt/uhttpd")
(mirror)
Features
--------
Built as a general purpose HTTP daemon suitable for embedded devices, uHTTPd features include:
* A lightweight, single-threaded and event-driven architecture with minimal memory footprint
* HTTP and HTTPS (TLS) support
* CGI script execution
* Scripting via Lua and [UCode](https://ucode.mein.io/ "https://ucode.mein.io/")
* Basic authentication
* File serving with directory listing capabilities
* URL rewriting and aliasing
Installation
------------
uHTTPd is the standard HTTP server for OpenWrt, and is usually included by default in the system image for the main OpenWrt releases. The package name is `uhttpd`. In case the package is not installed, it can be installed manually:
opkg update
opkg install uhttpd
However, it is usually installed automatically as a dependency for the [LuCI](https://openwrt.org/docs/techref/luci "docs:techref:luci")
[web interface](https://openwrt.org/docs/guide-user/luci/webinterface.overview "docs:guide-user:luci:webinterface.overview")
.
Configuration
-------------
The configuration of uHTTPd is performed via OpenWrt's standard [uci](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
system. The configuration file is `/etc/config/uhttpd`. See the [uHTTPd UCI configuration page](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
for further details.
### Using the default installation for publishing files
One can use the default installation to publish files under `/www`. Here's a quick example:
mkdir /www/test
echo "Hello world" \>> /www/test/message.txt
The file should now be available at e.g. `https://192.168.1.1/test/`.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/07/26 17:55
* by alphix
[](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] PHP
PHP
===
Installation
------------
1. List available php packages
opkg update
opkg list php\*
2. Install php
opkg install php7 php7-cgi
Configuration
-------------
For configuration please see the wiki-page for the particular web server: [webserver](https://openwrt.org/docs/guide-user/services/webserver/start "docs:guide-user:services:webserver:start")
, e.g.
* [Configuring Apache and PHP5](https://openwrt.org/docs/guide-user/services/webserver/http.apache#configuring_apache_and_php5 "docs:guide-user:services:webserver:http.apache")
* [Configuring Lighttpd and PHP5](https://openwrt.org/docs/guide-user/services/webserver/lighttpd#configuring_lighttpd_and_php5 "docs:guide-user:services:webserver:lighttpd")
* [Configuring Hiawatha and PHP5](https://openwrt.org/docs/guide-user/services/webserver/http.hiawatha#configuring_hiawatha_and_php5 "docs:guide-user:services:webserver:http.hiawatha")
* [Configuring Nginx and PHP5](https://openwrt.org/docs/guide-user/services/webserver/nginx#configuring_nginx_and_php5 "docs:guide-user:services:webserver:nginx")
* [Configuring uhttpd and PHP5](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
* or see [Configuring PHP](https://openwrt.org/docs/guide-user/services/webserver/lamp#configuring_php "docs:guide-user:services:webserver:lamp")
Troubleshooting
---------------
If you encounter PHP errors, like undefined functions, you need take a look into the `php.ini` file. Search for the appropriate extension line(s), and uncomment them (remove the ; sign). If the problem persists, you probably need to install the appropriate extension too. If PHP runs out of memory, you can increase the amount of memory which the script can consume:
memory\_limit = 8M ; Maximum amount of memory a script may consume.
post\_max\_size = 8M
Do not specify more memory than is available, and remember that other processes need memory too. Please note, some things will probably never run on the router. Especially under Backfire 10.03. PHP compiled without the SimpleXML extension, and libxml is missing too. If they are necessary, you need to recompile your own PHP. Without this extensions, some software, like Joomla 1.6 will never run. If you do manage to achieve to run, serious software solutions will run extremely slow, and will consume too much memory.
PHP Development Server
----------------------
This section explains how to quickly setup a php test server for prototyping php web applications, using php's own internal web server.
A little known trick about php is that it has it's own built in web server.
If you install the command line php binary, you can run a quick, no frills web server on OpenWrt for development work and prototyping.
In no way should you expect a fully production ready web server from this method. php's internal web server is recommended for your own internal network testing and is not recommended as an alternative to a fully fledged http server daemon.
With that said; complete the following steps to create a quick php development server inside of an OpenWrt instance:
Install the [php7-cgi](https://openwrt.org/packages/pkgdata/php7-cgi "packages:pkgdata:php7-cgi")
package using [opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
.
opkg update && opkg install php7-cli
_(This pulls in packages [libpcre](https://openwrt.org/packages/pkgdata/libpcre "packages:pkgdata:libpcre")
[zlib](https://openwrt.org/packages/pkgdata/zlib "packages:pkgdata:zlib")
[libxml2](https://openwrt.org/packages/pkgdata/libxml2 "packages:pkgdata:libxml2")
[zoneinfo-core](https://openwrt.org/packages/pkgdata/zoneinfo-core "packages:pkgdata:zoneinfo-core")
[php7](https://openwrt.org/packages/pkgdata/php7 "packages:pkgdata:php7")
as part of the installation.)_
Optionally, now remove the package cache if you are low on memory space.
rm \-r /tmp/opkg-lists/
Create a www directory (during testing, I skipped this normal step and just used the /root directory instead.)
mkdir /www
Use a text editor ([nano](https://openwrt.org/packages/pkgdata/nano "packages:pkgdata:nano")
in this example) to create the file **index.php** inside of the **/www** directory (nano can be installed via [opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
if need be.)
nano /www/index.php
Add the text “**It works!**” into the file, save and close it.
Start the webserver from the command line.
php-cli \-S 172.16.0.1:8080 \-t /www
_(Replace **172.16.0.1:8080** with the ip address of your OpenWrt instance and the port number you want to use to access the server by.)_
Open a web browser and visit the address **http://172.16.0.1:8080** (or whatever you used instead) and you should see the text “**It works!**” on the page.
That's all there is to it.
Taking it further, you could optionally [create a startup script](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
which automates starting the server.
To stop the server use the **ctrl + c** key combination.
To spawn the server into a separate process and return command back to the console, add a double ampersand to the end of the command line options you use to start the server.
php-cli \-S 172.16.0.1:8080 \-t /www &&
The web server will then remain running until it's process is manually ended or the OpenWrt instance has been rebooted.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/04/04 07:08
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/webserver/php#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] BusyBox HTTP Daemon (httpd) webserver
BusyBox HTTP Daemon (httpd) webserver
=====================================
[BusyBox](https://openwrt.org/docs/techref/busybox "docs:techref:busybox")
is a toolbox with tiny replacements of essential Linux programs. One of them is a tiny HTTP server `httpd` (HTTP Daemon). Early versions of OpenWrt before Attitude Adjustment 12.0 release used the `httpd` server but then switched to own [uHTTPd](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd")
which has a built-in Lua interpreter so can serve Luci faster.
For a long period before BusyBox v1.37 (Dec 2024) the Luci didn't worked with plain BB httpd. So now it should be possible to use it with the Luci. The BB httpd can be compiled with only basic features like CGI and ETag and will have only 8Kb against 32Kb of stock uhttpd.
Features
--------
It's is a single threaded daemon with most needed features:
* [ETag](https://en.wikipedia.org/wiki/HTTP_ETag "https://en.wikipedia.org/wiki/HTTP_ETag")
to avoid re-downloading of files cached in browser
* [CGI](https://en.wikipedia.org/wiki/Common%20Gateway%20Interface "https://en.wikipedia.org/wiki/Common Gateway Interface")
to execute server side request processing
* [Basic authentication](https://en.wikipedia.org/wiki/Basic_access_authentication "https://en.wikipedia.org/wiki/Basic_access_authentication")
to limit access by a password
* Serving pre-compressed gzip files with [Content-Encoding: gzip](https://en.wikipedia.org/wiki/HTTP_compression "https://en.wikipedia.org/wiki/HTTP_compression")
* [Range requests](https://datatracker.ietf.org/doc/html/rfc7233 "https://datatracker.ietf.org/doc/html/rfc7233")
to get only part of a file.
* ACL by IP to allow or deny access
* [Reverse proxy](https://en.wikipedia.org/wiki/Reverse%20proxy "https://en.wikipedia.org/wiki/Reverse proxy")
* Custom error pages e.g. 404.html
But it doesn't support Keep Alive, TLS (HTTPS), Virtual Hosting, FastCGI and many other features so it's often replaced in embedded systems with [Lighttpd](https://openwrt.org/docs/guide-user/services/webserver/lighttpd "docs:guide-user:services:webserver:lighttpd")
Installation
------------
There is no package called `httpd` that you can install with `opkg`. The `httpd` is part of BusyBox functionality. You could either compile BusyBox with this functionality included, or you could install a second BusyBox binary with this functionality included.
Usage
-----
From [https://busybox.net/downloads/BusyBox.html#httpd](https://busybox.net/downloads/BusyBox.html#httpd "https://busybox.net/downloads/BusyBox.html#httpd")
:
httpd \[-ifv\[v\]\] \[-c CONFFILE\] \[-p \[IP:\]PORT\] \[-u USER\[:GRP\]\] \[-r REALM\] \[-h HOME\]
Listen for incoming HTTP requests
Options:
-i Inetd mode
-f Do not daemonize and run in foreground
-v\[v\] Verbose (-vv for debug)
-p \[IP:\]PORT Bind to IP:PORT (default \*:80 i.e. 80 port on all interfaces both IPv4 and IPv6)
-u USER\[:GRP\] Set uid/gid after binding to port
-r REALM Authentication Realm for Basic Authentication (default "Web Server Authentication")
-h HOME Home directory (default . i.e. current folder)
-c FILE Configuration file (default /etc/httpd.conf)
Note that multiple instances of httpd can be run, which would have different `.conf` files:
/usr/sbin/httpd \-p 80 \-h /www
/usr/sbin/httpd \-p \[::\]:8080 \-h /www2 \-c /etc/httpd2.conf
The `httpd` command can be used a `crypt` tool to encode password hash for the Basic Auth credentials or to make URL/HTML encode:
httpd -d/-e/-m STRING
Options:
-m STRING MD5 crypt STRING
-e STRING HTML encode STRING
-d STRING URL decode STRING
For example to encode password:
busybox httpd \-m secret \# returns $1$ws7RyNs5$52kZnHcfhffHaWs8XRX5A.
Configuration
-------------
`httpd` may work without a configuration file. But by default it will try to read config from `/etc/httpd.conf`. There were also some brief uci support for this: [httpd](https://openwrt.org/docs/guide-user/base-system/httpd "docs:guide-user:base-system:httpd")
.
The `httpd` documented itself [directly in source code](https://git.busybox.net/busybox/tree/networking/httpd.c "https://git.busybox.net/busybox/tree/networking/httpd.c")
Example of config file:
[/etc/httpd.conf](https://openwrt.org/_export/code/docs/guide-user/services/webserver/http.httpd?codeblock=4 "Download Snippet")
H:/serverroot \# define the server root. It will override -h
\# Allow/Deny part
#
\# \[aA\]:from ip address allow, \* for wildcard, network subnet allow
\# \[dD\]:from ip address deny, \* for wildcard, network subnet allow
#
\# network subnet definition
\# 172.20. address from 172.20.0.0/16
\# 10.0.0.0/25 address from 10.0.0.0-10.0.0.127
\# 10.0.0.0/255.255.255.128 address that previous set
#
\# The Deny/Allow IP logic:
#
\# - Default is to allow all. No addresses are denied unless
\# denied with a D: rule.
\# - Order of Deny/Allow rules is significant
\# - Deny rules take precedence over allow rules.
\# - If a deny all rule (D:\*) is used it acts as a catch-all for unmatched
\# addresses.
\# - Specification of Allow all (A:\*) is a no-op
#
\# Example:
\# 1. Allow only specified addresses
\# A:172.20 # Allow any address that begins with 172.20.
\# A:10.10. # Allow any address that begins with 10.10.
\# A:127.0.0.1 # Allow local loopback connections
\# D:\* # Deny from other IP connections
#
\# 2. Only deny specified addresses
\# D:1.2.3. # deny from 1.2.3.0 - 1.2.3.255
\# D:2.3.4. # deny from 2.3.4.0 - 2.3.4.255
\# A:\* # (optional line added for clarity)
#
\# Note:
\# A:\*
\# D:\*
\# Mean deny ALL !!!!
#
A:\*
#
\# Authentication part
#
\# /path:user:pass username/password
#
\# password may be clear text or MD5 cript
#
\# Example :
\# /cgi-bin:admin:FOO
#
\# MD5 crypt password :
\# httpd -m "\_password\_"
\# Example :
\# httpd -m "astro" => $1$$e6xMPuPW0w8dESCuffefU.
\# /work:toor:$1$$e6xMPuPW0w8dESCuffefU.
#
#
\# MIME type part
#
\# .ext:mime/type new mime type not compiled into httpd
#
\# Example :
\# .ipk:application/octet-stream
#
\# MIME type compiled into httpd
#
\# .htm:text/html
\# .html:text/html
\# .jpg:image/jpeg
\# .jpeg:image/jpeg
\# .gif:image/gif
\# .png:image/png
\# .txt:text/plain
\# .h:text/plain
\# .c:text/plain
\# .cc:text/plain
\# .cpp:text/plain
\# .css:text/css
\# .wav:audio/wav
\# .avi:video/x-msvideo
\# .qt:video/quicktime
\# .mov:video/quicktime
\# .mpe:video/mpeg
\# .mpeg:video/mpeg
\# .mid:audio/midi
\# .midi:audio/midi
\# .mp3:audio/mpeg
#
\# Default MIME type is application/octet-stream if extension isn't set
\# Use Unicode for text files
.txt:text/plain;charset\=utf-8
.md:text/plain;charset\=utf-8
.htm:text/html;charset\=utf-8
.html:text/html;charset\=utf-8
\# configure interpreters.
\*.php:/usr/bin/php-cgi
\*.pl:/usr/bin/perl
\*.rb:/usr/bin/ruby
\*.erb:/usr/bin/eruby
\*.py:/usr/bin/python
\# The \*.cgi often are Perl files but may be just a shell with shebang
#\*.cgi:/usr/bin/perl
Example of BB httpd options and their analogues in Apache HTTPD:
| BB httpd conf option | Apache HTTPD conf option |
| --- | --- |
| `I:default.htm` | `DirectoryIndex default.htm` |
| `H:/srv/www/` | `DocumentRoot /srv/www/` |
| `A:192.168.11.1` | `Allow from 192.168.11.1` |
| `D:*` | `Deny from all` |
| `E401:401.html` | `ErrorDocument 401 /401.html` |
| `P:/blog:wp/` | `ProxyPass /blog:[http://wp/](http://wp/ "http://wp/") ` |
| `.webp:image/webp` | `AddType image/webp webp` |
| `*.py:/usr/bin/python` | `AddHandler mod_python .py` (the mod\_python must be enabled) |
| `/cgi-bin:admin:SECRET` | `AuthType Basic`, `AuthUserFile /etc/.htpasswd` (you'll need to create a separate file) |
CGI scripts
-----------
`httpd` expects it's CGI script files to be in the subdirectory `cgi-bin` under main web directory set by options `-h` (default is `/www`, so `/www/cgi-bin`). The CGI script files must also have permission to be executed (min mode 700). If directory URL is given, no `index.html` is found and CGI support is enabled, then `cgi-bin/index.cgi` will be executed.
BusyBox sources contains two useful CGI programs:
* [httpd\_indexcgi.c](https://git.busybox.net/busybox/tree/networking/httpd_indexcgi.c "https://git.busybox.net/busybox/tree/networking/httpd_indexcgi.c")
generates a directory listing i.e. list of files. Other Web Servers has this as built-in feature but for BB http this is delegated to a CGI program.
* [httpd\_ssi.c](https://git.busybox.net/busybox/tree/networking/httpd_ssi.c "https://git.busybox.net/busybox/tree/networking/httpd_ssi.c")
processes [Server Side Includes](https://en.wikipedia.org/wiki/Server%20Side%20Includes "https://en.wikipedia.org/wiki/Server Side Includes")
Use `httpd_helpers.sh` to compile them. Also there is and example of shell script to process File Upload [httpd\_post\_upload.cgi](https://git.busybox.net/busybox/tree/networking/httpd_post_upload.cgi "https://git.busybox.net/busybox/tree/networking/httpd_post_upload.cgi")
Check more [CGI shell samples](https://gist.github.com/stokito/a9a2732ffc7982978a16e40e8d063c8f "https://gist.github.com/stokito/a9a2732ffc7982978a16e40e8d063c8f")
.
### CGI Variables
Standard set of Common Gateway Interface environment variables are described in [RFC3875](https://datatracker.ietf.org/doc/html/rfc3875 "https://datatracker.ietf.org/doc/html/rfc3875")
. For example:
CONTENT\_TYPE\=application/x-www-form-urlencoded
CONTENT\_LENGTH\=128
REQUEST\_METHOD\=POST
REQUEST\_URI\=/cgi-bin/printenvs
QUERY\_STRING\=param1\=12345¶m2\=¶m3\=some%20text
REMOTE\_USER\=\[http basic auth username\]
HTTP\_HOST\=example.com
HTTP\_USER\_AGENT\=Chrome
HTTP\_ACCEPT\=\*/\*
HTTP\_REFERER\=http://192.168.1.1/index1.html
REMOTE\_ADDR\=192.168.1.180
REMOTE\_PORT\=2292
SERVER\_PORT\=80
PATH\=/bin:/sbin:/usr/bin:/usr/sbin
PATH\_INFO\=
PWD\=/www/cgi-bin
SCRIPT\_NAME\=/cgi-bin/printenvs
SERVER\_PROTOCOL\=HTTP/1.0
GATEWAY\_INTERFACE\=CGI/1.1
SERVER\_SOFTWARE\=busybox httpd/1.30.1
Example of CGI script that prints them:
[/cgi-bin/printenvs](https://openwrt.org/_export/code/docs/guide-user/services/webserver/http.httpd?codeblock=6 "Download Snippet")
#!/bin/sh
echo "Content-Type: text/html"
echo ""
echo "Environment variables:"
env
Environment variables are set up and the script is invoked with pipes for stdin/stdout.
All request headers are available with HTTP prefix e.g. Host header will be passed in HTTP\_HOST env.
### HTTPS
BB httpd doesn't support TLS but you may try to use [stunnel](https://www.stunnel.org/index.html "https://www.stunnel.org/index.html")
. Alternatively `socat` tool may be used:
[/etc/config/socat](https://openwrt.org/_export/code/docs/guide-user/services/webserver/http.httpd?codeblock=7 "Download Snippet")
config socat 'http'
option enable '1'
list SocatOptions '-T30'
list SocatOptions '-dd'
list SocatOptions 'OPENSSL-LISTEN:443,pf=ip6,reuseaddr,rcvtimeo=10,sndtimeo=10,keepalive,fork,cert=/etc/acme/example.com/combined.cer,cipher=!CBC:!RSA:!DHE:!PSK:HIGH,verify=0'
list SocatOptions 'TCP:127.0.0.1:80'
### Reverse Proxy
BB httpd has a very basic reverse proxy support but it's not compiled by default. Use `FEATURE_HTTPD_PROXY` to enable it.
This option allows you to define URLs that will be forwarded to another HTTP server (the HTTPS is not supported). To setup add the following line to the configuration file:
P:/old/path:\[http://\]hostname\[:port\]/new/path
Then a request to `/old/path` will be forwarded to `[http://hostname[:port]/new/path](http://hostname[:port]/new/path "http://hostname[:port]/new/path") `.
### Serve gzipped files
For every file that should be served gzipped, add a matching `[FILENAME].gz`. The `.gz` file will be server instead of the original file so you may remove the original file.
### See also
\* [Using the busybox HTTP server](http://wiki.chumby.com/index.php?title=Using_the_busybox_HTTP_server "http://wiki.chumby.com/index.php?title=Using_the_busybox_HTTP_server")
\* [docker-static-website](https://github.com/forksss/docker-static-website "https://github.com/forksss/docker-static-website")
a Docker image to run the BusyBox httpd
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/11/18 20:56
* by stokito
[](https://openwrt.org/docs/guide-user/services/webserver/http.httpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] BitTorrent
BitTorrent
==========
[BitTorrent (protocol)](https://en.wikipedia.org/wiki/BitTorrent%20(protocol) "https://en.wikipedia.org/wiki/BitTorrent (protocol)")
* [24C3 lecture on BitTorrent especially on tracker software (german)](http://events.ccc.de/congress/2007/Fahrplan/events/2355.en.html "http://events.ccc.de/congress/2007/Fahrplan/events/2355.en.html")
BitTorrent Client Software
--------------------------
| Name | Version | Dependencies | Size | Description |
| --- | --- | --- | --- | --- |
| aria2 | 1.35.0 | libc, zlib, libstdcpp6, libopenssl1.1, libsqlite30 | 842.038 | [aria2](https://aria2.github.io/ "https://aria2.github.io") is a lightweight multi-protocol & multi-source command-line download utility. It can be configured via LuCi web interface app and it comes with its own web GUI for URI downloadings |
| transmission-daemon | 2.40-1 | libcurl, libopenssl, libpthread, libevent2, librt | 182.225 | [Transmission](https://en.wikipedia.org/wiki/Transmission%20(BitTorrent%20client) "https://en.wikipedia.org/wiki/Transmission (BitTorrent client)") is a simple BitTorrent client. It features a very simple, intuitive interface on top on an efficient, cross-platform back-end. This package contains the daemon itself. See →`[/etc/config/transmission](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission "docs:guide-user:services:downloading_and_filesharing:transmission") ` to configure it |
| transmission-remote | 2.40-1 | | 189.729 | CLI remote interface for transmission. |
| transmission-cli | 2.40-1 | transmission-daemon | 709.887 | CLI utilities for transmission. |
| transmission-web | 2.40-1 | transmission-daemon | 138.156 | Webinterface resources for transmission. |
| | | | | |
| rtorrent | 0.9.8-2 | libc, libcurl4, libncurses6, libpthread, libopenssl1.1, libstdcpp6, zlib | 562.281 | [rTorrent](https://en.wikipedia.org/wiki/rTorrent "https://en.wikipedia.org/wiki/rTorrent") is a BitTorrent client for ncurses, using the [LibTorrent](https://en.wikipedia.org/wiki/LibTorrent "https://en.wikipedia.org/wiki/LibTorrent") library. The client and library is written in C + + with emphasis on speed and efficiency, while delivering equivalent features to those found in GUI based clients in an ncurses client. |
| rtorrent-rpc | 0.9.8-2 | libc, libcurl4, libncurses6, libpthread, libopenssl1.1, libstdcpp6, zlib, xmlrpc-c-server | 558.708 | [rTorrent](https://en.wikipedia.org/wiki/rTorrent "https://en.wikipedia.org/wiki/rTorrent") is a BitTorrent client for ncurses, also has a built-in daemon mode, clients can control it via [XML-RPC](https://en.wikipedia.org/wiki/XML-RPC "https://en.wikipedia.org/wiki/XML-RPC") . LuCI based client: [luci-app-rtorrent](https://github.com/wolandmaster/luci-app-rtorrent "https://github.com/wolandmaster/luci-app-rtorrent") |
| | | | | |
| ctorrent | dnh3.3.2-5 | uclibcxx, libopenssl | 86.767 | [CTorrent](https://en.wikipedia.org/wiki/CTorrent "https://en.wikipedia.org/wiki/CTorrent") is a BitTorrent client written in the C programming language, known to be a very robust and mature programming language, which produces fast and optimized application. This package is built with OpenSSL support. |
| ctorrent-nossl | dnh3.3.2-5 | uclibcxx | 86.720 | CTorrent is a BitTorrent client written in the C programming language, known to be a very robust and mature programming language, which produces fast and optimized application. This package is built with builtin (Steve Reid's public-domain) SHA-1 support |
| | | | | |
| deluge\* | | | | [Deluge](https://en.wikipedia.org/wiki/Deluge%20(software) "https://en.wikipedia.org/wiki/Deluge (software)") is written in Python and should be available since [R20178](https://dev.openwrt.org/changeset/20178 "https://dev.openwrt.org/changeset/20178") . Deluge is broken in OpenWrt: [6888](https://dev.openwrt.org/ticket/6888 "https://dev.openwrt.org/ticket/6888") deluge needs rblibtorrent, which is broken and won't probably be fixed anytime soon [https://dev.openwrt.org/browser/packages/net/deluge](https://dev.openwrt.org/browser/packages/net/deluge "https://dev.openwrt.org/browser/packages/net/deluge") |
| btpd | 0.16-2 | | | BTPD is a bittorrent client consisting of a daemon and client commands, which can be used to read and/or manipulate the daemon state. The daemon is capable of running several torrents simultaneously and only uses one tcp port. It's fairly low on resource usage and should be perfect for file distribution sites. Efficient downloads and ease of use makes this client a good choice for the casual user as well. |
BitTorrent Tracker Software
---------------------------
| Name | Version | Dependencies | Size | Description |
| --- | --- | --- | --- | --- |
| cbtt | 20060727-2 | libc, libpthread, uclibcxx, zlib | | Bittorrent tracker |
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/05/21 18:40
* by danitool
[](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/bittorrent#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] E-MailRelay
E-MailRelay
===========
E-MailRelay is an e-mail store-and-forward message transfer agent and proxy server. E-MailRelay does three things: it stores any incoming e-mail messages that it receives, it forwards e-mail messages on to another remote e-mail server, and it serves up stored e-mail messages to local e-mail reader programs. More technically, it acts as a SMTP storage daemon, a SMTP forwarding agent, and a POP3 server.
E-MailRelay does not do routing of individual messages; it is not a routing MTA. It forwards all e-mail messages to a pre-configured SMTP server, regardless of any message addressing or DNS redirects.
Package [emailrelay](https://openwrt.org/packages/pkgdata/emailrelay "https://openwrt.org/packages/pkgdata/emailrelay")
takes up to 1.4mb space and installs following files:
/usr/bin/emailrelay
/usr/bin/emailrelay-filter-copy
/usr/bin/emailrelay-passwd
/usr/bin/emailrelay-submit
/etc/config/emailrelay
/etc/emailrelay.auth
Its uci configuration is located in `/etc/config/emailrelay`. The config starts _emailrelay_ command with options that are described in [manual](https://emailrelay.sourceforge.net/ "https://emailrelay.sourceforge.net/")
. You can also use plain config file `/etc/emailrelay.conf`. See full sample [emailrelay.conf](https://sourceforge.net/p/emailrelay/code/HEAD/tree/trunk/etc/emailrelay.conf.in "https://sourceforge.net/p/emailrelay/code/HEAD/tree/trunk/etc/emailrelay.conf.in")
.
Sections
--------
The default emailrelay config file contains _server_, _proxy_ and _cmdline_ sections.
The possible options are listed in the table below.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | yes | _0_ | Listen SMTP |
| `mode` | string | yes | _server_, _proxy_, _client_ or _cmdline_ | Mode: _\--as-server_ or _\--as-proxy_. The _cmdline_ means append _extra\_cmdline_ |
| `smarthost` | string | yes | _(none)_ | For _proxy_ mode specify the SMTP to forward emails. The option for _\--as-proxy _ |
| `port` | integer | yes | _25_ | Port to listen incoming emails. |
| `remote_clients` | boolean | yes | _0_ | To allow connections from anywhere. By default only local allowed. Check your firewall to avoid spam. See _\--remote-clients_ |
| `dnsbl` | list | no | _(none)_ | List of DNSBL servers that are used to reject SMTP connections from blocked addresses. See _\--dnsbl_ |
| `address_verifier` | string | no | _(none)_ | Runs the specified external program to verify a message recipient's e-mail address. See _\--address-verifier_ |
| `domain` | string | no | _(none)_ | Specifies the network name that is used in SMTP `EHLO`. The default is derived from a DNS lookup of the local hostname. See _\--domain_ |
| `anonymous` | boolean | no | _0_ | Disables the server's SMTP VRFY command. See _\--anonymous_ |
| `server_tls` | boolean | no | _0_ | For _server_ and _proxy_ mode. See _\--server-tls_ Doesn't work in v2.1, see [fix](https://github.com/openwrt/packages/pull/18536 "https://github.com/openwrt/packages/pull/18536") |
| `server_tls_required` | boolean | no | _0_ | Makes the TLS mandatory for incoming SMTP and POP connections. See _\--server-tls-required_ |
| `server_tls_key` | string | no | _(none)_ | Path to private key PEM file. See _\--server-tls-certificate_ |
| `server_tls_certificate` | string | no | _(none)_ | Path to certificate PEM file. See _\--server-tls-certificate_ |
| `server_tls_verify` | string | no | _(none)_ | Path to trusted CAs. Verify remote SMTP and POP clients certificates against the trusted CA certificates. See _\--server-tls-verify_ |
| `server_auth` | string | no | _(none)_ | For _server_ and _proxy_ mode. See _\--server-auth_ and /etc/emailrelay.auth |
| `filter` | list | no | _(none)_ | Filter program whenever a mail message is stored. See _\--filter_ |
| `client_tls` | boolean | no | _0_ | For _proxy_ mode. See _\--client-tls_ |
| `client_tls_required` | boolean | no | _0_ | Makes the use of TLS mandatory for outgoing SMTP connections. The SMTP `STARTTLS` command will be used before mail messages are sent out. See _\--client-tls-required_ |
| `client_tls_key` | string | no | _(none)_ | Path to TLS private key PEM file when acting as a SMTP client. See _\--client-tls-certificate_ |
| `client_tls_certificate` | string | no | _(none)_ | Path to TLS certificate file when acting as a SMTP client. See _\--client-tls-certificate_ |
| `client_tls_verify` | string | no | _(none)_ | Enables verification of the remote SMTP server's certificate against any of the trusted CA certificates in the specified file or directory. See _\--client-tls-verify_ |
| `client_auth` | string | no | _(none)_ | For _proxy_ mode. See _\--client-auth_ and `/etc/emailrelay.auth` |
| `smtp_client_interface` | list | no | _(none)_ | The IP network address to be used to bind the local end of outgoing SMTP connections. See _\--client-interface_ |
| `client_filter` | list | no | _(none)_ | Filter program whenever a mail message is forwarded. See _\--client-filter_ |
| `pop` | boolean | no | _0_ | Enable POP server. See _\--pop_ |
| `pop_port` | integer | no | _110_ | Port for incoming POP connections. See _\--pop-port_ |
| `pop_auth` | string | no | _(none)_ | A file containing POP account details. See _\--pop-auth_ and `/etc/emailrelay.auth` |
| `pop_by_name` | boolean | no | _0_ | Makes spool directory to be the sub-directory with the same name as the user-id used for POP authentication. See _\--pop-by-name_ |
| `pop_server_interface` | list | no | _(none)_ | The IP network address to for POP connections. See _\--interface_ |
| `spool_dir` | string | no | _/var/spool/emailrelay_ | The directory used for holding mail messages that have been received but not yet forwarded. See _\--spool-dir_ |
| `delivery_dir` | string | no | _/var/spool/emailrelay/in_ | The base directory for mailboxes when delivering messages that have local recipients. See _\--delivery-dir_ |
| `extra_cmdline` | string | no | _(none)_ | Extra command line options. See [https://emailrelay.sourceforge.net/#reference\_md\_Reference](https://emailrelay.sourceforge.net/#reference_md_Reference "https://emailrelay.sourceforge.net/#reference_md_Reference") for command line reference |
### Server
A minimal `server` declaration:
config emailrelay 'server'
option enabled '0'
option mode 'server'
option port '25'
option remote\_clients '0'
### Proxy
A minimal `proxy` declaration:
config emailrelay 'proxy'
option enabled '0'
option mode 'proxy'
option smarthost '192.0.2.1:25'
option port '25'
option remote\_clients '0'
### Plain commands
A minimal `cmdline` declaration:
config emailrelay 'cmdline'
option enabled '0'
option mode 'cmdline'
# specify all arguments that should be passed to emailrelay here
# see https://emailrelay.sourceforge.net/#reference\_md\_Reference for command line reference
option extra\_cmdline '--some-other --cmdline-options'
Useful options
--------------
### Configure TLS
[Obtain a TLS cert](https://openwrt.org/docs/guide-user/services/tls/certs "docs:guide-user:services:tls:certs")
Then configure `server_tls` option and put private key and then after a comma a fullchain.
### Mail storage location
By default mails are stored into `/var/spool/emailrelay`. On the OpenWrt the entire `/var/` directory is tmpfs stored in RAM memory and will be lost on a router reboot. So you need to change it to store them into some USB disk. To do this you have to create a folder e.g. `/mnt/usb_disk/spool/` and configure emailrelay to use it by setting:
option extra\_cmdline '--spool-dir /mnt/usb\_disk/spool/'
In next versions of the emailrelay package you'll have a separate UCI option `spool_dir`
Also if you are using the “POP by name” option then you need to create a subfolders for each account
### Reading email with POP
If you are using email client (MUA) like Thunderbird, Outlook then you can fetch received mails by enabling POP protocol.
`option extra_cmdline '--pop --pop-auth=/etc/pop.auth`'. Also you must allow an access so set `option remote_clients='1`'. Then you must create the `/etc/pop.auth` file as described in [https://emailrelay.sourceforge.net/index.html#userguide\_md\_Running\_as\_a\_POP\_server](https://emailrelay.sourceforge.net/index.html#userguide_md_Running_as_a_POP_server "https://emailrelay.sourceforge.net/index.html#userguide_md_Running_as_a_POP_server")
. Please note that if you are going to read emails from internet then you have to configure TLS for security. See below how to open a port for internet.
Open ports for internet in Firewall
-----------------------------------
This is a very bad idea for security and don't do this unless you know what are you doing. Add to `/etc/config/firewall`:
config rule
option name 'Allow-WAN-SMTP'
option target 'ACCEPT'
option src 'wan'
option proto 'tcp'
option dest\_port '25'
config rule
option name 'Allow-WAN-SMTP-Submission'
option target 'ACCEPT'
option src 'wan'
option proto 'tcp'
option dest\_port '587'
config rule
option name 'Allow-WAN-POP'
option target 'ACCEPT'
option src 'wan'
option proto 'tcp'
option dest\_port '110'
You can add these rules with command line:
uci add firewall rule
uci set firewall.wan\_https\_turris\_rule=rule
uci set firewall.wan\_https\_turris\_rule.name='Allow-WAN-SMTP'
uci set firewall.wan\_https\_turris\_rule.src='wan'
uci set firewall.wan\_https\_turris\_rule.proto='tcp'
uci set firewall.wan\_https\_turris\_rule.dest\_port='25'
uci set firewall.wan\_https\_turris\_rule.target='ACCEPT'
uci add firewall rule
uci set firewall.wan\_https\_turris\_rule=rule
uci set firewall.wan\_https\_turris\_rule.name='Allow-WAN-SMTP-Submission'
uci set firewall.wan\_https\_turris\_rule.src='wan'
uci set firewall.wan\_https\_turris\_rule.proto='tcp'
uci set firewall.wan\_https\_turris\_rule.dest\_port='587'
uci set firewall.wan\_https\_turris\_rule.target='ACCEPT'
uci add firewall rule
uci set firewall.wan\_https\_turris\_rule=rule
uci set firewall.wan\_https\_turris\_rule.name='Allow-WAN-POP'
uci set firewall.wan\_https\_turris\_rule.src='wan'
uci set firewall.wan\_https\_turris\_rule.proto='tcp'
uci set firewall.wan\_https\_turris\_rule.dest\_port='110'
uci set firewall.wan\_https\_turris\_rule.target='ACCEPT'
uci commit firewall
service firewall restart
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/05/21 20:09
* by stokito
[](https://openwrt.org/docs/guide-user/services/email/emailrelay#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Samba Advanced Settings
Samba Advanced Settings
=======================
For installation instructions see [Samba How To](https://openwrt.org/docs/guide-user/services/nas/cifs.server "docs:guide-user:services:nas:cifs.server")
UCI configuration options
-------------------------
The UCI configuration file is located at /etc/config/samba. Be extremely careful editing this file by hand - the samba shell interface (`service samba restart`) will ignore invalid options, but LuCI Services/Network Shares will bring up an error like this:
/usr/lib/lua/luci/dispatcher.lua:449: Failed to execute cbi dispatcher target for entry '/admin/services/samba'.
 It is hence **strongly recommended** that you use LuCI to establish the initial configuration and then edit the template file (/etc/samba/smb.conf.template) via LuCI Edit Template tab or from the shell as needed.
If luci-app-samba not working or can't find in web gui - > type “rm /tmp/luci-indexcache” or restart router.
### Common Options
The config section type `samba` determines values and options relevant to the overall operation of samba. The following table lists all available options, their default value and respectively a short characterization. See [smb.conf man page](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#idp58030944 "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#idp58030944")
for further details.
These are the default settings for the common options:
config 'samba'
option 'name' 'OpenWrt'
option 'workgroup' 'OpenWrt'
option 'description' 'Samba on OpenWrt'
option 'charset' 'UTF-8'
option 'homes' '0'
option 'interface' 'loopback lan'
| Name | Type | Required | Default | Option | Description |
| --- | --- | --- | --- | --- | --- |
| `name` | string | no | hostname or OpenWrt | | Name of the Server |
| `workgroup` | string | no | hostname or OpenWrt | | Name of the Workgroup |
| `description` | string | no | Samba on hostname or OpenWrt | | Description of the Server |
| `charset` | string | no | UTF-8 | | Display charset & unix charset |
| `homes` | boolean | no | 0 | 0, 1 | Share the user directory |
| `interface` | string | no | loopback lan | | Interfaces samba should listen on. Syntax: “ ...”. Note, that it is _not_ of type list. |
### Sambashare
The daemons are up and running and recheable via NetBIOS. Now you only need to configure the directories you intend to make accesible to users in your LAN. This example assumes you attached a USB harddisk to the USB-Port and _correctly_ mounted a partition. You can now choose to share the partition as a whole, or just individual directories on it. Fo each entry you need to create an individual config 'sambashare' section.
config 'sambashare'
option 'name' 'Shares'
option 'path' '/mnt/sda3'
\# option 'users' 'sandra'
option 'guest\_ok' 'yes'
option 'create\_mask' '0700'
option 'dir\_mask' '0700'
option 'read\_only' 'yes'
| Name | Type | Required | Default | Option | Description |
| --- | --- | --- | --- | --- | --- |
| `name` | string | yes | _(none)_ | | Name of the entry. Will be shown in the filebrowser. |
| `path` | file path | yes | _(none)_ | | The complete path of the directory. [path](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#PATH "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#PATH") |
| `users` | string | no | guest account or from global template | | the samba-users allowed access to this entry; use `smbpasswd` to create a user-pwd combination! Several users can be specified, separated by a coma (ex : option 'users' 'root,nobody' ). Translated to [valid users](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#VALIDUSERS "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#VALIDUSERS") . |
| `read_only` | string | no | yes or from global template | no, yes | no allows for read/write, else only read access is granted; (for rw, you also need to mount fs rw!). [read only](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#READONLY "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#READONLY") . |
| `guest_ok` | string | no | no or from global template | no, yes | Specifies if you need to login via samba-username and password to access this share. [guest ok](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#GUESTOK "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#GUESTOK") . |
| `create_mask` | integer | no | 0744 or from global template | | chmod mask for files created (need write access). [create mask](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#CREATEMASK "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#CREATEMASK") |
| `dir_mask` | integer | no | 0755 or from global template | | chmod mask for directories created (need write access). [directory mask](http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#DIRECTORYMASK "http://www.samba.org/samba/docs/man/manpages-3/smb.conf.5.html#DIRECTORYMASK") . |
Additional Configuration Options
--------------------------------
### Common Options
In addition to the UCI file (`/etc/config/samba`), modifications can be made to the `/etc/samba/smb.conf.template` file.
### Sambashare
Modifications can be made to the `/etc/samba/smb.conf.template` file, based on `/var/etc/smb.conf` file, created by the `samba` service.
The full section from `/var/etc/smb.conf` should be added to `/etc/samba/smb.conf.template` and removed from UCI.
For example:
uci show samba | grep name
samba.@sambashare\[0\].name=over9000
sed \-e '/\\\[over9000\\\]/,/^$/ !d' /var/etc/smb.conf \>> /etc/samba/smb.conf.template
uci delete samba.@sambashare\[0\]
uci commit samba
service samba restart
In a second approach the `samba` service could also be edited for spit whatever to `/var/etc/smb.conf` associated with UCI.
For example, hack once:
sed \-i \-e '/dir\_mask/p;s/dir\_mask\\|directory mask/browsable/g' /etc/init.d/samba
Then, anytime:
uci show samba | grep name
samba.@sambashare\[0\].name=over9000
uci set samba.@sambashare\[0\].browsable=no
uci commit samba
service samba restart
cat /var/etc/smb.conf
Configuration examples
----------------------
Samba can be configured at either share level access or user level access. At share level access all users on the network can access the share, and all files are shared with all users. At user level access a username and password are needed to access the share. By default Samba is configured for user level access.
These configurations have proven to work for some:
### Share level access
At share level access all users on the network can access the share, and all files are shared with all users. To set share level access change `security = user` to `security = share` in `/etc/samba/smb.conf.template`:
\[global\]
netbios name \= |NAME|
workgroup \= |WORKGROUP|
server string \= |DESCRIPTION|
syslog \= 10
encrypt passwords \= true
passdb backend \= smbpasswd
obey pam restrictions \= yes
socket options \= TCP\_NODELAY
unix charset \= ISO-8859-1
local master \= yes
preferred master \= yes
os level \= 20
security \= share
guest account \= nobody
invalid users \= root
smb passwd file \= /etc/samba/smbpasswd
Then add a share to `/etc/config/samba`. Make sure that `guest ok` is set to `yes`
config 'samba'
option 'name' 'openwrt'
option 'workgroup' 'WORKGROUP'
option 'description' 'openwrt'
option 'homes' '1'
config 'sambashare'
option 'read\_only' 'no'
option 'create\_mask' '0700'
option 'dir\_mask' '0700'
option 'name' 'name-of-share'
option 'path' '/path/of/share'
option 'guest\_ok' 'yes'
This share should now be accessible by `\\ip-adress-openwrt\name-of-share` (windows, username and password can be anything).
### User level access
At user level access a username and password are needed to access the share.
Steps:
#### 1\. Add user to system
To access a samba share with user level access there must be a user added to the system. Edit `/etc/passwd` and add a line for the new user “foo”. Choose a user id (the first number in the line) of 1000 or higher that does not exist yet.
root:!:0:0:root:/root:/bin/ash
nobody:\*:65534:65534:nobody:/var:/bin/false
daemon:\*:65534:65534:daemon:/var:/bin/false
foo:x:1001:1001:smb user:/dev/null:/bin/false
Edit `/etc/group` and add a line for the new user “foo”.
root:x:0:
nogroup:x:65534:
daemon:x:1:
foo:x:1001:foo
**Note:** keep in mind that the user(s) and group(s) utilized by Samba need to have the proper permissions for their shares, i.e. they need write access in order to write via smb.
#### 2\. Add samba password to user
`smbpasswd -a foo`
#### 3\. Change samba config to accept users with null passwords
Edit `/etc/samba/smb.conf.template` and add `null passwords = yes`:
\[global\]
netbios name \= |NAME|
workgroup \= |WORKGROUP|
server string \= |DESCRIPTION|
syslog \= 10
encrypt passwords \= true
passdb backend \= smbpasswd
obey pam restrictions \= yes
socket options \= TCP\_NODELAY
unix charset \= ISO-8859-1
local master \= yes
preferred master \= yes
os level \= 20
security \= user
null passwords \= yes
guest account \= nobody
invalid users \= root
smb passwd file \= /etc/samba/smbpasswd
#### 4\. Add a share
Then add a share to `/etc/config/samba`. Make shure that `guest ok` is set to `no`
config 'samba'
option 'name' 'openwrt'
option 'workgroup' 'WORKGROUP'
option 'description' 'openwrt'
option 'homes' '1'
config 'sambashare'
option 'read\_only' 'no'
option 'create\_mask' '0700'
option 'dir\_mask' '0700'
option 'name' 'name-of-share'
option 'path' '/path/of/share'
option 'guest\_ok' 'no'
This share should now be accessible by `\\ip-adress-openwrt\name-of-share` (windows, correct username and password are needed).
Notes
-----
If you use a trunk version and experience connection aborts take a look at this file `/etc/samba/samba.conf.template` and search for `reset on zero vc = yes`, remove this line or set it to `no`.
More information about this issue here: [https://dev.openwrt.org/ticket/9992](https://dev.openwrt.org/ticket/9992 "https://dev.openwrt.org/ticket/9992")
If your CPU is your samba bottleneck, disabling sendfile might help. See [http://www.linksysinfo.org/index.php?threads/speeding-up-the-samba-by-30.52240/](http://www.linksysinfo.org/index.php?threads/speeding-up-the-samba-by-30.52240/ "http://www.linksysinfo.org/index.php?threads/speeding-up-the-samba-by-30.52240/")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/05/25 15:17
* by trigger2k20
[](https://openwrt.org/docs/guide-user/services/nas/samba#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] APC BackUps ES-500 - Linksys EA3500 - LuCI graphs
APC BackUps ES-500 - Linksys EA3500 - LuCI graphs
=================================================
This describes how to connect an APC BackUps ES-500 via the USB port on a Linksys EA3500 router. This includes collecting the data, and displaying graphs. This page is closely related to [APC SmartUps SU-700 - Linksys EA3500 - LuCI graphs](https://openwrt.org/docs/guide-user/services/ups/apcupsd_su700 "docs:guide-user:services:ups:apcupsd_su700")
, which is worth reviewing as well, especially if you run into difficulties.
Note that the collected data will be lost after a reboot of the router. To save the data, you need to put it on an external device, like a USB flash drive. Connecting both the UPS and a flash drive to a USB hub, which is then connected to the router, works fine for me.
* Plug in UPS, and connect the cable from the UPS to the router USB port. This is a custom cable that comes with the UPS.
* in the router command line or LuCI web pages, install packages: apcupsd, collectd-mod-apcups and kmod-usb-hid
* for command line, the commands are:
opkg update
opkg install kmod-usb-hid
opkg install apcupsd
opkg install collectd-mod-apcups
* On the router command line, verify that the USB HID driver is installed and working with command and response:
\# ls -la /dev/usb
crw------- 1 root root 180, 96 Jul 13 14:34 hiddev0
* If you don't see a line for hiddev#, then something is wrong with the install of kmod-usb-hid.
* Resolve this, before proceeding.
* The next step is to customize the apcupsd config file.
* Details of the options can be found at [http://www.apcupsd.org/manual/manual.html](http://www.apcupsd.org/manual/manual.html "http://www.apcupsd.org/manual/manual.html")
, in the section “Configuration Directive Reference”.
* On the router command line, go to the /etc/apcupsd directory, and edit it
\# cd /etc/apcupsd
# vi
* use the dd command to delete all the lines in the file
* use the i command to set the VI editor into “insert” mode.
* Copy and paste this text into the editor:
\## apcupsd.conf v1.1 ##
UPSNAME myups
UPSCABLE usb
UPSTYPE usb
DEVICE /dev/usb/hid/hiddev\[0-15\]
LOCKFILE /var/lock
ONBATTERYDELAY 6
BATTERYLEVEL 5
MINUTES 3
TIMEOUT 0
ANNOY 300
ANNOYDELAY 60
NOLOGON disable
KILLDELAY 0
NETSERVER on
NISIP 0.0.0.0
NISPORT 3551
EVENTSFILE /var/log/apcupsd.events
# max kilobytes
EVENTSFILEMAX 10
UPSCLASS standalone
UPSMODE disable
# ===== Configuration statements to control apcupsd system logging ========
# Time interval in seconds between writing the STATUS file; 0 disables
STATTIME 0
# Location of STATUS file (written to only if STATTIME is non-zero)
STATFILE /var/log/apcupsd.status
LOGSTATS off
# Time interval in seconds between writing the DATA records to
# the log file. 0 disables.
DATATIME 0
* type :wq into the editor, to write the new apcupsd.conf, and quit the edit session
* restart the apcupsd deamon process:
# /etc/init.d apcupsd restart
* Enter the apcaccess command into the command line, and you should get output like this:
\# apcaccess
root@g70outside:~# apcaccess
APC : 001,034,0829
DATE : 2017-07-15 12:29:26 -0700
HOSTNAME : myrouter
VERSION : 3.14.14 (31 May 2016) unknown
UPSNAME : myups
CABLE : USB Cable
DRIVER : USB UPS Driver
UPSMODE : Stand Alone
STARTTIME: 2017-07-13 14:34:46 -0700
MODEL : Back-UPS ES 500
STATUS : ONLINE
...
* Note the STATUS : ONLINE
* If you don't have “ONLINE”, then something is wrong
* Restart the LuCI statistics data collection:
\# /etc/init.d/luci\_statistics restart
* In the router web interface, go to Statistics, Graphs, APC UPS
* You should see the graphs, with data starting on the right side.
* If not, wait a minute, refresh your browser and you should start to see data being written.
Troubleshooting
---------------
If you don't have APC UPS graphs at this point, here are some things to check:
* There should be a tab for APC UPS on the General Plugins page at:
http://192.168.1.1:88/cgi-bin/luci/admin/statistics/collectd/general
* /var/etc/collectd.conf should have a section for apcups:
LoadPlugin apcups
Host localhost
Port "3551"
If it does not, you can regenerate /var/etc/collectd.conf with this command:
/usr/bin/stat-genconfig > /var/etc/collectd.conf
* If you still don't have APC UPS graphs, you may not have the patches that added luci-statistics support for the apcups plugin: [https://github.com/openwrt/luci/pull/1227](https://github.com/openwrt/luci/pull/1227 "https://github.com/openwrt/luci/pull/1227")
. The best fix for this is to upgrade to a version that does.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/09/20 20:19
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/ups/apcupsd_es500#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] VPN (Virtual Private Network)
VPN (Virtual Private Network)
=============================
See also: [Cryptographic hardware acceleration](https://openwrt.org/docs/techref/hardware/cryptographic.hardware.accelerators "docs:techref:hardware:cryptographic.hardware.accelerators")
, [Random generator](https://openwrt.org/docs/guide-user/services/rng "docs:guide-user:services:rng")
[VPN](https://en.wikipedia.org/wiki/Virtual%20private%20network "https://en.wikipedia.org/wiki/Virtual private network")
extends a private network across a public network providing connectivity and security. VPN typically relies on the [client-server](https://en.wikipedia.org/wiki/Client%E2%80%93server%20model "https://en.wikipedia.org/wiki/Client–server model")
model and works as L2TP or L3TP depending on the protocol and service configuration. There are multiple software packages to implement different VPN protocols, which are generally incompatible with each other.
VPN server
----------
The VPN server running on your router can provide a secure connection to your home network while you're away. If you need to access the router itself or any of your home network devices from afar, the VPN server is a great solution.
VPN client
----------
You may want to run a VPN client on your router to encrypt your connection to the internet and prevent your ISP from snooping on your traffic and DNS requests, which in some countries is now legal for ISPs to monetize, as well as meddling with DNS requests or HTTP traffic. In order to use a VPN client on your router, you would need to obtain credentials to a corresponding VPN server. Your connection to the VPN server is encrypted, preventing your ISP from snooping/meddling on your traffic. A wide variety of commercial VPN providers exist. Once you install and run a VPN client on your router, it's best to route all your traffic via a VPN tunnel.
All articles
------------
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
==========================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[VPN (Virtual Private Network)](https://openwrt.org/docs/guide-user/services/vpn/start "docs:guide-user:services:vpn:start")
* [Cloudflare tunnel](https://openwrt.org/docs/guide-user/services/vpn/cloudfare_tunnel "docs:guide-user:services:vpn:cloudfare_tunnel")
* [Netbird](https://openwrt.org/docs/guide-user/services/vpn/netbird "docs:guide-user:services:vpn:netbird")
* [Pseudowire](https://openwrt.org/docs/guide-user/services/vpn/pseudowire "docs:guide-user:services:vpn:pseudowire")
* [Zerotier](https://openwrt.org/docs/guide-user/services/vpn/zerotier "docs:guide-user:services:vpn:zerotier")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[Libreswan / IPsec](https://openwrt.org/docs/guide-user/services/vpn/libreswan/start "docs:guide-user:services:vpn:libreswan:start")
* [IPsec site-to-site](https://openwrt.org/docs/guide-user/services/vpn/libreswan/site2site "docs:guide-user:services:vpn:libreswan:site2site")
* [Libreswan L2TP/IPsec](https://openwrt.org/docs/guide-user/services/vpn/libreswan/openswanxl2tpvpn "docs:guide-user:services:vpn:libreswan:openswanxl2tpvpn")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[OpenConnect](https://openwrt.org/docs/guide-user/services/vpn/openconnect/start "docs:guide-user:services:vpn:openconnect:start")
* [OpenConnect client](https://openwrt.org/docs/guide-user/services/vpn/openconnect/client "docs:guide-user:services:vpn:openconnect:client")
* [OpenConnect extras](https://openwrt.org/docs/guide-user/services/vpn/openconnect/extras "docs:guide-user:services:vpn:openconnect:extras")
* [OpenConnect server](https://openwrt.org/docs/guide-user/services/vpn/openconnect/server "docs:guide-user:services:vpn:openconnect:server")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[OpenVPN](https://openwrt.org/docs/guide-user/services/vpn/openvpn/start "docs:guide-user:services:vpn:openvpn:start")
* [OpenVPN client](https://openwrt.org/docs/guide-user/services/vpn/openvpn/client "docs:guide-user:services:vpn:openvpn:client")
* [OpenVPN client using LuCI](https://openwrt.org/docs/guide-user/services/vpn/openvpn/client-luci "docs:guide-user:services:vpn:openvpn:client-luci")
* [OpenVPN extras](https://openwrt.org/docs/guide-user/services/vpn/openvpn/extras "docs:guide-user:services:vpn:openvpn:extras")
* [OpenVPN PC script automated](https://openwrt.org/docs/guide-user/services/vpn/openvpn/automated_pc "docs:guide-user:services:vpn:openvpn:automated_pc")
* [OpenVPN performance](https://openwrt.org/docs/guide-user/services/vpn/openvpn/performance "docs:guide-user:services:vpn:openvpn:performance")
* [OpenVPN server](https://openwrt.org/docs/guide-user/services/vpn/openvpn/server "docs:guide-user:services:vpn:openvpn:server")
* [OpenVPN server with dynamic IPv6 GUA prefix](https://openwrt.org/docs/guide-user/services/vpn/openvpn/server_ip6prefix "docs:guide-user:services:vpn:openvpn:server_ip6prefix")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[PPPoSSH](https://openwrt.org/docs/guide-user/services/vpn/pppossh/start "docs:guide-user:services:vpn:pppossh:start")
* [PPPoSSH client](https://openwrt.org/docs/guide-user/services/vpn/pppossh/client "docs:guide-user:services:vpn:pppossh:client")
* [PPPoSSH extras](https://openwrt.org/docs/guide-user/services/vpn/pppossh/extras "docs:guide-user:services:vpn:pppossh:extras")
* [PPPoSSH server](https://openwrt.org/docs/guide-user/services/vpn/pppossh/server "docs:guide-user:services:vpn:pppossh:server")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[PPTP](https://openwrt.org/docs/guide-user/services/vpn/pptp/start "docs:guide-user:services:vpn:pptp:start")
* [PPTP client](https://openwrt.org/docs/guide-user/services/vpn/pptp/client "docs:guide-user:services:vpn:pptp:client")
* [PPTP extras](https://openwrt.org/docs/guide-user/services/vpn/pptp/extras "docs:guide-user:services:vpn:pptp:extras")
* [PPTP server](https://openwrt.org/docs/guide-user/services/vpn/pptp/server "docs:guide-user:services:vpn:pptp:server")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[SoftEther VPN](https://openwrt.org/docs/guide-user/services/vpn/softethervpn/start "docs:guide-user:services:vpn:softethervpn:start")
* [SoftEther VPN Client](https://openwrt.org/docs/guide-user/services/vpn/softethervpn/client "docs:guide-user:services:vpn:softethervpn:client")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[strongSwan / IPsec](https://openwrt.org/docs/guide-user/services/vpn/strongswan/start "docs:guide-user:services:vpn:strongswan:start")
* [IPsec basics](https://openwrt.org/docs/guide-user/services/vpn/strongswan/basics "docs:guide-user:services:vpn:strongswan:basics")
* [IPsec Firewall](https://openwrt.org/docs/guide-user/services/vpn/strongswan/firewall "docs:guide-user:services:vpn:strongswan:firewall")
* [IPsec Legacy IKEv1 Configuration](https://openwrt.org/docs/guide-user/services/vpn/strongswan/howto "docs:guide-user:services:vpn:strongswan:howto")
* [IPsec Modern IKEv2 Road-Warrior Configuration](https://openwrt.org/docs/guide-user/services/vpn/strongswan/roadwarrior "docs:guide-user:services:vpn:strongswan:roadwarrior")
* [IPsec Performance](https://openwrt.org/docs/guide-user/services/vpn/strongswan/performance "docs:guide-user:services:vpn:strongswan:performance")
* [IPsec Site-to-Site](https://openwrt.org/docs/guide-user/services/vpn/strongswan/site2site "docs:guide-user:services:vpn:strongswan:site2site")
* [IPsec With Overlapping Subnets](https://openwrt.org/docs/guide-user/services/vpn/strongswan/overlappingsubnets "docs:guide-user:services:vpn:strongswan:overlappingsubnets")
* [strongSwan IPsec Configuration via UCI](https://openwrt.org/docs/guide-user/services/vpn/strongswan/configuration "docs:guide-user:services:vpn:strongswan:configuration")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[Tinc](https://openwrt.org/docs/guide-user/services/vpn/tinc/start "docs:guide-user:services:vpn:tinc:start")
* [Tinc client](https://openwrt.org/docs/guide-user/services/vpn/tinc/client "docs:guide-user:services:vpn:tinc:client")
* [Tinc extras](https://openwrt.org/docs/guide-user/services/vpn/tinc/extras "docs:guide-user:services:vpn:tinc:extras")
* [Tinc server](https://openwrt.org/docs/guide-user/services/vpn/tinc/server "docs:guide-user:services:vpn:tinc:server")
[](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
##### [](https://openwrt.org/docs/guide-user/services/vpn/start#top-2135322984 "Continue with the « docs » section at the top...")
[WireGuard](https://openwrt.org/docs/guide-user/services/vpn/wireguard/start "docs:guide-user:services:vpn:wireguard:start")
* [WireGuard basics](https://openwrt.org/docs/guide-user/services/vpn/wireguard/basics "docs:guide-user:services:vpn:wireguard:basics")
* [WireGuard client](https://openwrt.org/docs/guide-user/services/vpn/wireguard/client "docs:guide-user:services:vpn:wireguard:client")
* [WireGuard extras](https://openwrt.org/docs/guide-user/services/vpn/wireguard/extras "docs:guide-user:services:vpn:wireguard:extras")
* [WireGuard multi-client server automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/automated "docs:guide-user:services:vpn:wireguard:automated")
* [WireGuard peers](https://openwrt.org/docs/guide-user/services/vpn/wireguard/serverclient "docs:guide-user:services:vpn:wireguard:serverclient")
* [WireGuard performance](https://openwrt.org/docs/guide-user/services/vpn/wireguard/performance "docs:guide-user:services:vpn:wireguard:performance")
* [WireGuard road-warrior automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/road-warrior "docs:guide-user:services:vpn:wireguard:road-warrior")
* [WireGuard routing all traffic](https://openwrt.org/docs/guide-user/services/vpn/wireguard/all-traffic-through-wireguard "docs:guide-user:services:vpn:wireguard:all-traffic-through-wireguard")
* [WireGuard server](https://openwrt.org/docs/guide-user/services/vpn/wireguard/server "docs:guide-user:services:vpn:wireguard:server")
* [WireGuard site-to-site automated](https://openwrt.org/docs/guide-user/services/vpn/wireguard/site-to-site "docs:guide-user:services:vpn:wireguard:site-to-site")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/16 20:48
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/vpn/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Network Traffic Monitor with vnStat
Network Traffic Monitor with vnStat
===================================
[vnStat](http://humdi.net/vnstat/ "http://humdi.net/vnstat/")
is a console-based network traffic monitor for Linux that keeps a log of network traffic for the selected interface(s). It uses the network interface statistics provided by the kernel. This means that vnStat won't actually be sniffing any traffic and also ensures light use of system resources.
Installing
----------
### Base
To use vnStat for the command-line simply [install](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
:
vnstat2
### LuCI web UI (optional)
To include LuCI support install the following, all dependancies will install automatically:
luci-app-vnstat2
If you want language translation with LuCI then install the following:
luci-i18n-vnstat-(YOUR\_COUNTRY\_CODE)
If you dont know which language codes are available you can search package manager or grep it with the following command:
grep luci-i18n-\*
Configuring
-----------
The only configuring it really needs is to tell it what interface(s) to monitor, and some method of updating the database such as a cronjob. You might want to backup your database file. The vnstati package comes with a 'restore' and init.d script that downloads the backup from a webserver upon reboot. Its up to you to chose how to backup/restore the data( via HTTP/FTP/SSH/ETC)
### Setup
| | |
| --- | --- |
|  | **This step is required for vnStat to function.** |
The common choice for monitoring is your WAN interface.
First, you have to find out which is your WAN Interface:
. /lib/functions/network.sh; if network\_get\_device if\_wan wan; then
echo "Your WAN Interface is: $if\_wan"; else echo "Cant find a active WAN Connection, please activate it"; fi
 The interface must be active for the above command to work. See ticket [19116](https://dev.openwrt.org/ticket/19116 "https://dev.openwrt.org/ticket/19116")
.
If you have an already activated WAN connection, you will get the following output, for example:
Your WAN Interface is: pppoe-wan. Now edit _/etc/vnstat.conf_ with your favourite editor and change the following two Lines:
Interface "pppoe-wan"
MaxBandwidth 1000
“Interface” is your WAN Interface you found out above and “MaxBandwidth” is the max possible bandwidth (in mbit) speed.
 MaxBandwidth must have the correct value, otherwise you will get wrong statistics from vnstat.
 MaxBandwidth means: How fast is your WAN Interface at most. _MaxBandwidth 1000 = 1000 Mbit_ and _MaxBandwidth 100 = 100 Mbit_ ! It has nothing to do with your Internet speed !
Then edit or create _/etc/config/vnstat_ and change (or add) the following lines:
config vnstat
list interface 'pppoe-wan'
**Please Note:** “pppoe-wan” is your WAN Interface you found out above !
Now you have to create the Database with this command:
vnstat \-u \-i pppoe-wan
**Hint:** vnStat normally uses “IEC prefixes” (MiB, GiB and so on). If you want old binary prefixes (MB, GB) change the following in _/etc/vnstat.conf_ : `UnitMode 1`.
### Database Updating
| | |
| --- | --- |
|  | **This step is required for vnStat to function.** The package doesn't setup database updating at all. Its up to you to configure when vnStat will update. Use the daemon or a cron job. |
#### Using included daemon:
Edit _/etc/vnstat.conf_ and search for “UpdateInterval”. Change “UpdateInterval” to the following: `UpdateInterval 300`.
UpdateInterval tells the daemon to update the Database every 300 seconds (5 minutes). If you want another Interval you can change it for your needs.
Run these commands to enable the daemon. This will also auto start the daemon if you reboot your device:
/etc/init.d/vnstat enable
/etc/init.d/vnstat start
| | |
| --- | --- |
|  | **`/etc/config/vnstat`** is the database restore config, _not the vnstatd config._ vnstatd config is also located at **`/etc/vnstat.conf`** |
This same init.d script will automatically download a database backup if you configured `/etc/config/vnstat` corrrectly. Useful for recovering db after a router reboot. Down side is that there is no implemented upload method using the uci config. You will need to write a script that cron will run to do all the uploading, so why not use the same protocol for downloading too? I suggest rsync, ftp, or scp.
#### Using a cronjob
Update the crontab:
cat << "EOF" \>> /etc/crontabs/root
\*/5 \* \* \* \* vnstat \-u
EOF
/etc/init.d/cron restart
| | |
| --- | --- |
|  | **I don't recommend using crontab to update the vnStat Database.** Because if you update the Database with cron you will get weird statistics like: 16777216.00 TiB in one day.
See: [https://bugzilla.redhat.com/show\_bug.cgi?id=711383](https://bugzilla.redhat.com/show_bug.cgi?id=711383 "https://bugzilla.redhat.com/show_bug.cgi?id=711383") |
### Image Generation
You can install webif and it will generate images. But thats not lightweight so RealOpty developed scripts based off webif code that will generate the images without webif.
You might want to setup a crontab to execute this script every 15 min.
I always output the images to the tmpfs so it dont always write to flash.
#!/bin/sh
\# vnstati image generation script.
\# Source: http://code.google.com/p/x-wrt/source/browse/trunk/package/webif/files/www/cgi-bin/webif/graphs-vnstat.sh
WWW\_D\=/tmp/www/vnstat \# output images to here
LIB\_D\=/var/lib/vnstat \# db location
BIN\=/usr/bin/vnstati \# which vnstati
outputs\="s h d t m" \# what images to generate
\# Sanity checks
\[ \-d "$WWW\_D" \] || mkdir \-p "$WWW\_D" \# make the folder if it dont exist.
\# You might want to setup a link if it dont exist.
\# \[ -L /www/vnstat \] || ln -sf /www/vnstat /tmp/www/
\# End of config changes
interfaces\="$(ls -1 $LIB\_D)"
##vnstat2 uses a different method:
#interfaces="$(vnstat --dbiflist | sed 's/.\*: //' | tr ' ' '\\n')"
if \[ \-z "$interfaces" \]; then
echo "No database found, nothing to do."
echo "A new database can be created with the following command: "
echo " vnstat -u -i eth0"
exit 0
else
for interface in $interfaces; do
for output in $outputs; do
$BIN -${output} \-i $interface \-o $WWW\_D/vnstat\_${interface}\_${output}.png
done
done
fi
exit 1
### Sample HTML
<[META](http://december.com/html/4/element/meta.html)
HTTP-EQUIV\="refresh" CONTENT\="300"\>
<[html](http://december.com/html/4/element/html.html)
\>
<[head](http://december.com/html/4/element/head.html)
\>
<[title](http://december.com/html/4/element/title.html)
\>Traffic of Interface eth1[title](http://december.com/html/4/element/title.html)
\>
[head](http://december.com/html/4/element/head.html)
\>
<[body](http://december.com/html/4/element/body.html)
\>
<[h2](http://december.com/html/4/element/h2.html)
\>Traffic of Interface eth1[h2](http://december.com/html/4/element/h2.html)
\>
<[table](http://december.com/html/4/element/table.html)
\>
<[tbody](http://december.com/html/4/element/tbody.html)
\>
<[tr](http://december.com/html/4/element/tr.html)
\>
<[td](http://december.com/html/4/element/td.html)
\>
<[img](http://december.com/html/4/element/img.html)
src\="vnstat\_eth1\_s.png" alt\="eth1 Summary" /\>
[td](http://december.com/html/4/element/td.html)
\>
<[td](http://december.com/html/4/element/td.html)
\>
<[img](http://december.com/html/4/element/img.html)
src\="vnstat\_eth1\_h.png" alt\="eth1 Hourly" /\>
[td](http://december.com/html/4/element/td.html)
\>
[tr](http://december.com/html/4/element/tr.html)
\>
<[tr](http://december.com/html/4/element/tr.html)
\>
<[td](http://december.com/html/4/element/td.html)
valign\="top"\>
<[img](http://december.com/html/4/element/img.html)
src\="vnstat\_eth1\_d.png" alt\="eth1 Daily" /\>
[td](http://december.com/html/4/element/td.html)
\>
<[td](http://december.com/html/4/element/td.html)
valign\="top"\>
<[img](http://december.com/html/4/element/img.html)
src\="vnstat\_eth1\_t.png" alt\="eth1 Top 10" /\>
<[br](http://december.com/html/4/element/br.html)
/\>
<[img](http://december.com/html/4/element/img.html)
src\="vnstat\_eth1\_m.png" alt\="eth1 Monthly" /\>
[td](http://december.com/html/4/element/td.html)
\>
[tr](http://december.com/html/4/element/tr.html)
\>
[tbody](http://december.com/html/4/element/tbody.html)
\>
[table](http://december.com/html/4/element/table.html)
\>
[body](http://december.com/html/4/element/body.html)
\>
[html](http://december.com/html/4/element/html.html)
\>
### Persistent stats
vnStat stores stats to /var/lib/vnstat by default and information will not persist across restarts. This means that one might want to relocate the database directory to other forms of persistent storage like your device's flash or external thumb drives.
By default, vnStat is configured to write to the directory in volatile memory every 30 minutes. Both the directory and the interval can be adjusted in vnStat's configuration. However, keep in mind that frequent writes to flash memory will deteriorate and potentially damage flash memory. Changing the directory to write to flash memory without changing the interval will result in around 17500 write operations each year, a number that could potentially cause problems.
Additionally, the database may not persist across firmware flashes.
#### Method 1
To store the database on the thumb drive, ensure that [usb-drives](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
is working. Then, edit DatabaseDir in /etc/vnstat.conf to point to your flash drive, you may also want to modify SaveInterval to a larger value (the default 30min is still a good value) to minimise writes to flash.
#### Method 2
This method automatically backs up the vnStat database to flash memory as **/etc/vnstat\_backup.tar.gz** on router shutdown and restores it on startup. Note that this cannot work when the router unexpectedly loses power (unplugging, turning off a hardware power switch, power outage). You can use a cronjob to backup in regular intervals while the router is running.
##### Script
cat << "EOF" \> /etc/init.d/vnstat\_backup
#!/bin/sh /etc/rc.common
EXTRA\_COMMANDS\="backup restore"
EXTRA\_HELP\=<> /etc/crontabs/root
0 \*/6 \* \* \* /etc/init.d/vnstat\_backup backup
EOF
/etc/init.d/cron restart
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/03/08 18:47
* by delacor
[](https://openwrt.org/docs/guide-user/services/network_monitoring/vnstat#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Darkstat
Darkstat
========
[https://unix4lyfe.org/darkstat/](https://unix4lyfe.org/darkstat/ "https://unix4lyfe.org/darkstat/")
Darkstat is a packet sniffer that runs as a background process on a cable/DSL router, gathers all sorts of statistics about network usage, and serves them over HTTP. One advantage of darkstat is that it can monitor IPv6 traffic in addition to IPv4 traffic.
It is a very stable application that runs smoothly and requires no maintenance.
~NOTE: on 2020-06-07 it was reported that darkstat prevent ssh of working due to a change of ownership of the file /tmp/empty that should be own by root for ssh to work. To correct this, stop darkstat and edit the file /etc.init.d/darkstat to comment the following line: chown $USER:$GROUP $RUN\_D The line should look like this: # chown $USER:$GROUP $RUN\_D and start darkstat again. Alternatively, instead of the solution above, edit the following line in the file /etc/init.d/darkstat: RUN\_D=/var/empty to be like that: RUN\_D=/var/empty/darkstat~
Installation
------------
Installation is very simple:
opkg install darkstat
/etc/init.d/darkstat enable
/etc/init.d/darkstat start
You can also install it through luci.
Then is you open a web browser at the address of the router on port 667, you will see the traffic graphs.
Configuration
-------------
In OpenWrt, **darkstat** can use almost all of the regular darkstat parameters. These are set in the file _/etc/config/darkstat_
config darkstat
option interface 'lan'
option syslog false
option verbose false
option no\_promisc false
option no\_dns false
option no\_macs false
option no\_lastseen false
option httpaddr '0.0.0.0'
# option httpport '667'
# option network\_filter 'not (src net 192.168.1 and dst net 192.168.1)'
# option network\_netmask '192.168.1.0/255.255.255.0'
option local\_only false
# option hosts\_max '1000'
# option hosts\_keep '500'
# option ports\_max '60'
# option ports\_keep '30'
# option highest\_port '65534'
# option export\_file 'darkstat\_export.log'
# option import\_file 'darkstat\_export.log'
# option daylog\_file 'darkstat\_daylog.log'
**Note** In OpenWrt/LEDE 17.01 and below, the last 3 parameters are not available. The config file above is the one currently 18.06 and above (you may need to update the package in 18.06 to have them). Also, in OpenWrt/LEDE 17.01 and below, the init script in /etc/init.d is not a procd script as in 18.06 and above.
**Note**: the init script and the config file found in trunk are compatible with the darkstat found in OpenWrt/LEDE 17.01 and below and provides the last 3 parameters.
| Option | Explanation | Default |
| --- | --- | --- |
| interface | Capture traffic on the specified network interface. This is the only mandatory argument. | 'lan' |
| syslog | Errors, warnings, and verbose messages will go to syslog (facility daemon, priority debug) instead of stderr. | false |
| verbose | Produce more verbose debugging messages. | false |
| no\_promisc | Do not use promiscuous mode to capture. | false |
| no\_dns | Do not resolve IPs to host names. This can significantly reduce memory footprint on small systems as an extra process is created for DNS resolution. | false |
| no\_macs | Do not display MAC addresses in the hosts table. | false |
| httpaddr | Bind the web interface to the specified address. The default is to listen on all interfaces. | '0.0.0.0' |
| httpport | Bind the web interface to the specified port. The default is 667. | Commented out |
| network\_filter | Use the specified filter expression when capturing traffic. The filter syntax is beyond the scope of this wiki page; please refer to the tcpdump documentation. | Commented out |
| network\_netmask | Define a “local network” according to the network and netmask addresses. All traffic entering or leaving this network will be graphed, as opposed to the default behaviour of only graphing traffic to and from the local host. | Commented out |
| local\_only | Make the web interface only display hosts on the “local network.” This is intended to be used together with the _network\_netmask_ argument. | false |
| hosts\_max | The maximum number of hosts that will be kept in the hosts table. This is used to limit how much accounting data will be kept in memory. The number of _hosts-max_ must be greater than _hosts-keep_. | Commented out |
| hosts\_keep | When the hosts table hits _hosts-max_ and traffic is seen from a new host, we clean out the hosts table, keeping only the top _hosts-keep_ number of hosts, sorted by total traffic. | Commented out |
| ports\_max | The maximum number of ports that will be tracked for each host. This is used to limit how much accounting data will be kept in memory. The number of _ports-max_ must be greater than _ports-keep_. | Commented out |
| ports\_keep | When a ports table fills up, this many ports are kept and the rest are discarded. | Commented out |
| highest\_port | Ports that are numerically higher than this will not appear in the per-host ports tables, although their traffic will still be accounted for. This can be used to hide ephemeral ports. By default, all ports are tracked. | Commented out |
| export\_file | On shutdown, or upon receiving SIGUSR1 or SIGUSR2, export the in-memory database to the named file in the /tmp/empty directory. | Commented out |
| import\_file | Upon starting, import a darkstat database from the named file in the /tmp/empty directory. | Commented out |
| daylog\_file | Log daily traffic statistics into the named file in the /tmp/empty directory. The daylog format is: localtime time\_t bytes\_in bytes\_out pkts\_in pkts\_outs. Lines starting with a # are comments stating when logging started and stopped. | Commented out |
Other Bandwidth Monitoring Applications
---------------------------------------
Darkstat shows the traffic in real time the traffic for different hosts within your network, but it does not show the traffic profile of the various host over time.
Another application, [Bandwidthd](https://openwrt.org/docs/guide-user/services/network_monitoring/bandwidthd "docs:guide-user:services:network_monitoring:bandwidthd")
allows to see the traffic profile of the various host over time. It also indicate the level of traffic for various type, such as TCP, UDP, ICMP, HTTP, SMTP, FTP. But it cannot show the IPv6 traffic (maybe one day!!).
The various application for monitoring bandwidth in OpenWrt can be found in the documentation page about [Network Monitoring](https://openwrt.org/docs/guide-user/services/network_monitoring/start "docs:guide-user:services:network_monitoring:start")
.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/04/13 12:10
* by ruralroots
[](https://openwrt.org/docs/guide-user/services/network_monitoring/darkstat#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Ostiary Client (run a fixed set of commands remotely)
Ostiary Client (run a fixed set of commands remotely)
=====================================================
The Ostiary client, “ostclient” is designed to talk to an [ostiaryd](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.server "docs:guide-user:services:remote_control:ostiary.server")
service that allows you to run a fixed set of commands remotely, without giving everyone else access to the same commands.
The following are the key design goals:
* “First, do no harm.” It should not be possible to use the Ostiary system itself to damage the host it's running on. In particular, it's willing to accept false negatives (denying access to legitimate users) in order to prevent false positives (allowing access to invalid users).
* Insofar as possible, eliminate any possibility of bugs causing undesired operations. Buffer overflows, timing attacks, etc. should be impossible for an external attacker to execute. There's no point in installing security software if it makes you less secure.
* Be extremely modest in memory and CPU requirements. (eg. running on a Mac SE/30, a 16MHz 68030 machine) and connecting from a Palm Pilot (a 16MHz 68000 machine).
* Keep things simple. This is not an ssh replacement. Each successful challenge/response will result in executing a corresponding script.
* It is immune to replay attacks
This wiki is a quick summary of the author's documentation followed by openwrt specific usage instructions. For any technical info you may wish to view the author's site: [http://ingles.homeunix.net/software/ost/index.html](http://ingles.homeunix.net/software/ost/index.html "http://ingles.homeunix.net/software/ost/index.html")
.
How to get it
-------------
The client installs as part of the server package [ostiaryd](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.server "docs:guide-user:services:remote_control:ostiary.server")
; both client and server will be located in /usr/bin
Client Syntax
-------------
osctlient v4.0 usage:
ostclient -a address \[-p port\] \[-f fd\]
-a address to contact - two formats:
address
address:port
-p port (only needed if unspecified in -a)
-f read passphrase from indicated file descriptor
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/06/20 05:00
* by cgretski
[](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.client#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] saned Scanner Server
saned Scanner Server
====================
This page attempts to document how to get a simple USB scanner working and accessible via network by using [The SANE project](http://www.sane-project.org/ "http://www.sane-project.org/")
.
Requirements
------------
1. [usb-installing](https://openwrt.org/docs/guide-user/storage/usb-installing "docs:guide-user:storage:usb-installing")
(or support for the parallel port, if you have a parallel port scanners)
2. install the right backend supporting your scanner
3. xinetd installed or alternatively manually starting up saned
### USB port
Note: I'm having a printer-scanner, which is why the “scanner” is recognized as a printer. I'm not actually sure, if this is needed for scanning functionality!
opkg update
opkg install kmod-usb-printer
Now plug in scanner, run `dmesg` and look for lines similar to the following ones:
hub.c: new USB ice 01:02.0-1, assigned address 2
printer.c: usblp0: USB Bidirectional printer 2 if 0 alt 0 proto 2 vid 0x04A9 pid 0x1094
usb.c: USB disconnect on ice 01:02.0-1 address 2
hub.c: new USB ice 01:02.0-1, assigned address 3
printer.c: usblp1: USB Bidirectional printer 3 if 0 alt 0 proto 2 vid 0x04A9 pid 0x1094
### Parallel port
In case you have a parallel port scanner, you will need this:
opkg update
opkg install kmod-lp
Check the output of the `dmesg`. If there is a device node `/dev/printers/0` then the installation succeeded.
**`TIP:`** p910nd is reported as working with some noname USB-to-Parport adapter/converter as well; maybe the same is true for some scanners?
### Install xinetd
Xinet makes possible to run saned only when the port is accessed via network. Because we're lazy, let's go trough this route. Install xinetd (if not already installed):
opkg install xinetd
Installation
------------
### Command line
At minimum, we need saned and a working backend. [The SANE project has a partial list of supported scanners](http://www.sane-project.org/sane-backends.html#SCANNERS "http://www.sane-project.org/sane-backends.html#SCANNERS")
. If you are not sure, what backend you need, xerox\_mfp is a good starting point.
Installing sane-all will presumably pull in all backends, but usually this is not needed and takes up unnecessary space. Sane-frontends is not strictly needed, but recommended for testing/troubleshooting as it includes scanimage. Scanimage will also tell you, what frontend it uses when/if it finds your scanner, so if unsure, one could install -all and remove the unneeded backends afterwards.
[opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
Basis-system
opkg update
opkg install sane-daemon
Scanner
opkg install sane-xerox\_mfp
#if you have a xerox scanner
opkg install sane-plustek
#example for Canon lide 20 (canon use sometimes plustek hardware)
all availble scanner can be install with
opkg install sane-backends-all
[package: sane-backends-all](https://openwrt.org/packages/pkgdata/sane-backends-all "packages:pkgdata:sane-backends-all")
there are also list of all avaible single scanner package
Optional
opkg install sane-frontend
(Optional): testing the scanner
-------------------------------
Run this on the router to see if the scanner is found and working :
scanimage -L
If you get this:
No scanners were identified. If you were expecting something different,
check that the scanner is plugged in, turned on and detected by the
sane-find-scanner tool (if appropriate). Please read the documentation
which came with this software (README, FAQ, manpages).
You most probably do not have the right backend installed. Please try again after installing the right backend. You should get something similar to this:
device \`xerox\_mfp:libusb:002:003' is a SAMSUNG ORION multi-function peripheral
Presumably you could try to brute-force, install all backends and then remove them as scanimage will tell you which backend it is using if/when it finds your scanner.
Configuration
-------------
### Use xinetd to start saned
sane-daemon should have come with a configuration file, enable it in /etc/xinetd.d/sane-port :
\# default: off
# description: The saned provides scanner service via the network. \\
# Applications like kooka, xsane or xscanimage can use the remote \\
# scanner.
service sane-port
{
socket\_type = stream
port = 6566
wait = no
user = saned
group = scanner
server = /usr/sbin/saned
disable = no
}
(i.e. change disable = yes to no)
### Start saned without xinetd
saned is already a deamon by default
you can start saned with rc.local
saned -a
The -a flag requests that saned run in standalone daemon mode. In this mode, saned will detach from the console and run in the background, listening for incoming client connections; inetd is not required for saned operations in this mode. If the optional username is given after -a , saned will drop root privileges and run as this user (and group).
[saned manpage](https://manpages.ubuntu.com/manpages/xenial/man8/saned.8.html "https://manpages.ubuntu.com/manpages/xenial/man8/saned.8.html")
### Enable saned to be accessible from the LAN
Put your subnet in `/etc/sane.d/saned.conf` :
192.168.1.1/24
**TODO:** IPv6 LAN addressing for those who need it?
### Firewall rules
**TODO:** Placeholder. Add examples here to open port 6566 if closed.
### Zeroconf
AirSane exposes a sane scanner over AirScan/eSCL, which is available by default on Windows and macOS. See [https://github.com/cmangla/AirSane-openwrt](https://github.com/cmangla/AirSane-openwrt "https://github.com/cmangla/AirSane-openwrt")
.
Access from your computer (client) on the network
-------------------------------------------------
You probably want to access the scanner from some client software.
### Linux
If you are using Linux, enable saned on all your computers you want to access the scanner from, and add your router IP in `/etc/sane.d/net.conf` on **the client machine** (if you have name resolving working on your LAN, presumably you can also use your router name here).
After adding the IP address, running `scanimage -L` on the client should produce something like this:
device 'net:192.168.1.1:xerox\_mfp:libusb:002:003' is a SAMSUNG ORION multi-function peripheral
Your scanner is now ready to use!
### OS X, Windows and other OSes
The SANE project has [a list of frontends (applications)](http://www.sane-project.org/sane-frontends.html "http://www.sane-project.org/sane-frontends.html")
, which includes a few choices for Windows and a choice for OS X. How to use these might be out of scope on this Wiki, but feel free to add links here to tips and right documentation. One thing worth mentioning is that at least on Linux, LibreOffice can use sane backend.
**TODO:** find out if LibreOffice requires a local running saned, or is it usable without one, and us such usable OOTB for a saned running somewhere on the network?
Troubleshooting
---------------
* Run `scanimage -L` on the router, if it does not find your scanner, you need to solve this first
* If scanimage does not find your scanner, install `sane-all` and try again?
* Run `scanimage -L` on your client (Linux), it should find the scanner. If it doesn't, but your router does, the saned on the client is not configured correctly
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/02 13:50
* by cm
[](https://openwrt.org/docs/guide-user/services/scanner_server/saned#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Autossh
Autossh
=======
Autossh monitors a ssh connection and reconnects the ssh-session if the connection fails.
To automatically log in you need to use an authentication key.
The package, slightly outdated, can be found in the 'oldpackages' feed.
Alternative packages:
* [https://github.com/hewenhao2008/autossh-openwrt](https://github.com/hewenhao2008/autossh-openwrt "https://github.com/hewenhao2008/autossh-openwrt")
* [https://github.com/aa65535/openwrt-autossh](https://github.com/aa65535/openwrt-autossh "https://github.com/aa65535/openwrt-autossh")
[sshtunnel](https://openwrt.org/docs/guide-user/services/ssh/sshtunnel "docs:guide-user:services:ssh:sshtunnel")
is a simpler, functionally-identical package.
Use Case
--------
* You want to forward a local port (e.g. the webserver/ssh) to a remote server.
* If your client running OpenWrt is behind a NAT, this allows to connect to a server that is not behind a NAT and create a reverse tunnel to the local ssh server.
Installation
------------
1. Install autossh
opkg install autossh
2. Create a key
dropbearkey -t rsa -f /etc/dropbear/id\_rsa
* On _**LEDE** 17.01.x_ use
dropbearkey -t rsa -f /root/.ssh/id\_dropbear
3. `dropbearkey` will print the public key, starting with `ssh-rsa`.
* You can reprint the key using
dropbearkey -y -f /etc/dropbear/id\_rsa
* or you can write it to a file (e.g. `/tmp/pubkey`)
dropbearkey -y -f /etc/dropbear/id\_rsa | grep ssh-rsa > /tmp/pubkey
4. Add the key to the `authorized_keys` file on your server, e.g. copy pubkey file to the server and do
cat pubkey >> ~/.ssh/authorized\_keys
Configuration
-------------
Autossh is configured using the [Unified Configuration Interface](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
(`/etc/config/autossh`).
A typical configuration is as follows:
config autossh
option ssh '-i /root/.ssh/dropbear -N -T -R 2222:192.168.1.1:22 remote\_host\_user\_name@remote\_host'
option gatetime '0'
option monitorport '20000'
option poll '100'
option enabled '1'
You need to replace `/root/.ssh/dropbear` with your key generated by dropbear.
Run as Service
--------------
Autossh is often used as reverse proxy. It's probably because your ISP does not give you a public address or your router firewall policies. To make autossh run even when router restarts, your need to set up a service.
In `/etc/init.d/autossh`, most content of the files has been generated when you first install autossh. But you need add a line `procd_set_param env HOME=“/root”` in `start_instance()` or the the service will **NOT** work when the router reboots. This is a known bug not fixed yet. [https://github.com/openwrt/packages/issues/5559](https://github.com/openwrt/packages/issues/5559 "https://github.com/openwrt/packages/issues/5559")
start\_instance() {
local section="$1"
config\_get ssh "$section" 'ssh'
config\_get gatetime "$section" 'gatetime'
config\_get monitorport "$section" 'monitorport'
config\_get poll "$section" 'poll'
config\_get\_bool enabled "$section" 'enabled' '1'
\[ "$enabled" = 1 \] || exit 0
procd\_open\_instance
procd\_set\_param command /usr/sbin/autossh -M ${monitorport:-20000} ${ssh}
procd\_set\_param respawn ${respawn\_threshold:-3600} ${respawn\_timeout:-5} ${respawn\_retry:-5}
procd\_set\_param env AUTOSSH\_GATETIME="${gatetime:-30}"
procd\_set\_param env AUTOSSH\_POLL="${poll:-600}"
procd\_set\_param env HOME="/root"
procd\_close\_instance
For the first time you connect, you need to make sure that the server is in the trusted-host list, otherwise autossh will restart in a loop.
user.info autossh\[17709\]: starting ssh (count 10)
user.info autossh\[17709\]: ssh child pid is 17742
user.info autossh\[17709\]: ssh exited with error status 1; restarting ssh
Just run an `ssh -p port user@host` and accept. Now you can enable the service by `/etc/init.d/autossh enable` and enjoy it.
Fixes
-----
To get ssh working you need to replace `localhost` in `2222:localhost:22` of the `ssh` variable to the local ip.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/11/30 22:27
* by stokito
[](https://openwrt.org/docs/guide-user/services/ssh/autossh#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Get a free HTTPS certificate from LetsEncrypt for OpenWrt with ACME.sh
Get a free HTTPS certificate from LetsEncrypt for OpenWrt with ACME.sh
----------------------------------------------------------------------
For HTTPS you need a [TLS certificate](https://openwrt.org/docs/guide-user/services/tls/certs "docs:guide-user:services:tls:certs")
. By default the OpenWrt generates one (self-signed). You can open the Luci by the HTTPS URL. But your browser will complain that the certificate is self made and we can't know if the cert was't forged by an attacker in the middle.
You can generate (“issue”) a TLS certificate on a device and ask a Certificate Authority (CA) to sign it so that browsers will accept it without a warning. The [LetsEncrypt](https://letsencrypt.org/ "https://LetsEncrypt.org")
and [ZeroSSL](https://zerossl.com/ "https://ZeroSSL.com")
are two CAs that allows to do that for free and automatically by using ACME verification protocol. You'll need an ACME client i.e. the `acme.sh` installed and configured that will do the work to issue certificate and renew it after 3 months. The acme.sh uses the ZeroSSL by default [starting from v3.0 Aug 2021](https://github.com/acmesh-official/acme.sh/wiki/Change-default-CA-to-ZeroSSL "https://github.com/acmesh-official/acme.sh/wiki/Change-default-CA-to-ZeroSSL")
but the OpenWrt package didn't followed the change and still uses the LetsEncrypt by default.
### Before starting
You must understand [ACME Challenge Validation Types](https://letsencrypt.org/docs/challenge-types/ "https://letsencrypt.org/docs/challenge-types/")
. In short the CA (i.e. LetsEncrypt, ZeroSSL) needs to ensure that you own the domain for which you trying to issue a certificate. So the CA generates a “challenge” random token that should ether
* Added as a `TXT` record to a domain via the DNS provider API. This validation called `DNS-01` challenge.
* Putted into a special folder on a web server accessible from outside by URL like `[http://YOUR_DOMAIN/.well-known/acme-challenge/TOKEN](http://your_domain/.well-known/acme-challenge/TOKEN "http://YOUR_DOMAIN/.well-known/acme-challenge/TOKEN") `. This validation called `HTTP-01` challenge.
Then the CA will check that the token is accessible and thus confirms that you do have a control over the server.
If you are using a [DDNS dynamic DNS](https://openwrt.org/packages/pkgdata/ddns-scripts "packages:pkgdata:ddns-scripts")
then you for sure better to use the `DNS-01` because you already have credentials on a device to update the DNS records.
If you making your router public or you are going to use a `HTTP-01` challenge validation via `Webroot` or `Standalone` validation method, then you need to [allow access from the internet](https://openwrt.org/docs/guide-user/luci/luci.secure#allow_access_from_internet "docs:guide-user:luci:luci.secure")
. The ACME protocol needs for the HTTP port 80 for a challenge validation but for a `Webroot` you better to enable a Redirect to HTTPS so the 443 port needs to be open too.
If you are want to have a valid cert for a domain without opening an access to a wild internet then the only option for you is a DNS challenge validation. But not all DNS providers have an API to do this, or you have to specify a password from a full admin panel which is not acceptable from security perspective.
### ACME clients
There are few ACME clients available on OpenWrt: `acme.sh`, `uacme`, `certbot`. Currently the acme.sh is best supported and the `acme` package will install it.
Since version 4.0.0 (Aug 2022) the `acme` package was reorganized and now we have a few packages:
* `acme-common` that provide the UCI config in the `/etc/config/acme`
* `acme-acmesh` that contains the acme.sh script
* `acme-acmesh-dnsapi` that contains additional `acme.sh` scripts to use DNS validation.
There was a [PR](https://github.com/openwrt/packages/pull/10792 "https://github.com/openwrt/packages/pull/10792")
to add `acme-uacme` package but it was lack of interest and staled. In future we may have more acme clients integrated.
The `acme` package now is empty and it become a transitional virtual package that installs the `acme-common` and `acme-acmesh`.
The `acme` v4 also had a breaking change. Auto deployment of cert to Luci was removed. Now you must configure certs manually, you may try the `luci-app-uhttpd` to set a path to a cert. Old options like `update_uhttpd` and `update_nginx` are gone.
### Using GUI
The Luci admin panel has apps that can be installed to extend GUI with additional configuration pages. The `luci-app-acme` provides a GUI to configure issuing of certificates.
Open LUCI dashboard then in main menu go to [System -> Software](http://192.168.1.1/cgi-bin/luci/admin/system/opkg "http://192.168.1.1/cgi-bin/luci/admin/system/opkg")
. Then click on “Update lists...” to load list of available packages. Type into the “Filter” search fields the package name `luci-app-acme` and press Enter. Click on install button. As a dependency it will install `acme` that itself will install `acme-common` and `acme-acmesh` packages. If you are going to use DNS validation please also install the `acme-acmesh-dnsapi`.
To configure in LUCI in the main menu open [Services -> ACME certs](http://192.168.1.1/cgi-bin/luci/admin/services/acme "http://192.168.1.1/cgi-bin/luci/admin/services/acme")
.
Basic configuration:
* “Account email”: put your email to receive expiry notices when your certificate is coming up for renewal.
* You'll see a two pre-configured but disabled EXAMPLE domains. But we'll make a new one for ourselves.
* At bottom find a field for a new domain config, type your domain but with underscores e.g. `example_com` and click on “Add”.
* A new config section will be added. Now let's edit it.
* Click on the “Enabled” checkbox.
* “Domain names”: add your domain `example.com`. If you need a wildcard cert then also add `*.example.com` (needs for DNS challenge).
* Switch to “Challenge Validation” tab and select “Validation method”:
* If your web server is public then select “Webroot”. The default webroot path is `/var/run/acme/challenge/`. See details below.
* If you wish to get a wildcard cert e.g. `*.example.com` or you don't have a public webserver then the only option is the “DNS” validation and you must configure DNS API.
* If you don't have any webserver or the it's not accessible from internet then you can may use the “Standalone” mode.
* Click on “Save and Apply”.
In a minute the cert should be generated. You can check logs in [Status -> System Log](http://192.168.1.1/cgi-bin/luci/admin/status/syslog "http://192.168.1.1/cgi-bin/luci/admin/status/syslog")
.
If any error occurred fix it and restart the acme service to trigger issuing. Go to [System -> Startup](http://192.168.1.1/cgi-bin/luci/admin/system/startup "http://192.168.1.1/cgi-bin/luci/admin/system/startup")
, find the acme service and click of “Restart”.
### By using command line
For experienced users this may be more preferable than GUI.
Step 1: Install packages Use a command line and type `opkg install acme`. If you want to use DNS\-based certificate verification, also install the DNS provider hooks: `opkg install acme-acmesh-dnsapi`
Step 2: Configure the acme.sh Edit `/etc/config/acme` to configure your personal email, domain name and validation method. For the Webroot challenge validation use `option validation_method 'webroot`'.
If you have `acme-common` version older that 1.4 (May 2024) then you may have to create a symlink before:
mkdir /www/.well-known/
ln \-s /var/run/acme/challenge/ /www/.well-known/acme-challenge
See next section with details.
For the DNS challenge validation use `option validation_method 'dns`'.
For example if you use the DuckDNS.org DDNS provider and wish to have a wildcard certificate `*.example.duckdns.org` then install the `acme-acmesh-dnsapi` package and configure the acme like:
config acme
option account\_email 'youremail@example.com'
config cert 'example\_duckdns\_wildcard'
option enabled '1'
option validation\_method 'dns'
option dns 'dns\_duckdns'
list credentials 'DuckDNS\_Token="YOUR\_TOKEN"'
list domains 'example.duckdns.org'
list domains '\*.example.duckdns.org'
See [Acme.sh DNS API: DuckDNS.org](https://github.com/acmesh-official/acme.sh/wiki/dnsapi#dns_duckdns "https://github.com/acmesh-official/acme.sh/wiki/dnsapi#dns_duckdns")
for details.
Step 3: Issue your certificate by restarting the acme service with `/etc/init.d/acme restart`. This may take for some time. You can read logs with `logread -e acme`. In case of problems please try to enable the `debug 1` option that will print more details.
### Webroot
When the `webroot` validation is used the acme client stores challenge files to a folder (called “webroot”) that is accessible from internet and the Certificate Authority (e.g. LetsEncrypt, ZeroSSL) checks it the files the site by a URL `[http://example.com/.well-known/acme-challenge/](http://example.com/.well-known/acme-challenge/ "http://example.com/.well-known/acme-challenge/") `. This allows for CA to ensure that you have an access to the domain settings.
The acme.sh has a an option `-w` to specify a path to the webroot folder and the UCI config at `/etc/config/acme` allowed to specify it too. The problem is that if you have to always change to a place where your website files are located e.g. `/www/.well-known/acme-challenge/`. Creating files on a disk may eventually ruin the NAND flash but also the folder may be actually read only.
Since version 4.0.0 (Aug 2022) the `acme` switched to always use the same `/var/run/acme/challenge/` folder for webroot. The folder is in memory and it's path is always the same so the `webroot` config option is not needed anymore and was deprecated.
Instead you can create a symlink:
mkdir /www/.well-known/
ln \-s /var/run/acme/challenge/ /www/.well-known/acme-challenge
Now test if it's accessible from internet:
mkdir \-p /var/run/acme/challenge/
echo Hi \> /var/run/acme/challenge/README.txt
\# open in browser or execute the wget
wget \-qO - http://example.com/.well-known/acme-challenge/README.txt
Since `acme-common` v1.4 (May 2024) the default symlink is automatically created on installation. But you may have other http document roots so please create the symlink yourself.
I hope that eventually OpenWrt web servers will serve the folder `/var/run/acme/challenge/` under `/.well-known/acme-challenge/` URL path by default. So no any additional symlinks will be needed.
### Using of the generated certificates
After that you can find the certificates in a folder at `/etc/ssl/acme/` e.g.:
* `/etc/ssl/acme/*.example.com.key` the TLS private key. **Never share it!**
* `/etc/ssl/acme/*.example.com.fullchain.crt` the TLS certificate and chain of CA that signed it.
Detailed certificate configs are stored in `/etc/acme/`.
You can use them in [uhttpd](https://openwrt.org/docs/guide-user/services/webserver/uhttpd#https_enable_and_certificate_settings_and_creation "docs:guide-user:services:webserver:uhttpd")
, [lighttpd](https://openwrt.org/docs/guide-user/services/webserver/lighttpd "docs:guide-user:services:webserver:lighttpd")
, [nginx](https://openwrt.org/docs/guide-user/services/webserver/nginx "docs:guide-user:services:webserver:nginx")
, [EmailRelay](https://openwrt.org/docs/guide-user/services/email/emailrelay "docs:guide-user:services:email:emailrelay")
and any other server that you want to configure with TLS.
### Standalone Mode Validation
The standalone mode is intended to be used if you don't have a webserver (e.g. mail only) or it's not publicly accessible from internet. It will start a `socat` that will imitate a temporary web-server to return a the file with a random value of ACME challenge to the CA (e.g. LetsEncrypt) so that they can ensure that you really own the server and the domain. That server needs to be publicly accessible, so you may have to forward the external public WAN port 80 to it. However, that server listens on port 80 by default, which might clash with `uhttpd` which by default listens 80 port on all interfaces and IPs. You can [change the listening port](https://forum.archive.openwrt.org/viewtopic.php?id=65090&p=1 "https://forum.archive.openwrt.org/viewtopic.php?id=65090&p=1")
to something like 8080, by editing the value of `Le_HTTPPort` in `/usr/lib/acme/acme.sh`, or by passing it the `--httpport` argument. Then you must forward WAN port 80 (external port remains the same) to device port 8080. See [Accessing LuCI web interface securely](https://openwrt.org/docs/guide-user/luci/luci.secure "docs:guide-user:luci:luci.secure")
for more details about port changing.
### Hooks
When a certificate issued or renewed the OpenWrt acme calls hotplug hooks in the `/etc/hotplug.d/acme/` with an $`ACTION` correspondingly `issued` or `renewed`. Then it also sends a [UBUS](https://openwrt.org/docs/techref/ubus "docs:techref:ubus")
event `acme.issue` and `acme.renew`.
The uhttpd, nginx, haproxy are listening for the UBUS event `acme.renew` and performing a service reload on a cert renewal. So no any additional deployment hooks are needed. Just specify a correct path to a cert.
But the reloading is triggered only on a renewal. So you need to issue a cert, then configure a path to it in uhttpd/nginx/haproxy config and then restart a service.
But other web webservers like Apache and Lighttpd don't have such a reload trigger.
You may try to add a hotplug script yourself:
Create a file `/etc/hotplug.d/acme/00-apache` with the content:
[/etc/hotplug.d/acme/00-apache](https://openwrt.org/_export/code/docs/guide-user/services/tls/acmesh?codeblock=4 "Download Snippet")
if \[ "$ACTION" = "renewed" \]; then
/etc/init.d/apache reload
fi
**NOTE**: Calling the `/etc/init.d/apache reload` directly in the acme hotplug script can inadvertently start a stopped instance.
### UCI config options
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `account_email` | string | yes | | Email address to associate with account key. If a certificate wasn't renewed in time then you'll receive a notice at 20 days before expiry. |
| `debug` | boolean | no | _0_ | Set _1_ to enable debug logging |
| `state_dir` | string | no | `/etc/ssl/acme` | Deprecated, now is unchangeable. The ACME.sh state folder where account data is stored. The generated certificates will be symlinked to `/etc/ssl/acme/` |
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `enabled` | boolean | no | _1_ | Enabled issuing of certs for the domains |
| `staging` | boolean | no | _0_ | Get certificate from the LetsEncrypt staging server (use for testing; the certificate won't be valid). |
| `domains` | list | yes | | Domain names to include in the certificate. The first name will be the subject name, subsequent names will be alt names. |
| `validation_method` | string | yes | | Challenge validation mode: _dns_, _webroot_ or _standalone_. Standalone mode will use the built-in webserver of acme.sh to issue a certificate. Webroot mode will use an existing webserver to issue a certificate. DNS mode will allow you to use the DNS API of your DNS provider to issue a certificate. |
| `dns` | string | yes for _dns_ mode | | DNS API name. See [acme.sh wiki: DNS API](https://github.com/acmesh-official/acme.sh/wiki/dnsapi "https://github.com/acmesh-official/acme.sh/wiki/dnsapi") for the list of available APIs. In DNS mode, the domain name does not have to resolve to the router IP. DNS mode is also the only mode that supports wildcard certificates. Using this mode requires the acme-dnsapi package to be installed. |
| `dns_wait` | integer | no | | Seconds to wait for a DNS record to be updated and then continue. See [acme.sh wiki: dnssleep](https://github.com/acmesh-official/acme.sh/wiki/dnssleep "https://github.com/acmesh-official/acme.sh/wiki/dnssleep") |
| `credentials` | list | yes for _dns_ mode | | The credentials for the DNS API mode selected above. See [acme.sh wiki: DNS API](https://github.com/acmesh-official/acme.sh/wiki/dnsapi "https://github.com/acmesh-official/acme.sh/wiki/dnsapi") for the credentials required by each API. Add multiple entries here in `KEY=VAL` shell variable format to supply multiple credential variables. |
| `calias` | string | no | | Challenge Alias. The challenge alias to use for ALL domains. See [acme.sh wiki: DNS Alias Mode](https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mode "https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mode") for the details of this process. LUCI only supports one challenge alias per certificate. |
| `dalias` | string | no | | Domain Alias. The domain alias to use for ALL domains. See [acme.sh wiki: DNS Alias Mode](https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mode "https://github.com/acmesh-official/acme.sh/wiki/DNS-alias-mode") for the details of this process. LUCI only supports one challenge domain per certificate. |
| `webroot` | string | no | `/var/run/acme/challenge` | **Deprecated.** Use the default folder and remove the option. Webserver root directory. Set this to the webserver document root to run Acme in `webroot` mode. The web server must be accessible from the internet on port 80. |
| `key_type` | string | no | _ec256_ | Key size (and type) for the generated certificate. `rsa2048`, `rsa3072`, `rsa4096`, `ec256`, `ec384` |
| `keylength` | string | no | | **Deprecated**. Use the `key_type` instead. The RSA key length in bits. |
| `acme_server` | string | no | _letsencrypt_ | A custom CA ACME server directory URL. See [acme.sh wiki: servers](https://github.com/acmesh-official/acme.sh/wiki/Server "https://github.com/acmesh-official/acme.sh/wiki/Server") . |
| `standalone` | boolean | no | _0_ | **Deprecated.** Use `option validation_method 'standalone`' instead. |
| `days` | integer | no | _60_ | Days until renewal |
| `update_uhttp` | boolean | no | _0_ | **Removed in acme v4.0.0**. After issuing a cert configure the uhttpd UCI main section (i.e. Luci) to use the new cert. I.e. set UCI `uhttpd.main.key` and `uhttpd.main.cert`. Then reload the uhttpd service. Update the uhttpd config with this certificate once issued (only select this for one certificate). It's also available the `luci-app-uhttpd` to configure uhttpd form the LuCI interface. |
| `update_nginx` | boolean | no | _0_ | **Removed in acme v4.0.0**. After issuing a cert configure the Nginx to use the new cert. I.e. call the `nginx-util add_ssl`. Then reload the nginx service. Update the nginx config with this certificate once issued (only select this for one certificate). Nginx must support ssl, if not it won't start as it needs to be compiled with ssl support to use cert options |
| `update_haproxy` | boolean | no | _0_ | **Removed in acme v4.0.0**. After issuing a cert configure the HAProxy to use the new cert. I.e. change the `bind` option in the `haproxy.cfg`. Then reload the haproxy service. |
| `user_setup` | path | no | _none_ | **Removed in acme v4.0.0**. User-provided setup script |
| `user_cleanup` | path | no | _none_ | **Removed in acme v4.0.0**. User-provided cleanup script |
### acme.sh command
The `acme-acmesh` package installs the full acme.sh script to `/usr/lib/acme/client/acme.sh` so you can call it directly without UCI config e.g.:
mkdir /www/.well-known/
ln \-s /var/run/acme/challenge/ /www/.well-known/acme-challenge
/usr/lib/acme/client/acme.sh \--issue \-d example.com \-w /var/run/acme/challenge/
See more samples in the [acme.sh wiki: How to issue a cert](https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert "https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert")
Before the `acme` v4 the path was `/usr/lib/acme/acme.sh`.
### See also
* [ACME.sh on OpenWrt Support forum topic](https://forum.openwrt.org/t/letsencrypt-acme-sh-and-luci-app-acme-support-topic/196821 "https://forum.openwrt.org/t/letsencrypt-acme-sh-and-luci-app-acme-support-topic/196821")
- feel free to ask questions here
* [LetsEncrypt forum](https://community.letsencrypt.org/ "https://community.letsencrypt.org/")
use for the LetsEncrypt related questions.
* [Acme.sh Wiki: How to run on OpenWrt](https://github.com/acmesh-official/acme.sh/wiki/How-to-run-on-OpenWrt "https://github.com/acmesh-official/acme.sh/wiki/How-to-run-on-OpenWrt")
also describes how to configure uhttpd and firewall.
* [Acme.sh DNS API: Part 1](https://github.com/acmesh-official/acme.sh/wiki/dnsapi "https://github.com/acmesh-official/acme.sh/wiki/dnsapi")
* [Acme.sh DNS API: Part 2](https://github.com/acmesh-official/acme.sh/wiki/dnsapi2 "https://github.com/acmesh-official/acme.sh/wiki/dnsapi2")
* [Arch Wiki: ACME.sh](https://wiki.archlinux.org/title/Acme.sh "https://wiki.archlinux.org/title/Acme.sh")
* [Acme.sh: How to issue a cert](https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert "https://github.com/acmesh-official/acme.sh/wiki/How-to-issue-a-cert")
using the acme.sh command directly
* [openwrt DDNS, acme commands](https://blog.gainskills.top/2021/09/15/openwrt-ddns-cert/ "https://blog.gainskills.top/2021/09/15/openwrt-ddns-cert/")
* [Dynu.com OpenWRT ACME.sh](https://forum.openwrt.org/t/dynu-openwrt-acme-lets-encrypt/110758 "https://forum.openwrt.org/t/dynu-openwrt-acme-lets-encrypt/110758")
* [acme: use the hotplug system](https://github.com/openwrt/packages/pull/17721 "https://github.com/openwrt/packages/pull/17721")
a PR with v4 that changed how the `acme` works in OpenWrt.
* Sources: [acme-common](https://github.com/openwrt/packages/tree/master/net/acme-common "https://github.com/openwrt/packages/tree/master/net/acme-common")
, [acme-acmesh](https://github.com/openwrt/packages/tree/master/net/acme-acmesh "https://github.com/openwrt/packages/tree/master/net/acme-acmesh")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/12/16 10:15
* by stokito
[](https://openwrt.org/docs/guide-user/services/tls/acmesh#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Share USB hard-drive with Samba using LuCI
Share USB hard-drive with Samba using LuCI
==========================================
USB ports are found on most routers, especially those with USB 3.0 ports can provide fast file sharing performance. A popular usage scenario is connecting a USB storage device like a flash or hard drive to share the content on your LAN. This recipe will guide you through how this can easily be set-up using the Luci web-interface.
Install dependencies
--------------------
You will find detailed walkthroughs on [Samba](https://openwrt.org/docs/guide-user/services/nas/cifs.server "docs:guide-user:services:nas:cifs.server")
and [Ksmbd](https://openwrt.org/docs/guide-user/services/nas/ksmbd "docs:guide-user:services:nas:ksmbd")
which includes info on USB drivers, filesystems, and settings. At a minimum, you will need to install the packages:
* block-mount
* kmod-usb3
* kmod-usb-storage-uas
* luci-app-samba4
Mount your USB drive
--------------------
Whether you have USB flash, SSD, or HDD. Simply plug it in the USB port, and it should show be automatically detected by OpenWrt (if you SSH into the router you will typically find a new entry /dev/sda for the device, and /dev/sda1 for it's first partition). Now go to the **Mount Points** tab under System in Luci. You will find your USB storage device listed already as show below. Provided you have the filesystem installed all you need is to tick **Enable** and then **Save & Apply**.  Mount Points is only visible if dependencies are already installed:
[ on your USB device is already listed in Luci.")](https://openwrt.org/_detail/media/doc/recipes/usb-storage-samba-webinterface-mountpoint.png?id=docs%3Aguide-user%3Aservices%3Anas%3Ausb-storage-samba-webinterface "media:doc:recipes:usb-storage-samba-webinterface-mountpoint.png")
In my case I used the btrfs filesystem due to its advanced features. In this case you will need to change the file system. Choose **Edit**, and you will be able to revise like this:
[](https://openwrt.org/_detail/media/doc/recipes/usb-storage-samba-webinterface-btrfsmount.png?id=docs%3Aguide-user%3Aservices%3Anas%3Ausb-storage-samba-webinterface "media:doc:recipes:usb-storage-samba-webinterface-btrfsmount.png")
Share the drive on your local network
-------------------------------------
We will only show how to do simply sharing here. Samba supports advanced access policies, but this recipe is meant for the most common use case. Please consult [Samba advanced](https://openwrt.org/docs/guide-user/services/nas/samba "docs:guide-user:services:nas:samba")
for more policy settings.
Open Luci, under **Services** choose the **Network Shares** tab. Here you will need to fill in the name of your shared folder as it will appear on you network. In our example we called it _Share_. You will also need to fill in the mount point from above, we used the default _/home_. You will also need to tick **Allow guests** (otherwise setting up user access control is necessary). Tick Read-Only if you only want to have read access for clients, we allowed write access here:
[](https://openwrt.org/_detail/media/doc/recipes/usb-storage-samba-webinterface-guest.png?id=docs%3Aguide-user%3Aservices%3Anas%3Ausb-storage-samba-webinterface "media:doc:recipes:usb-storage-samba-webinterface-guest.png")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/01/26 02:11
* by phinn
[](https://openwrt.org/docs/guide-user/services/nas/usb-storage-samba-webinterface#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Tor client
Tor client
==========
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
Introduction
------------
* This how-to describes the method for setting up [Tor](https://en.wikipedia.org/wiki/Tor_(anonymity_network) "https://en.wikipedia.org/wiki/Tor_(anonymity_network)")
client on OpenWrt.
* Tor is limited to DNS and TCP traffic, use [VPN](https://openwrt.org/docs/guide-user/services/vpn/start "docs:guide-user:services:vpn:start")
to protect all traffic.
* Follow [Tor extras](https://openwrt.org/docs/guide-user/services/tor/extras "docs:guide-user:services:tor:extras")
for automated setup and additional tuning.
Goals
-----
* Provide anonymous communication with onion routing.
* Access the dark net and Tor hidden services.
* Encrypt your internet connection to enforce security and privacy.
* Prevent traffic leaks and spoofing on the client side.
* Bypass regional restrictions using public relay providers.
* Escape client side content filters and internet censorship.
Command-line instructions
-------------------------
### 1\. Tor client
Install the required packages. Configure Tor client.
\# Install packages
opkg update
opkg install tor
\# Configure Tor client
cat << EOF \> /etc/tor/custom
AutomapHostsOnResolve 1
AutomapHostsSuffixes .
VirtualAddrNetworkIPv4 172.16.0.0/12
VirtualAddrNetworkIPv6 \[fc00::\]/8
DNSPort 0.0.0.0:9053
DNSPort \[::\]:9053
TransPort 0.0.0.0:9040
TransPort \[::\]:9040
EOF
cat << EOF \>> /etc/sysupgrade.conf
/etc/tor
EOF
uci del\_list tor.conf.tail\_include="/etc/tor/custom"
uci add\_list tor.conf.tail\_include="/etc/tor/custom"
uci commit tor
service tor restart
Disable [IPv6 GUA prefix](https://openwrt.org/docs/guide-user/network/ipv6/ipv6_extras#disabling_gua_prefix "docs:guide-user:network:ipv6:ipv6_extras")
and announce [IPv6 default route](https://openwrt.org/docs/guide-user/network/ipv6/ipv6_extras#announcing_ipv6_default_route "docs:guide-user:network:ipv6:ipv6_extras")
.
### 2\. DNS over Tor
Configure firewall to intercept DNS traffic.
\# Intercept DNS traffic
uci \-q del firewall.dns\_int
uci set firewall.dns\_int="redirect"
uci set firewall.dns\_int.name="Intercept-DNS"
uci set firewall.dns\_int.family="any"
uci set firewall.dns\_int.proto="tcp udp"
uci set firewall.dns\_int.src="lan"
uci set firewall.dns\_int.src\_dport="53"
uci set firewall.dns\_int.target="DNAT"
uci commit firewall
service firewall restart
Redirect DNS traffic to Tor and prevent DNS leaks.
\# Enable DNS over Tor
service dnsmasq stop
uci set dhcp.@dnsmasq\[0\].localuse="0"
uci set dhcp.@dnsmasq\[0\].noresolv="1"
uci set dhcp.@dnsmasq\[0\].rebind\_protection="0"
uci \-q delete dhcp.@dnsmasq\[0\].server
uci add\_list dhcp.@dnsmasq\[0\].server="127.0.0.1#9053"
uci add\_list dhcp.@dnsmasq\[0\].server="::1#9053"
uci commit dhcp
service dnsmasq start
### 3\. Firewall
Configure firewall to intercept LAN traffic. Disable LAN to WAN forwarding to prevent traffic leaks.
\# Intercept TCP traffic
cat << "EOF" \> /etc/nftables.d/tor.sh
TOR\_CHAIN\="dstnat\_$(uci -q get firewall.tcp\_int.src)"
TOR\_RULE\="$(nft -a list chain inet fw4 ${TOR\_CHAIN} \\
| sed -n -e "/Intercept-TCP/p")"
nft replace rule inet fw4 ${TOR\_CHAIN} \\
handle ${TOR\_RULE##\* } \\
fib daddr type !\= { local, broadcast } ${TOR\_RULE}
EOF
uci \-q delete firewall.tor\_nft
uci set firewall.tor\_nft="include"
uci set firewall.tor\_nft.path="/etc/nftables.d/tor.sh"
uci \-q delete firewall.tcp\_int
uci set firewall.tcp\_int="redirect"
uci set firewall.tcp\_int.name="Intercept-TCP"
uci set firewall.tcp\_int.src="lan"
uci set firewall.tcp\_int.src\_dport="0-65535"
uci set firewall.tcp\_int.dest\_port="9040"
uci set firewall.tcp\_int.proto="tcp"
uci set firewall.tcp\_int.family="any"
uci set firewall.tcp\_int.target="DNAT"
\# Disable LAN to WAN forwarding
uci \-q delete firewall.@forwarding\[0\]
uci commit firewall
service firewall restart
Testing
-------
Verify that you are using Tor.
* [check.torproject.org](https://check.torproject.org/ "https://check.torproject.org/")
Check your IP and DNS provider.
* [ipleak.net](https://ipleak.net/ "https://ipleak.net/")
* [dnsleaktest.com](https://www.dnsleaktest.com/ "https://www.dnsleaktest.com/")
Troubleshooting
---------------
Collect and analyze the following information.
\# Restart services
service log restart; service firewall restart; service tor restart
\# Log and status
logread \-e Tor; netstat \-l \-n \-p | grep \-e tor
\# Runtime configuration
pgrep \-f \-a tor
nft list ruleset
\# Persistent configuration
uci show firewall; uci show tor; grep \-v \-r \-e "^#" \-e "^$" /etc/tor
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/02/28 00:38
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/tor/client#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] uHTTPd Web Server Configuration
uHTTPd Web Server Configuration
===============================
The `/etc/config/uhttpd` configuration is provided by the [uhttpd](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd")
web server package. This file defines the behavior of the server and default values for certificates generated for SSL operation. uhttpd supports multiple instances (i.e. multiple listen ports, each with its own document root and other features) as well as cgi, php7, perl and lua.
Sections
--------
There are two sections defined, the section of type `uhttpd` contains general server settings while the `cert` one defines the default values for SSL certificates.
For information on sections and UCI configuration see [The UCI System](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
### Server Settings
A minimal `uhttpd` config section must consist of at least the document root and HTTP listen options:
config 'uhttpd' 'main'
option 'listen\_http' '80'
option 'home' '/www'
The options defined for this section are outlined below.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `listen_http` | list of port or address:port pairs | yes, if `'listen_https`' is not given | _(none)_ | Specifies the ports and addresses to listen on for plain HTTP access. If only a port number is given, the server will attempt to serve both IPv4 and IPv6 requests. Use `0.0.0.0:80` to bind at port 80 only on IPv4 interfaces or `[::]:80` to serve only IPv6. To run on multiple addresses, specifying each, you can list one address (or address:port) per line. You can use DNS or even [DynDNS](https://openwrt.org/docs/guide-user/services/ddns/client "docs:guide-user:services:ddns:client") domain instead of IP but note that this is not any kind of virtual hosting |
| `listen_https` | list of port or address:port pairs | yes, if `'listen_http`' is not given | _(none)_ | Specifies the ports and addresses to listen on for encrypted HTTPS access. The format is the same as for `listen_http`. **Read below for extra details** |
| `home` | directory path | yes | `/www` | Defines the server document root |
| `cert` | file path | yes if `listen_https` is given, else no | `/etc/uhttpd.crt` | ASN.1/DER or PEM certificate used to serve HTTPS connections. If you want to you use an intermediate certificate you concatenate it to one file (PEM only!). Some PEM formats may require the luci-ssl-openssl package. |
| `key` | file path | yes if `listen_https` is given, else no | `/etc/uhttpd.key` | ASN.1/DER or PEM private key used to serve HTTPS connections. Some PEM formats may require the luci-ssl-openssl package. |
| `cgi_prefix` | string | no | `/cgi-bin` | Defines the prefix for CGI scripts, relative to the document root. CGI support is disabled if this option is missing |
| `lua_prefix` | string | no | _(none)_ | Defines the prefix for dispatching requests to the embedded Lua interpreter, relative to the document root. Lua support is disabled if this option is missing |
| `lua_handler` | file path | yes if `lua_prefix` is given, else no | _(none)_ | Lua handler script used to initialize the Lua runtime on server start |
| `script_timeout` | integer | no | `60` | Maximum wait time for CGI or Lua requests in seconds. Requested executables are terminated if no output was generated until the timeout expired |
| `network_timeout` | integer | no | `30` | Maximum wait time for network activity. Requested executables are terminated and connection is shut down if no network activity occured for the specified number of seconds |
| `realm` | string | no | _local hostname_ | Basic authentication realm when prompting the client for credentials (HTTP 400) |
| `config` | file path | no | `/etc/httpd.conf` | Config file in Busybox httpd format for additional settings (currently only used to specify Basic Auth areas) |
| `index_file` | file name | no | `index.html`, `index.htm,` `default.html`, `default.htm` | Index file to use for directories, e.g. add index.php when using php |
| `index_page` | file name | no | `index.html` | Index file to use for directories, e.g. add index.php when using php (last, 20131015, replace index\_file ?) should be noted: list index\_page “index.html index.htm default.html default.htm index.php” |
| `error_page` | string | no | _(none)_ | Virtual URL of file or CGI script to handle 404 request. Must begin with '/' |
| `no_symlinks` | boolean | no | `0` | Do not follow symbolic links if enabled |
| `no_dirlists` | boolean | no | `0` | Do not generate directory listings if enabled |
| `rfc1918_filter` | boolean | no | `1` | Reject requests from [RFC1918](https://en.wikipedia.org/wiki/Private_network "https://en.wikipedia.org/wiki/Private_network") IP addresses directed to the servers public IPs. This is a DNS rebinding countermeasure. |
| `http_keepalive` | integer | no | `20` | connection reuse. Some bugs have been seen, you _may_ wish to disable this by setting to `0` (BB or later only) |
| `max_requests` | integer | no | `3` | Maximum number of concurrent requests. If this number is exceeded, further requests are queued until the number of running requests drops below the limit again. |
| `max_connections` | integer | no | `100` | Maximum number of concurrent connections. If this number is exceeded, further TCP connection attempts are queued until the number of active connections drops below the limit again. |
| `ubus_prefix` | string | no | _(none)_ | URL prefix for [UBUS via JSON-RPC handler](https://openwrt.org/docs/techref/ubus#access_to_ubus_over_http "docs:techref:ubus") e.g. `/ubus`. If not specified then UBUS is not enabled. |
| `ubus_socket` | file | no | _(none)_ | Override ubus socket path |
| `ubus_noauth` | boolean | no | `0` | Do not authenticate JSON-RPC requests against UBUS session api |
| `ubus_cors` | boolean | no | `0` | Enable CORS HTTP headers on JSON-RPC api |
Multiple sections if the type `uhttpd` may exist - the init script will launch one webserver instance per section.
As specified in the [The UCI System](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
documentation, each of the `uhttpd` sections must be named differently.
config 'uhttpd' 'main'
option 'listen\_http' '80'
option 'home' '/www'
config 'uhttpd' 'other'
option 'listen\_http' '8080'
option 'home' '/www/other'
### HTTPS Enable and Certificate Settings and Creation
In order to speak HTTPS/TLS, uhttpd needs one of several [cryptographic libraries](https://openwrt.org/docs/guide-user/services/tls/libs "docs:guide-user:services:tls:libs")
. Such `libuhttpd-...` packages can be installed via opkg, e.g. `libuhttpd-mbedtls`, `libuhttpd-openssl` or `libuhttpd-wolfssl`.
In the server configuration, the `listen_https` option needs to be defined as explained above.
uhttpd requires an X.509 certificate and a private key. You can create and copy them manually to the place specified in the configuration.
There is an alternative: In this case (as of 10.03.1) you'll need to install the `luci-ssl` meta-package which in turn will pull also the `px5g` script. With this utility the init script will generate the appropriate self signed certificate and key files when the server is started for the first time, either by reboot or by manual restart.
The `/etc/config/uhttpd` file contains in the end a section detailing the certificate and key files creation parameters:
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `days` | integer | no | `730` | Validity time of the generated certificates in days |
| `bits` | integer | no | `2048` | Size of the generated RSA key in bits |
| `country` | string | no | `ZZ` | ISO country code of the certificate issuer |
| `state` | string | no | `Somewhere` | State of the certificate issuer |
| `location` | string | no | `Unknown` | Location/city of the certificate issuer |
| `commonname` | string | no | `OpenWrt` | Common name covered by the certificate |
| `organization` | string | no | _“OpenWrt” followed by random string_ | Organization name covered by the certificate |
Those will be needed only once, at the next restart.
If you are hosting the website to internet you may want to [obtain LetsEncrypt certificates](https://openwrt.org/docs/guide-user/services/tls/certs "docs:guide-user:services:tls:certs")
.
Basic Authentication (httpd.conf)
---------------------------------
For backward compatibility reasons, _uhttpd_ uses the old _Busybox httpd_ config file `/etc/httpd.conf` to define authentication areas and the associated usernames and passwords. This configuration file is **not** in UCI format and usually shipped or generated by external packages like `webif` (X-Wrt).
Authentication realms are defined in the format `prefix:username:password` with one entry per line followed by a newline.
* `prefix` is the URL part covered by the realm, e.g. `/cgi-bin` to request basic auth for any CGI program
* `username` specifies the username a client has to login with
* `password` defines the secret password required to authenticate
The password can be either in plain text format, [crypt(1) MD5](https://en.wikipedia.org/wiki/Crypt_(Unix) "https://en.wikipedia.org/wiki/Crypt_(Unix)")
encoded or in the form `$p$user` where `user` refers to an account in `/etc/shadow` or `/etc/passwd`.
A plain text password can be converted to MD5 encoding by using the `-m` switch of the _uhttpd_ executable:
\# uhttpd -m secret
$1$$ysVNzQc4CTMkp5daOdZ.3/
If the `$p$...` format is used, _uhttpd_ will compare the client provided password against the one stored in the `shadow` or `passwd` database.
Example:
[/etc/httpd.conf](https://openwrt.org/_export/code/docs/guide-user/services/webserver/uhttpd?codeblock=3 "Download Snippet")
/dashboard/:admin:$1$$ysVNzQc4CTMkp5daOdZ.3/
/:root:$p$root
/:alice:P@$$w0rd
* Here the `/dashboard/` path is protected but allowed for user `admin` with the password `secret` that is hashed with crypt(1) MD5.
* The root path `/` is allowd to the user `root` and its password will be taken from `/etc/passwd`
* Also the `/` path is allowed for the user `alice` and her password is `P@$$w0rd` which is not hashed and stored in clear text.
URL decoding
------------
Like _Busybox HTTPd_, the URL decoding of strings on the command line is supported through the `-d` switch:
root@OpenWrt:/\# uhttpd -d "An%20URL%20encoded%20String%21%0a"
An URL encoded String!
Using PHP7
----------
A minimal php7 installation includes:
* php7
* php7-cgi
In `/etc/php.ini` ensure that the doc\_root is empty if you are using multiple uhttpd instances (each on its own port). This enables the uhttpd `home` variable to work for you.
Ensure that you uncomment the extension interpreter line for PHP in the main section of the uHTTPd config file:
list interpreter ".php=/usr/bin/php-cgi"
Securing uHTTPd
---------------
By default, uHTTPd is bind to `0.0.0.0` which also includes the WAN port of your router. To bind uHTTPd to the LAN port only you have to change the `listen_http` and `listen_https` options to your LAN IP address.
To get your current LAN IP address run this command:
\# uci get network.lan.ipaddr
192.168.1.1
Then edit `/etc/config/uhttpd` and bind `listen_http` to specific `192.168.1.1` IP instead of `0.0.0.0` and comment out IPv6 bindings:
config uhttpd main
\# HTTP listen addresses, multiple allowed
list listen\_http 192.168.1.1:80
\# list listen\_http \[::\]:80
\# HTTPS listen addresses, multiple allowed
list listen\_https 192.168.1.1:443
\# list listen\_https \[::\]:443
See [Accessing LuCI web interface securely](https://openwrt.org/docs/guide-user/luci/luci.secure "docs:guide-user:luci:luci.secure")
for more details.
Embedded Lua
------------
uHTTPd supports running Lua in-process, which can speed up Lua CGI scripts. Also LuCI works fine with the embedded Lua interpreter. See the next subsection for instructions on how to set it up.
Here is an example using a test file `test.lua` to show it works:
[/root/test.lua](https://openwrt.org/_export/code/docs/guide-user/services/webserver/uhttpd?codeblock=8 "Download Snippet")
function handle\_request(env)
uhttpd.send("Status: 200 OK\\r\\n")
uhttpd.send("Content-Type: text/plain\\r\\n\\r\\n")
uhttpd.send("Hello world.\\n")
end
Now to test it install the `uhttpd-mod-lua` plugin and configure it:
opkg install uhttpd-mod-lua
uci set uhttpd.main.lua\_prefix=/lua
uci set uhttpd.main.lua\_handler=/root/test.lua
/etc/init.d/uhttpd restart
wget \-qO- http://127.0.0.1/lua/
\# Hello world.
### LuCI with embedded Lua interpreter
You need to install `uhttpd-mod-lua` and `luci-sgi-uhttpd` to get it to work:
opkg install uhttpd-mod-lua luci-sgi-uhttpd
Since Chaos Calmer 15.05, the `luci-sgi-uhttpd` package is not needed. The appropriate files are included in `luci-base`.
Then uncomment the following lines in `/etc/config/uhttpd` (or add them if you don't have them):
option lua\_prefix /luci
option lua\_handler /usr/lib/lua/luci/sgi/uhttpd.lua
Then restart the server:
/etc/init.d/uhttpd restart
One thing remains to be done. By default `/www/index.html` redirects you to `/cgi-bin/luci` which is the default CGI gateway for LuCI. The config above puts LuCI through embedded interpreter under `/luci` (`lua_prefix` is what causes it) so you have to change that in `/www/index.html`. The path appears there twice (one for the `meta` tag which does the redirect and one for the anchor). You can also copy/paste the code below if you don't want to meddle with it on your own.
<[html](http://december.com/html/4/element/html.html)
\>
<[head](http://december.com/html/4/element/head.html)
\>
<[meta](http://december.com/html/4/element/meta.html)
http-equiv\="refresh" content\="0; URL=/luci" /\>
[head](http://december.com/html/4/element/head.html)
\>
<[body](http://december.com/html/4/element/body.html)
style\="background-color: black"\>
<[a](http://december.com/html/4/element/a.html)
style\="color: white; text-decoration: none" href\="/luci"\>LuCI - Lua Configuration Interface[a](http://december.com/html/4/element/a.html)
\>
[body](http://december.com/html/4/element/body.html)
\>
[html](http://december.com/html/4/element/html.html)
\>
Also remember to flush the browser's cache if you relied on the redirection because otherwise it will probably keep redirecting you to `/cgi-bin/luci` until the cache expires by itself.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/11/06 04:08
* by ziqin1
[](https://openwrt.org/docs/guide-user/services/webserver/uhttpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Apache HTTP Server
Apache HTTP Server
==================
Apache is one of the most popular web servers in the FOSS world. First, I strongly recommend that you install the apache server on an external drive width swapfile, especially if you need to use mysql. If you do not have the external drive and the swapfile installed, please look first below. You can copy text, and width right mouse click copy the contents to your PuTTY terminal.
Installation
------------
Installing apache with `[opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg") ` is very simple:
opkg update
opkg install apache
or alternatively install it to the external drive: (see below)
opkg -dest usb install apache
In case you manually mounted the hard drive, restart the drive, to make necessary links:
/etc/init.d/hdd stop
/etc/init.d/hdd start
Configuration
-------------
Edit `/etc/apache/httpd.conf` to change the configuration according to your needs.
Sometimes you need to uncomment a line (=remove the `#` character at the beginning of the line) to activate the respective config option.
Search for “Listen 12.34.56.78:80” and replace with your router's IP address and a port different then 80, because 80 is most likely already used by the OpenWrt GUI (LuCI).
`Listen 192.168.1.1:81`
Search for “ServerName” and do the same:
`ServerName YourServer:81`
where YourServer is [FQDN](https://en.wikipedia.org/wiki/FQDN "https://en.wikipedia.org/wiki/FQDN")
of your server name like [www.something99.com](http://www.something99.com/ "http://www.something99.com")
Connect to [http://192.168.1.1:81](http://192.168.1.1:81/ "http://192.168.1.1:81")
in your browser to see if your configuration works. Place your web server shared documents under `/usr/share/htdocs`.
External drive and the swapfile install
---------------------------------------
Since the _Apache HTTP Server_ is quite a big memory hog, we recommend to use it only in conjunction with additional storage. Please follow these guides to get that started:
* [usb.overview](https://openwrt.org/docs/guide-user/hardware/usb.overview "docs:guide-user:hardware:usb.overview")
* [usb-installing](https://openwrt.org/docs/guide-user/storage/usb-installing "docs:guide-user:storage:usb-installing")
* [usb-drives](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
* `[/etc/config/fstab](https://openwrt.org/docs/guide-user/storage/fstab "docs:guide-user:storage:fstab") `
Configuring Apache and PHP5
---------------------------
To install PHP see →[php](https://openwrt.org/docs/guide-user/services/webserver/php "docs:guide-user:services:webserver:php")
Edit
vi /etc/php.ini
Search for “doc\_root” and “extension=gd.so”. Do not specify the doc\_root, and uncomment the extension=gd.so.
`doc_root = extension=gd.so`
Configure Apache again:
vi /etc/apache/httpd.conf
NOTE: This is a rather unsafe configuration. If you use this, you are putting yourself at risk. ([http://insecurety.net/?p=912](http://insecurety.net/?p=912 "http://insecurety.net/?p=912")
)
Search for the portion of Your Apache configuration file which has the ScriptAlias section. Add the line from below immediately after the ScriptAlias line for “cgi-bin”. Make sure that the line goes before the closing for that section.
`ScriptAlias /php/ “/usr/bin/”`
Search for the “AddType” comment block, and add the AddType line below. You can find the AddType lines in the section. Add the following line just before the closing for that section.
`AddType application/x-httpd-php .php`
Add this line to the end of that file:
`Action application/x-httpd-php “/php/php-cgi”`
Search for this section:
` AllowOverride None Options None Order allow,deny Allow from all `
Add the following lines immediately after the section you just found.
` AllowOverride None Options none Order allow,deny Allow from all `
**`NOTE:`** The `/usr/bin` directory contains far more than just `php-cgi`. On a public server it could be wise to move `php-cgi` to its own directory and then configure Apache to use that separate directory instead!
### Configuring the default Index Page
Search for “DirectoryIndex index.html” and change to:
`DirectoryIndex index.php index.html`
Restart the Apache Web Server
apachectl restart
Test PHP
--------
Create `/usr/share/htdocs/index.php` with the following content:
``
Open your browser and access the file [http://192.168.1.1:81/index.php](http://192.168.1.1:81/index.php "http://192.168.1.1:81/index.php")
Troubleshooting
===============
When apache accept TCP connection, but not send respon. In log is: \[notice\] child pid 19745 exit signal Segmentation fault (11)
It's necessary to set lower debug level: LogLevel error
[Original solution](https://dev.openwrt.org/ticket/10273 "https://dev.openwrt.org/ticket/10273")
Start on boot
=============
Normally apache will not start on boot, I believe its deliberate so that it wont conflict with the default (uHTTPd) web-server, _you will need to add a file to '/etc/init.d/', probably naming it apache and setting it for execution (chmod +x),_ the file itself is rather simple :
`#!/bin/sh /etc/rc.common # Example script # Copyright (C) 2007 OpenWrt.org START=60 STOP=15 start() { echo launch apache # commands to launch application apachectl start } restart() { echo re-start apache # commands to launch application apachectl restart } stop() { echo stop apache # commands to kill application apachectl stop }`
once in place, you can issue the command **'/etc/init.d/apache enable'** to spawn the server @ boot
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/05/01 10:12
* by tmomas
[](https://openwrt.org/docs/guide-user/services/webserver/http.apache#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Transmission configuration
Transmission configuration
==========================
There are several implementations of the [bittorrent](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/bittorrent "docs:guide-user:services:downloading_and_filesharing:bittorrent")
peer-to-peer file sharing protocol. Transmission is only one of them. After installation (`opkg install transmission-daemon`) there should be a config file in the uci directory.
A few more details about configuration file (/etc/config/transmission) can be found [here](https://github.com/transmission/transmission/wiki/Editing-Configuration-Files "https://github.com/transmission/transmission/wiki/Editing-Configuration-Files")
.
You'll probably need to set up USB support and format your drives for storage first, see the articles [here](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
and [here](https://openwrt.org/docs/guide-user/storage/start "docs:guide-user:storage:start")
.
Proxy support was deprecated on version 1.4 and there is no plan to implement it [1)](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#fn__1)
[2)](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#fn__2)
. You can use [OpenVPN](https://openwrt.org/docs/guide-user/services/vpn/openvpn/server "docs:guide-user:services:vpn:openvpn:server")
as a global solution.
Install
-------
| Component | Description |
| --- | --- |
| `transmission-daemon` | A daemon that runs in the background and is designed to not have any form of visual interface, consult [transmission](http://man.cx/transmission "http://man.cx/transmission") . |
| `transmission-cli` | To control the transmission daemon via [CLI (Command-line interface)](https://en.wikipedia.org/wiki/Command-line%20interface "https://en.wikipedia.org/wiki/Command-line interface") on the server, consult [transmissioncli](http://man.cx/transmissioncli "http://man.cx/transmissioncli") . |
| `transmission-web` | To control the transmission daemon over [HTTP (Hypertext Transfer Protocol)](https://en.wikipedia.org/wiki/Hypertext%20Transfer%20Protocol "https://en.wikipedia.org/wiki/Hypertext Transfer Protocol") from a remote host machine with a web browser. |
| `transmission-remote` | To control the transmission daemon over the transmission JSON-[RPC (Remote Procedure Call)](https://en.wikipedia.org/wiki/Remote%20procedure%20call "https://en.wikipedia.org/wiki/Remote procedure call") from a remote host machine with a GUI program, e.g. [transmission-gtk](http://packages.debian.org/testing/transmission-gtk "http://packages.debian.org/testing/transmission-gtk") /[transmission-qt](http://packages.debian.org/testing/transmission-qt "http://packages.debian.org/testing/transmission-qt") or a [python-transmissionrpc](http://packages.debian.org/testing/python-transmissionrpc "http://packages.debian.org/testing/python-transmissionrpc") or [https://sourceforge.net/projects/transgui/](https://sourceforge.net/projects/transgui/ "https://sourceforge.net/projects/transgui/") for OS other then Debian. |
| `luci-app-transmission` | [LuCi](https://openwrt.org/docs/guide-user/luci/start "docs:guide-user:luci:start") web app for configuring the transmission daemon |
opkg update
opkg install transmission-daemon
opkg install transmission-cli
opkg install transmission-web
opkg install transmission-remote
opkg install luci-app-transmission
Basic setup
-----------
To enable Transmission:
uci set transmission.@transmission\[0\].enabled="1"
uci commit transmission
service transmission restart
It is recommended to install _luci-app-transmission_ to facilitate the configuration via LuCi web interface:
opkg install luci-app-transmission
### Frontend interfaces
* **Web user interface**: if you wish to use the web server, besides installing the package (see above), you might need to whitelist your IP address (if it is not in 192.168.1.0/24) via `option rpc_whitelist '127.0.0.1,192.168.1.*,your_ip_address`' in the transmission configuration. By default, the server listens on port 9091, eg: `http://192.168.1.1:9091`. See [Web Interface](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#web_interface "docs:guide-user:services:downloading_and_filesharing:transmission ↵")
[](https://openwrt.org/_media/media/doc/transmission-webgui.png "media:doc:transmission-webgui.png")
* **Desktop remote interface**: to control transmission remotely via RPC, install [Transmission Remote GUI](https://github.com/transmission-remote-gui/transgui "https://github.com/transmission-remote-gui/transgui")
on your desktop and set it up just like the webserver above. The RPC interface uses the same port as the web interface.
[](https://openwrt.org/_media/media/doc/transmission-transgui.png "media:doc:transmission-transgui.png")
Advanced setup
--------------
To access to all the config options edit the file `/etc/config/transmission`.
You'll probably want to change the config\_dir, download\_dir, and incomplete\_dir variables to point to locations on external storage.
config transmission
option enable 1
option config\_dir '/etc/transmission'
option alt\_speed\_down 50
option alt\_speed\_enabled false
option alt\_speed\_time\_begin 540
option alt\_speed\_time\_day 127
option alt\_speed\_time\_enabled false
option alt\_speed\_time\_end 1020
option alt\_speed\_up 50
option bind\_address\_ipv4 '0.0.0.0'
option bind\_address\_ipv6 '::'
option blocklist\_enabled false
option dht\_enabled true
option download\_dir '/mnt/sda4/'
option encryption 1
option incomplete\_dir '/mnt/sda4/incomplete'
option incomplete\_dir\_enabled false
option lazy\_bitfield\_enabled true
option lpd\_enabled false
option message\_level 2
option open\_file\_limit 32
option peer\_limit\_global 240
option peer\_limit\_per\_torrent 60
option peer\_port 51413
option peer\_port\_random\_high 65535
option peer\_port\_random\_low 49152
option peer\_port\_random\_on\_start false
option peer\_socket\_tos 0
option pex\_enabled true
option port\_forwarding\_enabled false
option preallocation 1
option ratio\_limit 2.0000
option ratio\_limit\_enabled false
option rename\_partial\_files true
option rpc\_authentication\_required false
option rpc\_bind\_address '0.0.0.0'
option rpc\_enabled true
option rpc\_password ''
option rpc\_port 9091
option rpc\_username ''
option rpc\_whitelist '127.0.0.1,192.168.1.\*'
option rpc\_whitelist\_enabled true
option script\_torrent\_done\_enabled false
option script\_torrent\_done\_filename ''
option speed\_limit\_down 100
option speed\_limit\_down\_enabled false
option speed\_limit\_up 40
option speed\_limit\_up\_enabled true
option start\_added\_torrents false
option trash\_original\_torrent\_files false
option umask 18
option upload\_slots\_per\_torrent 14
option watch\_dir\_enabled false
option watch\_dir ''
Extra details can be found [here](https://github.com/transmission/transmission/wiki/Editing-Configuration-Files "https://github.com/transmission/transmission/wiki/Editing-Configuration-Files")
.
| Name | Type | Required | Default | Option | Description |
| --- | --- | --- | --- | --- | --- |
| `config_dir` | path | | | | Where the configuration files are |
| `bind_address_ipv4` | IP Address | | | | |
| `bind_address_ipv6` | IPv6 Address | | | | |
| `mem_percentage` | integer | | | | Maximum percentage of virtual memory it can use |
| `cache-size-mb` | integer | | 2 | \[2, \] | The cache is used to help batch disk IO together, so increasing the cache size can be used to reduce the number of disk reads and writes. Recommended value (in MB): **RAM/8** |
| `nice` | integer | | 10 | \[-20, 19\] | Set the scheduling priority of the spawned process. [init.d service parameters](https://openwrt.org/docs/guide-developer/procd-init-scripts#service_parameters "docs:guide-developer:procd-init-scripts") |
| `config_overwrite` | boolean | | 1 | \[0, 1\] | Overwrite the config file in _config\_dir_ with contents in this file (/etc/config/transmission) |
| `download_dir` | path | | | | Where to store you downloaded files |
| `incomplete_dir_enabled` | boolean | | | | Whether to store incomplete files somewhere else |
| `incomplete_dir` | path | | | | Where to store files untill they are finished |
| `dht_enabled` | boolean | | | | Whether to enable dht (distributed hash tables) |
| `blocklist_enabled` | boolean | | | | Whether to make use of the blocklist defined in _config\_dir_ |
| `encryption` | integer | | | | Whether to use encrypted connections only (allow encryption: 0, prefer encryption: 1, require encryption: 2) |
| `pex_enabled` | boolean | | | | |
| `speed_limit_down_enabled` | boolean | | | | Whether transmission should limit its download speed |
| `speed_limit_down` | integer | | | | in KByte/s |
| `speed_limit_up_enabled` | boolean | | | | Whether transmission should limit its download speed |
| `speed_limit_up` | integer | | | | in KByte/s |
| `alt_speed_enabled` | boolean | | | | Whether transmission should use two speed limit settings |
| `alt_speed_down` | integer | | | | in KByte/s |
| `alt_speed_up` | integer | | | | in KByte/s |
| `alt_speed_time_enabled` | boolean | | | | Whether to switch between the two speed-setting on a time table |
| `alt_speed_time_day` | | | | | 7-bit bitmask, 0000001=sunday, 1000000=saturday |
| `alt_speed_time_begin` | | | | | default = 540, in minutes from midnight, 9am |
| `alt_speed_time_end` | | | | | default = 1020, in minutes from midnight, 5pm |
| `upload_slots_per_torrent` | | | | | how many peers can download a torrent at a time |
| `open_file_limit` | integer | | | | remember the low system memory |
| `peer_limit_global` | integer | | | | the max number of peers globaly |
| `peer_limit_per_torrent` | integer | | | | the max number of peers with connection per torrent |
| `peer_port` | integer | | | | the fixed port transmission listens to incomming connections |
| `peer_port_random_high` | integer | | | | highest port of the port range |
| `peer_port_random_low` | integer | | | | lowest port of the port range |
| `peer_port_random_on_start` | boolean | | | | whether to use random ports instead of a fixed one from the beginning |
| `peer_socket_tos` | boolean | | | | whether `type of service` is enabled |
| `port_forwarding_enabled` | boolean | | | | |
| `preallocation` | boolean | | | | whether to fill the space for chunks not yet downloaded with “0” (helps avoiding fragmentation) |
| `ratio_limit_enabled` | boolean | | | | whether to use a limit ratio |
| `ratio_limit` | integer | | | | automaticaly stop seeding a torrent when it reaches this ratio (with a GUI you can enable this for every torrent separately) |
| `rename_partial_files` | boolean | | | | |
| `rpc_enabled` | boolean | | | | Whether transmission-daemon should be remote controlled by a GUI on a host machine |
| `rpc_bind_address` | IP Address | | | | the address on which transmission-daemon listens to rpcs |
| `rpc_port` | IP Port | | | | the port on which transmission-daemon listens to rpcs |
| `rpc_authentication_required` | boolean | | | | whether rpc needs authentication |
| `rpc_username` | string | | | | user name |
| `rpc_password` | string | | | | password |
| `rpc_whitelist_enabled` | boolean | | | | whether to make use of the whitelist |
| `rpc_whitelist` | IP Addresses | | | | the IPs of the hosts allowed |
| `watch_dir_enabled` | boolean | | | | Whether to check a directory for new torrents put there. Leave this disabled It requres inotify enabled in kernel to works, which is not enabled by default in openwrt. |
| `watch_dir` | path | | | | Path to the directory |
| `script_torrent_done_enabled` | boolean | | | | |
| `script_torrent_done_filename` | | | | | |
| `start_added_torrents` | boolean | | | | |
| `trash_original_torrent_files` | | | | | |
| `umask` | integer | | | | Sets file mode creation mask. The mask should be in base 10 due to the json markup language used by Transmission. For instance, the standard umask octal notation `022` is written as `18`. If you want to save downloaded torrents to be world-writable (equivalent to `chmod 777` or `chmod a+rwx`) set this value to `0`. |
| `lazy_bitfield_enabled` | boolean | | | | |
| `lpd_enabled` | boolean | | | | |
| `message_level` | integer | | | | |
| ~`proxy_enabled`~ | boolean | | | Deprecated on 1.4 | whether to use a proxy |
| ~`proxy`~ | IP address | | | Deprecated on 1.4 | IP adress of the proxy |
| ~`proxy_port`~ | integer | | | Deprecated on 1.4 | IP port of the proxy |
| ~`proxy_type`~ | integer | | | Deprecated on 1.4 | Type of the proxy (http: 0, socks4: 1, socks5: 2) |
| ~`proxy_auth_enabled`~ | boolean | | | Deprecated on 1.4 | Whether proxy needs authentication |
| ~`proxy_auth_username`~ | string | | | Deprecated on 1.4 | username for the proxy |
| ~`proxy_auth_password`~ | string | | | Deprecated on 1.4 | password for the proxy |
[Reference](https://github.com/transmission/transmission/wiki/Editing-Configuration-Files "https://github.com/transmission/transmission/wiki/Editing-Configuration-Files")
Web Interface
-------------
Install the package transmission-web:
opkg install transmission-web
To open the web interface just click on the button at the Luci configuration screen:
[](https://openwrt.org/_detail/media/docs/tranmission-web-open.png?id=docs%3Aguide-user%3Aservices%3Adownloading_and_filesharing%3Atransmission "media:docs:tranmission-web-open.png")
You can use the default web interface, but it is minimalist and lacks some useful functions. Fortunately, there are alternatives for replacing the default web interface.
### Transmission Web Control
Transmission Web Control is a fully featured Web interface, see [https://github.com/ronggang/transmission-web-control/wiki](https://github.com/ronggang/transmission-web-control/wiki "https://github.com/ronggang/transmission-web-control/wiki")
As of 01-Jun-2025, the `transmission-web-control` GitHub repository has been archived and is no longer being maintained. As of 17-Feb-2026, it still works but I am not sure if it should be a concern. Anyway, I have found another alternative to this Web UI i.e. [Flood for Transmission](https://github.com/johman10/flood-for-transmission "https://github.com/johman10/flood-for-transmission")
. Setup details are available below on this page.
To install this new web interface:
1. Stop the daemon:
service transmission stop
2. Install wget-ssl:
opkg update
opkg install wget-ssl
3. Download the install script:
cd /tmp
wget https://github.com/ronggang/transmission-web-control/raw/master/release/install-tr-control.sh \--no-check-certificate
4. Execute the install script:
chmod +x /tmp/install-tr-control.sh
sh /tmp/install-tr-control.sh
5. A menu is shown, choose 1:
Welcome to the Transmission Web Control Installation Script.
Official help documentation: https://github.com/ronggang/transmission-web-control/wiki
Installation script version: 1.2.3
1. Install the latest release.
2. Install the specified version.
3. Revert to the official UI.
4. Re-download the installation script.
5. Check if Transmission is started.
6. Input the Transmission Web directory.
9. Installing from 'master' Repository.
===================
0. Exit the installation;
Please enter the corresponding number: 1
6. Start the daemon:
service transmission start
7. Done, now you can open the web interface, e.g: `[http://192.168.1.1:9091/transmission/web/](http://192.168.1.1:9091/transmission/web/ "http://192.168.1.1:9091/transmission/web/") `
This is the aspect of the new web interface:
[](https://openwrt.org/_detail/media/doc/tranmission-web-control.png?id=docs%3Aguide-user%3Aservices%3Adownloading_and_filesharing%3Atransmission "media:doc:tranmission-web-control.png")
### Flood for Transmission
The repository containing original releases can be found [here](https://github.com/johman10/flood-for-transmission "https://github.com/johman10/flood-for-transmission")
.
To install this Web UI, you first need to download the `.zip` or `.tar.gz` package from the [latest release](https://github.com/johman10/flood-for-transmission/releases/latest "https://github.com/johman10/flood-for-transmission/releases/latest")
. Log into your router through SSH and navigate to `/usr/share/transmission/public_html`. If the directory does not exist, then create it. Now extract the downloaded file in this directory, so the complete path becomes `/usr/share/transmission/public_html/flood-for-transmission/`. I think these extracted files can be placed anywhere, such as external USB drive etc. but someone with more experience can clarify this.
The main file in this folder will be named as `index.html` which the system will pick on its own once the `transmission` configuration has been updated.
After extraction, you have to update the configuration file `/etc/config/transmission` to point towards your Web UI directory. A teardown of `/etc/init.d/transmission` would confirm you that the required configuration parameter is `web_home` which is fed to the `transmission` client at the start through `TRANSMISSION_WEB_HOME` environment variable. You can find more about this in Transmission Wiki on the [Web](https://github.com/transmission/transmission/blob/main/docs/README.md "https://github.com/transmission/transmission/blob/main/docs/README.md")
.
You can edit the Transmission configuration file to add the following and restart the `transmission` client to take effect:
config transmission
...
\## other config options
...
option web\_home '/usr/share/transmission/public\_html/flood-for-transmission'
You can also view the screenshots of the Web UI at the [GitHub link](https://github.com/johman10/flood-for-transmission/tree/master/screenshots "https://github.com/johman10/flood-for-transmission/tree/master/screenshots")
.
Notes
-----
* Transmission performs much better when [swap](https://openwrt.org/docs/guide-user/storage/fstab#addingswappartitions "docs:guide-user:storage:fstab")
is mounted.
* \# settings.json is created with root permissions by default. It can cause an error:
\# Error: Unable to save resume file: No such file or directory
\# root root 1818 Dec 27 21:00 settings.json
\# this command can help:
chown transmission:transmission settings.json
#Also you can prevent this error if you set correct permissions for the download directory... Make sure that transmission is the owner of every path that is set in /etc/config/transmission
chown \-R transmission:transmission /transmission/
* If you experience a **network throughput drop** in your device after installing Transmission, this is likely caused by the settings at `/etc/sysctl.d/20-transmission.conf`
\# Transmission requests large buffers by default
net.core.rmem\_max = 4194304
net.core.wmem\_max = 1048576
\# Some firewalls block SYN packets that are too small
net.ipv4.tcp\_adv\_win\_scale = 4
Adjust these parameters or just delete this file and reboot OpenWrt.
Example
-------
A video demonstration of how Transmission 2.84 can be installed on OpenWrt 14.07 Barrier Breaker: [https://www.youtube.com/watch?v=\_R1Kcpy4pj4](https://www.youtube.com/watch?v=_R1Kcpy4pj4 "https://www.youtube.com/watch?v=_R1Kcpy4pj4")
(video removed)
Scripts
-------
### Add Trackers
A script ([GitHub oilervoss](https://github.com/oilervoss/transmission "https://github.com/oilervoss/transmission")
) for adding alternative trackers to the selected torrents filtered by its name or number. The public trackers are retrieved from a dynamical list ([ngosang](https://github.com/ngosang/trackerslist "https://github.com/ngosang/trackerslist")
). If the list is offline, it will use a static one.
\# Show current Torrents
./addtracker
\# Add public trackers to the Torrents of numbers $somenumber and $othernumber
./addtracker $somenumber $othernumber
\# Add public trackers to the Torrents found with $anyword or $otherword in the name (case insensitive)
./addtracker $anyword $otherword
\# Add public trackers to all torrents
./addtracker .
How to activate the external 'done' script on OpenWRT
-----------------------------------------------------
Since OpenWRT 24.10.x the transmission start to use the 'ujail' process system
which wrapping/isolating process hierarchy for security
that not allow any unpermitted(not whitelisted) operation as the docker system's concept.
So that, under the circumstances,
the external 'done' script treated as 'unknown & unsecure script which potentially danger'.
To avoid this restrict security matter,
and even want to use own custom shell script,
need to follow below steps.
**_(Be aware, by following below steps at your own risk destorying security protection._**
**_It's totally breaking multi level protection hierarchy that permission, system call filtering, access control that well prepared security.)_**
0\. Before performing below steps, you must setup the correct user:group ownership and permissions on the folders where the script needs access to.
If you don't do this, the script will not be able to run the commands. Troubleshooting will be a lot harder, since you won't know if it is due to the permissions that don't work, or if it is due to issues in the following steps.
Easiest way to allow the configured external 'done' script after a torrent is done, set the permissions like this to all directories where you reference to in the script:
chown \-R root:transmission /xxxxx
chmod \-R g+rw /xxxxx
This is the default user and group configured within the Transmission config file. If you changed that there, apply that accordingly in the example above.
1\. Edit
/etc/seccomp/transmission-daemon.json
so that the transmission process will not be killed when the script runs. By default, when the script runs, Transmission will crash. The following change in the json, will fix the crash. \\\\Changing the very first line as this
"defaultAction": "SCMP\_ACT\_LOG"
.
2\. Open up
/etc/init.d/transmission
to edit(nano, vim what ever you want).
To allow access the external 'done' script, you need to specify/add the 'ujail'([Syntax](https://openwrt.org/docs/guide-developer/procd-init-scripts#service_jails "docs:guide-developer:procd-init-scripts")
) in the script by following steps.
3\. Around the line number 78 or somewhere(where around the line
local seccomp\_path
) you need to add below.
local script\_torrent\_done\_filename
config\_get script\_torrent\_done\_filename "$cfg" 'script\_torrent\_done\_filename' '$config\_dir/done.sh'
4\. After adding above the step three,
Go to line number around 174
where right after the line
procd\_add\_jail\_mount\_rw "$config\_dir/stats.json"
5\. From now, add whatever folder and files which you need as below syntax(study 'ujail'([Syntax](https://openwrt.org/docs/guide-developer/procd-init-scripts#service_jails "docs:guide-developer:procd-init-scripts")
)).
This step below is one of example.
procd\_add\_jail\_mount\_rw "/tmp"
procd\_add\_jail\_mount "/bin"
procd\_add\_jail\_mount "/usr/bin"
procd\_add\_jail\_mount "/usr/lib"
procd\_add\_jail\_mount "/usr/lib/sudo"
procd\_add\_jail\_mount "/etc"
procd\_add\_jail\_mount\_rw "/var/run/some\_script.lock"
procd\_add\_jail\_mount\_rw "$config\_dir/settings.json"
procd\_add\_jail\_mount "$script\_torrent\_done\_filename"
procd\_add\_jail\_mount\_rw "/dev/null"
procd\_add\_jail\_mount "/etc/config"
You will need to find what directory actually need to access by checking
logread
.
The log will tell you what program access denied and where. Start a torrent, check the log and again repeat. you will find all of set where you need to access.
If cannot see appropriate logs, set the transmission log level in the transmission config/web ui.
Message level : 'Debug'
would be right.
6\. Do
service transmission restart
. (service transmission Reload not working. some of variable not even flushed.)
7\. Enjoy.
* * *
[1)](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#fnt__1)
[https://github.com/transmission/transmission/wiki/Editing-Configuration-Files#14x-and-older](https://github.com/transmission/transmission/wiki/Editing-Configuration-Files#14x-and-older "https://github.com/transmission/transmission/wiki/Editing-Configuration-Files#14x-and-older")
[2)](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#fnt__2)
[https://github.com/transmission/transmission/issues/344](https://github.com/transmission/transmission/issues/344 "https://github.com/transmission/transmission/issues/344")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/06/04 07:30
* by zolikonta
[](https://openwrt.org/docs/guide-user/services/downloading_and_filesharing/transmission#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Tor extras
Tor extras
==========
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
Introduction
------------
* This how-to describes the most common [Tor](https://en.wikipedia.org/wiki/Tor_(anonymity_network) "https://en.wikipedia.org/wiki/Tor_(anonymity_network)")
tuning scenarios adapted for OpenWrt.
* Follow [Tor client](https://openwrt.org/docs/guide-user/services/tor/client "docs:guide-user:services:tor:client")
for client setup and [Tor hidden service](https://openwrt.org/docs/guide-user/services/tor/hs "docs:guide-user:services:tor:hs")
for onion service setup.
* Follow [Random generator](https://openwrt.org/docs/guide-user/services/rng "docs:guide-user:services:rng")
to overcome low entropy issues.
Extras
------
### References
* [Tor manual](https://2019.www.torproject.org/docs/tor-manual.html.en "https://2019.www.torproject.org/docs/tor-manual.html.en")
* [Tor community documentation](https://community.torproject.org/ "https://community.torproject.org/")
* [Tor frequently asked questions](https://support.torproject.org/ "https://support.torproject.org/")
### Exit nodes
Exclude dubious exit nodes by their [country code](https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2 "https://en.wikipedia.org/wiki/ISO_3166-1_alpha-2")
.
\# Install packages
opkg update
opkg install tor-geoip
\# Exclude exit nodes
cat << EOF \>> /etc/tor/custom
ExcludeExitNodes {??}, {by}, {kz}, {ru}, {ua}
EOF
service tor restart
### Socks proxy
Enable Tor socks proxy.
\# Enable Tor socks proxy
cat << EOF \>> /etc/tor/custom
SOCKSPort 0.0.0.0:9050
SOCKSPort \[::\]:9050
EOF
service tor restart
### Pluggable transports
Circumvent ISP restrictions with [bridges](https://tb-manual.torproject.org/bridges/ "https://tb-manual.torproject.org/bridges/")
.
\# Install packages
opkg update
opkg install obfs4proxy
\# Configure bridges
cat << EOF \>> /etc/tor/custom
UseBridges 1
ClientTransportPlugin obfs4 exec /usr/bin/obfs4proxy
Bridge obfs4 154.35.22.10:443 8FB9F4319E89E5C6223052AA525A192AFBC85D55 \\
cert\=GGGS1TX4R81m3r0HBl79wKy1OtPPNR2CZUIrHjkRg65Vc2VR8fOyo64f9kmT1UAFG7j0HQ iat-mode=0
Bridge obfs4 154.35.22.12:80 00DC6C4FA49A65BD1472993CF6730D54F11E0DBB \\
cert\=N86E9hKXXXVz6G7w2z8wFfhIDztDAzZ/3poxVePHEYjbKDWzjkRDccFMAnhK75fc65pYSg iat-mode=0
EOF
service tor restart
### Onion services
Allow remote access to the router with [Tor Onion services](https://openwrt.org/docs/guide-user/services/tor/hs "docs:guide-user:services:tor:hs")
. Be sure to enable [client authorization](https://openwrt.org/docs/guide-user/services/tor/extras#client_authorization "docs:guide-user:services:tor:extras")
.
\# Install packages
opkg update
opkg install tor-hs
\# Configure Tor onion service
uci \-q delete tor-hs.ssh
uci set tor-hs.ssh="hidden-service"
uci set tor-hs.ssh.Name="ssh"
uci set tor-hs.ssh.Enabled="1"
uci set tor-hs.ssh.IPv4="127.0.0.1"
uci add\_list tor-hs.ssh.PublicLocalPort="22;22"
uci commit tor-hs
service tor-hs restart
\# Fetch onion service hostname
cat /etc/tor/hidden\_service/ssh/hostname
Access the onion service from Tor client.
\# Install packages
opkg update
opkg install torsocks
\# Access onion service
torsocks ssh ${TOR\_HOST}
### Client authorization
Secure access to onion services with [client authorization](https://community.torproject.org/onion-services/advanced/client-auth/ "https://community.torproject.org/onion-services/advanced/client-auth/")
.
\# Install packages
opkg update
opkg install openssl-util coreutils-base32
\# Enable client authorization
openssl genpkey \-algorithm x25519 \-out /etc/tor/hidden\_service.pem
TOR\_KEY\="$(openssl pkey -in /etc/tor/hidden\_service.pem -outform der \\
| tail -c 32 \\
| base32 \\
| sed -e "s/\=//g")"
TOR\_PUB\="$(openssl pkey -in /etc/tor/hidden\_service.pem -outform der -pubout \\
| tail -c 32 \\
| base32 \\
| sed -e "s/\=//g")"
TOR\_HOST\="$(cat /etc/tor/hidden\_service/ssh/hostname)"
cat << EOF \> client.auth\_private
${TOR\_HOST%.onion}:descriptor:x25519:${TOR\_KEY}
EOF
cat << EOF \> /etc/tor/hidden\_service/ssh/authorized\_clients/client.auth
descriptor:x25519:${TOR\_PUB}
EOF
chown \-R tor:tor /etc/tor/hidden\_service/
service tor restart
Configure authorization on the client using the private key.
\# Configure client authorization
cat << EOF \>> /etc/tor/custom
ClientOnionAuthDir /etc/tor/onion\_auth
EOF
umask go\=
TOR\_AUTH\="$(cat client.auth\_private)"
TOR\_HOST\="${TOR\_AUTH%%:\*}.onion"
mkdir \-p /etc/tor/onion\_auth
cat << EOF \> /etc/tor/onion\_auth/client.auth\_private
${TOR\_AUTH}
EOF
chown \-R tor:tor /etc/tor/onion\_auth
service tor restart
### Selective routing
Route only specific domains to Tor network. Selectively utilize DNS over Tor. Beware of privacy issues as each site may use multiple domains.
\# Process traffic by destination
for IPV in 4 6
do case ${IPV} in
(4) TOR\_DST\="172.16.0.0/12" ;;
(6) TOR\_DST\="fc00::/8" ;;
esac
uci \-q delete firewall.tcp\_int${IPV%4}
uci set firewall.tcp\_int${IPV%4}\="redirect"
uci set firewall.tcp\_int${IPV%4}.name="Intercept-TCP"
uci set firewall.tcp\_int${IPV%4}.src="lan"
uci set firewall.tcp\_int${IPV%4}.src\_dip="${TOR\_DST}"
uci set firewall.tcp\_int${IPV%4}.src\_dport="0-65535"
uci set firewall.tcp\_int${IPV%4}.dest\_port="9040"
uci set firewall.tcp\_int${IPV%4}.proto="tcp"
uci set firewall.tcp\_int${IPV%4}.target="DNAT"
uci \-q delete firewall.lan\_wan${IPV%4}
uci set firewall.lan\_wan${IPV%4}\="rule"
uci set firewall.lan\_wan${IPV%4}.name="Allow-NonTor-Forward"
uci set firewall.lan\_wan${IPV%4}.src="lan"
uci set firewall.lan\_wan${IPV%4}.dest="wan"
uci set firewall.lan\_wan${IPV%4}.dest\_ip="!${TOR\_DST}"
uci set firewall.lan\_wan${IPV%4}.proto="all"
uci set firewall.lan\_wan${IPV%4}.target="ACCEPT"
done
uci \-q delete firewall.tor\_nft
uci commit firewall
service firewall restart
\# Configure Tor domains
uci \-q delete dhcp.@dnsmasq\[0\].noresolv
uci \-q delete dhcp.@dnsmasq\[0\].server
uci add\_list dhcp.@dnsmasq\[0\].server="/onion/127.0.0.1#9053"
uci add\_list dhcp.@dnsmasq\[0\].server="/example.com/127.0.0.1#9053"
uci add\_list dhcp.@dnsmasq\[0\].server="/example.net/127.0.0.1#9053"
uci commit dhcp
service dnsmasq restart
### Hardware acceleration
Some devices have [hardware crypto accelerator chips](https://openwrt.org/docs/techref/hardware/cryptographic.hardware.accelerators "docs:techref:hardware:cryptographic.hardware.accelerators")
. Enabling Tor to use a hardware accelerator offloads CPU pressure. Because Tor uses the openssl library acceleration must also be enabled by openssl, which can be done by following these [instructions](https://openwrt.org/docs/techref/hardware/cryptographic.hardware.accelerators#cryptodev "docs:techref:hardware:cryptographic.hardware.accelerators")
. Then hardware acceleration must be enabled in Tor. In the Tor notice log after the above setup, you should notice multiple lines like **`Default OpenSSL engine for 3DES-CBC is /dev/crypto engine [devcrypto]`**.
\# Enable Tor hardware acceleration
cat << EOF \>> /etc/tor/custom
HardwareAccel 1
EOF
service tor restart
### Automated
Automated Tor client installation.
URL\="https://openwrt.org/\_export/code/docs/guide-user/services/tor/client"
cat << EOF \> tor-client.sh
$(wget \-U "" \-O - "${URL}?codeblock=0")
$(wget \-U "" \-O - "${URL}?codeblock=1")
$(wget \-U "" \-O - "${URL}?codeblock=2")
$(wget \-U "" \-O - "${URL}?codeblock=3")
EOF
sh tor-client.sh
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/02/09 00:04
* by stokito
[](https://openwrt.org/docs/guide-user/services/tor/extras#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Lighttpd webserver
Lighttpd webserver
==================
LuCI is the main web administration utility for OpenWrt. **By default LuCI uses [uHTTPd](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd")
**.
Lighttpd is a highly-configurable, lightweight web server. See [lighttpd](https://en.wikipedia.org/wiki/lighttpd "https://en.wikipedia.org/wiki/lighttpd")
and [https://www.lighttpd.net/](https://www.lighttpd.net/ "https://www.lighttpd.net/")
. There are many modules available for lighttpd that can be installed and configured. For more information on the modules see [https://redmine.lighttpd.net/projects/lighttpd/wiki/docs](https://redmine.lighttpd.net/projects/lighttpd/wiki/docs "https://redmine.lighttpd.net/projects/lighttpd/wiki/docs")
. This article explains how to get lighttpd working on OpenWrt.
Consult [luci.on.lighttpd](https://openwrt.org/docs/guide-user/luci/luci.on.lighttpd "docs:guide-user:luci:luci.on.lighttpd")
to make lighttpd serve the LuCI web interface.
Requirements
------------
Execute
opkg list lighttpd\*
to see what packages are available.
Installation
------------
Use [opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
opkg update
opkg install lighttpd
Configuration
-------------
Edit `/etc/lighttpd/lighttpd.conf`
### Basic Configuration
To get a basic server running make the following changes to `/etc/lighttpd/lighttpd.conf`:
_Server Root Directory_
server.document-root = "/www/"
where the `www` is the root directory of the web server.
_Enable Logging_
Uncomment (remove #) the following line so errors are written to the log:
server.errorlog = "/var/log/lighttpd/error.log"
_Set Server Port_
Uncomment the following line:
server.port = 8000
where 8000 is the port you want your webserver on.
### Advanced Configuration
* [Set up a LAMP stack on OpenWrt](https://openwrt.org/docs/guide-user/services/webserver/lamp "docs:guide-user:services:webserver:lamp")
* [WebDAV with Lighttpd on OpenWRT](https://openwrt.org/docs/guide-user/services/nas/webdav "docs:guide-user:services:nas:webdav")
Configuring Lighttpd and PHP
----------------------------
1. First, follow [php](https://openwrt.org/docs/guide-user/services/webserver/php "docs:guide-user:services:webserver:php")
to install a version of PHP
2. Second, follow [lighttpd1](https://openwrt.org/docs/guide-user/services/webserver/lamp#lighttpd1 "docs:guide-user:services:webserver:lamp")
to configure lighttpd
3. Third, to get PHP running with Lighttpd you need to install the package `lighttpd-mod-cgi`
Start on boot
-------------
To enable/disable start on boot:
`/etc/init.d/lighttpd enable` this simply creates a symlink: `/etc/rc.d/S80lighttpd → /etc/init.d/lighttpd`
`/etc/init.d/lighttpd disable` this removes the symlink again
To start the server:
/etc/init.d/lighttpd start
To stop the server:
/etc/init.d/lighttpd stop
Firewall
--------
To allow users on the WAN to access the server, make sure to configure the firewall in `[/etc/config/firewall](https://openwrt.org/docs/guide-user/firewall/start "docs:guide-user:firewall:start") ` and port forwarding settings.
config redirect
option src wan
option src\_dport 80
option dest lan
option dest\_ip 192.168.1.1
option dest\_port 8000
option proto tcp
config rule
option src wan
option dest\_port 8000
option target ACCEPT
option proto tcp
Restart the firewall with the following command: `/etc/init.d/firewall restart`
Administration
--------------
**Add virtual hosts via mod\_simple\_vhost**
The goal is to run only one server on port 80. At the same time, this server should distinguish between different websites or directories. First, the Lighttpd server is configured as described. It must be ensured that the server works on port 80 (or any other port). In my example, the local domain suffix was specified with “h” (see dnsmasq configuration).
Now add the following entries to your file: `/etc/config/dhcp`
config domain
option name 'luci'
option ip '192.168.1.1'
config domain
option name 'home'
option ip '192.168.1.1'
Add Module `mod_simple_vhost` to your: `/etc/lighttpd/lighttpd.conf` `server.modules = ( “mod_simple_vhost”, )`
Create virtual host Configuration: `/etc/lighttpd/conf.d/IntraNet.conf`
$HTTP\["host"\] =~ "^luci.h(\\:\[0-9\]\*)?$" {
dir-listing.activate = "disable"
server.document-root = "/www/"
$HTTP\["url"\] =~ "^/cgi-bin" {
cgi.assign += ( "" => "" )
}
}
$HTTP\["host"\] =~ "^home.h(\\:\[0-9\]\*)?$" {
dir-listing.activate = "enable"
server.document-root = "/www/Home/"
url.redirect = ( "^/config/" => "/www/status-403.html",
"^/data/" => "/www/status-403.html",
)
}
Restarted dnsmasq and lighttpd: `/etc/init.d/dnsmasq restart; /etc/init.d/lighttpd restart;`
Via the address luci.h the configuration can now be called, and another website via home.h The IntraNet.conf can be extended with more virtual host names. Within virtual host you can configure host specific configurations.
You can also configure Internet Websites with this, like example.org or second.example.org
_Make sure that the browser cache is deleted, often a new presence did not work because there is still some old information in the cache._
Troubleshooting
---------------
_Incorrect Event Handler_
If you get the following error:
(server.c.1105) fdevent\_init failed
you might need to set the event handler explicitly for your system. Add the following line to the configuration file:
server.event-handler = "poll"
See [https://redmine.lighttpd.net/projects/lighttpd/wiki/Server.event-handlerDetails](https://redmine.lighttpd.net/projects/lighttpd/wiki/Server.event-handlerDetails "https://redmine.lighttpd.net/projects/lighttpd/wiki/Server.event-handlerDetails")
Notes
-----
Note that lighttpd does not support `.htaccess` files as some web servers do to configure directory specific server settings. Instead, it uses a centrally configured system using `lighttpd.conf` to define all settings, using powerful matching functions. This still means that you have to manually set up directory settings. Especially for (opkg) packages that supply `.htaccess` files to define required settings. Allowing directory listings is one example that should be disabled or enabled as per the required security level.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/12/23 21:01
* by stokito
[](https://openwrt.org/docs/guide-user/services/webserver/lighttpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] NTP (time synchronization over Network Time Protocol)
NTP (time synchronization over Network Time Protocol)
=====================================================
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=========================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « docs » section at the top...")
[NTP (time synchronization over Network Time Protocol)](https://openwrt.org/docs/guide-user/services/ntp/start "docs:guide-user:services:ntp:start")
* [NTP client / NTP server](https://openwrt.org/docs/guide-user/services/ntp/client-server "docs:guide-user:services:ntp:client-server")
* [Ntpclient configuration](https://openwrt.org/docs/guide-user/services/ntp/client "docs:guide-user:services:ntp:client")
[](https://openwrt.org/docs/guide-user/services/ntp/start#top-549375571 "Continue with the « » section at the top...")
##### ...
* [Stratum 1 NTP server using USB GPS](https://openwrt.org/docs/guide-user/services/ntp/gps "docs:guide-user:services:ntp:gps")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/16 21:13
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/ntp/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] SNMP (Simple Network Management Protocol)
SNMP (Simple Network Management Protocol)
=========================================
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
===========================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « docs » section at the top...")
[SNMP (Simple Network Management Protocol)](https://openwrt.org/docs/guide-user/services/snmp/start "docs:guide-user:services:snmp:start")
* [Minimal SNMP Daemon (mini\_snmpd) configuration](https://openwrt.org/docs/guide-user/services/snmp/mini_snmpd "docs:guide-user:services:snmp:mini_snmpd")
* [SNMPD](https://openwrt.org/docs/guide-user/services/snmp/server "docs:guide-user:services:snmp:server")
[](https://openwrt.org/docs/guide-user/services/snmp/start#top-1662047919 "Continue with the « » section at the top...")
##### ...
* [snmpd](https://openwrt.org/docs/guide-user/services/snmp/snmpd "docs:guide-user:services:snmp:snmpd")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/16 20:49
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/snmp/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Asterisk
Asterisk
========
Introduction
------------
[Asterisk](https://www.asterisk.org/ "https://www.asterisk.org/")
is an open-source software PBX that can be extended by various modules. OpenWrt provides packages for Asterisk and most of its official modules via the telephony [feed](https://openwrt.org/docs/guide-developer/feeds "docs:guide-developer:feeds")
. On routers with Lantiq SoCs it's possible to use built in analogue FXS ports with Asterisk, turning these devices into [VoIP gateways](https://en.wikipedia.org/wiki/VoIP_gateway "https://en.wikipedia.org/wiki/VoIP_gateway")
(see [chan-lantiq for Asterisk](https://openwrt.org/docs/guide-user/services/voip/chan-lantiq "docs:guide-user:services:voip:chan-lantiq")
).
This article focuses on Asterisk installation and basic SIP configuration on OpenWrt.
Installation
------------
### Choosing an Asterisk version
Asterisk has standard and long term support (LTS) releases. Have a look at [Asterisk versions](https://docs.asterisk.org/About-the-Project/Asterisk-Versions/ "https://docs.asterisk.org/About-the-Project/Asterisk-Versions/")
on the Asterisk wiki for the current upstream support status. OpenWrt releases usually include the latest LTS release of Asterisk.
You can query the package table to get information about the Asterisk versions in OpenWrt, module names and their descriptions: [Asterisk packages](https://openwrt.org/packages/table/start?dataofs=50&dataflt[Name_pkg-dependencies*~]=asterisk "packages:table:start")
### SIP stack
Until Asterisk 20 it was possible to choose between two SIP stacks in Asterisk: `chan_sip` and `chan_pjsip`.
`chan_sip` was marked as [deprecated](https://www.asterisk.org/deprecating-chan_sip-asterisk-17-0-0-rc2-release/ "https://www.asterisk.org/deprecating-chan_sip-asterisk-17-0-0-rc2-release/")
with the release of Asterisk 17 and was [removed in Asterisk 21](https://docs.asterisk.org/Development/Asterisk-Module-Deprecations/ "https://docs.asterisk.org/Development/Asterisk-Module-Deprecations/")
.
You can find help on how to migrate your configuration [here](https://docs.asterisk.org/Configuration/Channel-Drivers/SIP/Configuring-res_pjsip/Migrating-from-chan_sip-to-res_pjsip/ "https://docs.asterisk.org/Configuration/Channel-Drivers/SIP/Configuring-res_pjsip/Migrating-from-chan_sip-to-res_pjsip/")
.
### Opkg
While it's perfectly possible to install Asterisk via [opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg")
, keep in mind that space on the [OverlayFS](https://openwrt.org/docs/techref/filesystems "docs:techref:filesystems")
ist limited on most devices.
opkg install asterisk asterisk-pjsip asterisk-bridge-simple asterisk-codec-alaw asterisk-codec-ulaw asterisk-res-rtp-asterisk
An Asterisk installation can be quite big. If you plan to use several modules, you may easily run out of space. In this case, you can try to build a custom image using the image builder.
### Image builder
The [image builder](https://openwrt.org/docs/guide-user/additional-software/imagebuilder "docs:guide-user:additional-software:imagebuilder")
can be used to build Asterisk packages directly into the SquashFS partition. Optionally you can exclude packages you don't need to save space.
Example command for an [o2 Box 6431](https://openwrt.org/toh/arcadyan/vgv7510kw22 "toh:arcadyan:vgv7510kw22")
:
make image PROFILE=arcadyan\_vgv7510kw22-nor PACKAGES="kmod-ltq-tapi kmod-ltq-vmmc kmod-ltq-ifxos asterisk asterisk-pjsip asterisk-bridge-simple asterisk-codec-alaw asterisk-codec-ulaw asterisk-res-rtp-asterisk asterisk-chan-lantiq"
Security considerations
-----------------------
VoIP services are a common attack target and it's important to implement at least some basic security measures before putting an Asterisk server online.
Asterisk security advisories are announced here: [https://www.asterisk.org/downloads/security-advisories](https://www.asterisk.org/downloads/security-advisories "https://www.asterisk.org/downloads/security-advisories")
### Modules
Only install modules you really need. For basic SIP operation it's enough to install a RTP stack (`*-res-rtp-asterisk`), a channel bridging module (`asterisk*-bridge-simple`) and needed audio codecs (normally `*-codec-alaw` or `*-codec-ulaw`) in addition to the SIP stack.
### Firewall
Don't expose SIP related ports on your WAN Interface. For in- and outgoing calls the registration process takes care to establish a connection to your SIP provider and to keep it alive.
If you have problems receiving incoming calls, you can try to install `kmod-nf-nathelper-extra`, see [here](https://forum.openwrt.org/t/solved-incoming-calls-not-reaching-hosts-on-the-network/77568/2 "https://forum.openwrt.org/t/solved-incoming-calls-not-reaching-hosts-on-the-network/77568/2")
or [here](https://forum.openwrt.org/t/voip-behind-a-openwrt-nat-router/40534/12 "https://forum.openwrt.org/t/voip-behind-a-openwrt-nat-router/40534/12")
.
### Blocking of unneeded numbers
Most SIP providers offer to block foreign or special numbers. It's highly recommended to make use of that if you don't need them. That way an attacker can't make calls to these numbers, even if your installation should get compromised.
Configuration
-------------
Asterisk configurations can differ to a great extend depending on provider/hardware/country, so it's difficult to provide generic configurations. On OpenWrt, Asterisk configuration files can be found under `/etc/asterisk/`. The most important files are the dialplan (`extensions.conf`) and the SIP channel configuration (`pjsip.conf` or `sip.conf`). Location specific tone indications are set in `indications.conf`. Links to the corresponding Asterisk-wiki-pages with details on configuration options are given below, together with working examples, taken from [this forum thread](https://forum.openwrt.org/t/voip-configuration-for-asterisk13-pjsip-chan-lantiq-and-vodafone-germany/9470 "https://forum.openwrt.org/t/voip-configuration-for-asterisk13-pjsip-chan-lantiq-and-vodafone-germany/9470")
.
After changing your Asterisk configuration, restart the server: `/etc/init.d/asterisk reload`
Before the asterisk service can be used it must be 'enabled'. Edit the config file /etc/config/asterisk and check the option enabled (0→1).
If asterisk is not started as a service and you see something like this in dmesg:
do\_page\_fault(): sending SIGSEGV to asterisk for invalid read access from 00000008
epc = 77d76e90 in libc.so\[77d46000+ab000\]
ra = 77d77394 in libc.so\[77d46000+ab000\]
you should let asterisk run as root. There seems to be a bug if the service is run as the user asterisk. To prevent this edit:
`nano /etc/init.d/asterisk` and comment the line “-U “$NAME” \\” → “#-U “$NAME” \\” also adjust the position if the “-f \\” parameter.
### pjsip.conf
[https://docs.asterisk.org/Asterisk\_16\_Documentation/API\_Documentation/Module\_Configuration/res\_pjsip/](https://docs.asterisk.org/Asterisk_16_Documentation/API_Documentation/Module_Configuration/res_pjsip/ "https://docs.asterisk.org/Asterisk_16_Documentation/API_Documentation/Module_Configuration/res_pjsip/")
_**Example for Vodafone Germany:**_
[pjsip.conf](https://openwrt.org/_export/code/docs/guide-user/services/voip/asterisk?codeblock=2 "Download Snippet")
\[global\]
type \= global
endpoint\_identifier\_order \= ip,username
\[acl\]
type \= acl
deny \= 0.0.0.0/0.0.0.0
permit \= 127.0.0.1
;permit = 192.168.1.0/24 ;uncomment if you want to connect clients from LAN
permit \= 88.79.152.xxx ;nslookup .sip.arcor.de
\[transport-udp\]
type \= transport
protocol \= udp
bind \= 0.0.0.0:5060
local\_net \= 127.0.0.1
local\_net \= 192.168.1.0/24
\[reg\_arcor\]
type \= registration
transport \= transport-udp
contact\_user \=
client\_uri \= sip:@.sip.arcor.de
server\_uri \= sip:.sip.arcor.de
outbound\_auth \= auth\_arcor
retry\_interval \= 30
forbidden\_retry\_interval \= 300
max\_retries \= 10
auth\_rejection\_permanent \= false
\[auth\_arcor\]
type \= auth
auth\_type \= userpass
realm \= arcor.de
username \=
password \=
\[aor\_arcor\]
type \= aor
contact \= sip:.sip.arcor.de
\[id\_arcor\]
type \= identify
match \= .sip.arcor.de
endpoint \= in\_arcor
\[in\_arcor\]
type \= endpoint
transport \= transport-udp
context \= lantiq1\_inbound
disallow \= all
allow \= alaw,g722,ulaw
disable\_direct\_media\_on\_nat \= yes
rewrite\_contact \= yes
\[out\_arcor\]
type \= endpoint
transport \= transport-udp
disallow \= all
allow \= alaw,g722,ulaw
disable\_direct\_media\_on\_nat \= yes
callerid \=
from\_user \=
from\_domain \= .sip.arcor.de
outbound\_auth \= auth\_arcor
aors \= aor\_arcor
Vodafone also supports the [line option](https://www.asterisk.org/the-pjsip-outbound-registration-line-option/ "https://www.asterisk.org/the-pjsip-outbound-registration-line-option/")
, which can simplify the configuration by omitting the `[id_arcor]` section. The above configuration is shown to present a more generic example.
_**Example for Telekom Germany:**_
In order to get trusted input ip-addresses which can be used in the \[acl\] section you can use: nslookup -q=SRV \_sip.\_udp.tel.t-online.de 1.1.1.1 .
[pjsip.conf](https://openwrt.org/_export/code/docs/guide-user/services/voip/asterisk?codeblock=3 "Download Snippet")
\[global\]
type \= global
endpoint\_identifier\_order \= ip,username
\[acl\]
type \= acl
deny \= 0.0.0.0/0.0.0.0
permit \= 127.0.0.1
permit \= 217.0.147.5
permit \= 217.0.146.5
permit \= 217.0.147.197
\[transport-udp\]
type \= transport
protocol \= udp
bind \= 0.0.0.0
\[transport-tcp\]
type \= transport
protocol \= tcp
bind \= 0.0.0.0
\[reg\_telekom\]
type \= registration
contact\_user \= ;(e.g. 0228...)
client\_uri \= sip:@tel.t-online.de ;(e.g.+49228...)
server\_uri \= sip:tel.t-online.de
outbound\_auth \= auth\_telekom
retry\_interval \= 30
forbidden\_retry\_interval \= 300
max\_retries \= 10
auth\_rejection\_permanent \= false
\[auth\_telekom\]
type \= auth
auth\_type \= userpass
username \= ;(former T-Online Number)
realm \= tel.t-online.de
\[aor\_telekom\]
type \= aor
contact \= sip:@tel.t-online.de
\[id\_telekom\]
type \= identify
match \= tel.t-online.de
endpoint \= in\_telekom
\[in\_telekom\]
type \= endpoint
context \= lantiq1\_inbound
disallow \= all
allow \= alaw,g722,ulaw
disable\_direct\_media\_on\_nat \= yes
rewrite\_contact \= yes
\[out\_telekom\]
type \= endpoint
disallow \= all
allow \= alaw,g722,ulaw
disable\_direct\_media\_on\_nat \= yes
callerid \=
from\_user \=
from\_domain \= tel.t-online.de
outbound\_auth \= auth\_telekom
aors \= aor\_telekom
_**Important!** Enable Telekom DNS server for \*t-online.de:_
`uci add_list dhcp.@dnsmasq[0].server=“/t-online.de/1.1.1.1”`
`uci commit dhcp`
`service dnsmasq restart`
### extensions.conf
[https://docs.asterisk.org/Configuration/Dialplan/](https://docs.asterisk.org/Configuration/Dialplan/ "https://docs.asterisk.org/Configuration/Dialplan/")
Example for Vodafone Germany:
[extensions.conf](https://openwrt.org/_export/code/docs/guide-user/services/voip/asterisk?codeblock=4 "Download Snippet")
\[general\]
static\=yes
writeprotect\=yes
autofallthrough\=yes
\[default\]
exten \=\> \_X.,1,Answer()
same \=\> n,Verbose(1,${CALLERID(num)} reached context DEFAULT by calling ${EXTEN})
same \=\> n,Hangup()
\[out\_arcor\]
; national numbers with country code
exten \=\> \_+49ZXX!.,1,Dial(PJSIP/${EXTEN}@out\_arcor,60,Trg)
same \=\> n,Hangup()
; national numbers called with leading 0
exten \=\> \_0Z.,1,Dial(PJSIP/${EXTEN}@out\_arcor,60,Trg)
same \=\> n,Hangup()
; local area numbers
exten \=\> \_Z.,1,Dial(PJSIP/${EXTEN}@out\_arcor,60,Trg)
same \=\> n,Hangup()
; emergency calls
exten \=\> 110,1,Dial(PJSIP/${EXTEN}@out\_arcor,60,Trg)
exten \=\> 110,n,Hangup()
exten \=\> 112,1,Dial(PJSIP/${EXTEN}@out\_arcor,60,Trg)
exten \=\> 112,n,Hangup()
; add rules for expensive special numbers. Get German examples from:
; https://www.linuxmaker.com//asterisk-pbx/dialplan-extensionsconf.html
exten \=\> \_0137Z.,1,Verbose(1,Blocked: ${EXTEN})
;same => n,Playback(forbidden)
same \=\> n,Hangup()
\[lantiq1\_inbound\]
exten \=\> ,1,Dial(TAPI/1,60,t)
same \=\> n,Hangup()
\[lantiq1\]
include \=\> out\_arcor
;\[lantiq2\]
;include => ltq2\_out
Just change arcor to telekom if you want to use it. Check on your router both ports for telephony in order to get the right one.
### indications.conf
[https://docs.asterisk.org/Configuration/Core-Configuration/Configuring-Localized-Tone-Indications/](https://docs.asterisk.org/Configuration/Core-Configuration/Configuring-Localized-Tone-Indications/ "https://docs.asterisk.org/Configuration/Core-Configuration/Configuring-Localized-Tone-Indications/")
Example for Vodafone Germany:
[indications.conf](https://openwrt.org/_export/code/docs/guide-user/services/voip/asterisk?codeblock=5 "Download Snippet")
\[general\]
country\=de
### lantiq.conf
If you plan to use Asterisk on a Lantiq device, see [chan-lantiq](https://openwrt.org/docs/guide-user/services/voip/chan-lantiq "docs:guide-user:services:voip:chan-lantiq")
for detailed configuration examples.
[lantiq.conf](https://openwrt.org/_export/code/docs/guide-user/services/voip/asterisk?codeblock=6 "Download Snippet")
\[interfaces\]
channels \= 2
per\_channel\_context \= on
`per_channel_context = on` is important, as it will place calls from the Lantiq FXS ports in contexts `lantiq1` and `lantiq2` instead of `default`, which should be avoided.
### SQM/QoS
For VoIP you will need some form of traffic shaping to reduce latency. On OpenWrt the best choice is using [SQM with cake](https://openwrt.org/docs/guide-user/network/traffic-shaping/sqm "docs:guide-user:network:traffic-shaping:sqm")
. To prioritize VoIP traffic choose `layer_cake.qos` as the queue setup script. For more details read [this forum thread](https://forum.openwrt.org/t/simple-qos-for-voip/10382 "https://forum.openwrt.org/t/simple-qos-for-voip/10382")
.
More information on TOS/CoS values can be found in the [IP QoS article](https://docs.asterisk.org/Configuration/Channel-Drivers/IP-Quality-of-Service/ "https://docs.asterisk.org/Configuration/Channel-Drivers/IP-Quality-of-Service/")
on the Asterisk documentation.
Asterisk GUI
------------
A GUI in LuCI is provided through [luci-app-asterisk](https://openwrt.org/packages/pkgdata/luci-app-asterisk "packages:pkgdata:luci-app-asterisk")
package, however it's been deprecated since Asterisk 17.
Asterisk CLI
------------
[Asterisk provides its own CLI](https://docs.asterisk.org/Operation/Asterisk-Command-Line-Interface/ "https://docs.asterisk.org/Operation/Asterisk-Command-Line-Interface/")
, which is especially useful for debugging. Execute `asterisk -r`, to connect to a already running Asterisk server.
Commands follow a general syntax of ``. The CLI supports command-line completion using the `` key.
You can stop the service `/etc/init.d/asterisk stop` and run the verbose CLI `asterisk -cvvvvv` while setting up the system.
### Increasing the log level
To see what's going on during a call run the following command inside the Asterisk CLI:
core set verbose 3
After that run `module reload logger` and make a call. To get even more verbose information, you can execute the following commands ( enabling all of them will produce a lot of output!):
core set verbose 5
core set debug 5
pjsip set logger on
rtp set debug on
### Other useful commands
dialplan show
pjsip show endpoints
pjsip show endpoint
pjsip show registration
During a call:
core show channels
core show channel
### Executing commands from outside the CLI
You can execute Asterisk commands from outside the CLI, for example to control the Asterisk server via a shell script:
asterisk -rx "pjsip show endpoints"
Finding further information about Asterisk
------------------------------------------
* The first place to look for information is [the Asterisk documentation](https://docs.asterisk.org/ "https://docs.asterisk.org/")
* Another great resource is _The Asterisk Book_. It's about an older Asterisk version, but explains the core principles in a very profound way: [English version](http://the-asterisk-book.com/ "http://the-asterisk-book.com/")
, [German version](http://das-asterisk-buch.de/ "http://das-asterisk-buch.de/")
* [Official Asterisk forum](https://community.asterisk.org/ "https://community.asterisk.org/")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/22 15:42
* by sebastian
[](https://openwrt.org/docs/guide-user/services/voip/asterisk#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Tor
Tor
===
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
==========================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[Additional services](https://openwrt.org/docs/guide-user/services/start "docs:guide-user:services:start")
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
#### [](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « docs » section at the top...")
[Tor](https://openwrt.org/docs/guide-user/services/tor/start "docs:guide-user:services:tor:start")
* [Tor client](https://openwrt.org/docs/guide-user/services/tor/client "docs:guide-user:services:tor:client")
* [Tor extras](https://openwrt.org/docs/guide-user/services/tor/extras "docs:guide-user:services:tor:extras")
[](https://openwrt.org/docs/guide-user/services/tor/start#top-1337222372 "Continue with the « » section at the top...")
##### ...
* [Tor onion services](https://openwrt.org/docs/guide-user/services/tor/hs "docs:guide-user:services:tor:hs")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/02 17:11
* by vgaetera
[](https://openwrt.org/docs/guide-user/services/tor/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Set up a LAMP webserver stack
Set up a LAMP webserver stack
=============================
Read here: [LAMP (software bundle)](https://en.wikipedia.org/wiki/LAMP%20(software%20bundle) "https://en.wikipedia.org/wiki/LAMP (software bundle)")
about the concept. This guide provides step by step instructions for installing a full featured LAMP stack on OpenWrt.
| Service | Examples | Description |
| --- | --- | --- |
| [Web server](https://openwrt.org/docs/guide-user/services/webserver/start "docs:guide-user:services:webserver:start") | [uHTTPd](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd") | OpenWrt's in-house server, used by default for the WebUI LuCI |
| [Lighttpd](https://openwrt.org/docs/guide-user/services/webserver/lighttpd "docs:guide-user:services:webserver:lighttpd") | Lightweight and flexible, many addons |
| [Apache](https://openwrt.org/docs/guide-user/services/webserver/http.apache "docs:guide-user:services:webserver:http.apache") | Powerful and widely used |
| [Nginx](https://openwrt.org/docs/guide-user/services/webserver/nginx "docs:guide-user:services:webserver:nginx") | Aimed at good performance, low memory |
| [Database server](https://openwrt.org/doc/howto/database.overview "doc:howto:database.overview") | [MySQL](https://openwrt.org/doc/howto/database.mysql "doc:howto:database.mysql") | Widely used SQL server |
| [PostgreSQL](https://openwrt.org/doc/howto/database.postgresql "doc:howto:database.postgresql") | Another popular SQL server |
| [SQLite](https://openwrt.org/doc/howto/database.sqlite "doc:howto:database.sqlite") | Easy to use SQL _library_ for low powered devices, runs within process |
| [Scripting language](https://openwrt.org/doc/howto/scripting.overview "doc:howto:scripting.overview") | [php](https://openwrt.org/docs/guide-user/services/webserver/php "docs:guide-user:services:webserver:php") | Specially designed for making websites |
| [perl](https://openwrt.org/doc/howto/perl "doc:howto:perl") | Flexible high level general purpose language |
| [python](https://openwrt.org/doc/howto/python "doc:howto:python") | Another high level scripting language |
Basic System Configuration
--------------------------
This article is a collection of examples of the configuration and integration of web servers, database servers and scripting languages, i.e. LAMP. For each example we assume to be creating a web page with `/srv/www/` as the document root and assume an otherwise standard OpenWrt configuration. Note that it currently has a lot of overlap with the main articles for the respective services.  It should be made more to the point and only about installing and especially integrating these services.
Installing and configuring a web server
---------------------------------------
You might already have a web server for the [Web UI](https://openwrt.org/docs/guide-user/luci/webinterface.overview "docs:guide-user:luci:webinterface.overview")
installed and running. Choose any of the available WebServer for this purpose: [webserver](https://openwrt.org/docs/guide-user/services/webserver/start "docs:guide-user:services:webserver:start")
. If the web server is not in the [OpenWrt packet repository](https://openwrt.org/packages/start "packages:start")
, you could always [crosscompile](https://openwrt.org/docs/guide-developer/toolchain/crosscompile "docs:guide-developer:toolchain:crosscompile")
it from source.
### uHTTPd
→ [http.uhttpd](https://openwrt.org/docs/guide-user/services/webserver/http.uhttpd "docs:guide-user:services:webserver:http.uhttpd")
is an in-house web server under BSD-license. [LuCI WebUI](https://openwrt.org/docs/guide-user/luci/luci.essentials "docs:guide-user:luci:luci.essentials")
already uses this. If uHTTPd is not already installed you can install it with:
opkg update
opkg install uhttpd
The default image runs a WebUI for OpenWrt on port 80 (HTTP) and port 443 (HTTPS). For our PHP5 enabled uHTTPd web server we start a new uHTTPd instance on a different port. We use port 81 here.
uci set uhttpd.llmp=uhttpd
uci set uhttpd.llmp.listen\_http=81
uci set uhttpd.llmp.home=/srv/www
uci commit uhttpd
Create a directory for our web server content
mkdir -p $(uci get uhttpd.llmp.home)
If uHTTPd was already installed and running restart it now with
/etc/init.d/uhttpd restart
If you installed uHTTPd via opkg start the web server manually and also at boot by enabling the init script
/etc/init.d/uhttpd start
/etc/init.d/uhttpd enable
Further configuration can also be performed manually, e.g. to enable php. [uhttpd](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
### Lighttpd
→ [lighttpd](https://openwrt.org/docs/guide-user/services/webserver/lighttpd "docs:guide-user:services:webserver:lighttpd")
is a lightweight and very flexible web server with lots of additional modules available.
opkg update
opkg install lighttpd lighttpd-mod-cgi
Edit `/etc/lighttpd/lighttpd.conf` and change a few settings:
Enable CGI:
server.modules = (
"mod\_cgi"
)
Set the document root and the port for our example:
server.document-root = "/srv/www/"
server.port = 81
Edit `/etc/php.ini` and set the document root here as well (or leave it empty, in which case it allows PHP serving anywhere outside the docroot):
doc\_root = "/srv/www"
Create a directory for our web server content:
mkdir \-p /srv/www
Start the server manually and also at boot by enabling the init script
/etc/init.d/lighttpd start
/etc/init.d/lighttpd enable
### Nginx
→ [nginx](https://openwrt.org/docs/guide-user/services/webserver/nginx "docs:guide-user:services:webserver:nginx")
is nice as well.
### Apache
→ [http.apache](https://openwrt.org/docs/guide-user/services/webserver/http.apache "docs:guide-user:services:webserver:http.apache")
is nice as well.
### Testing the web server
Create a little test web page, e.g. `/srv/www/index.html`:
echo "
apt install atftpd | Install atftpd from repository on RedHat/Fedora/Centos:
yum install atftpd |
Create directory where you want to put the recovery image file:
mkdir /srv/tftp
Put an image file into your directory - actual name will vary:
cp ~/tp\_recovery.bin /srv/tftp
Change the ownership of the folder and the file in it:
chown nobody:nogroup \-R /srv/tftp
Run TFTP server (run as daemon, do not fork, log events to stdout):
atftpd \--daemon \--no-fork \--logfile - /srv/tftp
Check if your TFTP server is listening:
netstat \-lunp | grep 69
Or if netstat is not available:
ss \-lunp | grep 69
* _If not set, you should try running TFTP server as superuser._
#### Testing TFTP server (on Linux):
**Check that you can in fact pull the file from your TFTP server.** Preferably from another computer call your TFTP server IP: (_or if not possible, in same server call IP 127.0.0.1_):
tftp 192.168.0.66
tftp\> get tp\_recovery.bin
Received 8152633 bytes in 0.8 seconds
tftp\> quit
If you have received the file, congratulations, it's ready.
Troubleshooting steps
---------------------
TFTP file transfer doesn't work from local computer
* Check if your TFTP server is running and listening
* Check if TFTP folder is set up correctly (location, access rights)
* Check if firmware file is set up correctly (location, access rights)
TFTP file transfer works from local computer, but not from another computer:
* Check if network cable is connected properly
* Check if server IP is set correctly
* Check that you have opened up UDP 69 traffic from the local subnet in the host firewall.
* Restart the server if you have just changed the local host IP address.
* Run a packet sniffing tool like [Wireshark](https://www.wireshark.org/ "https://www.wireshark.org/")
, while using `tftp` as the display filter.
TFTP file transfer works from another computer, but not from router:
* Check if server IP is set correctly (same as router is searching for)
* Check that the host running the TFTP server is using the specific fixed IP address and subnet mask that your router is expecting to use.
* Try using alternate cable, a crossover cable or alternate switch/speed
* Try connecting to an alternate port on the router / routers switch
* Pay attention to any output or verbosity from the router console or led activity if available
* Verify the arp cache on either host... server side is easier...
* Use arp -s to add a static mapping or arp -d to delete stale entries...
* Use a third host to simply ping the router, both with static addresses if possible
* Try an alternate server software, client software or TFTP transfer mode
* If you get some activity, timing can often yield results, power cycle the router and start the transfer earlier or later...
* Check that you have downloaded a firmware image that contains “tftp” in its filename, and that you have renamed this file to the specific OEM filename that your router is expecting.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/12/04 20:15
* by stokito
[](https://openwrt.org/docs/guide-user/troubleshooting/tftpserver#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt as DomU in Debian Xen4 in a private network
OpenWrt as DomU in Debian Xen4 in a private network
===================================================
Based on this other wiki article: [xen](https://openwrt.org/docs/guide-user/virtualization/xen "docs:guide-user:virtualization:xen")
The main point of this howto is the network configuration. We are using a dummy0 device from dom0 to communicate with domU openwrt nodes. So the domU network will be isolated from the real one. If we want to provide internet to nodes, we can use NAT from dom0.
* Install Debian Squeeze on the computer
* Install Xen (package version could vary)
aptitude install linux-image-2.6.32-5-xen-amd64 xen-hypervisor-4.0-amd64 xen-tools xen-utils-4.0 bridge-utils
* Update grub2 and reboot
mv /etc/grub.d/10\_linux /etc/grub.d/50\_linux
update-grub2
reboot
* Configure file `/etc/xen/xend-config.sxp`:
(network-script network-custom)
(vif-script vif-custom)
And comment the rest about network and vif
* Create the scripts
`/etc/xen/scripts/network-custom`
#!/bin/sh
dir=$(dirname "$0")
"$dir/network-route" "$@" netdev=eth0
"$dir/network-bridge" "$@" netdev=dummy0
`/etc/xen/scripts/vif-custom`
#!/bin/sh
dir=$(dirname "$0")
IFNUM=$(echo ${vif} | awk -F. '{ print $2 }')
if \[\[ "$IFNUM" == "0" \]\] ; then
"$dir/vif-route" "$@"
else
"$dir/vif-bridge" "$@"
fi
* Configure networking in `/etc/network/interfaces`:
auto dummy0
iface dummy0 inet static
address 192.168.1.254
netmask 255.255.255.0
* Compile OpenWrt for _x86_ and _XEN_ target (consult [OpenWrt Buildroot – Usage](https://openwrt.org/docs/guide-developer/toolchain/start "docs:guide-developer:toolchain:start")
)
* Example of xen domU configuration
memory = 256
name = "25"
kernel = "/root/VM/25/openwrt-x86-xen\_domu-vmlinuz"
disk = \["file:///root/VM/25/openwrt-x86-xen\_domu-rootfs-ext4.img,xvda2,w"\]
vif = \[ 'mac=00:16:3E:6:11:2' \]
vcpus = 1
on\_reboot = 'restart'
on\_crash = 'destroy'
root = '/dev/xvda2 rw'
* Start domU
xm create xen\_domU.conf -c
Script to manage nodes
----------------------
Using this system you will be able to create as nodes you need using just one command.
**Create needed directories**
cd /root/
mkdir VM
mkdir config
mkdir images
**Create this two files:**
* config/network
config interface loopback
option ifname lo
option proto static
option ipaddr 127.0.0.1
option netmask 255.0.0.0
config interface lan
option ifname eth0
option proto static
option ipaddr 192.168.1.#ID
option netmask 255.255.255.0
* config/template.conf
memory = 256
name = "#ID"
kernel = "/root/VM/#PROFILE/#ID/kernel.img"
disk = \["file:///root/VM/#PROFILE/#ID/fs.img,xvda2,w"\]
vif = \[ 'mac=00:16:3E:#R1:#R2:#R3' \]
vcpus = 1
on\_reboot = 'restart'
on\_crash = 'destroy'
root = '/dev/xvda2 rw'
**Put these two images from OpenWrt buildroot inside images directory**
mv openwrt-x86-xen\_domu-rootfs-ext4.img images/fs.img
mv openwrt-x86-xen\_domu-vmlinuz images/kernel.img
**Copy this script to /root/manage\_nodes.sh**
#!/bin/bash
CONFIG="config/template.conf"
NETWORK="config/network"
IMAGE\_DIR="images"
IMAGE\_FS="fs.img"
IMAGE\_KR="kernel.img"
VM\_DIR="VM"
MNT="/mnt"
CURRENT\_PROFILE=".xmn\_profile"
PROFILE="default"
function new\_node {
R1=\`echo $RANDOM%16 | bc\`
R2=\`echo $RANDOM%16 | bc\`
R3=\`echo $RANDOM%16 | bc\`
ID=\`echo $RANDOM%100 | bc\`
mkdir -p $VM\_DIR/$PROFILE/$ID
cat $CONFIG | sed -e s/#ID/$ID/g -e s/#PROFILE/$PROFILE/g \\
-e s/#R1/$R1/g -e s/#R2/$R2/g -e s/#R3/$R3/g > $VM\_DIR/$PROFILE/$ID/xen.conf
cp -f $IMAGE\_DIR/$PROFILE/$IMAGE\_FS $VM\_DIR/$PROFILE/$ID/
cp -f $IMAGE\_DIR/$PROFILE/$IMAGE\_KR $VM\_DIR/$PROFILE/$ID/
config\_network $ID
start\_node $ID
}
function rm\_node {
read -p "Are you sure you want do destroy node $1? \[y|N\] " q
\[ "$q" == "y" \] && rm -rf $VM\_DIR/$PROFILE/$1
}
function rm\_all {
read -p "Are you sure you want do destroy all nodes from profile $PROFILE? \[y|N\] " q
\[ "$q" == "y" \] && { stop\_all ; rm -rf $VM\_DIR/$PROFILE/\*; }
}
function multiple\_node {
\[ -z "$1" \] && { echo "Please, specify the number of nodes you wan to create"; exit 1;}
for i in $(seq 1 $1); do
echo "Creating node $i"
new\_node
sleep 3
done
}
function config\_network {
mount $VM\_DIR/$PROFILE/$1/$IMAGE\_FS $MNT -o loop
\[ $? -ne 0 \] && { echo "Cannot mount image!"; exit 1;}
cat $NETWORK | sed s/#ID/$1/g > /mnt/etc/config/network
umount $MNT
}
function dom0\_network {
ip tuntap add mode tap
brctl addbr br0
brctl addif br0 tap0
ifconfig tap0 0.0.0.0 promisc
ifconfig br0 192.168.1.254
}
function start\_node {
xm create $VM\_DIR/$PROFILE/$1/xen.conf
if \[ $? -eq 0 \]; then
echo "New node with ID $1 has been created"
else
echo "Some problem starting node, check previous log"
fi
}
function list\_nodes {
ls $VM\_DIR/$PROFILE/
}
function start\_all {
for m in $(ls $VM\_DIR/$PROFILE/); do
start\_node $m
done
}
function stop\_node {
xm destroy $1 2>/dev/null
}
function stop\_all {
for m in $(ls $VM\_DIR/$PROFILE/); do
xm destroy $m 2>/dev/null
done
}
function new\_profile {
profile="$1"
\[ -z "$profile" \] && { echo "You must specify profile name" ; help; }
\[ -d "$VM\_DIR/$profile" \] && { echo "Profile $profile exists, please remove it"; exit 1; }
mkdir -p $VM\_DIR/$profile
mkdir -p $IMAGE\_DIR/$profile
cp -f $IMAGE\_DIR/$IMAGE\_FS $IMAGE\_DIR/$profile/
cp -f $IMAGE\_DIR/$IMAGE\_KR $IMAGE\_DIR/$profile/
echo "New profile $profile successful created. Now you can use it: $0 profile $profile"
}
function profile {
profile="$1"
\[ -z "$profile" \] && { echo "You must specify profile name" ; help; }
\[ ! -d "$VM\_DIR/$profile" \] && { echo "This profile does not exist, please create it using: $0 new\_profile $profile"; exit 1; }
echo "$profile" > $CURRENT\_PROFILE
echo "Active profile is now $profile"
}
function rm\_profile {
\[ -z "$1" \] && help
read -p "Are you sure you want do destroy profile $1? \[y|N\] " q
\[ "$q" == "y" \] && { rm -rf $VM\_DIR/$1; rm -rf $IMAGE\_DIR/$1; }
echo "Profile $1 removed"
}
function show\_profile {
echo "Current profile is: $PROFILE"
}
function list\_profiles {
ls $VM\_DIR/
}
function help {
echo "Usage: $0 option \[arguments\]"
echo ""
echo "Available options are:"
echo ""
echo " profile : Select profile "
echo " new\_profile : Create a new profile "
echo " show\_profile : Show current profile"
echo " list\_profiles : List all available profiles"
echo " rm\_profile : Remove profile and all related files"
echo ""
echo " new\_node : Create a new node"
echo " rm\_node : Remove the node with name ID"
echo " rm\_all : Remove all nodes from current profile"
echo " multiple\_node <#n> : Create #n nodes"
echo " list\_nodes : List all nodes from current profile"
echo ""
echo " start\_node <#n> : Start node with ID #n"
echo " start\_all : Start all nodes from current profile"
echo " stop\_node <#n> : Stop node with ID #n"
echo " stop\_all : Stop all nodes"
echo ""
echo "The images used for new virtual machines are placed in $IMAGE\_DIR/\[CURRENT\_PROFILE\]/"
exit 0
}
\[ -z "$1" \] && help
\[ -f "$CURRENT\_PROFILE" \] && PROFILE="$(cat $CURRENT\_PROFILE)"
$1 $2 $3 $4 $5
Now you can execute it using bash to see help
root@p4u:~# bash manage\_nodes.sh
Usage: ./manage\_nodes.sh option \[arguments\]
Available options are:
profile : Select profile
new\_profile : Create a new profile
show\_profile : Show current profile
list\_profiles : List all available profiles
rm\_profile : Remove profile and all related files
new\_node : Create a new node
rm\_node : Remove the node with name ID
rm\_all : Remove all nodes from current profile
multiple\_node <#n> : Create #n nodes
list\_nodes : List all nodes from current profile
start\_node <#n> : Start node with ID #n
start\_all : Start all nodes from current profile
stop\_node <#n> : Stop node with ID #n
stop\_all : Stop all nodes
The images used for new virtual machines are placed in images/\[CURRENT\_PROFILE\]/
For instance, to create 10 nodes just use:
./manage\_nodes.sh new\_profile p4u
./manage\_nodes.sh profile p4u
./manage\_nodes.sh multiple\_node 10
You can see them using “xm list”. The name (ID), is the last IP digit for each one, so node 67 will be 192.168.1.67
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/10/15 09:06
* by bobafetthotmail
[](https://openwrt.org/docs/guide-user/virtualization/xen_debian_private_network#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt as QEMU/KVM host server
OpenWrt as QEMU/KVM host server
===============================
Introduction
------------
It's possible to use OpenWrt as a QEMU host and run guests on it. If you want to run OpenWrt as a QEMU guest itself, see [OpenWrt in QEMU](https://openwrt.org/docs/guide-user/virtualization/qemu "docs:guide-user:virtualization:qemu")
.
OpenWrt provides QEMU packages for ARM and x86 platforms. This article focuses on the x86 target, the networking is done via [qemu-bridge-helper](https://wiki.qemu.org/Features/HelperNetworking "https://wiki.qemu.org/Features/HelperNetworking")
.
Installing QEMU
---------------
You need the following packages on your device: [kmod-tun](https://openwrt.org/packages/pkgdata/kmod-tun "packages:pkgdata:kmod-tun")
, [qemu-bridge-helper](https://openwrt.org/packages/pkgdata/qemu-bridge-helper "packages:pkgdata:qemu-bridge-helper")
. Depending on the guest architecture, install [qemu-x86\_64-softmmu](https://openwrt.org/packages/pkgdata/qemu-x86_64-softmmu "packages:pkgdata:qemu-x86_64-softmmu")
or [qemu-arm-softmmu](https://openwrt.org/packages/pkgdata/qemu-arm-softmmu "packages:pkgdata:qemu-arm-softmmu")
. If your hardware supports it, also install [kmod-kvm-amd](https://openwrt.org/packages/pkgdata/kmod-kvm-amd "packages:pkgdata:kmod-kvm-amd")
or [kmod-kvm-intel](https://openwrt.org/packages/pkgdata/kmod-kvm-intel "packages:pkgdata:kmod-kvm-intel")
for better performance.
Example for an Intel system and a x86\_64 guest:
opkg install kmod-tun qemu-bridge-helper qemu-x86\_64-softmmu kmod-kvm-intel
After the first installation, reboot your device.
Running a guest
---------------
For the guest OS, use a distribution that comes with virtio drivers by default (Debian or Fedora for example).
Installing a guest OS
---------------------
If you don't have a prepared disk image, you can install a guest OS directly on your OpenWrt device. There are several guides available on how to install a Linux distribution on a QEMU image: [Debian](https://wiki.debian.org/QEMU#Setting_up_a_stable_system "https://wiki.debian.org/QEMU#Setting_up_a_stable_system")
for example. A quick way is to install Debian using the kernel and initrd of a Debian netboot installer.
### Create a disk image
qemu-img create \-f qcow2 debian.img 4G
More details on disk images: [https://en.wikibooks.org/wiki/QEMU/Images](https://en.wikibooks.org/wiki/QEMU/Images "https://en.wikibooks.org/wiki/QEMU/Images")
### Download installer files
wget https://ftp.debian.org/debian/dists/stable/main/installer-amd64/current/images/netboot/debian-installer/amd64/linux
wget https://ftp.debian.org/debian/dists/stable/main/installer-amd64/current/images/netboot/debian-installer/amd64/initrd.gz
Both files can be safely removed after finishing the installation.
### Run the installer
Edit the init script, add the options `display`, `vnc` and `cdrom` to the qemu command as mentioned in the comments in the script. Start the service as normal (`/etc/init.d/kvm-pihole start`). Connect over VNC to see the console and proceed with the installation. When finished, if the VM does not shut itself down, stop it with `/etc/init.d/kvm-pihole stop`. Follow the installation instructions and install GRUB on `/dev/vda`. It's also useful to install sshd (enabled by default).
### Run the new guest
After finishing the installation, you can remove those special options (display, vnc and cdrom). You can also delete the ISO if you don't need it anymore. Start the VM again. You should now be able to reach the VM via SSH from within `br-lan`. If you want to control the VM using the command line, you have to enable a serial console. To do this, edit the GRUB entry during boot and add `console=ttyS0` to the kernel command line. After the VM finished booting, edit `/etc/default/grub` and add `console=ttyS0` to `GRUB_CMDLINE_LINUX_DEFAULT` as well. After that run `update-grub`. To connect to the console, you can use: `socat STDIO,cfmakeraw,escape=0x1d UNIX:`.
Init script
-----------
Here is an example [init script](https://openwrt.org/docs/techref/initscripts "docs:techref:initscripts")
you can use. This is an example for PiHole, rename the script and the UNITNAME variable if needed. It connects to [QMP](https://wiki.qemu.org/Documentation/QMP "https://wiki.qemu.org/Documentation/QMP")
to cleanly shutdown the vm when you stop it.
Be careful with copying the heredoc part. This code block is left unindented on purpose to avoid problems with whitespaces. If you want, you can indent the lines with tabs and use `<<-QMP` instead of `<'
\# to install the first time, add these options:
#-vnc :0 \\
#-cdrom /storage/vms/ubuntu-24.04.1-live-server-amd64.iso \\
start\_service() {
procd\_open\_instance
procd\_set\_param command qemu-system-x86\_64 \\
\-enable-kvm \\
\-display none \\
\-cpu host \\
\-machine type\=q35,accel\=kvm \\
\-smp "$CPUS" \\
\-m "$MEM" \\
\-boot c \\
\-drive file\="$DISKIMAGE",cache\=none,if\=virtio,format\="$DISKFORMAT" \\
\-netdev bridge,br\="$NETBRIDGE",id\=lan \\
\-device virtio-net-pci,mac\="$NETMAC",netdev\=lan \\
\-object rng-random,id\=rng0,filename\=/dev/urandom \\
\-device virtio-rng-pci,rng\=rng0 \\
\-qmp unix:$QMPSOCKET,server,nowait \\
\-serial unix:$SERIALSOCKET,server,nowait
#procd\_set\_param respawn ${respawn\_threshold:-3600} ${respawn\_timeout:-5} ${respawn\_retry:-5}
#procd\_set\_param netdev dev
procd\_set\_param stdout 0
procd\_set\_param stderr 0
procd\_set\_param user root
procd\_set\_param pidfile $PIDFILE
procd\_set\_param term\_timeout 60
procd\_close\_instance
}
stop\_service() {
\# try to gracefully shut down VM before procd kills qemu
cmd\="sexpect -sock $SEXPECTSOCKET"
$cmd spawn \-timeout 5 \-autowait socat - unix-connect:$QMPSOCKET
$cmd expect 'QMP'
$cmd send \-enter '{ "execute": "qmp\_capabilities" }'
$cmd expect 'return'
$cmd send \-enter '{ "execute": "system\_powerdown" }'
$cmd expect 'SHUTDOWN'
$cmd wait
}
Test the the script by running `/etc/init.d/kvm-pihole start` and look for errors in `/var/log/qemu.log`. If the script works as desired, enable it for every boot: `/etc/init.d/kvm-pihole enable`
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/02/02 18:00
* by token47
[](https://openwrt.org/docs/guide-user/virtualization/qemu_host#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Podman Containers
Podman Containers
=================
I recently went through the process of getting **Podman** running properly on **OpenWrt 24.10.2** and configuring it to behave well with OpenWrt’s native networking, firewall setup and daemon startup and configuration logic. Since some of the information at [https://openwrt.org/docs/guide-user/virtualization/docker\_host](https://openwrt.org/docs/guide-user/virtualization/docker_host "https://openwrt.org/docs/guide-user/virtualization/docker_host")
was outdated, I’ve updated parts of it there, and I'm sharing this more complete guide here as well, for those who want a more practical walkthrough.
* * *
Installing Podman
-----------------
First, install Podman using
opkg install podman
It will pull in a number of dependencies, including networking tools and container runtimes.
* * *
Basic Configuration
-------------------
### Storage Setup
Update Podman’s storage path to point to a disk with enough space, this folder, depending how careful you'll select containers, will tend to take quite some space:
/etc/containers/storage.conf
graphroot = "/home/podman/storage"
Then create the directory:
mkdir -p /home/podman/storage
* * *
### Regular Cleanup
Add cleanup tasks to cron:
crontab -e
Add:
\# Podman cleanup
10 0 \* \* 0 /usr/bin/podman system prune --volumes -f > /dev/null 2>&1
20 0 \* \* 0 /usr/bin/podman image prune -a -f > /dev/null 2>&1
* * *
### Networking Setup
We want Podman to use a static bridge and be fully manageable by OpenWrt’s network config and firewall. Here’s how to set it up:
/etc/containers/networks/podman.json
{
"name": "podman",
"driver": "bridge",
"network\_interface": "podman0",
"subnets": \[\
{\
"subnet": "192.168.11.0/24",\
"gateway": "192.168.11.1"\
}\
\],
"ipv6\_enabled": false,
"internal": false,
"dns\_enabled": true,
"ipam\_options": {
"driver": "host-local"
}
}
/etc/containers/containers.conf
\[network\]
network\_backend = "netavark"
firewall\_driver = "none"
network\_config\_dir = "/etc/containers/networks/"
default\_network = "podman"
default\_subnet = "192.168.11.0/24"
default\_rootless\_network\_cmd = "slirp4netns"
/etc/config/network
config device
option type 'bridge'
option name 'podman0'
option bridge\_empty '1'
option ipv6 '0'
config interface 'podman0'
option proto 'static'
option device 'podman0'
option ipaddr '192.168.11.1'
option netmask '255.255.255.0'
/etc/config/firewall
Be careful that zone names for other zones must match your configuration
config zone
option name 'Podman'
option input 'DROP'
option output 'ACCEPT'
option forward 'REJECT'
list network 'podman0'
config forwarding
option src 'Podman'
option dest 'Internet'
config forwarding
option src 'lan'
option dest 'Podman'
config rule
option name 'DNS to Podman'
option src 'Podman'
option dest\_port '53'
option target 'ACCEPT'
* * *
### Giving Access to Container Ports
Since we're using 'firewall\_driver = “none”' Podman won't open ports automatically. If a container needs to be reachable, you'll need to manually create rules. For this reason I am explicitly adding an IP to each container, more of this later.
Example:
config rule
option src 'VPN'
option name 'NRPE to Nagios'
option dest\_port '5666'
option target 'ACCEPT'
list proto 'tcp'
list src\_ip '192.168.0.5'
option dest 'Podman'
config redirect
option dest 'Podman'
option target 'DNAT'
option name 'Serve NRPE from container'
option family 'ipv4'
list proto 'tcp'
option src 'VPN'
option src\_dport '5666'
option dest\_ip '192.168.11.2'
option dest\_port '5666'
option src\_ip '192.168.0.5'
* * *
Podman Init Script
------------------
Here’s how I run containers at boot using an init script. The set of parameters it understands is basic, and it's not smart when it comes to enforce containers to have name and images, but it's good enough for me and easy to mod in case needed. It is configurable via ^ /etc/config/containers ^ and is pretty flexible.
### /etc/init.d/containers
#!/bin/sh /etc/rc.common
START=90
STOP=20
USE\_PROCD=1
NAME=containers
PROG=/usr/bin/podman
. /lib/functions.sh
start\_service() {
# At boot time, wait longer for dependencies
local max\_wait=60
local count=0
logger -t "$NAME" "Waiting for system readiness"
# Wait for basic system services
while \[ $count -lt $max\_wait \]; do
# Check if essential services are ready
if \[ -S /var/run/ubus/ubus.sock \] && pgrep -f "ubusd" >/dev/null && \\
\[ -d /sys/class/net \] && $PROG system info >/dev/null 2>&1; then
break
fi
sleep 1
count=$((count + 1))
done
if \[ $count -ge $max\_wait \]; then
logger -t "$NAME" "Timeout waiting for system services and podman to be ready"
return 1
fi
logger -t "$NAME" "Starting containers service"
config\_load containers
config\_foreach start\_container container
}
start\_container() {
local cfg="$1" enabled name
config\_get enabled "$cfg" enabled 0
config\_get privileged "$cfg" privileged 0
config\_get name "$cfg" name "$cfg"
config\_get image "$cfg" image "$cfg"
config\_get dns "$cfg" dns ""
config\_get hostname "$cfg" hostname ""
config\_get image "$cfg" image ""
config\_get ip "$cfg" ip ""
config\_get memory "$cfg" memory ""
config\_get pid "$cfg" pid ""
config\_get pull "$cfg" pull "missing"
config\_get restart "$cfg" restart ""
caps=""
append\_cap() {
caps="$caps --cap-add=$1"
}
config\_list\_foreach "$cfg" cap append\_cap
envs=""
append\_env() {
envs="$envs -e $1"
}
config\_list\_foreach "$cfg" env append\_env
vols=""
append\_vol() {
vols="$vols -v $1"
}
config\_list\_foreach "$cfg" volume append\_vol
\[ "$enabled" -eq 0 \] && return 0
logger -t "$NAME" "Starting container $name"
logger -t "$NAME" "Pulling latest version for $name - $image"
$PROG pull $image >/dev/null 2>&1 || logger -t "$NAME" "Pulling failed for $image"
# Build the Podman command
podman\_cmd="$PROG run -d"
\[ -n "$dns" \] && podman\_cmd="$podman\_cmd --dns $dns"
\[ -n "$hostname" \] && podman\_cmd="$podman\_cmd --hostname $hostname"
\[ -n "$ip" \] && podman\_cmd="$podman\_cmd --ip $ip"
\[ -n "$memory" \] && podman\_cmd="$podman\_cmd --memory $memory"
\[ -n "$pid" \] && podman\_cmd="$podman\_cmd --pid $pid"
\[ -n "$restart" \] && podman\_cmd="$podman\_cmd --restart $restart"
\[ "$privileged" -eq 1 \] && podman\_cmd="$podman\_cmd --privileged"
podman\_cmd="$podman\_cmd $envs $vols $caps --name $name $image"
logger -t "$NAME" "Running '$podman\_cmd'"
procd\_open\_instance "$name"
procd\_set\_param command sh -c "
$podman\_cmd || exit 1
exec $PROG wait '$name'
"
procd\_set\_param respawn
procd\_close\_instance
}
stop\_service() {
config\_load containers
config\_foreach stop\_container container
}
stop\_container() {
local cfg="$1" name
config\_get name "$cfg" name "$cfg"
$PROG stop "$name" 2>/dev/null
$PROG rm "$name" 2>/dev/null
}
# Standard init handlers
start() { start\_service; }
stop() { stop\_service; }
restart() { stop; start; }
reload() { stop; start; }
Make it executable:
chmod +x /etc/init.d/containers
And enable it for next boot
/etc/init.d/containers enable
* * *
Example Container Config
------------------------
/etc/config/containers
config container 'test'
option enabled '1'
option privileged '0'
option name 'test'
option dns '9.9.9.9'
option image 'quay.io/podman/hello'
option memory '64m'
option hostname 'hello'
option ip '192.168.11.2'
option pid 'host'
option restart 'unless-stopped'
list env 'TZ=Europe/Amsterdam'
list volume '/etc/openwrt\_release:/etc/openwrt\_release:ro'
list volume '/home/test\_container/etc/:/etc/test'
list cmd 'ping'
list cmd '-c'
list cmd '4'
list cmd '192.168.11.1'
* * *
Preserving Configs During Sysupgrade
------------------------------------
Add this to
/etc/sysupgrade.conf
/etc/containers
/etc/config/containers
/etc/init.d/containers
/home/
* * *
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/09/01 13:59
* by killgufo
[](https://openwrt.org/docs/guide-user/virtualization/podman#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt on VMware HowTo
OpenWrt on VMware HowTo
=======================
This article describes how to use OpenWrt as a virtual machine with VMware virtualization.
Tested with
-----------
* Barrier Breaker 14.07 in combination with VMware ESXi 5.5 Update 2 Build 2068190
* Chaos Calmer 15.05.1 with VMware Fusion and vSphere ESXi 6.0
* 19.07.0-rc2 in combination with VMware ESXi 6.7.0 Update 2 Build 13981272
* 19.07.5 in combination with VMware ESXi 6.7.0 Update 2 Build 16713306
* 21.02.0-rc3 on a VMware vSphere Client version 6.7.0.42000 machine
* 23.05.2 on a VMware vSphere VM VMware ESXi, 6.7.0, 20497097
* 24.10.0 on VMWare Fusion 13.6.2
### Things you need
* [https://downloads.openwrt.org/barrier\_breaker/14.07/x86/generic/openwrt-x86-generic-combined-ext4.img.gz](https://downloads.openwrt.org/barrier_breaker/14.07/x86/generic/openwrt-x86-generic-combined-ext4.img.gz "https://downloads.openwrt.org/barrier_breaker/14.07/x86/generic/openwrt-x86-generic-combined-ext4.img.gz")
or
* [https://downloads.openwrt.org/chaos\_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz](https://downloads.openwrt.org/chaos_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz "https://downloads.openwrt.org/chaos_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz")
or
* Generic x86/64, version COMBINED-EFI (EXT4) from [https://firmware-selector.openwrt.org/](https://firmware-selector.openwrt.org/ "https://firmware-selector.openwrt.org/")
* Linux machine with qemu-utils & gunzip installed or MacOS machine with qemu installed (via [Homebrew](http://brew.sh/ "http://brew.sh")
)
* Hypervisor with VMware ESXi, Fusion, Player, or Workstation installed
First of all, you need to download the image from list above on your machine. After that you extract & convert it to a vmdk image:
gunzip openwrt-x86-generic-combined-ext4.img.gz
qemu-img convert -f raw -O vmdk openwrt-x86-generic-combined-ext4.img openwrt-x86-generic-combined-ext4.vmdk
or
yum -y install qemu-img
wget https://downloads.openwrt.org/chaos\_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz
gunzip openwrt-15.05-x86-64-combined-ext4.img.gz
qemu-img convert -f raw -O vmdk openwrt-15.05-x86-64-combined-ext4.img openwrt-15.05-x86-64-combined-ext4.vmdk
or on a Mac
brew install qemu
qemu-img convert -f raw -O vmdk ~/Downloads/openwrt-15.05-x86-64-combined-ext4.img openwrt-15.05-x86-64-combined-ext4.vmdk
after that, just create a new VM in Fusion, Workstation, or ESXi with “Linux\\Other Linux 32-bit” with LSI BUS Logic & add the vmdk there. Use Intel PRO/1000 Network adapters. This may require editing the .vmx file to include following definition: _(On Workstation 10, the e1000 gave a corrupted vmx file. Using V6 machine type did work. So it seems somewhere between V6.5 and V10 VMware dropped support for the e1000 driver and/or the virtualDev keyword.)_
ethernet0.virtualDev = "e1000"
On Fusion I had to use the IDE drive controller type. This also applies to recent ESXi versions, just switch the Virtual Device Node from default SCSI controller 0 to IDE 0. Also, recent OpenWRT and ESXi versions do support running VMXNET3 virtual NIC so you can achieve 10GE speeds.
Quick Start
-----------
NB: The first network interface is LAN, and the second is WAN.
⚠️This info is obsolete⚠️
Follow these steps to get an Up to Date VM with the latest code running on ESX in 15 minutes:
1. you can download an OVA image from the following location: [https://www.dropbox.com/s/ao805tl33mqe0an/openwrt15cc.ova](https://www.dropbox.com/s/ao805tl33mqe0an/openwrt15cc.ova "https://www.dropbox.com/s/ao805tl33mqe0an/openwrt15cc.ova")
This image was made by Iben in September 2015 based on a July build of CHAOS CALMER 15.05 trunk r46767
2. Import the OVA to VMware ESXi (tested with latest version 6 in July 2016)
The base image only has 1 virtual NIC setup with DHCP
3. Power on the VM - observe the MAC Address - find that on you DHCP server
4. Confirm the OpenWrt VM's IP address by opening the console
5. Press enter to get a prompt
6. Type `ifconfig | more` to see the DHCP assigned IP address for the Bridge assigned to the NIC
7. If you don't have a DHCP server on your network you can set the IP Address manually: `vi /etc/config/network`
The whole goal here is to get the OpenWrt VM on the network so you can hit the LuCI Web User Interface with a web browser. This way we can update the base image.
8. Once you've logged in to the LuCI web interface set a root password so you can ssh in
9. With the Web UI navigate to the System/Flash Operations page and find this text: _Flash new firmware image - Upload a sysupgrade-compatible image here to replace the running firmware_. Check “Keep settings” to retain the current configuration (requires an OpenWrt compatible firmware image).
10. On your admin system with the web browser download the latest file to prepare for the flash upgrade of OpenWrt: [https://downloads.openwrt.org/chaos\_calmer/15.05.1/x86/generic/openwrt-15.05.1-x86-generic-combined-ext4.img.gz](https://downloads.openwrt.org/chaos_calmer/15.05.1/x86/generic/openwrt-15.05.1-x86-generic-combined-ext4.img.gz "https://downloads.openwrt.org/chaos_calmer/15.05.1/x86/generic/openwrt-15.05.1-x86-generic-combined-ext4.img.gz")
←- this was the most current available from [https://downloads.openwrt.org/](https://downloads.openwrt.org/ "https://downloads.openwrt.org/")
dated 16 March 2016 (last checked 11 Sept 2016)
11. Then upload that to your running OpenWrt system and click “Flash Image...”
12. Reboot and login again.
13. Now you can add the second NIC to use the OpenWrt VM as a WAN router. I set mine up with both DHCP and Static IP addresses for the WAN - and the LAN interface was configured as a DHCP server.
14. To prepare for testing: install iperf3 and nmap from the System/Software page of the Web UI.
15. See the testing section below for details...
16. That's pretty much it. I'm very happy with this new setup. I was also looking at M0n0wall (monowall), and pfsense to run as VMs but OpenWrt has a lot more going for it as far as an Open Source eco-system and developer/vendor support.
### Testing
1. Start the server on OpenWrt: `iperf3 -s`
2. Download the iperf3 binaries for various Operating Systems from here: [https://iperf.fr/iperf-download.php](https://iperf.fr/iperf-download.php "https://iperf.fr/iperf-download.php")
3. Then install and run the client on other machines on your network.
4. `iperf3 -c `
Here are some results from my system:
* 2012 MacBook with 802.11n on 5GHz -→ 284 Mbits/sec
* 2011 MacMini with CentOS 7.1 -→ 958 Mbits/sec
* Ubuntu VM running on same old Dell T110 ESXi host and OpenWrt VM -→ 4.14 Gbits/sec
As you can see - the OpenWrt virtual machine running on VMware ESX is very capable of keeping up with your home internet router needs! And this is with only 1 virtual CPU and no tuning at all.
### ToDo List
Here's a wish list of things we would like to accomplish with OpenWrt - consider this technical debt.
(Is there a better place to make these requests?)
1. install open-vm-tools to enhance support on VMware hypervisors (possible via packages sources and LuCI or opkg)
2. use vmxnet3 paravirtualized network interface
3. learn how to create fresh builds from scratch
4. install cloud-init capabilities to allow auto-configuration on OpenStack based clouds like OPNFV
5. create jenkins job as part of CI to download and convert the raw image to vmdk with each build
6. create jenkins job as part of CI to download and convert the raw image to qcow2 with each build
7. do these conversions for both stable and trunk
8. integrate OpenWrt into the CI Pipeline for other network testing projects like OPNFV
Disk Size Issues
----------------
Disk size and problems with veeam backup and enlarging the disk Veeam backup and VMware will complain about the size of the virtual disk provided by the OpenWrt download because the disk is not multiple of 1KB. (this means: no backups available, and could be crucial in production environments)
VMware won't let you enlarge the disk in the normal way, so one simple way is:
1. make a snapshot of the vm, for possible rollback
2. move the original disk (from OpenWrt downloads) on ide 0:1
3. add a new disk, with a whole size, like 128 MB , on ide 0:0
4. use `sysrescuecdiso`
5. start the vm with the iso
6. with dd copy the disc on ide 0:1 to ide 0:0 like `dd if=/dev/sdb of=/dev/sda`
7. enter `fdisk /dev/sda` and write the partition table (without making changes, this helps sysrescuecd to see the partitions properly)
8. do `fsck -f` on the sda2 partition
9. with `fdisk` resize the sda2 partition to occupy all the space available (but still starting with the same sector of before, normally 9135)
10. use `resize2fs /dev/sda2`
11. do `fsck -f /dev/sda2`
12. restart the machine and boot with OpenWrt check that the system uses the new partition
13. stop the machine, delete the previous hd (with less than 128MB)
14. restart the machine and verify that everything is ok.
Community
---------
Please use these images in your home and work labs and provide any feedback you might have.
Feel free to update this wiki page with your results.
There is some feedback that the newer images are not booting properly. Has anyone else run into this issue?
@iben learn , well, your quickstart ova works great. Following the instructions in the paragraph above it by the letter doesn't. /shrug .
==== Upgrade to 19.07.5 from ova ==== - Create a snapshot from ESXI UI to allow easy rollback in case of issues - Use the following image from LuCi: [https://downloads.openwrt.org/releases/19.07.5/targets/x86/generic/openwrt-19.07.5-x86-generic-combined-squashfs.img.gz](https://downloads.openwrt.org/releases/19.07.5/targets/x86/generic/openwrt-19.07.5-x86-generic-combined-squashfs.img.gz "https://downloads.openwrt.org/releases/19.07.5/targets/x86/generic/openwrt-19.07.5-x86-generic-combined-squashfs.img.gz")
- You should be able to access console from ESXI, but no IPv4 network will be available - Beware of keyboard layout of the console which is qwerty, type ifconfig and find IPv6 address - From LuCi, go to Network/Interface and click edit on br-lan without doing any change, and save. The configuration will be automatically fixed. - Reboot your OpenWRT VM, you should then get the IPv4 address back. Here is an upgraded OVA VM export with version 19.07.5, using ext4 instead of squashfs and an extended /overlay filesystem, with DHCP enabled instead of a static IP for br-lan interface: [https://www.dropbox.com/s/4b0dy8d8iqf8a91/OpenWRT\_x86\_64\_19.07.05.ova?dl=0](https://www.dropbox.com/s/4b0dy8d8iqf8a91/OpenWRT_x86_64_19.07.05.ova?dl=0 "https://www.dropbox.com/s/4b0dy8d8iqf8a91/OpenWRT_x86_64_19.07.05.ova?dl=0")
---- ==== Upgraded/Updated OVA for OpenWRT21 ==== After import of the previous OVA-file to VMware Sphere, I was able to upgrade to the latest OpenWrt version (21-00-RC3). This machine,_ OpenWRT-21 _has \* 2 CPU \* 2 GB \* 2 NiCs \* WAN defined as DHCP client \* LAN static address 192.168.1.1 as DHCP server \* Compatibility ESXi 5.0 and later (VM version 8) \* Installed VMware tools, as well as vnet drivers_
_
[https://www.dropbox.com/s/nljp8todp99qggn/OpenWRT21.ova](https://www.dropbox.com/s/nljp8todp99qggn/OpenWRT21.ova "https://www.dropbox.com/s/nljp8todp99qggn/OpenWRT21.ova")
\==== Example Issues seen during VMWare Installs ==== VMDK (1st method): e1000 interface is found/loads intermittently. Corresponds to Seg Fault errors in **kmodloader** when loading **libuclibc**. === Build Summary === \* VMWare ESXi 6.1 \* 1 CPU \* 512 MB Memory \* Image Used for VMDK: [https://downloads.openwrt.org/chaos\_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz](https://downloads.openwrt.org/chaos_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz "https://downloads.openwrt.org/chaos_calmer/15.05/x86/64/openwrt-15.05-x86-64-combined-ext4.img.gz")
\* Extraneous devices (USB, etc) removed
_
_
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
_
_
* Last modified: 2025/02/21 19:11
* by robertod91
_
_[](https://openwrt.org/docs/guide-user/virtualization/vmware#dokuwiki__top "skip to content")
_
---
# [OpenWrt Wiki] Rescue from failed firmware upgrade
Rescue from failed firmware upgrade
===================================
If you can't reach the OpenWrt interface after installing packages, changing the password or the network configuration, try using [failsafe mode and factory reset](https://openwrt.org/docs/guide-user/troubleshooting/failsafe_and_factory_reset "docs:guide-user:troubleshooting:failsafe_and_factory_reset")
first.
Some device vendors provide built-in rescue functions in their device's flash ROM boot partition that remain there, even after a OpenWrt firmware upgrade, so a OpenWrt upgrade will not overwrite this rescue function.
These rescue functions can be used to recover a failed flash update (no matter if the failed flash was vendor firmware or OpenWrt) or recover from an otherwise dead device, as long as the device hardware and the rescue function is still intact. These rescue partitions do consume a tiny piece of the flash, but renders a device mostly unbrickable.
Unfortunately such rescue functions are not available from all vendors, sometimes not for all models from a vendor and the actual rescue process is mostly vendor specific. This page is meant to collect the known rescue methods of different router vendors or router models.
Check first: Device-specific firmware recovery procedures
---------------------------------------------------------
Check the “device page” of your device (look for a link in the last columns of the Table of Hardware). The device page may describe a rescue method for your specific device.
* [Table of Hardware](https://openwrt.org/toh/start "toh:start")
Some of the methods may require creating a custom RS232-serial-cable or soldering-skills, while most newer devices require just a certain software trick to remote flash the device from a PC client.
Manufacturer-generic firmware recovery procedures
-------------------------------------------------
Many devices of the following manufacturers support a recovery procedures as listed here:
| Manufacturer | Procedure | Links |
| --- | --- | --- |
| ASUS | TFTP\-like rescue procedure with a manufacturer utility to be installed on a client PC. | [Official ASUS recovery documentation](https://www.asus.com/support/faq/1000814/ "https://www.asus.com/support/faq/1000814/") |
| D-Link | Several devices have a dedicated [rescue firmware partition](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#rescue_firmware_partition "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") in their flash ROM. | |
| GL-iNet | HTTP recovery GUI provided by the u-boot bootloader. Note: no https. | [Official GL-iNet recovery documentation](https://docs.gl-inet.com/router/en/4/faq/debrick/ "https://docs.gl-inet.com/router/en/4/faq/debrick/") |
| Linksys | Several older devices support a remote TFTP recovery procedure. Several newer devices have [2 independent firmware partitions](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#dual_firmware_partition "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") . | \- [Official Linksys TFTP recovery documentation](https://www.linksys.com/us/support-article?articleNum=137928 "https://www.linksys.com/us/support-article?articleNum=137928")
\- For Linksys dual firmware, [see below](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#dual_firmware_partition "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") |
| Mikrotik | TFTP\-like rescure procedure with a manufacturer utility called 'netinstall' installed on a client PC. | [Official Microtik recovery documentation](https://wiki.mikrotik.com/wiki/Manual:Netinstall "https://wiki.mikrotik.com/wiki/Manual:Netinstall") |
| Netgear | TFTP on a PC client can be used to rescue the firmware. | [Official Netgear TFTP recovery documentation](https://kb.netgear.com/000059633/How-to-upload-firmware-to-a-NETGEAR-router-using-TFTP-client "https://kb.netgear.com/000059633/How-to-upload-firmware-to-a-NETGEAR-router-using-TFTP-client") |
| nmrpflash | [https://github.com/jclehner/nmrpflash](https://github.com/jclehner/nmrpflash "https://github.com/jclehner/nmrpflash") |
| TP-Link | TFTP on a PC client can be used to rescue the firmware. Several newer devices provide a [rescue partition](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#rescue_firmware_partition "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") . | [TP-Link forum TFTP recovery documentation](https://community.tp-link.com/en/home/forum/topic/81462?page=1 "https://community.tp-link.com/en/home/forum/topic/81462?page=1") |
| Webpage firmware recovery See link for models which support this method. | [https://www.tp-link.com/us/faq-1482.html](https://www.tp-link.com/us/faq-1482.html "https://www.tp-link.com/us/faq-1482.html") |
| Ubiquiti (UBNT) | [TFTP on a PC client](https://openwrt.org/docs/guide-user/installation/recovery_methods/ubiquiti_tftp "docs:guide-user:installation:recovery_methods:ubiquiti_tftp") can be used to rescue the firmware. | [Official UBNT site: site search for 'firmware recovery'](https://help.ubnt.com/hc/en-us/search?utf8=%E2%9C%93&query=firmware+recovery&commit=Search "https://help.ubnt.com/hc/en-us/search?utf8=%E2%9C%93&query=firmware+recovery&commit=Search") |
| Xiaomi | Several devices with USB port support a [rescue USB stick](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#rescue_usb_stick "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") method. | |
| ZBT (ZBTLink) | Several devices support a [rescue partition](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#rescue_firmware_partition "docs:guide-user:troubleshooting:vendor_specific_rescue ↵") . On some devices, TFTP on a PC client can be used to rescue the firmware. | |
Recovery for disk-image-based devices (e.g. SD-cards)
-----------------------------------------------------
Examples: the different Raspberry PI's, devices of PC Engines).
OpenWrt devices that use a drive-installed image.gz or sdcard.img.gz are not an issue to recover. The OpenWrt OS is not applied to flash ROM, but installed on a removable drive, e.g. an SD-card. For recovery, mount the removable drive in a working PC and reapply the OpenWrt image to the removable drive according to the device-specific instructions.
TFTP recovery mode
------------------
In several of these recovery procedures you will need a working TFTP server on your PC, see how to install and configure it in [Set up a TFTP Server](https://openwrt.org/docs/guide-user/troubleshooting/tftpserver "docs:guide-user:troubleshooting:tftpserver")
article.
Rescue USB stick
----------------
Supported by some Xiaomi devices process for [Xiaomi Mi](http://en.miui.com/thread-157895-1-1.html "http://en.miui.com/thread-157895-1-1.html")
:
1. Download firmware and store as `miwifi.bin` on an USB flash drive (must be FAT or FAT32)
2. Plug USB flash drive into device USB port
3. Unplug device cord
4. Press and hold the reset button and then re-plug the power cord
5. Release reset button, when the orange status LED starts blinking
6. Flashing is finished, when LED turns blue
Rescue firmware partition
-------------------------
Supported by several devices at least of the following vendors: D-Link, TP-Link, ZBTLink
This function is based on extra code in the boot partition in the flash ROM and it is still available on the device, even after the device has been flashed to OpenWrt. No further tools are needed, to trigger this rescue function.
Procedure, to boot into rescue partition:
1. Switch device power off (or pull the power cord).
2. Connect a client to the device via Ethernet to LAN1
3. Trigger the rescue function by pressing and holding the reset button of the device and then turning the device on (or plug in the power cord).
4. You can release the reset button after a few seconds.
5. The device will take ~15-20 seconds to boot a mini-web server, that provides only a single function: it can upload a firmware file and has a button to trigger the flash process. The web-server will usually be available under either (if in doubt, try both)
1. [http://192.168.0.1](http://192.168.0.1/ "http://192.168.0.1")
(TP-Link and newer D-Link devices) or [http://192.168.0.254](http://192.168.0.254/ "http://192.168.0.254")
(newer TP-Link devices)
2. [http://192.168.1.1](http://192.168.1.1/ "http://192.168.1.1")
(ZBT-Link and older D-Link devices)
6. Note: You need to set your PC client to a fixed IP address beforehand, as DHCP is not supported in this rescue mode. So depending on your device, so you need to set the PC client's to a matching IP address, either:
1. an IP of the 192.168.0.x range, e.g. 192.168.0.2 / 255.255.255.0
2. an IP of the 192.168.1.x range, e.g. 192.168.1.2 / 255.255.255.0
Notes:
* The rescue function provides no Internet access, WiFi or DHCP.
* OpenWrt firmware can be flashed directly using this rescue function when using a OpenWrt ...**factory.bin** firmware file. There is no need to first flash official D-Link firmware.
* Official D-Link documentation of this procedure is rare, a [german D-Link documentation for the DIR-600](ftp://ftp.dlink.de/dir/dir-600/documentation/DIR-600_revb12_howto_de_FirmwareRecovery.pdf "ftp://ftp.dlink.de/dir/dir-600/documentation/DIR-600_revb12_howto_de_FirmwareRecovery.pdf")
exists (with the same procedure also applying for other D-Link devices, if the device supports recovery). Inofficial documentation: [OpenWrt Wiki for DIR-505](https://openwrt.org/toh/d-link/dir-505#web_interface "toh:d-link:dir-505")
and [D-Link Forum](http://forums.dlink.com/index.php?topic=44909.msg162511#msg162511 "http://forums.dlink.com/index.php?topic=44909.msg162511#msg162511")
.
* Inofficial notes of [ZBTLink recovery](https://fccid.io/2AH9TW826/Users-Manual/User-Manual-2994820 "https://fccid.io/2AH9TW826/Users-Manual/User-Manual-2994820")
,
* Official [TP-Link rescue partition notes](http://www.tp-link.de/faq-1482.html "http://www.tp-link.de/faq-1482.html")
Dual firmware partition
-----------------------
Supported by newer Linksys devices
Most newer devices (mostly those with decent amount of flash ROM) have 2 independent firmware partitions. A usage strategy could be, to install OpenWrt only into one of the 2 partitions and leave the vendor firmware in the other partition. No further tools are required to toggle between the two partitions.
Procedure, to manually toggle between the two firmware partitions:
1. Switch device power off.
2. 3x Switch device power on for 2 seconds, then off again.
3. Switch device power on, the device should now boot to the alternative partition.
When successfully booted into any of the two partitions, a triggered firmware update will flash the other, secondary partition. The partition that is currently booted, stays untouched.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/03/14 07:32
* by hnyman
[](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt in QEMU
OpenWrt in QEMU
===============
QEMU is an an open source processor emulator (and virtualizer). This document describes how to run OpenWrt in QEMU. If you are looking to use OpenWrt as a QEMU host, see [Running QEMU guests on OpenWrt](https://openwrt.org/docs/guide-user/virtualization/qemu_host "docs:guide-user:virtualization:qemu_host")
.
It is mixed descriptions from Windows and Linux, so please read through all of it before starting.
 Choosing different emulation settings can affect performance greatly.
Example: 30s iperf-s@openwrt (QEMU running on host) to host
ne2k\_pci:0.0\-31.3 sec 14.6 MBytes 3.92 Mbits/sec
pcnet: 0.0\-30.0 sec 2.38 GBytes 682 Mbits/sec
e1000: 0.0\-30.0 sec 6.23 GBytes 1.79 Gbits/sec
vmxnet3: 0.0\-30.0 sec 8.67 GBytes 2.48 Gbits/sec
virtio-net-pci: 0.0\-30.0 sec 44.6 GBytes 12.8 Gbits/sec
*  Trunk: test kernel image with rootfs
*  Trunk: use SD card with rootfs, NFS rootfs, NBD rootfs
*  Trunk: no sound, pcibus, USB emulation in QEMU possible?
Getting QEMU
------------
QEMU runs on many different systems.
### Ubuntu Linux
Many Linux distributions like Debian, Ubuntu, SUSE, and Fedora provide a QEMU package in their package repositories.
Example for Debian 9 (Stretch):
sudo apt-get install qemu
 QEMU is rapidly developing so features and syntax might change between versions.
### Windows version
The [QEMU Wiki Links](http://wiki.qemu.org/Links "http://wiki.qemu.org/Links")
page provides you with several unofficial download links of Windows builds.
### MacOS version
Use homebrew. The [homebrew qemu](https://formulae.brew.sh/formula/qemu "https://formulae.brew.sh/formula/qemu")
page provides variants for different hardware and MacOS versions.
OpenWrt in QEMU ARM
-------------------
For OpenWrt releases 22 and older, use the [armvirt](https://archive.openwrt.org/releases/22.03.7/targets/armvirt/ "https://archive.openwrt.org/releases/22.03.7/targets/armvirt/")
target with QEMU to emulate an ARM system. For releases 23 and newer (including snapshots), use the [armsr](https://downloads.openwrt.org/releases/24.10.1/targets/armsr/ "https://downloads.openwrt.org/releases/24.10.1/targets/armsr/")
target instead.
### Boot with initramfs
This is the simplest method that can be used to test an image. However, it runs entirely in RAM: any modification made is lost upon reboot.
To use this boot method, here with 64 MB of RAM, run:
qemu-system-arm \-nographic \-M virt \-m 64 \-kernel openwrt-armvirt-zImage-initramfs
OpenWrt in QEMU aarch64
-----------------------
aarch64 is used by many modern Arm CPUs. The instruction set is called armv8. The target is [armsr armv8 variant](https://downloads.openwrt.org/releases/24.10.3/targets/armsr/armv8/ "https://downloads.openwrt.org/releases/24.10.3/targets/armsr/armv8/")
.
 Needs steps update from 22.03 to current: armvirt-64 to armsr-armv8 
qemu-system-aarch64 \-m 1024 \-smp 2 \-cpu cortex-a57 \-M virt \-nographic \\
\-kernel openwrt-19.07.3-armvirt-64\-Image-initramfs \\
\-drive if\=none,file\=disk.img,id\=hd0 \-device virtio-blk-device,drive\=hd0
Here's an example with network interface and persistent storage:
qemu-system-aarch64 \--enable-kvm \-M virt \-nographic \-nodefaults \\
\-m 128 \\
\-cpu host \-smp 2 \\
\-kernel openwrt-armvirt-64\-Image \-append "root=fe00" \\
\-blockdev driver\=raw,node-name=hd0,cache.direct=on,file.driver=file,file.filename=openwrt-armvirt-64\-root.ext4 \\
\-device virtio-blk-pci,drive\=hd0 \\
\-netdev type\=tap,id\=nic1,ifname\=kvm0,script\=no,downscript\=no \\
\-device virtio-net-pci,disable-legacy=on,disable-modern=off,netdev\=nic1,mac\=ba:ad:1d:ea:01:02 \\
\-device qemu-xhci,id\=xhci,p2\=8,p3\=8 \\
\-device usb-host,vendorid\=0x7392,productid\=0x7822
* kernel without initrd will automatically attempt to mount ext4 partition, but it has to be told where it is with the `-append “root=fe00”` parameter (if you don't specify this, the kernel will list available block devices and reboot)
* `-blockdev` followed by `-device` is the new way of specifying block devices in qemu - I could've used -drive, but I copied most of the config from elsewhere
* `-netdev` binds a virtual NIC to host tap interface kvm0, which should be created before starting qemu; if you need multiple NICs, just copy the `-netdev` and `-device virtion-net-pci` lines and adjust ifname (tap device on host), id (device id, ties -netdev and -device together) and mac address
* last two lines add a USB3 controller and attach a physical USB WiFi dongle to the VM
### OpenWrt in QEMU aarch64 on Apple Silicon (MacOS, M1+ hardware, Native)
It is possible to use native virtualisation on Apple arm64 hardware under MacOS (high performance variant)
The target is [armsr armv8 variant](https://downloads.openwrt.org/snapshots/targets/armsr/armv8/ "https://downloads.openwrt.org/snapshots/targets/armsr/armv8/")
Non-persistent variant (with **openwrt-armvirt-64-Image-initramfs**):
qemu-system-aarch64 \-m 1024 \-smp 2 \-cpu host \-M virt,highmem\=off \\
\-nographic \\
\-accel hvf \\
\-kernel openwrt-armvirt-64\-Image-initramfs \\
\-device virtio-net,netdev\=net0 \-netdev user,id\=net0,net\=192.168.1.0/24,hostfwd\=tcp:127.0.0.1:1122\-192.168.1.1:22 \\
\-device virtio-net,netdev\=net1 \-netdev user,id\=net1,net\=192.0.2.0/24
Persistent (squashfs) variant (with **openwrt-armvirt-64-Image** and **openwrt-armvirt-64-rootfs-squashfs.img**):
qemu-system-aarch64 \-m 1024 \-smp 2 \-cpu host \-M virt,highmem\=off \\
\-nographic \\
\-accel hvf \\
\-kernel openwrt-armvirt-64\-Image \\
\-drive file\=openwrt-armvirt-64\-rootfs-squashfs.img,format\=raw,if\=virtio \\
\-append root\=/dev/vda \\
\-device virtio-net,netdev\=net0 \-netdev user,id\=net0,net\=192.168.1.0/24,hostfwd\=tcp:127.0.0.1:1122\-192.168.1.1:22 \\
\-device virtio-net,netdev\=net1 \-netdev user,id\=net1,net\=192.0.2.0/24
Both variants provide two network interfaces to OpenWrt:
1. eth0 (LAN)
2. eth1 (WAN). qemu dhcp-server will allocate 192.0.2.15 IP address for OpenWrt host and provide IPv4 Internet access
To access OpenWrt via SSH from host:
ssh \-p1122 root@127.0.0.1
It is possible to connect from OpenWrt guest to host by IP 192.168.1.2 (via eth0) or 192.0.2.2 (via eth1)
OpenWrt in QEMU MIPS
--------------------
 Use QEMU >= 2.2 (earlier versions can have bugs with MIPS16) [ticket 16881](https://dev.openwrt.org/ticket/16881 "https://dev.openwrt.org/ticket/16881")
- Ubuntu 14.03.x LTS uses QEMU 2.0 which is has this bug.
The “[malta](https://openwrt.org/docs/techref/targets/malta "docs:techref:targets:malta")
” platform is meant for use with QEMU for emulating a MIPS system.
The `malta` target supports both big and little-endian variants, pick the matching files and qemu version (`qemu-system-mips`, or `qemu-system-mipsel`).
qemu-system-mipsel \\
\-kernel openwrt-malta-le-vmlinux-initramfs.elf \\
\-nographic \-m 256
In recent enough versions one can enable ext4 root filesystem image building, and since [r46269](https://dev.openwrt.org/changeset/46269 "https://dev.openwrt.org/changeset/46269")
( only in trunk, it's not part of the 15.05 CC release) it's possible to boot straight from that image (without an initramfs):
qemu-system-mipsel -M malta \\
-hda openwrt-malta-le-root.ext4 \\
-kernel openwrt-malta-le-vmlinux.elf \\
-nographic -append "root=/dev/sda console=ttyS0"
OpenWrt in QEMU RISC-V
----------------------
Use the build documentation found on the HiFive Unleashed page. The process described there will generate the bbl.qemu (BBL+vmlinux) image required to boot with QEMU. For reference, use [https://git.openwrt.org/?p=openwrt/staging/wigyori.git;a=shortlog;h=refs/heads/riscv-201810](https://git.openwrt.org/?p=openwrt/staging/wigyori.git;a=shortlog;h=refs/heads/riscv-201810 "https://git.openwrt.org/?p=openwrt/staging/wigyori.git;a=shortlog;h=refs/heads/riscv-201810")
Until 4.19 support is merged into openwrt/trunk, the port itself cannot be merged into trunk, and manual builds are required.
RISC-V support is in mainline qemu, refer to [https://wiki.qemu.org/Documentation/Platforms/RISCV](https://wiki.qemu.org/Documentation/Platforms/RISCV "https://wiki.qemu.org/Documentation/Platforms/RISCV")
The suggested QEMU startup is:
$ qemu-system-riscv64 \-nographic \-machine virt \\
\-kernel bbl.qemu \-append "root=/dev/vda2 ro console=ttyS0" \\
\-drive file\=sdcard.img,format\=raw,id\=hd0 \\
\-device virtio-blk-device,drive\=hd0 \\
\-device virtio-net-device,netdev\=net0 \-netdev user,id\=net0 \\
\-smp 2
OpenWrt in QEMU x86-64
----------------------
The x86-64 target has support for ESXi images by default. Booting the VMDK / VDI images might not work with newer QEMU versions.
 IMG/VDI/VMDK with “-hda” switch do not work with QEMU 2.x.
pc-q35-2.0 / q35 emulates a different machine. With new syntax (no -hda , -net) the IMG / VDI / VMDK works here. Some emulated network cards might have performance issues.
Features:
* 2 HDDs (1 OpenWrt image, 1 data)
* 1 drive per bus, 6 bus available (until ide.5)
* 2 Network cards : 1 bridged to host (need higher permission) and 1 “user” (default, NAT 10.x.x.x)
### Preparation
Unpack the archive and expand the F2FS data partition if necessary. This partition is generated on first boot and needs the drive to have free space available. Perform [hard factory reset](https://openwrt.org/docs/guide-user/troubleshooting/failsafe_and_factory_reset#hard_factory_reset "docs:guide-user:troubleshooting:failsafe_and_factory_reset")
if F2FS is corrupted or failed to set up properly. The exact expanding method depends on your virtualization system.
#### KVM/QEMU
If you are using KVM/QEMU virtualization.
gunzip openwrt-\*.img.gz
qemu-img resize \-f raw openwrt-\*.img 300M
#### Resizing rootfs on combined EFI image
Increase base image size to 512M:
qemu-img resize \-f raw openwrt-x86-64\-generic-squashfs-combined-efi.img 512M
Loop mount the base image so it can be modified:
loop\_device\=$(sudo losetup -f)
sudo losetup $loop\_device openwrt-x86-64\-generic-squashfs-combined-efi.img
Fix the GPT partition and increase the root partition size to 100% (512M):
echo \-e "OK\\nFix" | sudo parted \---pretend-input-tty "$loop\_device" print
sudo parted "$loop\_device" resizepart 2 100%
sudo parted "$loop\_device" print
Remove the loop mount device
sudo losetup \-d $loop\_device
#### libvirt + KVM/QEMU
If you are using KVM/QEMU with libvirt management framework. Import the image as-is and stop the first boot on the GRUB screen. Then expand the block device online as follows and continue the boot.
virsh blockresize openwrt vda 300M
virsh vol-resize openwrt 300M default
#### Other virtualization systems
If you are using other virtualization systems like Proxmox, VMWare ESXi/Workstation, VirtualBox, XenServer/XCP-ng, and any other self-respecting virtualization software it is also possible to expand the drive but you will have to look at its own documentation for guidance.
### Configuration examples
qemu-system-x86\_64 \\
\-enable-kvm \\
\-M pc-q35-2.0 \\
\-drive file\=openwrt-x86\_64-combined-ext4.vdi,id\=d0,if\=none \\
\-device ide-hd,drive\=d0,bus\=ide.0 \\
\-drive file\=data.qcow2,id\=d1,if\=none \\
\-device ide-hd,drive\=d1,bus\=ide.1 \\
\-soundhw ac97 \\
\-netdev bridge,br\=virbr0,id\=hn0 \\
\-device e1000,netdev\=hn0,id\=nic1 \\
\-netdev user,id\=hn1 \\
\-device e1000,netdev\=hn1,id\=nic2
qemu-system-x86\_64 \-M q35 \\
\-drive file\=openwrt-x86\_64-combined-ext4.img,id\=d0,if\=none,bus\=0,unit\=0 \\
\-device ide-hd,drive\=d0,bus\=ide.0
UEFI firmware requires ovmf package installed.
qemu-system-x86\_64 \\
\-enable-kvm \-m 1G \-drive if\=pflash,format\=raw,readonly,file\=/usr/share/edk2-ovmf/x64/OVMF\_CODE.fd \\
\-drive if\=pflash,format\=raw,file\=my\_uefi\_vars.fd
### Network configuration
QEMU has several options to provide network connectivity to emulated images, see all `-net` options in qemu(1). Although this option is considered obsolete since QEMU 0.12, it continues to work although it is. The new syntax uses either `-nic` for emulating a particular embedded board, or it uses the two options `-netdev` and `-device`, see the [official documentation](https://wiki.qemu.org/Documentation/Networking "https://wiki.qemu.org/Documentation/Networking")
.
### Provide Internet access to OpenWrt
The default networking mode for QEMU is “user mode network stack”.
In this mode, `qemu` acts as a proxy for outbound TCP/UDP connections. It also provides DHCP and DNS service to the emulated system.
To provide Internet access to the emulated OpenWrt system, use (the example uses an armvirt system, adjust for your setup):
qemu-system-arm \-net nic,vlan\=0 \-net nic,vlan\=1 \-net user,vlan\=1 \\
\-nographic \-M virt \-m 64 \-kernel lede-17.01.0-r3205-59508e3-armvirt-zImage-initramfs
Here, we set up two network cards inside the emulated OpenWrt system:
* `eth0`, used as LAN in OpenWrt (not connected to anything here)
* `eth1`, used as WAN in OpenWrt, and connected to qemu that will proxy all TCP/UDP connections towards the Internet
The OpenWrt system should get both an IPv4 and an IPv6 on `eth1` (via DHCP/DHCPv6). The ranges will be 10.0.2.0/24 and fec0::/64 (qemu defaults, see qemu(1) to configure other ranges).
### Provide access to LuCI inside OpenWrt
LuCI is the web UI used by OpenWrt. If you want to check how LuCI works or to poke around with LuCI-apps this setup is for you. (the example uses an armvirt system, adjust for your setup)
**Note**: This setup requires some privileges (`CAP_NET_ADMIN` and `CAP_MKNOD` under Linux) so it's easier to run it under `sudo`
Save the script and edit `IMAGE` variable to reflect your OpenWrt version, then run it under `sudo`
#!/bin/sh
IMAGE\=lede-17.01.0-r3205-59508e3-armvirt-zImage-initramfs
LAN\=ledetap0
\# create tap interface which will be connected to OpenWrt LAN NIC
ip tuntap add mode tap $LAN
ip link set dev $LAN up
\# configure interface with static ip to avoid overlapping routes
ip addr add 192.168.1.101/24 dev $LAN
qemu-system-arm \\
\-device virtio-net-pci,netdev\=lan \\
\-netdev tap,id\=lan,ifname\=$LAN,script\=no,downscript\=no \\
\-device virtio-net-pci,netdev\=wan \\
\-netdev user,id\=wan \\
\-M virt \-nographic \-m 64 \-kernel $IMAGE
\# cleanup, delete tap interface created earlier
ip addr flush dev $LAN
ip link set dev $LAN down
ip tuntap del mode tap dev $LAN
How networking works:
* `eth0`, used as LAN in OpenWrt, and connected to `ledetap0` in host system(static address `192.168.1.101/24`), providing access to LuCI at `[http://192.168.1.1](http://192.168.1.1/ "http://192.168.1.1") `
* `eth1`, used as WAN in OpenWrt, and connected to qemu that will proxy all TCP/UDP connections towards the Internet
### Forward ports of the host
If you configure NICs on embedded systems, which cannot be used via `-device`, you can access them from the host by forwarding a (high) port in the `-nic` option using `hostfwd=hostip:hostport-guestip:guestport`.
For example, to [access SSH](https://wiki.qemu.org/Documentation/Networking#How_to_get_SSH_access_to_a_guest "https://wiki.qemu.org/Documentation/Networking#How_to_get_SSH_access_to_a_guest")
by `ssh root@127.1 -p 1122` from the host on the guest system `malta-be`, you can use:
qemu-system-mips \-M malta \-nographic \-hda openwrt-malta-be-rootfs-ext4.img \\
\-kernel openwrt-malta-be-vmlinux.elf \-append 'root=/dev/sda console=ttyS0' \\
\-nic hostfwd\=tcp::1122\-:22
If the network adapter is a WAN interface, you have to add firewall rules in the guest to allow SSH:
uci \-q delete firewall.ssh
uci set firewall.ssh="rule"
uci set firewall.ssh.name="Allow-SSH"
uci set firewall.ssh.src="wan"
uci set firewall.ssh.dest\_port="22"
uci set firewall.ssh.proto="tcp"
uci set firewall.ssh.target="ACCEPT"
uci commit firewall
/etc/init.d/firewall restart
### Use KVM igb network interfaces
(taken from mailing list post by Philip Prindeville)
On my Centos 7.4 KVM host, I did:
To provision 10 VFs per NIC:
cat << EOF \> /etc/modprobe.d/sr-iov.conf
\# for SR-IOV support
options igb max\_vfs\=10
EOF
This will take effect after the next reboot. Alternatively by unloading and reloading the IGB module.
Create XML files for each NIC you want to support virtualization on:
\# cat << EOF > /tmp/hostdev-net0.xml
hostdev-net0$(uuidgen)
EOF
cat << EOF \> /tmp/hostdev-net1.xml
hostdev-net1$(uuidgen)
EOF
virsh net-destroy default
virsh net-define /tmp/hostdev-net0.xml
virsh net-autostart hostdev-net0
virsh net-define /tmp/hostdev-net1.xml
virsh net-autostart hostdev-net1
To create the pool of VF interfaces.
Then to add interfaces to VMs, I did:
\# cat << EOF > /tmp/new-interface-0.1.xml
EOF
\# Where the ‘0d:84:f4’ is 3 unique bytes
dd status\=none bs\=1 count\=3 if\=/dev/urandom | hexdump \-e '/1 "%x"\\n'
virsh attach-device my-machine-1 /tmp/new-interface-0.1.xml
Advanced boot methods
---------------------
### Use KVM acceleration
This will be much faster, but will only work if the architecture of your CPU is the same as the target image (here, ARM cortex-a15).
qemu-system-arm \-nographic \-M virt,accel\=kvm \-cpu host \-m 64 \-kernel openwrt-armvirt-zImage-initramfs
### Boot with a separate rootfs
qemu-system-arm \-nographic \-M virt \-m 64 \\
\-kernel openwrt-armvirt-zImage \\
\-drive file\=openwrt-armvirt-root.ext4,format\=raw,if\=virtio \\
\-append 'root=/dev/vda rootwait'
### Boot with local directory as rootfs
qemu-system-arm \-nographic \-M virt \-m 64 \-kernel openwrt-armvirt-zImage \\
\-fsdev local,id\=rootdev,path\=root-armvirt/,security\_model\=none \\
\-device virtio-9p-pci,fsdev\=rootdev,mount\_tag\=/dev/root \\
\-append 'rootflags=trans=virtio,version=9p2000.L,cache=loose rootfstype=9p'
### Run with kvmtool
\# start a named machine
lkvm run \-k openwrt-armvirt-zImage \-i openwrt-armvirt-rootfs.cpio \--name armvirt0
\# start with virtio-9p rootfs
lkvm run \-k openwrt-armvirt-zImage \-d root-armvirt/
\# stop "armvirt0"
lkvm stop \--name armvirt0
\# stop all
lkvm stop \--all
Examples
--------
This example uses OpenWrt virtualized using Debian, QEMU with KVM and a Lex twitter system with Intel Atom D525 and ICH8M chipset. Normally OpenWrt works on most of the hardware mentioned in the table of hardware (search in this wiki), and also on most of the hardware that support **Intel x86 ISA** or `x86` in the address bar.
Anyway some embedded x86 board have particular hardware that is not always well supported by the OpenWrt platform, even if all the `kmod` packages are included in the basic image. One of this x86 compatible hardware family are systems based on Intel Atom and ICH8M chipset (maybe also others), like the Lex twitter system 3I525U.
OpenWrt is able to run on that system, but for example, is not able to manage the possibility of having two WAN connections with different metric. The request will be always routed to the interface with higher metric also using `ping -I 8.8.8.8`. Moreover software like `Nmap` will fail to be bind to certain interfaces. Someone with more knowledge could explain why this happens but as workaround one can use a more complete linux system (for example Debian) as base and then virtualize (`virtualization OR qemu OR kvm OR hypervisor` in the address bar) openwrt, that in the end requires really a little resources most of the time, or one can assign plenty of resources because at the end the base system is quite powerful.
### Prepare debian (7.1 in the test) for virtualization
Debian was installed on a 2 GB CF card through a USB stick and netinstaller, having only the basic system utilities and ssh utilities. 1.1 GB of space were used, 600 MB free and the rest swap.
Install the following packages: `apt-get install qemu-kvm bridge-utils libvirt-bin virtinst`
* Qemu-kvm for QEMU and KVM additional software components.
* bridge-utils for managing bridges in debian
* libvirt-bin for additional virtualization packages
* virtinst for handy virtualization management
If you don't want to use any user but just work with root (the objective is to let OpenWrt run on the twitter system, not having a well set up Debian system):
* Change /etc/libvirt/qemu.conf uncommenting user/group to work as root.
* restart /etc/init.d/libvirt\* entries.
Then we have to prepare the network. Modify `/etc/network/interfaces` a follows (adapt according to your needs)
auto br0 br1 br2 br3
iface br0 inet dhcp
bridge\_ports eth0
iface br1 inet dhcp
bridge\_ports eth1
iface br2 inet dhcp
bridge\_ports eth2
iface br3 inet dhcp
bridge\_ports eth3
The bridges ( [https://wiki.debian.org/BridgeNetworkConnections](https://wiki.debian.org/BridgeNetworkConnections "https://wiki.debian.org/BridgeNetworkConnections")
) are helpful because they allows different network adapters, real or virtual ( [network.interfaces](https://openwrt.org/docs/guide-developer/networking/network.interfaces "docs:guide-developer:networking:network.interfaces")
to exchange data (as the word 'bridge' suggests) and not only, because the bridge will have a certain mac address but also the virtual interfaces attached to it can have different mac addresses. Here the marvels of the linux networking system have to be explained by someone with more knowledge.
### Virtualization proper
Then we need to create our virtual machine. The additional packages, apart from QEMU, will help here. We can issue the following command, using the x86 generic image placed in the folder `/root/openwrt_kvm/`:
virt-install \--name\=openwrt \--ram\=256 \--vcpus\=1 \--os-type\=linux \\
\--disk path\=/root/openwrt\_kvm/openwrt-x86-generic-combined-ext4.img,bus\=ide \\
\--network bridge\=br0,model\=e1000 \--import
\# be careful to the model, e1000 let's openwrt recognize the interface.
\# http://manpages.ubuntu.com/manpages/lucid/man1/virt-install.1.html
If you want to interact with the system from command line, use `virsh`. For example to force the shutdown of a virtual machine `virsh destroy openwrt` or to delete the virtual machine (but not the disk file) `virsh undefine openwrt`.
For having multiple interfaces
virt-install \--name\=openwrt \--ram\=256 \--vcpus\=1 \--os-type\=linux \\
\--disk path\=/root/openwrt\_kvm/openwrt-x86-generic-combined-ext4.img,bus\=ide \\
\--network bridge\=br0,model\=e1000 \--network bridge\=br3,model\=e1000 \--import
Remember that the console requires `ctrl+5` to exit.
To mark a virtual machine for the autostart, type: `virsh autostart openwrt`.
### Known issues
\* Virtual interfaces with macvtap: [problems with IPv6 because of multicast](https://bugzilla.redhat.com/show_bug.cgi?id=1035253#c15 "https://bugzilla.redhat.com/show_bug.cgi?id=1035253#c15")
\* USB-host devices in qemu might not work like on bare metal, might be related to USB3 or driver issues (mt7601u); consider virtualizing whole USB controller via PCIe VFIO.
### Notes
In qemu x86\_64 images you need to create a wan interface is not defined by default (you can forward port 80 if you want to use the web interface to do it) hostfwd=tcp:127.0.0.1:8080-192.168.1.1:80
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/05/20 16:05
* by echogolf123
[](https://openwrt.org/docs/guide-user/virtualization/qemu#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt running as metarouter on mikrotik routerOS
OpenWrt running as metarouter on mikrotik routerOS
==================================================
Premises
--------
Openwrt as metarouter is highly experimental but is also very promising, therefore if someone knows useful resources, please contribute! This should be valid for the entire openwrt wiki in general.
Resources
---------
### Discussion forums
One obvious resource is the mikrotik forum and related searches on it. For example with google `site:miktrotik.com openwrt metarouter`.
Discussion about patching the openwrt sources to get the metarouter image working: [http://forum.mikrotik.com/viewtopic.php?t=75849](http://forum.mikrotik.com/viewtopic.php?t=75849 "http://forum.mikrotik.com/viewtopic.php?t=75849")
### Articles
* [http://naberius.de/2015/01/10/openwrt-barrier-breaker-metarouter-instance-on-mikrotik-rb-2011/](http://naberius.de/2015/01/10/openwrt-barrier-breaker-metarouter-instance-on-mikrotik-rb-2011/ "http://naberius.de/2015/01/10/openwrt-barrier-breaker-metarouter-instance-on-mikrotik-rb-2011/")
* [metarouter](https://openwrt.org/docs/guide-user/virtualization/metarouter "docs:guide-user:virtualization:metarouter")
### Openwrt metarouter images and repositories
* A resource is provided by a user of the mikrotik forum, **liquidcz**, that is providing patched metarouter images with openwrt for mips and pppc architectures, here: [http://forum.mikrotik.com/viewtopic.php?p=414386#p414386](http://forum.mikrotik.com/viewtopic.php?p=414386#p414386 "http://forum.mikrotik.com/viewtopic.php?p=414386#p414386")
. Thanks a ton to this guy.
* Mirror based on the liquicz's work: [http://download.bmsoft.de/mikrotik/12.09/metarouter/](http://download.bmsoft.de/mikrotik/12.09/metarouter/ "http://download.bmsoft.de/mikrotik/12.09/metarouter/")
* Repository for openwrt metarouter: [https://github.com/TheSkorm/openwrt-metarouter-cjdns](https://github.com/TheSkorm/openwrt-metarouter-cjdns "https://github.com/TheSkorm/openwrt-metarouter-cjdns")
#### Providing alternatives mirrors
The metarouter image is based on a 'proper patch' for building the openwrt sources, so everyone can build its own version. The point is that (a) publishing the compiled packages online is not for everyone (b) providing the right procedure to build a mips/ppc version of openwrt is not for everyone. Therefore providing mirror of already compiled packages or informations (for example in this wiki) is highly reccomended - as in every open source/community project.
##### Use alternative mirrors
Editing `/etc/opkg.conf` like
src/gz packages http://download.bmsoft.de/mikrotik/12.09/metarouter/mr-mips/packages
#src/gz packages http://openwrt.wk.cz/attitude\_adjustment/mr-mips/packages
dest root /
dest ram /tmp
lists\_dir ext /var/opkg-lists
option overlay\_root /overlay
Experiences
-----------
### Routerboard r493g , routerOS 6.27 , openwrt 12.09 mips compiled by liquidcz
* CPU usage when idle, checked by winbox and routerOS: Around 15%. Around 8% if winbox shows few information.
* Ping answers when idle, direct connection: around 3000 ms.
* mwan3 version 1.4-24 works.
* With 2 wan connections: each wan connection seems to achieve an quite stable average of 25 Mbit/s using mwan3 (100+ firewall rules shown by `iptables-save`), and the CPU stays on an average of 40%. Could be that the test setup was limiting the system somehow, maybe due to the overhead in processing the IRQ request, like: when the IRQ is processed natively one can send more data, while with the hypervisor one can send less data, but then it is strange that both the flow from 2 wan connections goes through one lan connection without problems.
* Openvpn connection able to send or receive (not made synchronous tests) 6.5 ~ 7 Mbit/s of data. used by a system that use a metarouter as gateway. Could be the same problem of the speed through wan connections, that is the IRQ processing is the bottleneck.
* The system can be shut down like a normal openwrt or the metarouter can be shut down (via 'disable') or started (via 'enable') forcefully. On the mikrotik terminal a way to disable/enable is: `metarouter disable ; ping count=2 127.0.0.1 ; metarouter enable `
* When the mikrotik (re)starts, if the metatarouter is enabled, it starts too, finishing the start procedure in 4-5 minutes.
* Long time '30s+' to restart single services (firewall, dropbear, etc...)
* Software reboot of the metarouter itself takes 4-5 minutes to show up the system again (except for ping, that replies way earlier. Note that the openwrt is almost a basic installation).
* 'Forced' reboot (disable-enable in the RouterOS) takes 4-5 minutes to be completed.
* Long term usage (+ 30 days) has to be tested.
* Rebooting/power outage tests has to be done.
* The 'console' management, using winbox, is way better through the terminal. New terminal → metarouter console . But remember that openwrt offer one global console therefore opening two console is not possible, in that case try to go by ssh.
* It seems possible to assign a miximum of 7 interfaces out of 9, over 7 openwrt won't recognize the other interface.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2019/01/12 14:45
* by tmomas
[](https://openwrt.org/docs/guide-user/virtualization/mikrotik_metarouter_openwrt#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt security hardening
OpenWrt security hardening
==========================
Good news, OpenWrt is secure on the WAN/Internet side by default, such that no unsolicited traffic is allowed in by the [firewall](https://openwrt.org/docs/guide-user/firewall/overview "docs:guide-user:firewall:overview")
. If you are inexperienced in Linux hardening, firewalls, and web security, there is little need to worry, inexperienced muggles may begin using it right away. This page contains some best practices for security with OpenWrt and what you should do to keep your router in a properly secured state.
Setting the root password
-------------------------
First thing you should do is set your root password. Using LuCI:
1. Navigate to LuCI → System → Administration page
2. Enter the new password in the Router Password section
3. Click **Save & Apply**
You can also set the root password using SSH/command-line with `passwd`.
A word about high-value weak points on OpenWrt
----------------------------------------------
The OpenWrt firewall does not accept connections on the WAN by default. However the LAN side has several common services running, which can mark high-value targets for malware. While uncommon, any harmless looking web site you visit could use cross site request forgery tricks, abusing an unpatched security flaw in one of these services. This could lead to malicious redirect attacks where a [website redirects to a malware site](https://attack.mitre.org/techniques/T1189/ "https://attack.mitre.org/techniques/T1189/")
and so on. Below is a simple list of best practices for security.
Common high-value services in particular are:
* The webserver for LuCI web interface monitoring and configuration
* The Dropbear SSH server for command-line access
* WiFi access points that are unsecured can be used to gain access to your network
* Samba/Ksmbd share to provide user network file shares (only if manually activated, it's not there by default)
* The SFTP daemon for GUI file explorer admin access (only if manually activated, it's not there by default)
It is your responsibility to counter potential weak points on your OpenWrt device(s):
* Password: set the root password by using `passwd` from command-line or from in LuCI
* Firmware: keep up to date so that CVEs are patched etc., read more about this in the section down below
* WiFi: set the latest security features in LuCI: Network → Wireless → SSIDs, enable WPA2 and KRACK mitigation, or better yet WPA3 if your hardware supports it
* Services: periodically check for package updates which may contain security fixes, keeping your firmware updated also handles this.
* Samba/Ksmbd or SFTP packages: set a user password for access
Setting HTTPS for LuCI
----------------------
It is good practice to [activate HTTPS](https://openwrt.org/docs/guide-user/luci/luci.essentials#providing_encryption "docs:guide-user:luci:luci.essentials")
encryption for your LuCI web interface. Install the package `luci-ssl` and tell the web server to redirect to HTTPS with the command-line:
uci set uhttpd.main.redirect\_https=1
uci commit uhttpd && service uhttpd reload
Now when connecting to the LuCI web UI it will use HTTPS.
If you don't wish to use LuCI web interface at all, you can [disable the webserver](https://openwrt.org/docs/guide-user/luci/luci.secure#more_secure_configuration "docs:guide-user:luci:luci.secure")
entirely.
Securing TTY and serial console
-------------------------------
Enable password prompt for TTY and serial console.
uci set system.@system\[0\].ttylogin="1"
uci commit system
service system restart
Authentication for OpenWrt TTY and serial console is disabled by default. Using TTY and serial console requires physical access to the device. You can reduce the attack surface by enabling authentication.
Note that hardware attacks on serial console pins are also possible. However, it requires physical access, time and skill.
My OpenWrt web interface page is always open in the background for ease of access...
------------------------------------------------------------------------------------
...and that is a bad idea. Treat your root account with respect.
Do what every major company does with the root accounts of their Linux servers:
* Stay away from admin access (SSH and web interface) when you don't need it
* Log off your root admin sessions once your are done administrating
* Only connect as root when really in the need for administration
* Never share your root password with others
Let's just open this one port for incoming traffic, what could possibly go wrong?...
------------------------------------------------------------------------------------
Handle adding firewall rules with care:
* Do not expose services on the WAN port if you do not understand the security implications. Automatic scanners and script kids will find any open port on your WAN side and could then run extensive intrusion software suits on such open ports, probing a lot of attack vectors without any manual effort. The Internet is always being scanned for careless people.
* If you want to access home services while being on the road, consider using a WireGuard VPN instead of opening service-related ports publicly on the WAN side.
* A lot of online games have “recommended settings” to permanently open port ranges for the best gaming experience. Before blindly following these settings, check first, if any server connection problems are due to a [double NAT from cascaded routers](https://openwrt.org/docs/guide-user/network/switch_router_gateway_and_nat "docs:guide-user:network:switch_router_gateway_and_nat")
at your home.
* Always use reasonable comments, when you add your own custom firewall rules (e.g. “...that's the rule that a random nice guy on the Internet asked me to add, promising me some really hot skateboarding penguin pictures in return...”)
If you have already performed various firewall rule changes and are now concerned about your custom rules, you can always reset all your OpenWrt settings back to the to the initial default with the `firstboot && reboot` command.
So I've switched from insecure vendor firmware to OpenWrt. Finally, I am safe...
--------------------------------------------------------------------------------
Initially yes, but not so fast... Did you notice that even OpenWrt firmware gets updated periodically?
As with your former vendor/OEM firmware, you should check regularly if OpenWrt has a new firmware release and apply this to your device. The good news with OpenWrt is that popular devices are often updated for many, many years. There is even a configuration backup and restore feature so you do not have to start from scratch after each update. Update your firmware via:
* For manually installing updates, download the latest builds from [Firmware Selector](https://firmware-selector.openwrt.org/ "https://firmware-selector.openwrt.org/")
* For an assisted process from SSH/command-line, install and use [owut](https://openwrt.org/docs/guide-user/installation/sysupgrade.owut "docs:guide-user:installation:sysupgrade.owut")
* For an assisted process from LuCI webUI, install and use `luci-app-attendedsysupgrade`
Dive into the deep end with SELinux
-----------------------------------
OpenWrt supports Security-Enhanced Linux (SELinux). This is a Linux security module that provides support for access control policies including mandatory access controls (MAC) and could be useful for advanced users with complex network setups. Do the the complexity of this feature see this guide [selinux\_policy\_development](https://openwrt.org/docs/guide-developer/selinux_policy_development "docs:guide-developer:selinux_policy_development")
.
I have extra packages installed...
----------------------------------
 This section is only recommended if you know there is a fix you need. Use this with caution as this may break functionality and it is often better to wait for a full firmware update.
If you added packages you can check for package updates and update them as needed. Not every listed package upgrade is due to security issues, it can also be a bug fix or feature.
Performing a [backup](https://openwrt.org/docs/guide-user/troubleshooting/backup_restore "docs:guide-user:troubleshooting:backup_restore")
never hurts as precaution before upgrading packages. By default OpenWrt uses squashfs, a read-only root filesystem, plus a writable overlay partition for configuration and added packages. To maximize use of your precious flash space applying firmware updates and including or reinstalling packages will be more space efficient than upgrading packages.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/01/21 20:41
* by phinn
[](https://openwrt.org/docs/guide-user/security/openwrt_security#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt as Docker container host
OpenWrt as Docker container host
================================
[Docker](https://docs.docker.com/get-started/docker-overview/#docker-architecture "https://docs.docker.com/get-started/docker-overview/#docker-architecture")
uses OS\-level virtualization to deliver software in packages called containers. This is used to automate deployment of applications so that they work efficiently in different environments. To run containers, users may install Docker Community Edition, native OpenWrt tools, or Podman.
Prerequisites
-------------
For devices using internal flash storage you may need to add [external storage](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
, using a Linux filesystem such as **ext4**, for the containers and data. Leaving the default storage in place (the internal **overlay2** filesystem) will cause Docker to use the very inefficient **vfs** [storage driver](https://docs.docker.com/engine/storage/drivers/select-storage-driver/ "https://docs.docker.com/engine/storage/drivers/select-storage-driver/")
.
Also in many cases you will be running the container as a specific user that will need access to some folder outside the container for its configuration and data. So you will probably need to [create new users and groups](https://openwrt.org/docs/guide-user/additional-software/create-new-users "docs:guide-user:additional-software:create-new-users")
for applications, create folders, and then change the owner of these folders to the user who will run the container.
Docker Community Edition
------------------------
First install dockerd, `dockerd`. This daemon provides the [Docker Engine API](https://docs.docker.com/engine/api/ "https://docs.docker.com/engine/api/")
and manages Docker objects such as images, containers, networks, and volumes.
Then you need a client, e.g. docker, `docker` to connect to the daemon and start containers. This client is command line based.
For a LuCI web client install luci-app-dockerman, `luci-app-dockerman`. This package will also install dockerd and docker-compose as dependencies. It can work with dockerd on local and remote hosts. The default folder for docker in dockerman is **/opt/docker/**, this will cause dockerd to fallback to the slow and very space-inefficient **vfs** driver - instead change the path in **Docker** > **Overview** > **Docker Root Dir** to within mounted external storage, then restart the dockerd service.
### Adding images
Search for an image on [Docker Hub](https://hub.docker.com/ "https://hub.docker.com/")
, then copy the image name from the **Docker Pull Command** text box. For example, if the text is **docker pull linuxserver/transmission**, then copy **linuxserver/transmission**.
In Luci go to **Docker** > **Images** and paste that text in the **Pull Image** box, then click **Pull**. The page will show the download progress.
Note for larger container pulls LuCI could timeout, so you will need to use the command line. For example, Unifi-network-application includes java runtime environment and approaches 500MB. For this use SSH and enter: `docker pull lscr.io/linuxserver/unifi-network-application:latest`.
Once you have your images, in Luci go to **Docker** > **Containers** > **Add**. In the new container page select the docker image from the **Docker Image** menu, then set all other parameters (usually the available/useful parameters are described in the description of the container on Docker Hub), then press Submit to create the container.
### Configure the Docker daemon
Config is located in `/etc/config/dockerd`.
* `data_root` a folder where to store images and containers. It's also mounted by a docker. You may want to change it to a USB disk. It's file system can't be fat or ntfs. By default `/opt/docker/`
* `log_level` Default `warn`.
* `hosts` an API listener. By default is used a UNIX socket `/var/run/docker.sock`.
* `iptables` Enable iptables rules. Default `1`
* `bip` network bridge IP. Default `172.18.0.1/24`
* `fixed_cidr` Allocate IPs from a range. Default `172.17.0.0/16`
* `fixed_cidr_v6` same as fixed\_cidr for IPv6. Default 'fc00:1::/80'
* `ipv6` Enable IPv6 networking. Default `1`
* `ip` Default `::ffff:0.0.0.0`
* `dns` DNS Servers. Default `172.17.0.1`
* `registry_mirrors` URL of a registries. Default `[https://hub.docker.com](https://hub.docker.com/ "https://hub.docker.com") `
The following settings require a restart of docker to take full effect, A reload will only have partial or no effect:
* bip
* blocked\_interfaces
* extra\_iptables\_args
* device
Native OpenWrt tools
--------------------
Instead of running Docker CE users may want to use the procd init system which supports Open Container Initiative Runtime Specification set by [Opencontainers.org](https://opencontainers.org/ "https://opencontainers.org/")
. This extends its slim containers ('ujail') capability. The uxc command line tool handles the basic operations on containers as defined by the spec. This allows to use it as a drop-in replacement for Docker's 'runc' (or 'crun') on OpenWrt hosts with a reduced footprint.
Detailed but possibly outdated info available on [https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc](https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc "https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc")
### Install packages
Install the following:
kmod-veth uxc procd-ujail procd-ujail-console
### Create veth pair for container
uci batch <), change your _additionalimagestores_ back to \[\], disable podman service, and make sure, podman service doesn't start by creation/start of containers during boot. Then you remove all files, from /srv/.podman/images:
rm -rf /srv/.podman/images
reboot again, and begin this again from start of this section of guide.
### Pod
We will start by creating a pod. Pod can hold multiple containers, they share some attributes, such as ip address. As we are trying to build a web server setup, we want IP address to be always same for this pod. I have created a script /srv/create.sh to construct this pod:
#!/bin/sh
podman pod create \\
\--replace \\
\--name servers \\
\--hostname srv \\
\--ip 10.129.0.2
\--ip fda7:d793:5373:d0d7::2
podman pod start servers
This creates, or replaces if one exists, pod named servers, gives it a hostname srv (not important) and static IPs 10.129.0.2 /fda7:d793:5373:d0d7::2.
### Containers
All configurations and statically exported data is also in /srv. In /srv/caddy I have all needed to build my caddy container, such as configurations and what ever caddy container of your choice needs. I also have a build script there, /srv/caddy/create.sh:
#!/bin/sh
podman create \\
\--name caddy \\
\--pod servers \\
\--replace \\
\--systemd false \\
\--label app\=caddy \\
\--volume /srv/caddy/conf/:/etc/caddy/:Z,rw \\
\--volume /srv/caddy/htdocs/:/var/htdocs/:z,rw \\
\--volume /srv/caddy/logs/:/var/log/:z,rw \\
\--volume /dev/log:/dev/log:Z,rw \\
\--mount\="type=bind,src=/etc/acme/domain.tld\_ecc/domain.tld.cer,dst=/etc/caddy/ssl/server.pem,ro=true,idmap=uids=0-82-1;gids=0-82-1" \\
\--mount\="type=bind,src=/etc/acme/domain.tld\_ecc/domain.tld.key,dst=/etc/caddy/ssl/server.key,ro=true,idmap=uids=0-82-1;gids=0-82-1" \\
docker.io/me/my\_caddy\_image:latest
podman start caddy
In this guide I do not review configuration of Caddy, look it up from caddy's docs. My caddy is set to run as user www:www-data which in that setup are uid 82 and gid 82, acme is used to fetch certificates, but user www(82) cannot read root owned files, so we use idmapping to map those 2 files for user www:www-data. There are multiple ways to do this, this is just one approach. You could also setup a system that chmod's those files to be available for reading to everyone, or at least for user and/or group 82. Or copy them locally and chown them in that location statically.
And I have a similar script for nginx:
#!/bin/sh
podman create \\
\--name nginx \\
\--pod servers \\
\--replace \\
\--systemd false \\
\--label app\=nginx \\
\--volume /srv/nginx/conf/:/etc/nginx/:Z,rw \\
\--volume /srv/nginx/logs/:/var/log/nginx/:Z,rw \\
\--volume /srv/nginx/htdocs/:/var/htdocs/:z,rw \\
\--volume /dev/log:/dev/log:Z,rw \\
docker.io/me/my\_nginx\_image:latest
podman start nginx
Now after you have configured properly your caddy and nginx, we should have a server properly running. We need to setup redirections from wan.
### Expose to WAN
Now that we have caddy serving at 10.129.0.2, ports 80 and 443, we edit /etc/config/firewall again:
config redirect
option name 'Allow-HTTP'
option src 'wan'
option dest 'podman'
option src\_dport '80'
option dest\_ip '10.129.0.2'
option dest\_port '80'
option proto 'tcp'
option reflection '0'
option target 'DNAT'
option enabled '1'
config redirect
option name 'Allow-HTTPS'
option src 'wan'
option dest 'podman'
option src\_dport '443'
option dest\_ip '10.129.0.2'
option dest\_port '443'
option proto 'tcp'
option reflection '0'
option target 'DNAT'
option enabled '1'
### Automation
Finally, we want our pod and containers to build and start during boot, we also have acme handling our certificates, so we want to restart caddy when certificates are renewed.
I added /srv/scripts directory, and added there file restart\_caddy.sh:
#!/bin/sh
/etc/init.d/podman enabled || exit
logger \-t acme \-p daemon.info "SSL certificates renewed, restarting container servers:caddy"
podman stop caddy
sleep 1
podman start caddy
And then rest is handled by /etc/rc.local:
\# Put your custom commands here that should be executed once
\# the system init finished. By default this file does nothing.
add\_podman\_trigger() {
local counter\=10
local running\=0
\[ \-x "/etc/init.d/acme" \] || exit
/etc/init.d/acme enabled || exit
while \[ "$counter" \-gt 0 \]; do
\[ "$(service podman status)" = "running" \] && {
running\=1
counter\=0
} || {
sleep 1
counter\=$(($counter\-1))
}
done
\[ "$running" \-eq 1 \] && {
ubus call service set '{ "name": "podman", "triggers": \[\[ "acme.renew", \[\[ "run\_script", "/srv/scripts/restart\_caddy.sh" \]\], 2000 \]\], "data": {}}'
logger \-t podman \-p daemon.info "podman: added service trigger for acme.renew event to restart servers:caddy"
}
}
start\_podman\_services() {
/etc/init.d/podman enabled && {
\[ \-f /tmp/.podman\_created \] || {
touch /tmp/.podman\_created
sleep 1
/srv/create.sh
sleep 2
/srv/caddy/create.sh
sleep 2
/srv/nginx/create.sh
add\_podman\_trigger &
}
}
}
This is why starting podman service with /etc/init.d/podman comes handy, we can ignore all container related during boot, by just simply disabling service as nothing podman related is started if service is disabled. This builds our pod and both containers and then adds a trigger for podman service to restart caddy when SSL certificates are renewed. There's a routine that checks if podman service has started, because trigger must be added AFTER podman service has started.
### Network Restarts workaround
Lastly we need a fix for when network is restarted in OpenWrt. Network connectivity breaks every time for every container when e.g.
/etc/init.d/network restart
is invoked. For that we will place a hotplug script that will reload podman network. Place in /etc/hotplug.d/iface/99-podman-reload.
#!/bin/sh
\# We only want to act when interfaces are fully configured
\[ "$ACTION" = "ifup" \] || \[ "$ACTION" = "ifupdate" \] || exit 0
\# Ensure podman is available
command \-v podman \>/dev/null 2\>&1 || exit 0
\# Run podman network reload
podman network reload \-a
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/06/29 05:42
* by benl
[](https://openwrt.org/docs/guide-user/virtualization/docker_host#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Troubleshooting
Troubleshooting
===============
[](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=============================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/troubleshooting/start#top-1955535913 "Continue with the « docs » section at the top...")
[Troubleshooting](https://openwrt.org/docs/guide-user/troubleshooting/start "docs:guide-user:troubleshooting:start")
* [Backup and restore](https://openwrt.org/docs/guide-user/troubleshooting/backup_restore "docs:guide-user:troubleshooting:backup_restore")
* [Failsafe mode, factory reset, and recovery mode](https://openwrt.org/docs/guide-user/troubleshooting/failsafe_and_factory_reset "docs:guide-user:troubleshooting:failsafe_and_factory_reset")
* [For Developers: Activating EAD (Emergency Access Daemon) Before Running into Problems](https://openwrt.org/docs/guide-user/troubleshooting/ead "docs:guide-user:troubleshooting:ead")
* [OpenWrt Debricking Guide](https://openwrt.org/docs/guide-user/troubleshooting/generic.debrick "docs:guide-user:troubleshooting:generic.debrick")
* [Rescue from failed firmware upgrade](https://openwrt.org/docs/guide-user/troubleshooting/vendor_specific_rescue "docs:guide-user:troubleshooting:vendor_specific_rescue")
* [Resetting the root password](https://openwrt.org/docs/guide-user/troubleshooting/root_password_reset "docs:guide-user:troubleshooting:root_password_reset")
* [What is TFTP Recovery over Ethernet?](https://openwrt.org/docs/guide-user/troubleshooting/tftpserver "docs:guide-user:troubleshooting:tftpserver")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/02 18:33
* by vgaetera
[](https://openwrt.org/docs/guide-user/troubleshooting/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Backup and restore
Backup and restore
==================
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
Introduction
------------
* This how-to describes the method for using OpenWrt file-level backup/restore.
* Follow [Preserving packages](https://openwrt.org/docs/guide-user/installation/sysupgrade.packages "docs:guide-user:installation:sysupgrade.packages")
to back up user-removed/installed packages.
* Follow [Preserving configuration](https://openwrt.org/docs/guide-quick-start/admingui_sysupgrade_keepsettings "docs:guide-quick-start:admingui_sysupgrade_keepsettings")
to determine whether to keep the settings.
* Follow [Generic backup](https://openwrt.org/docs/guide-user/installation/generic.backup "docs:guide-user:installation:generic.backup")
for block-level backup/restore.
* Extroot or additional overlay setups require extra measures.
Goals
-----
* Back up and restore OpenWrt configuration.
Web interface instructions
--------------------------
### 1\. Customize and verify
Customize your backup configuration.
1. Navigate to **LuCI → System → Backup / Flash Firmware → Configuration**.
2. Add/remove files/directories and click **Submit** when done editing.
3. Click **Open list...** button to view the list of files for backup.
Make sure the list contains all the files you want to save.
### 2\. Back up
Back up OpenWrt configuration to local PC.
1. Navigate to **LuCI → System → Backup / Flash Firmware → Actions: Backup**.
2. Click **Generate archive** button to download the archive.
### 3\. Restore
Restore previously saved OpenWrt configuration from local PC.
1. Navigate to **LuCI → System → Backup / Flash Firmware → Actions: Restore**.
2. Click **Choose File** button to select the archive.
3. Click **Upload archive...** button to upload the archive.
Command-line instructions
-------------------------
OpenWrt provides [Sysupgrade](https://openwrt.org/docs/techref/sysupgrade "docs:techref:sysupgrade")
utility for file-level backup/restore.
### 1\. Customize and verify
Customize and verify your backup configuration.
\# Add files/directories
cat << EOF \>> /etc/sysupgrade.conf
/etc/sudoers
/etc/sudoers.d
EOF
\# Edit backup configuration
vi /etc/sysupgrade.conf
\# Verify backup configuration
sysupgrade \-l
### 2\. Back up
Back up OpenWrt configuration to local PC.
\# Generate backup
umask go\=
sysupgrade \-b /tmp/backup-${HOSTNAME}\-$(date +%F).tar.gz
ls /tmp/backup-\*.tar.gz
\# From the client, download backup
scp root@openwrt.lan:/tmp/backup-\*.tar.gz .
\# On recent clients, it may be necessary to use the -O flag for compatibility reasons
scp \-O root@openwrt.lan:/tmp/backup-\*.tar.gz .
### 3\. Restore
Restore previously saved OpenWrt configuration from local PC. Reboot to apply changes.
\# Upload backup
scp backup-\*.tar.gz root@openwrt.lan:/tmp
\# Restore backup
ls /tmp/backup-\*.tar.gz
sysupgrade \-r /tmp/backup-\*.tar.gz
reboot
Extras
------
### Configuration
Backup combines multiple sources and covers most configurations by default.
\# Automatically detected modifications
opkg list-changed-conffiles
\# System configurations supplied by individual packages
grep \-r \-e . /lib/upgrade/keep.d
\# User configuration to edit if necessary
grep \-e . /etc/sysupgrade.conf
\# Obsolete settings no longer supported
uci show luci.flash\_keep
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/04/28 11:01
* by silejonu
[](https://openwrt.org/docs/guide-user/troubleshooting/backup_restore#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt on VirtualBox HowTo
OpenWrt on VirtualBox HowTo
===========================
This document describes how to run the x86-64 OpenWrt images in VM [VirtualBox](https://www.virtualbox.org/ "https://www.virtualbox.org")
, or VBox for short.
Prerequisites
-------------
* Download and install [VirtualBox](https://www.virtualbox.org/wiki/Downloads "https://www.virtualbox.org/wiki/Downloads")
* Download and install the VirtualBox Guest Additions (needed for USB connectivity among others)
### Select an OpenWrt image
You need a [x86 64 bit version of OpenWrt](https://openwrt.org/docs/guide-user/installation/openwrt_x86 "docs:guide-user:installation:openwrt_x86")
. There is two versions of them:
* `combined-squashfs.img.gz` This disk image uses the traditional OpenWrt layout, a squashfs read-only root filesystem and a read-write partition where settings and packages you install are stored. Due to how this image is assembled, you will have only 230-ish MB of space to store additional packages and configuration, and Extroot does not work.
* `combined-ext4.img.gz` This disk image uses a single read-write ext4 partition with no read-only squashfs root filesystem, which allows to enlarge the partition. Features like Failsafe Mode or Factory Reset won't be available as they need a read-only squashfs partition to function.
In the guide we'll use _openwrt-x86-64-combined-ext4.img.gz_ because it has fewer limitations.
* Download a stable release of the _openwrt-x86-64-combined-ext4.img.gz_ image from [targets/x86/64/ folder](https://archive.openwrt.org/releases/ "https://archive.openwrt.org/releases/")
e.g. [22.03.5](https://archive.openwrt.org/releases/22.03.5/targets/x86/64/openwrt-22.03.5-x86-64-generic-ext4-combined.img.gz "https://archive.openwrt.org/releases/22.03.5/targets/x86/64/openwrt-22.03.5-x86-64-generic-ext4-combined.img.gz")
. Or you can try the fresher but unstable [snapshot](https://downloads.openwrt.org/snapshots/targets/x86/64/openwrt-x86-64-generic-ext4-combined.img.gz "https://downloads.openwrt.org/snapshots/targets/x86/64/openwrt-x86-64-generic-ext4-combined.img.gz")
image
* Uncompress the gziped img file. On Linux use the command `gzip -d openwrt-*.img.gz`. As a result you should get the raw `openwrt-x86-64-combined-ext4.img` image file.
#### Custom Images
You can compile your own image (_Target System → x86-64_ and _Target Images → Build VirtualBox image files_). `ext4` needs to be enabled first.
### Convert openwrt.img to VBox drive
* Open a terminal and go in the folder where you have downloaded the file (sorry, the tool has only a command line interface). On Windows, the `VBoxManage.exe` is available in the installation path `C:\Program Files\Oracle\VirtualBox`.
* Convert it to native VBox format by writing this in command line (the same for Windows, macOS and Linux. Sadly this tool does not have graphical user interface): `VBoxManage convertfromraw --format VDI openwrt-*.img openwrt.vdi`. This will create the `openwrt.vdi` file which a virtual drive for VBox virtual machine.
#### Error
If you receive an error similar to:
VBoxManage: error: VD: The given disk size 19444018 is not aligned on a sector boundary (512 bytes)
VBoxManage: error: Error code VERR\_VD\_INVALID\_SIZE at /Users/vbox/tinderbox/5.1-mac-rel/src/VBox/Storage/VD.cpp(7002) in function int VDCreateBase(PVBOXHDD, const char \*, const char \*, uint64\_t, unsigned int, const char \*, PCVDGEOMETRY, PCVDGEOMETRY, PCRTUUID, unsigned int, PVDINTERFACE, PVDINTERFACE)
VBoxManage: error: Cannot create the disk image "openwrt.vdi": VERR\_VD\_INVALID\_SIZE
or:
VBoxManage.exe: error: VDI: cannot create image 'openwrt.vdi'
VBoxManage.exe: error: Error code VERR\_ACCESS\_DENIED at D:\\tinderboxb\\win-6.1\\src\\VBox\\Storage\\VDI.cpp(691) in function int \_\_cdecl vdiImageCreateFile(struct VDIIMAGEDESC \*,unsigned int,struct VDINTERFACEPROGRESS \*,unsigned int,unsigned int)
VBoxManage.exe: error: Cannot create the disk image "openwrt.vdi": VERR\_ACCESS\_DENIED
you may need to pad the image with `dd if=openwrt-x86-64-combined-ext4.img of=openwrt.img bs=128000 conv=sync` and use the padded image as input to VBoxManage convertfromraw or try another with this command line: `VBoxManage convertdd openwrt-*.img openwrt.vdi`.
* Enlarge the image to a useful size (size is in MB)
$ VBoxManage modifymedium openwrt.vdi --resize 128
0%...10%...20%...30%...40%...50%...60%...70%...80%...90%...100%
* Resize /dev/sda2 partition to new size, or create new partition and copy all files from root partition there and amend /boot/grub/grub.cfg
VM Setup in VirtualBox
----------------------
### VM creation
 Tutorial and screenshots from VirtualBox 5.1.8 on Linux host, on Windows or macOS hosts there will be some cosmetic differences (a different top bar) but the VirtualBox panels and buttons will be exactly the same
[](https://openwrt.org/_media/docs/guide-user/vboxstart.png "docs:guide-user:vboxstart.png")
Start VirtualBox and click _New_ to add a virtual machine (VM)
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm1.png "docs:guide-user:vboxaddvm1.png")
Choose a _Name_ for your virtual machine, choose `Linux` for _Type_, and `Linux 2.6 / 3.x / 4.x (64-bit)` for _Version_, then click _Next_.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm2.png "docs:guide-user:vboxaddvm2.png")
OpenWrt will work fine with much less RAM than the recommended amount, 128 MiB will be enough.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm3.png "docs:guide-user:vboxaddvm3.png")
Choose _Use an existing hard disk file_, click the _file_ icon to open _Virtual Media Manager_, click _Add_ and choose your `openwrt.vdi` file using the file chooser window. Click _Create_ to end this guided procedure.
* * *
 It's recommended to place the disk image in a permanent place _before_ linking it with VBox. If you move it _afterwards_, VBox will not find it anymore and will complain about this issue on next start (or when you try to start the VM). It will offer a guided procedure to link the disk image again, so don't worry.
 If the Virtual machine keeps restarting with `Kernel Panic - not syncing: Attempted to kill the idle task!` message, try changing the number of CPUs to 2 and then start the VM. Reference: [https://forums.virtualbox.org/viewtopic.php?t=106196](https://forums.virtualbox.org/viewtopic.php?t=106196 "https://forums.virtualbox.org/viewtopic.php?t=106196")
.
### VM setup
This article may contain network configuration that depends on migration to DSA in OpenWrt 21.02
* Check if your device uses DSA or swconfig as not all devices have been migrated
* ifname@interface has been moved to device sections
* [DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Mini tutorial for DSA network config](https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998 "https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998")
on the forum
* [DSA in the 21.02 release notes](https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change "https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change")
This part of the configuration will deal with setting up networking manually.
The configuration you will set up by following this tutorial is:
* **eth0** of the VM on **mng** (management) interface, fixed address 192.168.56.2, set in VirtualBox as **Host-only Adapter** on adapter **vboxnet0**. This interface will be _always_ available to the host even if host or VM are disconnected from any network.
* **eth1** of the VM on **wan** interface, dynamic address, set in VirtualBox as **NAT**. This interface will be used to access the Internet through whatever setup the host also uses.
* _(optional) **eth2** of the VM on **lan** interface, configured depending on your local network, set in VirtualBox as **Bridged Adapter**. This interface allows other devices (host included) to connect to the VM as if it was a physical device in the local network. Will only work if there is already a local network of some kind._
* _For a setup with 2 bridged physical network cards WAN/LAN Setup see [troubleshooting](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm#troubleshooting "docs:guide-user:virtualization:virtualbox-vm ↵")
. The rest of this guide applies to a setup with 2 physical cards as well._
Note that the _order_ of the “Host-only Adapter” as “Adapter 1” and “NAT” as “Adapter 2” is important for turn-key operation of OpenWrt in the VM. While it can be configured using the console, configuration in this way simplifies getting to a running configuration.
#### Virtualbox settings
##### Host-only network adapter
we first need to make sure there is a Host-only network adapter and that it has the right settings
Note: this is found in VBox 6.0 (at least for Windows) under Tools, and is pre-configured.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network1.png "docs:guide-user:vboxvmhost-only-network1.png")
Click on **File** → **Preferences** → **Network**
On macOS, this setting may be found through **File** → **Host Network Manager...**
VirtualBox 7.1: **File** → **Tools** → **Network Manager**, or press **CTRL-H**.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network2.png "docs:guide-user:vboxvmhost-only-network2.png")
Click on Host-only Networks tab and then if you don't see a **vboxnet0** entry click on the **+** icon on the right of the window to add a new one.
Now select the **vboxnet0** entry, and click on the screwdriver icon on the right to open its settings.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network3.png "docs:guide-user:vboxvmhost-only-network3.png")
**IPv4 Address** should be **192.168.56.1**, **IPv4 Network Mask** should be **255.255.255.0**, **IPv6 Address** should be empty and **IPv6 Network Mask** should be **0**
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network4.png "docs:guide-user:vboxvmhost-only-network4.png")
_(optional) you can also set the DHCP server as shown in the screenshot if you want to have dynamic addresses to the VM, but for this tutorial it is not required as we set a static address in the VM itself_
* * *
Press OK to save and close until you are back to VirtualBox Manager interface again.
##### Network Settings
[](https://openwrt.org/_media/docs/guide-user/vboxvmsettings1.png "docs:guide-user:vboxvmsettings1.png")
Open the VM's settings
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmsettings2.png "docs:guide-user:vboxvmsettings2.png")
Go in the **Network** tab
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmsettings3.png "docs:guide-user:vboxvmsettings3.png")
configure **Adapter 1**:
1. with **Host-only Adapter**
2. select vboxnet0 as (adapter) **Name**
3. click on **Advanced** and in **Adapter Type** select **Intel PRO/1000 MT Desktop**
4. **Promiscuous mode** should be set to **Deny** unless you have good reasons to enable it.
* Configure **Adapter 2**
1. with **NAT**
* _(optional) Configure **Adapter 3**_
1. _with **Bridged Adapter**_
2. _in the Name field select the name of the network card (ethernet or wifi) of your PC that connected to a local network. On Windows it has a full device name, on Linux it will have codenames like **eth0**, **eth1** for ethernet or **wlp2s0** for wifi._
3. _Click on **Advanced** and do the same you did for **Adapter 1**'s advanced options_
#### Virtual Machine Settings
 Due to limitations, the keyboard in the virtual machine's terminal is set to US, so some (or most) of your keys may not print the symbols as indicated by the keycaps.
Also, due to the fact that what you see there is a bare machine terminal and not a smart thing like a SSH program (Putty/Kitty/whatever) or a terminal emulator program, you cannot copy-paste text into it.
Don't worry, most of the setup will be done after you are connected with SSH (remote terminal) that does not have any of these issues.
[](https://openwrt.org/_media/docs/guide-user/1280px-qwerty.png "docs:guide-user:1280px-qwerty.png")
Look at this US keyboard layout to find what button you need to press on your keyboard to generate the right symbol.
* * *
1. Boot into your Virtual Machine
2. Wait 4 seconds for GRUB to boot automatically
3. Press Enter to activate the console when the boot messages have finished scrolling by. It may take two or three minutes for “entropy” to be generated (`random: crng init done` with OpenWrt 17.01.4). Until there is sufficient entropy, SSH and other cryptographic functions may fail.
4. Display the current network configuration
root@openwrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula\_prefix='fd1b:e541:8f1a::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0'
network.lan.proto='static'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.lan.ipaddr='192.168.1.1'
network.wan=interface
network.wan.ifname='eth1'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.ifname='eth1'
network.wan6.proto='dhcpv6'
Note that the default LAN address of 192.168.1.1 is present on first boot.
1. Edit the network configuration to allow SSH access by writing these commands and pressing enter:
1. **uci set network.lan.ipaddr='192.168.56.2'**
2. **uci commit**
3. **reboot**
2. Now your VM should be accessible from SSH, user **root** (no password) address **192.168.56.2**.
3. After you have logged in successfully, we can actually do the true configuration. For 22.03 and earlier, copy-paste the following block of code and press enter:
uci batch < /etc/sudoers.d/00-custom
%sudo ALL\=(ALL) ALL
EOF
Testing
-------
Log in as an unprivileged user. Elevate privileges for a specific command.
sudo \-i \-u test
id
sudo id
Troubleshooting
---------------
Collect and analyze the following information.
id test
ls \-l /etc/sudoers /etc/sudoers.d/\*
grep \-v \-e "^#" \-e "^$" /etc/sudoers /etc/sudoers.d/\*
Extras
------
### References
* [useradd](http://man.cx/useradd%288%29 "http://man.cx/useradd%288%29")
* [usermod](http://man.cx/usermod%288%29 "http://man.cx/usermod%288%29")
* [groupadd](http://man.cx/groupadd%288%29 "http://man.cx/groupadd%288%29")
* [passwd](http://man.cx/passwd%288%29 "http://man.cx/passwd%288%29")
* [sudo](http://man.cx/sudo%288%29 "http://man.cx/sudo%288%29")
* [visudo](http://man.cx/visudo%288%29 "http://man.cx/visudo%288%29")
### Manual setup
Add the user by hand using a unique UID and GID.
\# Edit configs
vi /etc/passwd
vi /etc/group
vi /etc/shadow
\# Create home directory
mkdir \-p /home/test
\# Set permissions
chown test:test /home/test
\# Set user password
passwd test
Check the resulting configs.
\# Check configs
\> grep \-e test /etc/passwd /etc/group /etc/shadow
/etc/passwd:test:x:1000:1000::/home/test:/bin/ash
/etc/group:test:!:1000:
/etc/shadow:test:$1$uPzGJ3jI$n7ld4E73SPsIx0QTXPMfu1:19615:0:99999:7:::
### Removing user and group
Install the required packages. Remove the user and group.
\# Install packages
opkg update
opkg install shadow-userdel shadow-groupdel
\# Remove user and group
userdel test
groupdel sudo
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/02/20 11:32
* by elif
[](https://openwrt.org/docs/guide-user/security/sudo#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt on UTM on Apple Silicon HowTo
OpenWrt on UTM on Apple Silicon HowTo
=====================================
This document describes how to run the `armsr/armv8` OpenWrt images in a VM hosted on macOS (Apple Silicon hardware) using [UTM](https://docs.getutm.app/ "https://docs.getutm.app/")
.
Prerequisites
-------------
* [UTM](https://docs.getutm.app/installation/macos/ "https://docs.getutm.app/installation/macos/")
installed
* Familiarity with the command line on macOS (Terminal window)
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
This article may contain network configuration that depends on migration to DSA in OpenWrt 21.02
* Check if your device uses DSA or swconfig as not all devices have been migrated
* ifname@interface has been moved to device sections
* [DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Mini tutorial for DSA network config](https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998 "https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998")
on the forum
* [DSA in the 21.02 release notes](https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change "https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change")
### Select an OpenWrt image
You need an ARM system-ready 64-bit version of OpenWrt. There are two versions:
* `generic-squashfs-combined-efi.img.gz`: This edition uses a squashfs read-only root with a writable overlay.
* `generic-ext4-combined-efi.img.gz` This disk image uses a single read-write ext4 partition with no read-only squashfs root filesystem. Features like Failsafe Mode or Factory Reset won't be available as they need a read-only squashfs partition to function.
In the guide we'll use _generic-squashfs-combined-efi.img.gz_ because it supports sysupgrade.
* Download a stable release of the _generic-squashfs-combined-efi.img.gz_ image from [targets/armsr/arvm8/ folder](https://downloads.openwrt.org/releases/ "https://downloads.openwrt.org/releases/")
, e.g. [24.10.5](https://downloads.openwrt.org/releases/24.10.5/targets/armsr/armv8/openwrt-24.10.5-armsr-armv8-generic-squashfs-combined-efi.img.gz "https://downloads.openwrt.org/releases/24.10.5/targets/armsr/armv8/openwrt-24.10.5-armsr-armv8-generic-squashfs-combined-efi.img.gz")
.
* Or you can try a more recent release: as of this writing, the pre-release [25.12.0-rc1](https://downloads.openwrt.org/releases/25.12.0-rc1/targets/armsr/armv8/openwrt-25.12.0-rc1-armsr-armv8-generic-squashfs-combined-efi.img.gz "https://downloads.openwrt.org/releases/25.12.0-rc1/targets/armsr/armv8/openwrt-25.12.0-rc1-armsr-armv8-generic-squashfs-combined-efi.img.gz")
image is available.
* Uncompress the gzip'ed img file. On macOS in a Terminal window use the command `gzcat openwrt-*combined.img.gz > openwrt.img`. As a result you get the raw `openwrt.img` image file.
 Tip: keep a copy of the original gzip'ed image file, it can be used as an image for sysupgrade.
VM Setup in UTM
---------------
### VM creation
 Tutorial and screenshots from UTM 4.4.4 on Apple Silicon
[](https://openwrt.org/_media/media/virtualization/utm/1-utmstart.png "media:virtualization:utm:1-utmstart.png")
Start UTM and click _Create a new Virtual Machine_
* * *
[](https://openwrt.org/_media/media/virtualization/utm/2-virtualize.png "media:virtualization:utm:2-virtualize.png")
Select _Virtualize_
* * *
[](https://openwrt.org/_media/media/virtualization/utm/3-other.png "media:virtualization:utm:3-other.png")
Select _Other_ (because the _Linux_ install path assumes an install ISO image, which we are not using for OpenWrt)
* * *
[](https://openwrt.org/_media/media/virtualization/utm/4-no-iso-boot.png "media:virtualization:utm:4-no-iso-boot.png")
Check the _Skip ISO boot_ box
* * *
[](https://openwrt.org/_media/media/virtualization/utm/5-cpu-memory.png "media:virtualization:utm:5-cpu-memory.png")
Configure 512MB and 2 CPUs (enough memory for running sysupgrade later)
* * *
[](https://openwrt.org/_media/media/virtualization/utm/6-storage.png "media:virtualization:utm:6-storage.png")
Accept the default storage setting (we will remove this drive later and replace it with the OpenWrt image)
* * *
[](https://openwrt.org/_media/media/virtualization/utm/7-shared.png "media:virtualization:utm:7-shared.png")
Leave the shared directory configuration blank
* * *
[](https://openwrt.org/_media/media/virtualization/utm/8-summary.png "media:virtualization:utm:8-summary.png")
Check the _Open VM Settings_ box. Fill in a name for the VM. Click _Save_. This brings you to the VM settings page.
* * *
### VM configuration
The configuration you will set up by following this tutorial is:
* **br-lan** of the VM on **lan** interface, fixed address 10.0.2.2, set in UTM as **Host Only Network**. This interface will _always_ be available to the host even if host or VM are disconnected from any network.
* **eth1** of the VM on **wan** interface, dynamic address, set in UTM as **Shared Network** (NAT). This interface will be used to access the Internet through whatever setup the host also uses.
Note that the _order_ of the “Host Only” and “Shared Network” networks is important for turn-key operation of OpenWrt in the VM. While it can be configured using the console, configuration in this way simplifies getting to a running configuration.
#### VM settings
##### Remove unused devices
[](https://openwrt.org/_media/media/virtualization/utm/10-remove.png "media:virtualization:utm:10-remove.png")
Control-click on _Display_ and remove it. Control-click on _Sound_ and remove it. Control-click on the _VirtIO Drive_ and remove it. Confirm deleting the drive with _Delete_. (This is the blank disk that UTM creates during VM creation. We don't need it.)
* * *
##### Network Settings
[](https://openwrt.org/_media/media/virtualization/utm/11-host-only.png "media:virtualization:utm:11-host-only.png")
Select _Network_. Change the Network Mode to _Host Only_. Check the _Show Advanced Settings_ box. In the _Guest Network_ box, type in the network range for the VM's LAN: _10.0.2.0/24_.
* * *
[](https://openwrt.org/_media/media/virtualization/utm/12-wan.png "media:virtualization:utm:12-wan.png")
Under Devices, click the _+New_ entry and add a new _Network_. Click on the network and confirm it is configured as _Shared Network_.
* * *
##### Other Device Settings
[](https://openwrt.org/_media/media/virtualization/utm/13-serial.png "media:virtualization:utm:13-serial.png")
Under Devices, click the _+New_ entry and add a new _Serial_ device. Click on the Serial device and check the mode. The default is a built-in terminal window that supports copy and paste with native macOS keyboard shortcuts.
* * *
[](https://openwrt.org/_media/media/virtualization/utm/14-disk.png "media:virtualization:utm:14-disk.png")
Under the _Drives_ section, select _New..._. Accept the interface default (VirtIO) and click on _Import..._. Navigate to the `openwrt.img` file you unpacked in previous steps.
* * *
_Save_ the configuration.
#### Virtual Machine OpenWrt Settings
* * *
* Start your Virtual Machine (click the Play icon button)
* Wait 4 seconds for GRUB to boot automatically
* Press Enter to activate the console when the boot messages have finished scrolling by.
* Display the current LAN network configuration. Note that the default LAN address of 192.168.1.1 is present on first boot.
root@openwrt:~# uci show network.lan
network.lan=interface
network.lan.device='br-lan'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
* Edit the network configuration to allow SSH access by pasting these commands into the console:
uci set network.lan.ipaddr='10.0.2.2'
uci commit
service network restart
* Now your VM is accessible from SSH, user **root** (no password) address **10.0.2.2**
* If you installed a release image such as 23.05.0, the LuCi web interface is available at [http://10.0.2.2/](http://10.0.2.2/ "http://10.0.2.2/")
(no password)
* If you installed a snapshot that doesn't include LuCi, install it with
opkg update && opkg install luci
* You should have both internet access (try a **opkg update**) AND a LAN interface with a static address you can connect your SSH client program to even if your PC is disconnected from a local network.
* If you have more complex requirements you will have to set that up on your own by reading the documentation, or through LuCi.
See also
--------
* [Other virtualization options](https://openwrt.org/docs/guide-user/virtualization/start "docs:guide-user:virtualization:start")
: Docker, VMware etc.
* [VMware Fusion](https://openwrt.org/docs/guide-user/virtualization/fusion "docs:guide-user:virtualization:fusion")
: Configuring on a VM hosted on VMware Fusion
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/12/22 00:30
* by atownlede
[](https://openwrt.org/docs/guide-user/virtualization/utm#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] VirtualBox Advanced
VirtualBox Advanced
===================
**Work in Progress!**
This page is a continuous work in progress. You can edit this page to contribute information.
Overview
--------
This guide extends the basic VirtualBox HowTo with broader setup recommendations, samples and common “gotcha-s”.
NOTE: Use a wired virtualbox host (unless you are really confident with virtualbox i.e. 80211 bridging issues ).
Prerequisite Concepts
---------------------
### x86\_64 Basics
As the operating system within VirtualBox is basically an x86\_64 host, having a general grasp of the hard drive partition setup, bootloader operation et. al. is beneficial. Particularly, when you need to undertake more advanced network interface setup within the VM and then translate that to VBox nics. In other words, lack of confidence performing bare metal config will compound troubleshooting if you are unable to clearly differentiate what is physical and what is virtual. In this case perhaps using an old pc or spare usb disk to test on real hardware first is a good first step.
### squashfs vs ext4
You'll likely need to select between a combined squashfs vs ext4 OpenWrt image to use[1)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fn__1)
. For most hardware supported by OpenWrt, **combined-squashfs** is recommended (and in many cases the only type of image offered). For x86 hardware where space is not an issue, OpenWrt is offered also in **combined-ext4** images. Let's look at what are the differences.
### Where is my router?
[](https://openwrt.org/_media/media/netdiag1c.png "media:netdiag1c.png")
#### Using squashfs:
* sysupgrade at any time to update the kernel, which is useful if you are tracking snapshot to have the latest and greatest
* factory reset
* the default read-write partition in a squashfs image is 128MB, it's uncommon to actually fill it up with common package additions
* If you need more space for data you can always increase the virtual disk size and add a data partition (which will be preserved on sysupgrade), or even better add more virtual drives you would use just for storage.
Squashfs images are neat when you are using the [Imagebuilder](https://openwrt.org/docs/guide-user/additional-software/imagebuilder "docs:guide-user:additional-software:imagebuilder")
to integrate all packages you want in a single re-settable image. You can install with sysupgrade, and not lose any of your “installed packages” as you have integrated them in the base firmware image.
Since you have Virtualbox anyway, why not have a Debian or Ubuntu VM and use the Imagebuilder too. It's a very convenient way of tracking snapshot(master) to have the latest and greatest, and the only practical way to do so for most other devices supported by OpenWrt, so this is more or less the best “choice” for OpenWrt veterans that have deployed many devices and are using the imagebuilder already.
NB: With Imagebuilder, the size of the read-write partition is irrelevant as all packages are embedded in the squashfs read-only partition that is enlarged as needed, so 128MB is available for config only.
#### Using ext4:
* With ext4 you lose the ability to sysupgrade but you can keep updating packages over and over. ( todo: clarify see final sentence )
* Depending on your hdd durability, there is more wear but most users have zero issues. Kindof mute for vm's.
* Updating the kernel must be done manually by mounting the first partition (**/dev/sda1** if you have only one disk) and replacing the “**vmlinuz**” file you find in the **/boot** folder with the file with the same name you find in the download folder [https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/](https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/ "https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/")
, then installing the “**kernel\_xxxx.ipk**” package you find here [https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/packages/](https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/packages/ "https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/packages/")
for example if you just updated to 18.06.04 stable release, and then reboot. \\\\That's a virtual package, it exists only to tell the system what kernel version is installed but does not actually install anything. The reason this is not done is that the kernel installation in 99% of OpenWrt targets happens through Sysupgrade process, not through packages, so none took the time and effort to actually have kernel upgrades done properly in this fashion. But anyway, it's easy enough to script around this issue I guess.
* With ext4 you can increase the partition size to your heart's content, but you will need to do it “offline”, i.e. by booting a Gparted liveCD in your Virtualbox VM, as the default ext4 image is too small (technical reason: _the filesystem does not contain enough inodes at this size_) to allow online resizing (_ext4 can be enlarged without using a liveCD if it is big enough at the start_)
This type of image mimics a more conventional Linux distro like Debian or Ubuntu, where you have packages and you keep updating or installing them as needed. But afaik this is a bit of a pain to do if you try to follow snapshot, as OpenWrt does not implement the ability to have multiple ( non-identical ) kernels with kernel modules (the Linux “device drivers”) installed at the same time, and select what kernel to boot when you reboot. Although it is possible to manually edit grub.cfg to support this manually using differing rootfs partitions for each kernel ( without sysupgrade support )
So when you go and update the kernel or the kernel modules (packages that start with **kmod-xxxx.ipk**) you will probably experience breakage or will have to fight against opkg that refuses to install them as they are not compatible with the kernel in use. I _think_ that you could actually do this if you install the kernel first, which is a virtual package, and then install the kmod packages and then reboot immediately, but I never tried so YMMV.
Therefore, using sysupgrade to flash a new combined-ext.bin will typically zap the “boot” and “rootfs” partitions, config is migratable, packages are not.
### VirtualBox Networking Basics
Knowledge of the basic network types offered by VirtualBox will help you immensely...
* Take a few minutes to draw a simple diagram of how a HOST network maps to a GUEST machines networks/interfaces will save you much drama and need to reconfigure down the track. [2)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fn__2)
Networking Ideas
----------------
### Example 1
Example 1 is useful for testing both LAN and WAN sides of OpenWrt.
* All connections use the same physical network and separation is logical only.
* Both sides of the router are accessible.
* Changing the gateway and dns on your HOST will send your traffic via OpenWrt ( dual-nat ).
[](https://openwrt.org/_media/media/netdiag1.png "media:netdiag1.png")
OpenWrt VM
vmnic0 bridged LAN 192.168.1.1 (disable dhcp server)
vmnic1 bridged WAN (dhcp from normal network)
HostOS
hostnic0 dhcp (or normal setting)
hostnic0:2 192.168.1.2
This configuration is highly adaptable... with the caveats of not using the OpenWrt dhcp server, and the shared physical medium ( lesser isolation ). You could easily run an openvpn client and assign LAN hosts the 192.168.1.x range etc. so send them via the OpenWrt VM.
### Linux VirtualBox Auto Create
NOTE: Requires: wget, gunzip and VBoxManage ( VirtualBox )
#!/bin/bash
sNAME\="openwrtx64-\`date +%Y%m%d-%H%M\`"
dirCACHE\="${HOME}/cache"; mkdir \-p $dirCACHE
VMFOLD\="\`cat ~/.config/VirtualBox/VirtualBox.xml | grep -i SystemProperties | cut -d'"' -f2\`"
VDI\="${sNAME}.vdi"
DISKSIZE\='512000000'
VMNAME\="${sNAME}"
IMGC\="${dirCACHE}/openwrt-18.06.4-x86-64-combined-ext4.img.gz"
URL\="https://downloads.openwrt.org/releases/18.06.4/targets/x86/64/openwrt-18.06.4-x86-64-combined-ext4.img.gz"
WGET\="wget"; GUNZIP\="gunzip"; VBOXMANAGE\="VBoxManage"
echo " Creating VM: $VMNAME"
echo " Cache: ${HOME}/cache"
echo " Disksize: $DISKSIZE"
sleep 2
if \[ ! \-f "${IMGC}" \]; then
echo "Downloading Image: $URL"
$WGET "${URL}" \-O "${IMGC}" || echo "Failed to download: ${URL}" && exit 1
else
echo "Using cached Image: $IMGC"
fi
sleep 2
$VBOXMANAGE createvm \--name $VMNAME \--register
$VBOXMANAGE modifyvm $VMNAME \\
\--description "openwrt vbox" \\
\--ostype "Linux26" \\
\--memory "512" \\
\--cpus "1" \\
\--nic1 "bridged" \\
\--nictype1 82540EM \\
\--nic2 "bridged" \\
\--nictype2 82540EM
$VBOXMANAGE storagectl $VMNAME \\
\--name "SATA Controller" \\
\--add "sata" \\
\--portcount "4" \\
\--hostiocache "on" \\
\--bootable "on" && \\
$GUNZIP \--stdout "${IMGC}" | $VBOXMANAGE convertfromraw \--format VDI stdin ${VMFOLD}/${VMNAME}/${VDI} $DISKSIZE
$VBOXMANAGE storageattach $VMNAME \\
\--storagectl "SATA Controller" \\
\--port "1" \\
\--type "hdd" \\
\--nonrotational "on" \\
\--medium $VMFOLD/${VMNAME}/$VDI
echo "Open the VNIC in VirtualBox to populate bridged adapter name"
echo "############################################################"
echo " DISABLE DHCP on router! "
echo "############################################################"
echo ""
exit 0
#### Add some shaping
As virtualbox built in shaping only works in one direction... example 1 is the perfect network architecture to perform shaping using the built in virtualbox bandwidth limits. It is possible to change the speed on the fly while the vm is running.
( NOTE: “wan” in the script below refers to the vm-nic1(second) )
#!/bin/bash
VMNAME\="openwrtx64-20191002-2352"
lannicspeed\="350k" \# .35mb/s use m for mbps
wannicspeed\="360k" #
VBoxManage bandwidthctl "$VMNAME" add Limitlan \--type network \--limit $lannicspeed
VBoxManage bandwidthctl "$VMNAME" add Limitwan \--type network \--limit $wannicspeed
VBoxManage modifyvm "$VMNAME" \--nicbandwidthgroup1 Limitlan #assign to nic1
VBoxManage modifyvm "$VMNAME" \--nicbandwidthgroup2 Limitwan #assign to nic2
#### Tagging for VM's
Note: example ip link is non-permanent... see your distro for appropriate place to configure your host nic for a vlan.
You can use a single cable as a “trunk”. This essentially turns your wired link into a managed switch as you will tag VLAN per vm upstream on the wired link.
This can be used for clients... with openwrt on a “real router” running several vlans over a single LAN port. Or you could use this method for an OpenWrtVM... tag several of it's interfaces outside of the guest software... “mimicking” a managed switch.
This example shows clientVM's to an upstream OpenWrt router.
######################################################### Step1 ONHOST
NIC\="enp0s25"
ip link add link $NIC name $NIC.50 type vlan id 50
ip link set dev $NIC.50 up
######################################################### Step2
In VirtualBox change bridge for a VM to interface NIC.50
######################################################### Step3 In Openwrt
#-Go to switch... add vlan 50 tagged on same port as pc/server + cpu1
#-Go to interfaces... add interface... NAME + INTERFACE:ethNcpu.50 + IP:192.168.50.1 etc. etc.
################################## debugging on host
#ip -d link show $NIC.50
#ip link delete $NIC.50
#tcpdump -nnei $NIC -vvv
### Example:1b SameSegment-same-Subnet PreRouter
#### Advantages
* no dual nat
* seamless client redirection via dhcp gateway re-assignment
* reduces management / configuration overhead due to single subnet/range
* cpu and memory intensive services can be run on your best hardware
#### Disadvantages
* firewall is dependent on edge router
* introduces second point of failure for clients using the “middle” router
* vm host / guest power consumption
[](https://openwrt.org/_media/media/netdiag1b.png "media:netdiag1b.png")
As show in the diagram;
* Only the LAN interface is bridged, with a static ip on your LAN subnet
* The LAN interface has both gateway and dns servers set to the edge router
* Clients gateway and/or dns pointed to the VM should you wish to use say VPN etc. there...
You now have a powerful internal router for VPN and any other service you wish. Leaving the edge router to do simple routing, nat and firewalling tasks. Give some clients your normal LAN gateway and some clients the OpenWrt VM, and presto! poor mans PBR ;).
#### CLI Basic Network Access Setup (vi dhcp)
\* use gateway and dns options for static ip
[vbox-simple-opkg-as-client.webm](https://openwrt.org/_media/media/vbox-simple-opkg-as-client.webm?cache= "media:vbox-simple-opkg-as-client.webm (1.9 MB)")
#### CLI Install LUCI on snapshot
[vbox-simple-opkg-add-luci-to-snapshot.webm](https://openwrt.org/_media/media/vbox-simple-opkg-add-luci-to-snapshot.webm?cache= "media:vbox-simple-opkg-add-luci-to-snapshot.webm (6.4 MB)")
### Buildroot Export
When testing anything not hardware specific. Using the buildroot and firing it up straight away can be a big time saver. The sample script shows basic buildroot to vbox quick setup.
#!/bin/bash
sNAME\="openwrtx64-\`date +%Y%m%d-%H%M\`"
VMFOLD\="\`cat ~/.config/VirtualBox/VirtualBox.xml | grep -i SystemProperties | cut -d'"' -f2\`"
VDI\="${sNAME}.vdi"; DISKSIZE\='512000000'; VDIOSZ\='1920'; VIDMEM\="16"
VMNAME\="${sNAME}"
VBOXMANAGE\="VBoxManage"
brvdi\="bin/targets/x86/64/openwrt-x86-64-combined-ext4.vdi"
cat .config | grep \-q '^CONFIG\_VMDK\_IMAGES=y' || echo "Enable vm-image creation and run make" && exit 1
if \[ ! \-f "${brvdi}" \]; then echo "You no built vdi at: $brvdi ... ran make?" && exit 2
echo "Creating VM: $VMNAME" && sleep 2
$VBOXMANAGE createvm \--name $VMNAME \--register 2\>/dev/null \>/dev/null
echo "Copying buildroot vdi to ${VMFOLD}/${VMNAME}/${VDI}"
cp $brvdi ${VMFOLD}/${VMNAME}/${VDI}
$VBOXMANAGE modifyvm $VMNAME \--description "openwrt vbox" \--ostype "Linux26" \\
\--memory "512" \--vram "$VIDMEM" \--cpus "1" \\
\--nic1 "nat" \--nictype1 82540EM \\
\--nic2 "nat" \--nictype2 82540EM 2\>/dev/null \>/dev/null
$VBOXMANAGE storagectl $VMNAME \--name "SATA Controller" \--add "sata" \\
\--portcount "4" \--hostiocache "on" \\
\--bootable "on" 2\>/dev/null \>/dev/null
$VBOXMANAGE storageattach $VMNAME \--storagectl "SATA Controller" \\
\--port "1" \--type "hdd" \--nonrotational "on" \\
\--medium $VMFOLD/${VMNAME}/$VDI 2\>/dev/null \>/dev/null
exit 0
### Openvswitch
Openvswitch can be useful when you wish to go beyond basic virtualbox networking options. For a basic test. Try running your VM LAN interface bridged to a vswitch bridge.
sudo apt-get install \-y openvswitch-switch bridge-utils
sudo ovs-vsctl add-br br201
sudo ifconfig br201 192.168.1.2 netmask 255.255.255.0 up
Then change the correct VM>bridged-to interface to br201 in VirtualBox.
NOTE: You may need to set the vbox-nic promiscous mode to Allow if bridging to a host bridge [https://forum.openwrt.org/t/only-the-first-interface-in-br-lan-is-working-properly-with-a-virtualbox-x86-64-openwrt/62539/5](https://forum.openwrt.org/t/only-the-first-interface-in-br-lan-is-working-properly-with-a-virtualbox-x86-64-openwrt/62539/5 "https://forum.openwrt.org/t/only-the-first-interface-in-br-lan-is-working-properly-with-a-virtualbox-x86-64-openwrt/62539/5")
### ToDo Serial and SSH console examples
### Video of Boot
For boot-time debugging purposes... you would generally want to attach a vbox-console. One nice and easy trick is to use the capture facility of VirtualBox. Not so handy for copy paste but this method has it's own advantages.
Settings ⇒ Display ⇒ Recording \[x\] Enable Recording
( NB: you must repeat this every boot, you can find the default .webm file in the VirtualBox machines directory )
Tips beyond the Basic
---------------------
* vnic0 ( LAN ) is key. Get access to it... Know how it works at each level of abstraction.
* Don't test 500 things at once... check each connection piece by piece. No WAN access in a VM is the same as no WAN access on any network, etc. etc. etc. Simplify and conquer.
* If the VM is to be used for mission critical traffic... test thoroughly, and configure all HOST settings in a persistent manner.
* If you really need to isolate clients. Seriously consider using 2 HOST NICs.
Gotcha-s
--------
### Initial vmnicX>LAN access
If your having a hard time accessing the OpenWrtVBox-LAN ( LUCI )
1. Check the network layers
2. Your HOST or CLIENT ip in 192.168.1.x
3. No other network 192.168.1.x in use!
4. Use the VirtualBox GUI to access the OpenWrtVbox commandline ( ifconfig OR ping OR edit /etc/config/network and /etc/init.d/network restart
5. Check the VirtualBox GUI and selectively bridge each vnic and check that “Connected” is ticked. If the CLIENT is another VM... Change the network type to bridged also.
NOTE:
* You may need to clone eth0 for eth2, eth3 etc, if you have more than two virtual nics.
### I ran out of space
Easy! Power Down the VM, add a new disk ( VirtualBox → Machine-Settings → Storage → Add Storage Attachment → Add New Disk → Create New Disk) then follow [3)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fn__3)
from step 3-ish... to setup /overlay storage.
### Can I make it simpler?
Sure! Use hostonly ( no dhcp ← VirtualBox Network Settings ) for OpenWrtVBoxLAN and a SECOND VM with it's single VNIC also set to hostonly as the client. Set OpenWrtVBox VNIC2-WAN to bridged.
Questions you should have answers to
------------------------------------
* What are your disk requirements? ( many packages will need an additional disk as overlay, resizing the default partition within an official img or using the buildroot to specify disk parameters from the get-go )
* How many Network Interfaces will the GUEST require? ( i.e.; LAN, WAN and SPARE )
* Which physical or HOST interfaces/networks will these GUEST interfaces be mapped to?
* On what network will your GUEST client/s reside? Are you comfortable troubleshooting basic connectivity?
* Disk space available on the host? Its lovely to generate a router with 30GB space in the buildroot... but do you want to be cloning/using/backing up that much?
* Do you need to start the VM with networking disconnected to disable dhcp or change the LAN ipaddress?
### Resources
VirtualBox Networking Overview [https://www.youtube.com/watch?v=cDF4X7RmV4Q](https://www.youtube.com/watch?v=cDF4X7RmV4Q "https://www.youtube.com/watch?v=cDF4X7RmV4Q")
OpenWrt x86 Basics [OpenWrt on x86 hardware aka PC or Servers](https://openwrt.org/docs/guide-user/installation/openwrt_x86 "docs:guide-user:installation:openwrt_x86")
\[3\] [OpenWrt on VirtualBox HowTo](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm "docs:guide-user:virtualization:virtualbox-vm")
\[5\] Image filesystems and alteration in detail [https://quantumwarp.com/kb/articles/25-dsl-broadband/899-run-lede-as-a-virtualbox-virtual-machine](https://quantumwarp.com/kb/articles/25-dsl-broadband/899-run-lede-as-a-virtualbox-virtual-machine "https://quantumwarp.com/kb/articles/25-dsl-broadband/899-run-lede-as-a-virtualbox-virtual-machine")
\[7\] forum re: macos 80211 bridging issues [https://forum.openwrt.org/t/virtualbox-openwrt-works-fine-but-clients-connecting-to-vm-router-have-no-internet/71398](https://forum.openwrt.org/t/virtualbox-openwrt-works-fine-but-clients-connecting-to-vm-router-have-no-internet/71398 "https://forum.openwrt.org/t/virtualbox-openwrt-works-fine-but-clients-connecting-to-vm-router-have-no-internet/71398")
* * *
[1)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fnt__1)
[OpenWrt on x86 hardware aka PC or Servers](https://openwrt.org/docs/guide-user/installation/openwrt_x86 "docs:guide-user:installation:openwrt_x86")
[2)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fnt__2)
[https://www.youtube.com/watch?v=cDF4X7RmV4Q](https://www.youtube.com/watch?v=cDF4X7RmV4Q "https://www.youtube.com/watch?v=cDF4X7RmV4Q")
[3)](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#fnt__3)
[Adding Overlay](https://openwrt.org/docs/guide-user/additional-software/extroot_configuration "docs:guide-user:additional-software:extroot_configuration")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/08/15 16:11
* by someothertime
[](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Secure access to your router
Secure access to your router
============================
See also: [Elevating privileges with sudo](https://openwrt.org/docs/guide-user/security/sudo#goals "docs:guide-user:security:sudo")
There are some possibilities to grant access to the router (or to any PC/Server):
1. ask for nothing: anybody who can establish a connection gets access
2. ask for username and password on an unsecured connection (e.g. telnet)
3. ask for username and password on an encrypted connection (e.g. SSH) (e.g. by following [walkthrough\_login](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
)
4. ask for username and merely a **`signature`** instead of a **`password`** (e.g. SSH with [dropbear.public-key.auth](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth "docs:guide-user:security:dropbear.public-key.auth")
)
If you ask for username/password, an attacker has to guess the combination. If you use an unencrypted connection, they could eavesdrop on you and obtain your credentials.
If you use an encrypted connection, any eavesdropper would have to decrypt the packets first. This is always possible. How long it takes to decrypt the content, depends on the algorithm and key length you used.
Also, as long as an attacker has network access to the console, they can always run a brute-force attack to find out your username and password. They does not have to do that themself: they can let their computer(s) do the guessing. To render this option improbable or even impossible you can:
1. not offer access from the Internet at all, or restrict it to certain IP addresses or IP address ranges
1. by letting the SSH server [Dropbear](https://openwrt.org/docs/guide-user/base-system/dropbear "docs:guide-user:base-system:dropbear")
and the web server [uHTTPd](https://openwrt.org/docs/guide-user/services/webserver/uhttpd "docs:guide-user:services:webserver:uhttpd")
not listen on the external/WAN port
2. by blocking incoming connections to those ports (TCP 22, 80 and 443 by default) in your firewall
2. make it more difficult to guess:
1. don't use the username `root`
2. don't use a weak password with 8 or less characters
3. don't let the SSH server Dropbear listen on the default port (22)
3. use the combination of
1. set up [Dropbear key-based authentication](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth "docs:guide-user:security:dropbear.public-key.auth")
2. username different than `root`
3. tell Dropbear to listen on a random port (should be >1024): System → Administration → Dropbear Instance → Port[](https://openwrt.org/_detail/media/doc/howtos/secure-access-02-ssh-port.png?id=docs%3Aguide-user%3Asecurity%3Asecure.access "media:doc:howtos:secure-access-02-ssh-port.png")
System hardening
----------------
If you have an external disk you may want to [encrypt it](https://openwrt.org/docs/guide-user/storage/disk.encryption "docs:guide-user:storage:disk.encryption")
.
Network hardening
-----------------
1. [Fwknop](https://www.cipherdyne.org/fwknop/ "https://www.cipherdyne.org/fwknop/")
(FireWall KNock OPerator) implements an authorization scheme called [Single Packet Authorization](https://en.wikipedia.org/wiki/Single%20Packet%20Authorization "https://en.wikipedia.org/wiki/Single Packet Authorization")
(SPA) alongwith [setting up two factor authentication](https://secure.wphackedhelp.com/blog/wordpress-two-factor-authentication/ "https://secure.wphackedhelp.com/blog/wordpress-two-factor-authentication/")
. This method of authorization is based around a default-drop packet filter and libpcap. SPA is essentially next generation port knocking. For example: it can open the port for SSH on WAN, but just for a short period of time, until you can establish a new connection through that port.
* See detailed instructions at: [Fwknop](https://openwrt.org/docs/guide-user/services/fwknop "docs:guide-user:services:fwknop")
2. [Ostiary](http://ingles.homeunix.net/software/ost/index.html "http://ingles.homeunix.net/software/ost/index.html")
, like port knocking, adds an additional layer of security. It can be used to simply initiate a script or task remotely (without needing SSH access). See detailed instructions for configuring Server or Client by going to the corresponding links below.
* [Ostiary Server](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.server "docs:guide-user:services:remote_control:ostiary.server")
* [Ostiary Client](https://openwrt.org/docs/guide-user/services/remote_control/ostiary.client "docs:guide-user:services:remote_control:ostiary.client")
3. To protect open ports against brute force attack, the attacker ip address can be banned via iptables configuration:
* [forum thread 7493](https://forum.openwrt.org/viewtopic.php?id=7493 "https://forum.openwrt.org/viewtopic.php?id=7493")
* [forum thread 27103](https://forum.openwrt.org/viewtopic.php?id=27103 "https://forum.openwrt.org/viewtopic.php?id=27103")
4. Dependent on you situation you may want to employ an [Intrusion prevention system](https://en.wikipedia.org/wiki/Intrusion%20prevention%20system "https://en.wikipedia.org/wiki/Intrusion prevention system")
like [fail2ban](https://en.wikipedia.org/wiki/fail2ban "https://en.wikipedia.org/wiki/fail2ban")
or better yet implement your own one based on `logtrigger`.
Protecting web interface
------------------------
For secure web access, OpenWrt can be accessed via HTTPS (TLS) instead of the unencrypted HTTP protocol. If HTTP is not secure enough for you, you can disable the existing (unencrypted) web access and either
* [Tunnel your connection via SSH](https://openwrt.org/docs/guide-user/luci/luci.secure "docs:guide-user:luci:luci.secure")
* Follow [Providing encryption](https://openwrt.org/docs/guide-user/luci/luci.essentials#providing_encryption "docs:guide-user:luci:luci.essentials")
to set up SSL protected access
1. While luci-ssl automatically installs px5g that can be utilized, you can also use openssl to generate your own certificate authority and certs, then use that certificate authority to sign the certificate you use for uhttpd. Certificates can also be named or placed in whatever directory you wish by editing **/etc/config/uhttpd**
2. Optionally instruct the server to not listen on plain HTTP anymore:
uci \-q delete uhttpd.main.listen\_http
uci commit uhttpd
/etc/init.d/uhttpd restart
**OR** Rebind to LAN only and redirect all http requests to https:
uci set uhttpd.main.listen\_http="192.168.1.1:80"
uci set uhttpd.main.listen\_https="192.168.1.1:443"
uci set uhttpd.main.redirect\_https="1"
uci commit
/etc/init.d/uhttpd restart
Can mandatory client certificate checking be set up with uhttpd? → [not possible with uhttpd](http://lists.infradead.org/pipermail/lede-dev/2017-August/008692.html "http://lists.infradead.org/pipermail/lede-dev/2017-August/008692.html")
If you require remote SSH access, follow the hardening instructions on SSH mentioned above.
Protecting PPP credentials
--------------------------
When using PPP, protect its credentials from unprivileged users.
PPP\_IF\="wan"
PPP\_USER\="$(uci -q get network.${PPP\_IF}.username)"
PPP\_PASS\="$(uci -q get network.${PPP\_IF}.password)"
cat << EOF \>> /etc/ppp/options
user ${PPP\_USER}
EOF
cat << EOF \>> /etc/ppp/chap-secrets
${PPP\_USER} \* ${PPP\_PASS}
EOF
ln \-f /etc/ppp/chap-secrets /etc/ppp/pap-secrets
chmod go\= /etc/ppp/chap-secrets
uci \-q delete network.${PPP\_IF}.username
uci \-q delete network.${PPP\_IF}.password
uci commit network
/etc/init.d/network restart
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/09/15 17:59
* by vgaetera
[](https://openwrt.org/docs/guide-user/security/secure.access#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Dropbear key-based authentication
Dropbear key-based authentication
=================================
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
Introduction
------------
* This how-to describes the method for setting up [key-based authentication](https://en.wikipedia.org/wiki/Key%20authentication "https://en.wikipedia.org/wiki/Key authentication")
for [Dropbear](https://openwrt.org/docs/guide-user/base-system/dropbear "docs:guide-user:base-system:dropbear")
.
* Follow [SSH access for newcomers](https://openwrt.org/docs/guide-quick-start/sshadministration#terminal_emulators "docs:guide-quick-start:sshadministration")
to set up key-based authentication for PuTTY.
Goals
-----
* Enable key-based authentication for Dropbear for convenience
* Improve security by disabling password authentication
Generating public and private keys using SSH-Keygen on a host machine
---------------------------------------------------------------------
Skip this if you already have a public / private key pair on your client machine that you intend to use to connect to the OpenWrt SSH server.
The [ssh-keygen](http://man.cx/ssh-keygen%281%29 "http://man.cx/ssh-keygen%281%29")
utility can be used to generate a key pair to use for authentication. After you have used this utility, you will have two files, by default _~/.ssh/id\__ (the private key) and _~/.ssh/id\_.pub_ (the public key). **Always keep your private key (e.g. _~/.ssh/id\__) secret and secure.**
\# Generate a new key pair, 3072-bit RSA by default
ssh-keygen
\# Generate a new Ed25519 key pair
ssh-keygen \-t ed25519
Note that Dropbear on OpenWrt devices with small flash memory [does not support Ed25519 type keys](https://github.com/openwrt/openwrt/commit/d0f295837a03f7f52000ae6d395827bdde7996a4 "https://github.com/openwrt/openwrt/commit/d0f295837a03f7f52000ae6d395827bdde7996a4")
.
Keep your software up-to-date to safely rely on the cryptography-related defaults.
Generating public and private keys on the OpenWrt machine
---------------------------------------------------------
You might want to generate a key for your device so that logins from your router can be authenticated when you connect to other machines from your router.
Dropbearkey can generate a key directly on your device, it should be placed in the `~/.ssh` directory of your user so you might need to create this directory first on a new install:
mkdir ~/.ssh
dropbearkey \-t ed25519 \-f ~/.ssh/id\_dropbear
And you can inspect the corresponding public key for your OpenWrt device like this:
dropbearkey \-y \-f ~/.ssh/id\_dropbear
By default Dropbear reads `~/.ssh/id_dropbear` so putting the private key there avoids the need to create an SSH configuration file.
From the LuCI Web Interface
---------------------------
Once your terminal program on your laptop/desktop has a public key, you can forgo entering a password each time you SSH to your device. (This is secure: only your terminal program with the appropriate private key can log in without a password.) First, generate the public and private keys (see above). Then add your PUBLIC key (it's often called _id\_rsa.pub_ - **it MUST have “.pub”** in the filename) to the device.
To do this from LuCI:
1. Navigate to **LuCI → System → Administration → SSH\-Keys**
2. Copy the contents of your public key file. It will be a long string starting with `ssh-rsa ...` and ending with something like `... some-name@some-host.lan`
3. Paste that string into _Paste or drag key file..._ field on the web page
4. Click the **Add key** button
5. To test: open a new window in your terminal program and enter `ssh root@your-router-address` You should be logged in without entering your password.
From the Command-line
---------------------
Read your public key (it's usually in **~/.ssh/id\_rsa.pub** on a linux system) and add it to **/etc/dropbear/authorized\_keys**.
Example:
ssh root@192.168.1.1 "tee -a /etc/dropbear/authorized\_keys" < ~/.ssh/id\_rsa.pub
### Using ssh-copy-id
Add your public key to the router using [ssh-copy-id](http://man.cx/ssh-copy-id%281%29 "http://man.cx/ssh-copy-id%281%29")
.
ssh-copy-id root@openwrt.lan
[Generate](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth#generating_public_and_private_keys "docs:guide-user:security:dropbear.public-key.auth")
a new authentication key if necessary.
Testing
-------
Use [ssh](http://man.cx/ssh%281%29 "http://man.cx/ssh%281%29")
to log in your router using command-line interface, temporarily disabling password authentication to verify that you can login and that it does not ask you for a password:
ssh \-o PasswordAuthentication\=no root@openwrt.lan
Until you have sucessfully completed this test, it is unwise to disable password authentication on the OpenWrt SSH server as you may lock yourself out.
Troubleshooting
---------------
Collect and analyze the following information.
\# Restart services
service log restart; service dropbear restart
\# Log and status
logread \-e dropbear; netstat \-l \-n \-p | grep \-e dropbear
\# Runtime configuration
pgrep \-f \-a dropbear
\# Persistent configuration
uci show dropbear; ls \-l /etc/dropbear; cat /etc/dropbear/authorized\_keys
Additionally, run your ssh client with maximum verbosity (`ssh -vvv`) and check the output. If you see something like
send\_pubkey\_test: no mutual signature algorithm
you might want to try to run the ssh client with the `-o PubkeyAcceptedKeyTypes=ssh-rsa` option. You can save this setting in your `.ssh/config` file in an entry dedicated to your router.
* * *
Dropbear **DOES NOT** support [ECDSA key types](https://github.com/openwrt/openwrt/issues/7984 "https://github.com/openwrt/openwrt/issues/7984")
and LuCI [will not warn you](https://github.com/openwrt/luci/issues/6263 "https://github.com/openwrt/luci/issues/6263")
when adding one. For wider support of more key types and other features, you should consider [Replacing Dropbear with OpenSSH + SFTP](https://openwrt.org/docs/guide-user/services/ssh/openssh_instead_dropbear "docs:guide-user:services:ssh:openssh_instead_dropbear")
.
Extras
------
### Showing the device's public key
This is useful if you want to connect with ssh from this device to another device, using public key auth.
dropbearkey \-y \-f /etc/dropbear/dropbear\_rsa\_host\_key
And an example answer is
Public key portion is:
ssh-rsa AAAAB3NzaC1yc2EAdrgdftergdsfgdfgdfgdfgdfgdfgdfgJOYPF6nc41DUWDQdRrv8Ihe/zINq5CaFOsysL3LNOg90C9uDYRIp89nq9ydUIrwvjz9r8U/7HFOkLX6YQUevUZHxEyUexhWRSBLbnoQSKLHlB5WhodghdfgdfgdfgdfgdfgdfgfdgdfgfdgdfasdaaedadfasEUxiDTj74l0dqLpCCM1r9BcQd12hvQwfHvbMAcY/7l3Wb5fdAvXI5mMIXXzWPkLhSLHP1Hw1trEmuUeL2rie+WzSjaOGMzVDjOpEaZD0dT7Ib9yDwem8UDMPFuXnNmsUvpxNHakWbw+465uxlyeAzL root@VM-router
Fingerprint: sha1!! ec:66:c1:57:92:c1:ec:66:c1:57:92:c1:c7:9e:71:50:25:65:61:53:dd
You will copy-paste the “public key portion” to the other device's accepted keys
### Non-root users
Add authentication keys for the current non-root user.
ssh openwrt.lan "mkdir -p ~/.ssh; tee -a ~/.ssh/authorized\_keys" < ~/.ssh/id\_ed25519.pub
### Disabling password authentication
Harden security by disabling password authentication.
uci set dropbear.@dropbear\[0\].PasswordAuth="0"
uci set dropbear.@dropbear\[0\].RootPasswordAuth="0"
uci commit dropbear
service dropbear restart
### Fixing permissions
Set up the proper permissions.
chmod \-R u\=rwX,go\= /etc/dropbear
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2026/07/09 06:35
* by knarrff
[](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt on VMware Fusion on Apple Silicon HowTo
OpenWrt on VMware Fusion on Apple Silicon HowTo
===============================================
This document describes how to run the `armsr/armv8` OpenWrt images in a VM hosted on macOS (Apple Silicon hardware) using [VMware Fusion](https://www.vmware.com/products/fusion.html "https://www.vmware.com/products/fusion.html")
.
Prerequisites
-------------
* [VMware Fusion](https://www.vmware.com/products/fusion.html "https://www.vmware.com/products/fusion.html")
installed
* qemu installed (via [Homebrew](http://brew.sh/ "http://brew.sh")
)
* Familiarity with the command line on macOS (Terminal window)
This article relies on the following:
* Accessing [web interface](https://openwrt.org/docs/guide-quick-start/walkthrough_login "docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
* Managing [configs](https://openwrt.org/docs/guide-user/base-system/uci "docs:guide-user:base-system:uci")
/ [packages](https://openwrt.org/docs/guide-user/additional-software/managing_packages "docs:guide-user:additional-software:managing_packages")
/ [services](https://openwrt.org/docs/guide-user/base-system/managing_services "docs:guide-user:base-system:managing_services")
/ [logs](https://openwrt.org/docs/guide-user/base-system/log.essentials "docs:guide-user:base-system:log.essentials")
This article may contain network configuration that depends on migration to DSA in OpenWrt 21.02
* Check if your device uses DSA or swconfig as not all devices have been migrated
* ifname@interface has been moved to device sections
* [DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Mini tutorial for DSA network config](https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998 "https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998")
on the forum
* [DSA in the 21.02 release notes](https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change "https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change")
### Select an OpenWrt image
You need an ARM system-ready 64-bit version of OpenWrt. There are two versions:
* `combined-squashfs.img.gz`: This edition, as of release 23.05.0, does not work correctly with sysupgrade.
* `combined-ext4.img.gz` This disk image uses a single read-write ext4 partition with no read-only squashfs root filesystem. Features like Failsafe Mode or Factory Reset won't be available as they need a read-only squashfs partition to function.
In the guide we'll use _openwrt-armsr-armv8-generic-ext4-combined.img.gz_ because it supports sysupgrade.
* Download a stable release of the _generic-ext4-combined.img.gz_ image from [targets/armsr/arvm8/ folder](https://downloads.openwrt.org/releases/ "https://downloads.openwrt.org/releases/")
, e.g. [23.05.0](https://downloads.openwrt.org/releases/23.05.0/targets/armsr/armv8/openwrt-23.05.0-armsr-armv8-generic-ext4-combined.img.gz "https://downloads.openwrt.org/releases/23.05.0/targets/armsr/armv8/openwrt-23.05.0-armsr-armv8-generic-ext4-combined.img.gz")
.
* Or you can try the fresher but unstable [snapshot](https://downloads.openwrt.org/snapshots/targets/armsr/armv8/openwrt-armsr-armv8-generic-ext4-combined.img.gz "https://downloads.openwrt.org/snapshots/targets/armsr/armv8/openwrt-armsr-armv8-generic-ext4-combined.img.gz")
image.
* Uncompress the gzip'ed img file. On macOS in a Terminal window use the command `gzcat openwrt-*ext4-combined.img.gz > openwrt.img`. As a result you get the raw `openwrt.img` image file.
* Convert the raw image to a VMDK-formatted disk image: `qemu-img convert -O vmdk openwrt.img openwrt.vmdk`
* Check your VMware Fusion networking configuration. You need to know the subnet used by the host-only networking:
user@host demo % grep VNET\_1\_HOSTONLY\_SUBNET '/Library/Preferences/VMware Fusion/networking'
answer VNET\_1\_HOSTONLY\_SUBNET 172.16.132.0
 Tip: keep a copy of the original gzip'ed image file, it can be used as an image for sysupgrade.
VM Setup in VMware Fusion
-------------------------
### VM creation
 Tutorial and screenshots from VMware Fusion 13.5.0 on Apple Silicon
[](https://openwrt.org/_media/media/virtualization/fusion/1-custom.png "media:virtualization:fusion:1-custom.png")
Start VMware fusion and use the _File→New_ menu. Select _Create a custom virtual machine_
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/2-linux-5.png "media:virtualization:fusion:2-linux-5.png")
Select the appropriate Linux kernel version (OpenWrt 23.05.0 for armsr/armv8 uses Linux kernel 5.x).
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/3-existing.png "media:virtualization:fusion:3-existing.png")
Select _Use an existing virtual disk_ and _Choose virtual disk..._
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/4-select-vmdk.png "media:virtualization:fusion:4-select-vmdk.png")
Select the `openwrt.vmdk` you created earlier, and _Make a separate copy of the virtual disk_.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/5-finish.png "media:virtualization:fusion:5-finish.png")
On the _Finish_ page, click Customize Settings.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/6-saveit.png "media:virtualization:fusion:6-saveit.png")
Select a location to save the VM. After saving, edit the configuration.
* * *
### VM configuration
The configuration you will set up by following this tutorial is:
* **br-lan** of the VM on **lan** interface, fixed address 172.16.132.2 (or whatever subnet VMware Fusion is using for VNET\_1), set in VMware Fusion as **Private to my Mac**. This interface will _always_ be available to the host even if host or VM are disconnected from any network.
* **eth1** of the VM on **wan** interface, dynamic address, set in VMware Fusion as **Share with my Mac** (NAT). This interface will be used to access the Internet through whatever setup the host also uses.
Note that the _order_ of the “Private to my Mac” and “Share with my Mac” networks is important for turn-key operation of OpenWrt in the VM.
#### VM settings
[](https://openwrt.org/_media/media/virtualization/fusion/7-settings.png "media:virtualization:fusion:7-settings.png")
Reconfigure some of the devices shown on the configuration page.
* * *
##### Remove unused devices
[](https://openwrt.org/_media/media/virtualization/fusion/8-remove-sound.png "media:virtualization:fusion:8-remove-sound.png")
Click on the sound card. Remove the sound card.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/9-remove-camera.png "media:virtualization:fusion:9-remove-camera.png")
Click on the camera. Remove the camera.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/10-remove-dvd.png "media:virtualization:fusion:10-remove-dvd.png")
Click on the CD/DVD. Open the advanced options section. Remove the CD/DVD drive.
* * *
##### Network Settings
[](https://openwrt.org/_media/media/virtualization/fusion/11-network-private.png "media:virtualization:fusion:11-network-private.png")
Click on the existing Network. Change it to _Private to my Mac_.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/12-add-network.png "media:virtualization:fusion:12-add-network.png")
Click on the _Add Device..._ button on the main settings panel. Click on _Network Adapter_. (This will add the network for the WAN.)
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/13-shared-network.png "media:virtualization:fusion:13-shared-network.png")
Configure it to _Share with my Mac_.
* * *
##### Other Device Settings
Optional: check the _USB & Bluetooth_ settings and choose your desired options.
* * *
[](https://openwrt.org/_media/media/virtualization/fusion/14-memory.png "media:virtualization:fusion:14-memory.png")
Click on the _Processors and Memory_ icon. Configure the system for 512MB and 2 processor cores.
* * *
Close the settings panel.
* * *
Optional: make a snapshot to capture the original unconfigured state, using the application menu Virtual Machine→Snapshots→Take Snapshot
#### Virtual Machine OpenWrt Settings
* Start your Virtual Machine (click the Play icon button)
* Wait 4 seconds for GRUB to boot automatically
* Press Enter to activate the console when the boot messages have finished scrolling by.
 [](https://openwrt.org/_media/media/virtualization/fusion/15-allow-network.png "media:virtualization:fusion:15-allow-network.png")
OpenWrt by default configures the LAN into a bridge. This sets the virtual network adapter into promiscuous mode, which requires approval from VMware for the host-only network it uses. Promiscuous access is not required, so you can either approve or cancel the request.
* Display the current LAN network configuration. Note that the default LAN address of 192.168.1.1 is present on first boot. Type the `uci show network.lan` command into the virtual console window to see:
root@openwrt:~# uci show network.lan
network.lan=interface
network.lan.device='br-lan'
network.lan.proto='static'
network.lan.ipaddr='192.168.1.1'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
* Edit the network configuration to allow SSH access. Use the VNET\_1\_HOSTONLY\_SUBNET value from above, replacing the last octet with `2`, and restart the network. An example to type into the console:
uci set network.lan.ipaddr=172.16.132.2
uci commit
service network restart
* Now your VM is accessible from SSH, user **root** (no password) address **10.0.2.2**
* If you installed a release image such as 23.05.0, the LuCi web interface is available at your chosen IP address (such as [http://172.16.132.2/](http://172.16.132.2/ "http://172.16.132.2/")
).
* If you installed a snapshot that doesn't include LuCi, install it with
opkg update && opkg install luci
* You should have both internet access (try a **opkg update**) **and** a LAN interface with a static address you can connect your SSH client program to even if your PC is disconnected from a local network.
* If you have more complex requirements you will have to set that up on your own by reading the documentation, or through LuCi.
See also
--------
* [Other virtualization options](https://openwrt.org/docs/guide-user/virtualization/start "docs:guide-user:virtualization:start")
: Docker, VMware etc.
* [UTM on Apple Silicon](https://openwrt.org/docs/guide-user/virtualization/utm "docs:guide-user:virtualization:utm")
: Configuring using the open-source UTM virtual machine GUI
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/10/21 19:27
* by atownlede
[](https://openwrt.org/docs/guide-user/virtualization/fusion#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Security
Security
========
[](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
=====================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/security/start#top-786683754 "Continue with the « docs » section at the top...")
[Security](https://openwrt.org/docs/guide-user/security/start "docs:guide-user:security:start")
* [Dropbear key-based authentication](https://openwrt.org/docs/guide-user/security/dropbear.public-key.auth "docs:guide-user:security:dropbear.public-key.auth")
* [Elevating privileges with sudo](https://openwrt.org/docs/guide-user/security/sudo "docs:guide-user:security:sudo")
* [Key Generation](https://openwrt.org/docs/guide-user/security/keygen "docs:guide-user:security:keygen")
* [OpenWrt Public Keys](https://openwrt.org/docs/guide-user/security/signatures "docs:guide-user:security:signatures")
* [OpenWrt security features](https://openwrt.org/docs/guide-user/security/security-features "docs:guide-user:security:security-features")
* [OpenWrt security hardening](https://openwrt.org/docs/guide-user/security/openwrt_security "docs:guide-user:security:openwrt_security")
* [Regaining access to an OpenWrt device in client mode](https://openwrt.org/docs/guide-user/security/recovering_from_clientmode "docs:guide-user:security:recovering_from_clientmode")
* [Release Signing](https://openwrt.org/docs/guide-user/security/release_signatures "docs:guide-user:security:release_signatures")
* [Secure access to your router](https://openwrt.org/docs/guide-user/security/secure.access "docs:guide-user:security:secure.access")
* [Security Guide for the Paranoid](https://openwrt.org/docs/guide-user/security/security_guide_for_the_paranoid "docs:guide-user:security:security_guide_for_the_paranoid")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/02 19:48
* by vgaetera
[](https://openwrt.org/docs/guide-user/security/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Virtualization
Virtualization
==============
[](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
[Documentation](https://openwrt.org/docs/start "docs:start")
===========================================================================================================================================================================================
[](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
[](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
[User guide](https://openwrt.org/docs/guide-user/start "docs:guide-user:start")
--------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
[](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
### [](https://openwrt.org/docs/guide-user/virtualization/start#top-145372229 "Continue with the « docs » section at the top...")
[Virtualization](https://openwrt.org/docs/guide-user/virtualization/start "docs:guide-user:virtualization:start")
* [Docker OpenWrt Image Generation](https://openwrt.org/docs/guide-user/virtualization/obtain.firmware.docker "docs:guide-user:virtualization:obtain.firmware.docker")
* [Metarouter Virtualization on Mikrotik RouterBoard](https://openwrt.org/docs/guide-user/virtualization/metarouter "docs:guide-user:virtualization:metarouter")
* [OpenWrt as a Docker Image](https://openwrt.org/docs/guide-user/virtualization/docker_openwrt_image "docs:guide-user:virtualization:docker_openwrt_image")
* [OpenWrt as a Xen DomU guest](https://openwrt.org/docs/guide-user/virtualization/xen "docs:guide-user:virtualization:xen")
* [OpenWrt as Docker container host](https://openwrt.org/docs/guide-user/virtualization/docker_host "docs:guide-user:virtualization:docker_host")
* [OpenWrt as DomU in Debian Xen4 in a private network](https://openwrt.org/docs/guide-user/virtualization/xen_debian_private_network "docs:guide-user:virtualization:xen_debian_private_network")
* [OpenWrt as QEMU/KVM host server](https://openwrt.org/docs/guide-user/virtualization/qemu_host "docs:guide-user:virtualization:qemu_host")
* [OpenWrt in LXC containers](https://openwrt.org/docs/guide-user/virtualization/lxc "docs:guide-user:virtualization:lxc")
* [OpenWrt in QEMU](https://openwrt.org/docs/guide-user/virtualization/qemu "docs:guide-user:virtualization:qemu")
* [OpenWrt on UTM on Apple Silicon HowTo](https://openwrt.org/docs/guide-user/virtualization/utm "docs:guide-user:virtualization:utm")
* [OpenWrt on VirtualBox HowTo](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm "docs:guide-user:virtualization:virtualbox-vm")
* [OpenWrt on VMware Fusion on Apple Silicon HowTo](https://openwrt.org/docs/guide-user/virtualization/fusion "docs:guide-user:virtualization:fusion")
* [OpenWrt on VMware HowTo](https://openwrt.org/docs/guide-user/virtualization/vmware "docs:guide-user:virtualization:vmware")
* [OpenWrt running as metarouter on mikrotik routerOS](https://openwrt.org/docs/guide-user/virtualization/mikrotik_metarouter_openwrt "docs:guide-user:virtualization:mikrotik_metarouter_openwrt")
* [Podman Containers](https://openwrt.org/docs/guide-user/virtualization/podman "docs:guide-user:virtualization:podman")
* [VirtualBox Advanced](https://openwrt.org/docs/guide-user/virtualization/virtualbox-advanced "docs:guide-user:virtualization:virtualbox-advanced")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2021/08/02 18:29
* by vgaetera
[](https://openwrt.org/docs/guide-user/virtualization/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] ar:docs:guide-user:installation:generic.uninstall
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/ar/docs/guide-user/installation/generic.uninstall#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] ar:docs:guide-user:virtualization:virtualbox-vm
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/ar/docs/guide-user/virtualization/virtualbox-vm#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:firewall:shorewall:shorewall-on-openwrt
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/firewall/shorewall/shorewall-on-openwrt#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.owut
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/sysupgrade.owut#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:installation:sysupgrade.owut
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/installation/sysupgrade.owut#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:services:nas:pure-ftpd
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/services/nas/pure-ftpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:services:voip:stund
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/services/voip/stund#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:services:vpn:tinc
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/services/vpn/tinc#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:firewall:netfilter-iptables:iptables_and_firewall
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/firewall/netfilter-iptables/iptables_and_firewall#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:generic.flashing.xmodem
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/generic.flashing.xmodem#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:ar71xx.to.ath79
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/ar71xx.to.ath79#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.packages
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/sysupgrade.packages#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:generic.sysupgrade
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/generic.sysupgrade#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:user.beginner.cli
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/user.beginner.cli#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:luci.themes
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/luci.themes#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:openwrt_as_routerdevice
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/openwrt_as_routerdevice#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:statistics.chart.public
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/statistics.chart.public#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:architecture
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/architecture#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:static_ip
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/static_ip#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:bonding
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/bonding#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:integrating-openwrt-introduction
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/integrating-openwrt-introduction#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:protocol.dhcp
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/protocol.dhcp#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:network_interface_alias
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/network_interface_alias#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:routedclient
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/routedclient#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:network_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/network_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:switch_router_gateway_and_nat
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/switch_router_gateway_and_nat#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:map
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/map#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:webinterface.overview
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/webinterface.overview#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:high-availability
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/high-availability#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:lirc
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/lirc#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:watchdog
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/watchdog#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:pwm
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/pwm#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:filtering_traffic_at_ip_addresses_by_dns
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/filtering_traffic_at_ip_addresses_by_dns#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:firewall_components
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/firewall_components#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:basic
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/basic#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:clarifying_interface_usage
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/clarifying_interface_usage#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:advanced:ntp_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/advanced/ntp_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:fw3_network
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/fw3_network#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:openwrt_as_clientdevice
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/openwrt_as_clientdevice#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:overview
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/overview#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:terminate.console.on.serial
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/terminate.console.on.serial#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:turnoff.uart.to.gpio
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/turnoff.uart.to.gpio#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:owsip
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/owsip#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:usb.i2c-tiny-usb
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/usb.i2c-tiny-usb#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:services:bbstored
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/services/bbstored#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] docs:guide-user:firewall:freifunk_p2pblock
This page does not exist anymore
================================
You've followed a link to a page that no longer exists. You can check the list of **Old revisions** to see when and why it was deleted, access old revisions or restore it.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/docs/guide-user/firewall/freifunk_p2pblock#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] syslog-ng
syslog-ng
=========
Installation
------------
### Replacing Default Logging with syslog-ng -- 2018
As of February, 2019, version of syslog-ng in OpenWrt master is 3.19.1
As of March, 2018, [https://openwrt.org/packages/pkgdata/syslog-ng](https://openwrt.org/packages/pkgdata/syslog-ng "https://openwrt.org/packages/pkgdata/syslog-ng")
is version 3.8.1
On `master` of April, 2018, the following steps will replace the default OpenWRT logging with `syslog-ng`
* Install `syslog-ng` and its dependencies
* Disable the default logging with `/etc/init.d/log disable` or by removing the symlink in `/etc/rc.d`
* Confirm that `syslog-ng` is enabled; `/etc/rc.d/S20syslog-ng → ../init.d/syslog-ng`
* reboot
* * *
 Much of the following appears to be from Backfire, c. 2011
\# opkg install syslog-ng
Configuration
-------------
Configuration is controlled by `/etc/syslog-ng.conf` The default configuration logs to `/var/log/messages`.
Below is a sample configuration for logging to a remote server via TCP (extended from default config file):
#############################################################################
# OpenWrt syslog-ng.conf specific file
# which collects all local logs into a single file called /var/log/messages.
# More details about these settings can be found here:
# https://www.syslog-ng.com/technical-documents/doc/syslog-ng-open-source-edition/3.16/release-notes/global-options
@version: 3.19
@include "scl.conf"
@include "/etc/syslog-ng.d/" # Put any customization files in this directory
options {
chain\_hostnames(no); # Enable or disable the chained hostname format.
create\_dirs(yes);
keep\_hostname(yes); # Enable or disable hostname rewriting.
log\_fifo\_size(256); # The number of messages that the output queue can store.
log\_msg\_size(1024); # Maximum length of a message in bytes.
stats\_freq(0); # The period between two STATS messages (sent by syslog-ng, containing statistics about dropped logs) in seconds.
flush\_lines(0); # How many lines are flushed to a destination at a time.
use\_fqdn(no); # Add Fully Qualified Domain Name instead of short hostname.
};
filter notice\_or\_higher {
level(notice..emerg) # remove debug and info message
};
# syslog-ng gets messages from syslog-ng (internal) and from /dev/log
source src {
internal();
unix-dgram("/dev/log");
};
source kernel {
file("/proc/kmsg" program\_override("kernel"));
};
source net {
tcp(ip(0.0.0.0) port(514));
};
destination messages {
file("/var/log/messages");
};
destination syslogd\_tcp {
tcp("syslog." port(514)); # hostname is syslog, replace with your own loghost name or IP
};
log {
source(src);
source(kernel);
filter(notice\_or\_higher);
destination(messages);
destination(syslogd\_tcp);
};
#### Reconfiguration
To apply changes, it is not sufficient to simply restart the `syslog-ng` daemon. Instead, stop and start the daemon as follows (taken from [http://baheyeldin.com/technology/linux/logging-with-syslog-ng-on-openwrt.html](http://baheyeldin.com/technology/linux/logging-with-syslog-ng-on-openwrt.html "http://baheyeldin.com/technology/linux/logging-with-syslog-ng-on-openwrt.html")
):
\# killall syslog-ng
# /etc/init.d/syslog-ng start
#### IPv6 Logserver
To log to a logserver listening on an IPv6 address, use a `udp6()` destination in the configuration file:
...
destination d\_udp6 { udp6("1234:5678:1011:1314::01" port(514)); };
...
log {
source(src);
source(kernel);
destination(d\_udp6);
};
...
Startup
-------
\# /etc/init.d/syslog-ng enable
# /etc/init.d/syslog-ng start
logread
-------
The logread is an interface to read log messages. When the `syslog-ng` installed then the default OpenWrt [logread](https://openwrt.org/docs/guide-user/base-system/log.essentials#logread "docs:guide-user:base-system:log.essentials")
command from ubox package will be overridden with the `/usr/sbin/logread` script that reads `/var/log/messages` instead of ring buffer.
To show all log messages that contains a specific text (like a daemon name) and follow (like in tail -f) use:
logread \-fe firewall
The script has less options than the ubox logread:
\-l Got only the last 'count' messages
-e Filter messages with a regexp
-f Follow log messages
-h Print this help message
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/06/02 06:40
* by stokito
[](https://openwrt.org/docs/guide-user/perf_and_log/log.syslog-ng3#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:esp8266-serial-bridge
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/esp8266-serial-bridge#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:usb_gadget
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/usb_gadget#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:usb.overview
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/usb.overview#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:mmc_over_gpio
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/mmc_over_gpio#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:lirc-audio_alsa
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/lirc-audio_alsa#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:debrick.ath79.using.jtag
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/debrick.ath79.using.jtag#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:lirc-gpioblaster
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/lirc-gpioblaster#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:writable_ntfs
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/writable_ntfs#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:disk.encryption
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/disk.encryption#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:piratebox.librarybox.openwrt.routers
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/piratebox.librarybox.openwrt.routers#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:babeld
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/babeld#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:crowdsec
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/crowdsec#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:usb-installing
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/usb-installing#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:filesystems-and-partitions
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/filesystems-and-partitions#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:mountd
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/mountd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:fstab
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/fstab#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:vblade
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/vblade#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:storage:hd-idle
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/storage/hd-idle#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:hardware:devolo-stream-radio
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/hardware/devolo-stream-radio#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Ad blocking
This translation is older than the [original page](https://openwrt.org/docs/guide-user/services/ad-blocking)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/services/ad-blocking?do=diff&rev=1700117865)
.
 **This page is not fully translated, yet. Please help completing the translation.**
_(remove this paragraph once the translation is finished)_
Ad blocking
===========
Network-wide ad blocking may be desired for content filtering to reduce ads, reduce bandwidth usage, reduce tracking and increase privacy. This can be accomplished with OpenWrt by installing one of the options below.
Solutions
---------
### Adblock
* Packages: [adblock](https://openwrt.org/packages/pkgdata/adblock "packages:pkgdata:adblock")
, [luci-app-adblock](https://openwrt.org/packages/pkgdata/luci-app-adblock "packages:pkgdata:luci-app-adblock")
* Configuration: **LuCI → Services → Adblock**
* Follow: [documentation](https://github.com/openwrt/packages/blob/master/net/adblock/files/README.md "https://github.com/openwrt/packages/blob/master/net/adblock/files/README.md")
, [forum](https://forum.openwrt.org/t/adblock-support-thread/507 "https://forum.openwrt.org/t/adblock-support-thread/507")
### Adblock-Fast
* Configuration: **LuCI → Services → Adblock-Fast**
* Follow: [documentation](https://docs.openwrt.melmac.net/adblock-fast/ "https://docs.openwrt.melmac.net/adblock-fast/")
, [forum](https://forum.openwrt.org/t/adblock-fast-ad-blocking-service-for-dnsmasq-and-unbound/170530 "https://forum.openwrt.org/t/adblock-fast-ad-blocking-service-for-dnsmasq-and-unbound/170530")
### AdGuard Home
* Packages: [adguardhome](https://openwrt.org/packages/pkgdata/adguardhome "packages:pkgdata:adguardhome")
* Follow: [documentation](https://openwrt.org/docs/guide-user/services/dns/adguard-home "docs:guide-user:services:dns:adguard-home")
, [forum](https://forum.openwrt.org/t/how-to-updated-2021-installing-adguardhome-on-openwrt-manual-and-opkg-method/113904 "https://forum.openwrt.org/t/how-to-updated-2021-installing-adguardhome-on-openwrt-manual-and-opkg-method/113904")
### Adblock-lean
super simple and lightweight adblocking script, good for small router
* Follow: [documentation](https://github.com/lynxthecat/adblock-lean/tree/master "https://github.com/lynxthecat/adblock-lean/tree/master")
, [forum](https://forum.openwrt.org/t/adblock-lean-set-up-adblock-using-dnsmasq-blocklist/157076 "https://forum.openwrt.org/t/adblock-lean-set-up-adblock-using-dnsmasq-blocklist/157076")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/20 17:31
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/services/ad-blocking#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:gitolite
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/gitolite#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:dns_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/dns_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:notuci.config
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/notuci.config#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:log.essentials
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/log.essentials#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:mptcp
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/mptcp#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:managing_services
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/managing_services#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:ddns
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/ddns#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:system_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/system_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:getting_rid_of_luci_https_certificate_warnings
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/getting_rid_of_luci_https_certificate_warnings#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:persistent-ethernet-interface-naming-by-mac-address
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/persistent-ethernet-interface-naming-by-mac-address#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:dropbear
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/dropbear#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:httpd
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/httpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:luci_app_statistics
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/luci_app_statistics#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:luci.on.lighttpd
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/luci.on.lighttpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:singleportrouter
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/singleportrouter#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:dhcp.dnsmasq
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/dhcp.dnsmasq#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:led_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/led_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:users
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/users#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:luci.secure
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/luci.secure#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:basic-networking
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/basic-networking#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:protocol.static
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/protocol.static#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Quick Start for Adding a USB drive
Quick Start for Adding a USB drive
==================================
This page describes how to add a USB drive to your OpenWrt device. This is commonly used to add more storage or share files on your network.
Requirements
------------
* USB drive (HDD, SSD, Flash, etc.) of any capacity.
* OpenWrt device with at least 8 MB free.
* Computer on the same network for LuCI/SSH.
* This procedure includes **erasing the USB drive**. Skip those steps to retain data and mount a preformatted drive.
Procedure
---------
USB drives can be installed using either LuCI or the command line as described below.
### LuCI
1\. On the Software page, click update, then install the packages. The instructions below use **ext4** filesystem, however you can replace the final package with any of these: `kmod-fs-ext4`, `kmod-fs-exfat`, `kmod-fs-ntfs3`, etc.
block-mount e2fsprogs kmod-usb-storage-uas kmod-usb3 luci-app-hd-idle kmod-fs-ext4
2\. Plug in your USB drive, it will be detected automatically as **/dev/sdXX** depending on the drive and partitions.
3\. Go to the **System → Mount Points**, click Enabled on the drive to mount, click Save & Apply. If it does not show up after plugging in, click Generate Config, then it should show up on page refresh.
4\. Go to the **Services → HDD Idle**, enable to idle the drive to save power and lifespan, click Save & Apply.
Done! The drive is ready to read/write data.
### Command Line
1\. Use a computer to format your USB drive using the default options. This prepares the drive for the process below, which will erase those settings. _Warning: This initial formatting will erase the entire USB drive._
2\. SSH into your device to enter the following steps. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_1)
The [SSH Access for Newcomers](https://openwrt.org/docs/guide-quick-start/sshadministration "docs:guide-quick-start:sshadministration")
page tells how to install and use a terminal emulator on your computer.
3\. Install the required packages. Below uses ext4 filesystem, you can use any you prefer: `kmod-fs-ext4`, `kmod-fs-exfat`, `kmod-fs-ntfs3`, etc). [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_2)
You may see error messages about installing kmod-usb3 on certain routers. These can be ignored if the hardware does not support USB3.
opkg update && opkg install block-mount e2fsprogs kmod-usb-storage-uas kmod-usb3 kmod-fs-ext4
4\. Enter `ls -al /dev/sd*` to show all attached USB devices. The list may be empty if there are no USB devices. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_3)
**/dev/sda** is the first USB device; **/dev/sdb** is the second, and so on. **/dev/sda1** is the first partition on the first device; **/dev/sda2** is the second partition, etc.
5\. Plug the USB drive into your router. Enter `ls -al /dev/sd*` again, now you should see a new **/dev/sdXX** device. **sdXX** is the _device name_ of your new USB device. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_4)
If you do not see `/dev/sda` AND `/dev/sda1` listed, format the USB device on your computer beforehand.
root@OpenWrt:~# ls -al /dev/sd\*
brw------- 1 root root 8, 0 Feb 4 15:13 /dev/sda
brw------- 1 root root 8, 1 Feb 4 14:06 /dev/sda1
6\. Make an ext4 filesystem on the USB device using the device name you just discovered. **Note**: Be certain you enter the proper device name - this step will completely erase the device. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_5)
This command creates an ext4 file system on the first partition of the first USB device - /dev/sda1.
mkfs.ext4 /dev/sda1
7\. Create the fstab config file based on all the block devices found. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_6)
This command writes the current state of all block devices, including USB drives, into the `/etc/config/fstab` file.
block detect | uci import fstab
8\. Update the fstab config file to mount all drives at startup. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_7)
**/dev/sda** is mount\[0\], **/dev/sdb** is mount\[1\], etc. If you have more than one USB device attached, substitute the proper index (0 or 1 or ...) as needed. This command mounts all drives - named or anonymous.
uci set fstab.@mount\[0\].enabled='1' && uci set fstab.@global\[0\].anon\_mount='1' && uci commit fstab
9\. Mount the device. [More...](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#folded_554a7a978115c3609df2483485f0cb63_8)
Automount is enabled on boot.
/etc/init.d/fstab boot
Done! The drive is ready to read/write data.
### Network Shares
To share the drives (or even specific folders) on your network see [Samba](https://openwrt.org/docs/guide-user/services/nas/cifs.server "docs:guide-user:services:nas:cifs.server")
or [Ksmbd](https://openwrt.org/docs/guide-user/services/nas/ksmbd "docs:guide-user:services:nas:ksmbd")
.
More Details
------------
* For NTFS filesystem refer to [Writable NTFS](https://openwrt.org/docs/guide-user/storage/writable_ntfs "docs:guide-user:storage:writable_ntfs")
* The full [USB Drive tutorial](https://openwrt.org/docs/guide-user/storage/usb-drives "docs:guide-user:storage:usb-drives")
has much more about USB drives
* Look at the [fstab documentation](https://openwrt.org/docs/guide-user/storage/fstab "docs:guide-user:storage:fstab")
to configure from the command line
* To temporarily mount the drive (say, for testing), you can enter: `mkdir /tmp/MyDrive; mount /dev/sda1 /tmp/MyDrive`, after finishing the test reading/writing the drive: `umount /tmp/MyDrive`
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2025/07/23 17:43
* by phinn
[](https://openwrt.org/docs/guide-user/storage/usb-drives-quickstart#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:sysupgrade.cli
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/sysupgrade.cli#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:installation:attended.sysupgrade
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/installation/attended.sysupgrade#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] rsyslog
rsyslog
=======
The [rsyslog](https://www.rsyslog.com/ "https://www.rsyslog.com/")
is a [Syslog](https://en.wikipedia.org/wiki/Syslog "https://en.wikipedia.org/wiki/Syslog")
logging daemon.
#### Install
opkg install rsyslog
#### Route all or specific logs to a (central) rsyslog receiver
With the config file: /etc/rsyslog.conf
\*.info;mail.none;authpriv.none;cron.none;kern.none /var/log/messages
..
kern.\* @192.168.1.119:514
If you add to the rsyslog receiver's /etc/rsyslog.conf e.g. this template:
$template DynamicFile,"/mnt/sda1/logs/%HOSTNAME%/forwarded-logs.log"
\*.\* -?DynamicFile
you get the messages separated from every sender in a own folder.
### rsyslog and Logz.io
You can support logging direct to a cloud ELK provider like Logz.io by adding a few lines to your `rsyslog.conf`.
Replace `codecodecode` with your unique Logz.io identifier, it's 32 characters. And will appear in help manuals when you're logged in, reference the guide [here](https://app.logz.io/#/dashboard/data-sources/rsyslog "https://app.logz.io/#/dashboard/data-sources/rsyslog")
.
$template logzFormatFileTagName,"\[codecodecodecode\] <%pri%>%protocol-version% %timestamp:::date-rfc3339% %HOSTNAME% %app-name% %procid% %msgid% \[type=TYPE\] %msg%\\n"
\*.\* @@listener.logz.io:5000;logzFormatFileTagName
Confirm you have the right config with:
rsyslogd \-N1
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2024/06/03 07:13
* by stokito
[](https://openwrt.org/docs/guide-user/perf_and_log/log.rsyslog#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Dashboard
This translation is older than the [original page](https://openwrt.org/docs/guide-user/luci/dashboard)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/luci/dashboard?do=diff&rev=1701128289)
.
Dashboard
=========
Esta es una versión simplificada del dashboard del enrutador, que se utiliza para ver la información de conexión en algunos dispositivos y enrutadores.
Instale `luci-mod-dashboard` paquete: `opkg install luci-mod-dashboard`
[](https://openwrt.org/lib/exe/fetch.php?tok=04f27d&media=https%3A%2F%2Fimgur.com%2FG08zs8U.png "https://imgur.com/G08zs8U.png")
Responsivo
==========
[](https://openwrt.org/lib/exe/fetch.php?tok=a2589f&media=https%3A%2F%2Fimgur.com%2FUFc1h5w.png "https://imgur.com/UFc1h5w.png")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/11/27 23:38
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/luci/dashboard#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:luci:luci.essentials
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/luci/luci.essentials#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Usar dispositivos de almacenamiento
This translation is older than the [original page](https://openwrt.org/docs/guide-user/storage/usb-drives)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/storage/usb-drives?do=diff&rev=1680210111)
.
Usar dispositivos de almacenamiento
===================================
_Tip:_ El **[Inicio rápido para instalar una unidad USB](https://openwrt.org/es/docs/guide-user/storage/usb-drives-quickstart "es:docs:guide-user:storage:usb-drives-quickstart")
** resuelve el caso muy común de instalar una sola unidad USB en su dispositivo OpenWrt. La gente hace esto para usar Samba u otros programas que necesitan almacenar datos en un disco externo. El resto de esta página proporciona mucha más información sobre dispositivos y controladores USB.
Muchos dispositivos compatibles tienen puertos para conectar dispositivos de almacenamiento, los más comunes son USB o Sata.
Este artículo describirá cómo configurar su dispositivo para usar dichos dispositivos de almacenamiento para almacenar o compartir. Si desea ampliar el espacio de su firmware (para instalar más paquetes), lea el artículo sobre [Configuración de Extroot](https://openwrt.org/es/docs/guide-user/additional-software/extroot_configuration "es:docs:guide-user:additional-software:extroot_configuration")
.
Para configurar el espacio en disco externo, siga los procedimientos de esta página:
1. Verificar los controladores de almacenamiento
2. Verificar que el sistema operativo reconozca el disco adjunto y sus particiones
3. Crear una partición en el disco USB
4. Crear un sistema de archivos en la partición
5. Automontar la partición
6. Inactivar el giro de los discos duros
Instalar y verificar los controladores USB
------------------------------------------
Este paso garantiza que los controladores de almacenamiento USB necesarios estén instalados correctamente.
1. Comience actualizando la lista de paquetes de software disponibles:
opkg update
2. El paquete OpenWrt típico ya tiene instalados los controladores principales de dispositivos USB (si su dispositivo tiene puertos USB), pero es posible que aún no tenga instalado un controlador de dispositivo de almacenamiento USB. Primero instale este controlador de almacenamiento (si ya está instalado, el siguiente comando simplemente dirá “ya está instalado”:
opkg install kmod-usb-storage
3. Algunos dispositivos de almacenamiento USB pueden requerir el controlador UAS:
opkg install kmod-usb-storage-uas
4. Para comprobar si toda la cadena de controladores USB funciona correctamente, instale el paquete opcional **usbutils**:
opkg install usbutils
5. Ahora conecte su disco/memoria USB y enumere sus dispositivos conectados con un comando de **usbutils**:
lsusb -t
6. Esto generará una lista de puertos concentradores USB del dispositivo y dispositivos de almacenamiento externos conectados:
/: Bus 02.Port 1: Dev 1, Class=root\_hub, Driver=xhci-mtk/1p, 5000M
/: Bus 01.Port 1: Dev 1, Class=root\_hub, Driver=xhci-mtk/2p, 480M
|\_\_ Port 1: Dev 5, If 0, Class=Mass Storage, Driver=usb-storage, 480M
* Las líneas “Bus...” representan el chip anfitrión. Aquí, el “Controlador” será `xhci` para USB3.0, `ehci` para USB2.0 y `uhci` u `ohci` para USB1.1.
* Las líneas con “Class=Mass Storage” representan dispositivos USB conectados. Aquí el “Controlador” es `usb-storage` para almacenamiento de tipo [Bulk only Transport](https://en.wikipedia.org/wiki/USB_mass_storage_device_class "https://en.wikipedia.org/wiki/USB_mass_storage_device_class")
o `usb-storage-uas` para almacenamiento de tipo [USB\_Attached\_SCSI](https://en.wikipedia.org/wiki/USB_Attached_SCSI "https://en.wikipedia.org/wiki/USB_Attached_SCSI")
En el paso 5, verifique que la salida no imprima ningún error y tenga al menos una línea de salida para **root\_hub** y **Mass Storage** y que cada **Driver=** incluya un nombre de controlador. De lo contrario, consulte [Instalación de controladores USB](https://openwrt.org/es/docs/guide-user/storage/usb-installing "es:docs:guide-user:storage:usb-installing")
para obtener más sugerencias sobre controladores.
Verifique que el OS reconozca el disco conectado y las particiones
------------------------------------------------------------------
Este paso de verificación opcional se puede utilizar para comprobar que el sistema operativo puede detectar correctamente una unidad externa conectada.
1. Asegúrese de que su disco/memoria USB esté conectado
2. Ejecute en una línea de comando:
ls -l /dev/sd\*
3. Esto ahora debería mostrar una lista de dispositivos de bloque conocidos por el OS
brw------- 1 root root 8, 0 Oct 30 12:49 /dev/sda
brw------- 1 root root 8, 1 Oct 30 12:49 /dev/sda1
Esto debería imprimir al menos un disco conectado como “/dev/sda” o “/dev/sdb”. Si no aparece ningún disco, vuelva a verificar la instalación del controlador USB y reinicie su dispositivo OpenWrt una vez.
4. Instale la herramienta **block** para obtener más información sobre las particiones existentes
opkg install block-mount
para exFAT, también necesita libblkid
opkg install libblkid
5. Ejecute la herramienta **block**:
block info | grep "/dev/sd"
y debería ver un resultado como este, si su disco ya tiene particiones:
/dev/sda1: UUID="2eb39413-83a4-4bae-b148-34fb03a94e89" VERSION="1.0" TYPE="ext4"
Si un disco ya tiene particiones existentes, aparecen como /dev/sda1, /dev/sda2,/dev/sda3, etc. Si hubiéramos conectado más de un dispositivo de almacenamiento tendríamos también /dev/sdb1 (primera partición del segundo dispositivo), /dev/sdc1 (primera partición del tercer dispositivo) y así sucesivamente.
Crear una partición en el disco USB
-----------------------------------
Si el capítulo anterior no enumeró ninguna partición existente (como “/dev/sda1”, “/dev/sda2”, “/dev/sdb1”...), primero debe crear una partición para un uso posterior del almacenamiento.
1. Para hacerlo, instale **gdisk**:
opkg install gdisk
2. Inicie **gdisk** con el nombre del disco identificado en el capítulo anterior:
gdisk /dev/sda
3. En el menú interactivo de gdisk, cree una partición con el comando gdisk
n
. Esto activa un diálogo interactivo: use los valores predeterminados sugeridos para la creación de la partición (número, sector inicial, tamaño, código hexadecimal)
4. Cuando haya terminado, confirme los cambios con el comando interactivo gdisk
w
y luego confirme su elección con
Y
.
5. Tome nota del nombre de la partición creada para el siguiente paso
Consulte el texto de ayuda de gdisk (escriba “?”) en caso de que necesite ayuda adicional. Apéguese a una sola partición para mantenerte alineado con el siguiente tutorial.
Instale los controladores del sistema de archivos y cree un sistema de archivos en la partición
-----------------------------------------------------------------------------------------------
Para utilizar una partición para el almacenamiento de datos, es necesario formatearla con un sistema de archivos.
La siguiente es la configuración predeterminada más simple (y recomendada) para el uso del sistema de archivos OpenWrt.
Para usuarios avanzados, hay [más opciones disponibles de sistemas de archivos opcionales](https://openwrt.org/es/docs/guide-user/storage/filesystems-and-partitions "es:docs:guide-user:storage:filesystems-and-partitions")
.
**ADVERTENCIA: Este paso elimina los datos existentes en esa partición. ¡Asegúrese de tener una copia de seguridad de los archivos importantes antes de comenzar!**
* Para discos duros USB, instale el sistema de archivos EXT4 y use EXT4 para formatear la partición (en este ejemplo '/dev/sda1'):
opkg install e2fsprogs
opkg install kmod-fs-ext4
mkfs.ext4 /dev/sda1
* Para unidades USB formateadas con exFAT:
opkg install kmod-fs-exfat
* Para unidades USB formateadas como NTFS, consulte [Sistemas de archivos](https://openwrt.org/es/docs/guide-user/storage/filesystems-and-partitions#setup_ntfs "es:docs:guide-user:storage:filesystems-and-partitions")
and [NTFS con permiso de Escritura](https://openwrt.org/es/docs/guide-user/storage/writable_ntfs "es:docs:guide-user:storage:writable_ntfs")
* Para unidades SSD y memorias USB, instale el sistema de archivos F2FS y use F2FS para formatear la partición (en este ejemplo, '/dev/sda1'):
opkg install f2fs-tools
opkg install kmod-fs-f2fs
mkfs.f2fs /dev/sda1
Automomontar la partición
-------------------------
El montaje automático garantiza que la partición del disco externo esté disponible automáticamente para su uso al iniciar el dispositivo OpenWrt.
1. Genere una entrada de configuración para el archivo fstab:
block detect | uci import fstab
2. Ahora habilite el montaje automático en esa entrada de configuración:
uci set fstab.@mount\[-1\].enabled='1'
uci commit fstab
3. Opcionalmente, habilite la verificación automática del sistema de archivos cada vez que se enciende el dispositivo OpenWrt:
uci set fstab.@global\[0\].check\_fs='1'
uci commit fstab
4. Reinicie su dispositivo OpenWrt (para verificar que el montaje automático funcione)
5. Después del reinicio, verifique sus resultados: ejecute
uci show fstab
para ver algo como esto
fstab.@global\[0\]=global
fstab.@global\[0\].anon\_swap='0'
fstab.@global\[0\].anon\_mount='0'
fstab.@global\[0\].auto\_swap='1'
fstab.@global\[0\].auto\_mount='1'
fstab.@global\[0\].check\_fs='0'
fstab.@global\[0\].delay\_root='5'
fstab.@mount\[0\]=mount
fstab.@mount\[0\].target='/mnt/sda1'
fstab.@mount\[0\].uuid='49c35b1f-a503-45b1-a953-56707bb84968'
fstab.@mount\[0\].enabled='1'
6. Verifique la entrada “enabled”. Debería ser '1'.
7. Tenga en cuenta la entrada “target”. Esta es la ruta del archivo, donde se puede acceder a la unidad de almacenamiento USB conectada a partir de ahora. P.ej. ahora puede listar archivos desde su disco externo:
ls -l /mnt/sda1
8. Ejecute el siguiente comando para verificar que el disco esté montado correctamente en esta ruta
block info
El resultado será:
...
/dev/sda1: UUID="2eb39413-83a4-4bae-b148-34fb03a94e89" VERSION="1.0" MOUNT="/mnt/sda1" TYPE="ext4"
9. Su almacenamiento externo ahora está listo para su uso posterior:
service fstab boot
Opcional: tiempo de espera de inactividad en discos para uso de NAS
-------------------------------------------------------------------
Paso opcional para discos duros.
Si desea utilizar OpenWrt como NAS permanente, es posible que desee reducir la velocidad del motor del disco duro durante los momentos de inactividad. Ya sea porque desea tener silencio en su habitación durante la noche o para aumentar la vida útil del disco duro (por ejemplo, cuando utiliza un disco duro de edición doméstica (en lugar de una edición de centro de datos 24×7).
Hay diferentes opciones para apagar automáticamente el motor del disco duro conectado después de un cierto tiempo de inactividad. Ambos requieren la instalación de paquetes opcionales en OpenWrt.
**1\. Opción: hdparm**
Esta herramienta guarda permanentemente un temporizador de giro en el propio disco duro, utilizando comandos estandarizados de disco SATA (el disco duro recordará ese valor del temporizador de giro, incluso si está apagado, incluso después de un reinicio e incluso si está conectado a un dispositivo diferente). En realidad, es solo una interfaz de línea de comando para una función incorporada del disco duro. Por lo tanto, no es necesario ejecutar ningún servicio OpenWrt en segundo plano para esto y 'hdparm' podría incluso desinstalarse después de configurar este parámetro. Desafortunadamente, muchos adaptadores USB2.0-PATA/SATA antiguos no soportan el comando SATA requerido, aunque incluso los discos duros con una década de antigüedad sí lo soportan. Pero, afortunadamente, la mayoría de las cajas USB3.0-SATA parecen admitir el comando SATA requerido. Para instalar el paquete
opkg update && opkg install hdparm
P.ej. Para establecer un tiempo de inactividad razonable de 20 minutos en el disco duro, utilice:
hdparm -S 240 /dev/sda2
* si el comando falló con un mensaje de error, lamentablemente su carcasa USB-SATA no lo admite y no podrá usar 'hdparm' para desactivar el disco mientras use esta carcasa USB.
* para obtener todos los detalles de los códigos permitidos, consulte [https://linux.die.net/man/8/hdparm](https://linux.die.net/man/8/hdparm "https://linux.die.net/man/8/hdparm")
en el parámetro “-S”
* 0 significa “tiempo de espera de inactividad deshabilitado”
* 1 a 240 especifica múltiplos de 5 segundos, para tiempos de espera de 5 segundos a 20 minutos.
* 241 a 251 especifican de 1 a 11 unidades de 30 minutos, para tiempos de espera de 30 minutos a 5,5 horas.
Por supuesto, siempre puede cambiar el tiempo de espera o desactivar el giro automático nuevamente más adelante. Dependiendo de su disco duro, el valor puede estar activo hasta el próximo reinicio o almacenado permanentemente en el disco duro. El firmware del disco duro es quien gestiona el tiempo de espera de inactividad, no un servicio OpenWrt. Para cambios persistentes utilice el archivo `/etc/rc.local`, como:
\# set timeout to put the drive into idle (low-power) mode
/sbin/hdparm \-S 240 /dev/sda2
exit 0
**2\. Opción: hd-idle (integrado con LuCI)**
[hd-idle](https://openwrt.org/es/docs/guide-user/storage/hd-idle "es:docs:guide-user:storage:hd-idle")
es un servicio que se ejecuta en segundo plano del dispositivo OpenWrt y mantiene su propio contador de tiempo de inactividad. Una vez que el contador de tiempo de espera definido llegue a 0, enviará un comando Spindow SATA “en vivo” al disco. A diferencia del comando permanente hdparm de reducción giro, muchas más carcasas USB2.0-SATA parecen admitir este comando SATA de ““spindown-now””.
Para instalar el paquete que incluso tiene integración frontal de LuCi:
opkg update && opkg install luci-app-hd-idle
Para configurarlo, utilice el menú “Services” de la GUI web LuCi de su dispositivo.
Para instalar el paquete CLI (sin LuCi):
opkg update && opkg install hd-idle
Para configurarlo, puede editar el archivo `/etc/config/hd-idle` y luego habilitar el inicio automático y arrancar el servicio hd-idle `service hd-idle enable && service hd-idle start`.
Opciones para configurar:
| Nombre | Tipo | Predeterminado | Descripción |
| --- | --- | --- | --- |
| `disk` | string | `sda` | Reemplace `sda` con el identificador de su dispositivo |
| `enabled` | boolean | `0` | Habilita la operación de inactividad de disco duro |
| `idle_time_unit` | string | `minutos` | La unidad de tiempo usada en la opción `idle_time_interval` |
| `idle_time_interval` | integer | `10` | Cuánto tiempo de inactividad antes del 'spindown' |
 Tenga en cuenta que debe habilitarlo ya que no lo está de forma predeterminada.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/03 20:45
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/storage/usb-drives#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:additional-software:opkg
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/additional-software/opkg#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:additional-software:smartmontools
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/additional-software/smartmontools#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:additional-software:opkg-to-apk-cheatsheet
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/additional-software/opkg-to-apk-cheatsheet#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:additional-software:show_upgradable_packages_after_ssh_login
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/additional-software/show_upgradable_packages_after_ssh_login#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:kerberos
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/kerberos#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:additional-software:imagebuilder
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/additional-software/imagebuilder#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:irqbalance
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/irqbalance#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:banip
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/banip#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] SSH 설정
SSH 설정
======
SSH 설정은 uci의 **dropbear** 서브시스템에 의해 처리됩니다. 설정파일은 **_/etc/config/dropbear_**에 있습니다..
**dropbear**란 LEDE에서 SSH서비스를 책임지고 있는 기본 데몬입니다.
dropbear SSH 서버 인스턴스는 각각 단일 세션 설정파일을 사용하며 여러 개의 인스턴스를 가질 수 있습니다.
### 기본 설정
root@lede:~# uci show dropbear
dropbear.@dropbear\[0\]=dropbear
dropbear.@dropbear\[0\].RootPasswordAuth='on'
dropbear.@dropbear\[0\].PasswordAuth='on'
dropbear.@dropbear\[0\].Port='22'
root@lede:~# cat /etc/config/dropbear
config dropbear
option RootPasswordAuth 'on'
option PasswordAuth 'on'
option Port '22'
option Interface 'lan'
dropbear의 단일 인스턴스입니다.
### 사용 가능한 설정
| 이름 | Type | Required | 기본값 | 설명 |
| --- | --- | --- | --- | --- |
| _enable_ | boolean | no | 1 | 시스템 부팅시 dropbear의 자동 시작을 비활성화 하려면 _0_ 으로 설정하세요. |
| _verbose_ | boolean | no | 0 | 시작 스크립트로 자세한 출력을 사용하려면 _1_ 로 설정하십시오. |
| _BannerFile_ | string | no | _없음_ | 사용자가 성공적으로 인증되기 전에 인쇄 할 파일의 이름입니다. |
| _PasswordAuth_ | boolean | no | 1 | 암호 인증을 사용하지 않으려면 _0_ 으로 설정하세요. |
| _Port_ | integer | no | 22 | 수신 할 포트 번호 |
| _RootPasswordAuth_ | boolean | no | 1 | 비밀번호로 root 인증을 비활성화 하려면 _0_ 으로 설정하세요. |
| _RootLogin_ | boolean | no | 1 | root로 SSH 로그인을 비활성화 하려면 _0_ 으로 설정하세요. |
| _GatewayPorts_ | boolean | no | 0 | 포워드된 포트에 원격 호스트들이 연결할 수 있게 하려면 _1_ 으로 설정하세요. |
| _Interface_ | string | no | _없음_ | 지정된 인터페이스로만 수신하도록 dropbear에게 지시한다.e.g. _lan_ |
| _rsakeyfile_ | file | no | _없음_ | RSA 파일 경로 |
| _dsskeyfile_ | file | no | _없음_ | DSS/DSA 파일 경로 |
| _SSHKeepAlive_ | integer | no | 300 | Keep Alive |
| _IdleTimeout_ | integer | no | 0 | Idle Timeout |
| _mdns_ | integer | no | 1 | [mDNS](https://openwrt.org/docs/guide-developer/mdns "docs:guide-developer:mdns") 를 통해 서비스를 알릴지 여부 |
### 여러 개의 dropbear 인스턴스
두번째 dropbear 인스턴스를 추가하려면 dropbear 설정에 다른 세션을 추가 해야 합니다. 다음과 같이 해야 합니다.
root@lede:~# uci show dropbear
dropbear.@dropbear\[0\]=dropbear
dropbear.@dropbear\[0\].RootPasswordAuth='on'
dropbear.@dropbear\[0\].PasswordAuth='on'
dropbear.@dropbear\[0\].Port='22'
dropbear.@dropbear\[0\].Interface='lan'
dropbear.@dropbear\[1\]=dropbear
dropbear.@dropbear\[1\].RootPasswordAuth='on'
dropbear.@dropbear\[1\].PasswordAuth='on'
dropbear.@dropbear\[1\].Port='2022'
dropbear.@dropbear\[1\].Interface='wan'
root@lede:~# cat /etc/config/dropbear
config dropbear
option RootPasswordAuth 'on'
option PasswordAuth 'on'
option Port '22'
option Interface 'lan'
config dropbear
option RootPasswordAuth 'on'
option PasswordAuth 'on'
option Interface 'wan'
option Port '2022'
위 예제는 두개의 dropbear 인스턴스를 보여줍니다:
* 첫번째 인스턴스는 lan 인터페이스를 이용하여 22번 포트로 수신 할 것입니다.(기본 내부 네트워크)
* 두번째 인스턴스는 wan 인터페이스를 이용하여 2022로 수신 할 것입니다.(기본 외부 네트워크)
또한 wan의 포트(2022)를 사용하는 경우 접근 할 수 있도록 방화벽 DNAT(포트 포워드)를 확인하세요.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/08/08 07:31
* by tmomas
[](https://openwrt.org/ko/docs/guide-user/ssh_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] IPv4/IPv6 transition technologies
 **This page is not fully translated, yet. Please help completing the translation.**
_(remove this paragraph once the translation is finished)_
IPv4/IPv6 transition technologies
=================================
See also: [NAT64 for IPv6-only networks](https://openwrt.org/docs/guide-user/network/ipv6/nat64 "docs:guide-user:network:ipv6:nat64")
, [NAT66 and IPv6 masquerading](https://openwrt.org/docs/guide-user/network/ipv6/ipv6.nat6 "docs:guide-user:network:ipv6:ipv6.nat6")
, [IPv6 NAT and NPT](https://openwrt.org/docs/guide-user/firewall/fw3_configurations/fw3_nat#ipv6_nat "docs:guide-user:firewall:fw3_configurations:fw3_nat")
Transition technologies can be installed using the following packages:
* IPv6\-in-IPv4 tunnels: [6rd](https://openwrt.org/packages/pkgdata/6rd "packages:pkgdata:6rd")
, [6to4](https://openwrt.org/packages/pkgdata/6to4 "packages:pkgdata:6to4")
, [6in4](https://openwrt.org/packages/pkgdata/6in4 "packages:pkgdata:6in4")
.
* IPv4\-in-IPv6 tunnels: [ds-lite](https://openwrt.org/packages/pkgdata/ds-lite "packages:pkgdata:ds-lite")
.
6in4 Tunnel / HE.net Tunnel Broker
----------------------------------
See also: [Setting up an IPv6 Tunnel with LuCI](https://openwrt.org/docs/guide-user/network/ipv6/ipv6tunnel-luci "docs:guide-user:network:ipv6:ipv6tunnel-luci")
, [IPv6 with Hurricane Electric](https://openwrt.org/docs/guide-user/network/ipv6/ipv6_henet "docs:guide-user:network:ipv6:ipv6_henet")
6in4 tunnels are usually provided by external tunnel providers like HE.net.
 The package [6in4](https://openwrt.org/packages/pkgdata/6in4 "packages:pkgdata:6in4")
must be installed to use this protocol.
 6in4 requires you to have a public IPv4 address, clients behind CGNAT are [not supported](https://forums.he.net/index.php?topic=488.0 "https://forums.he.net/index.php?topic=488.0")
.
### Static IPv6-in-IPv4 Tunnel
The example below illustrates a static tunnel configuration for the Hurricane Electric (he.net) broker. option `ipaddr` specifies the local IPv4 address, `peeraddr` is the broker IPv4 address and `ip6addr` the local IPv6 address routed via the tunnel.
\# /etc/config/network
config interface 'wan6'
option proto '6in4'
option ipaddr '178.24.115.19'
option peeraddr '216.66.80.30'
option ip6addr '2001:0DB8:1f0a:1359::2/64'
### Dynamic IPv6-in-IPv4 Tunnel (HE.net only)
The example below illustrates a dynamic tunnel configuration for the Hurricane Electric (he.net) broker with enabled IP update. The local IPv4 address is determined automatically. The options `tunnelid`, `username` and `updatekey` are provided for IP update.
\# /etc/config/network
config interface 'wan6'
option proto '6in4'
option mtu '1424' \# the IPv6 tunnel MTU (optional)
option peeraddr '216.66.80.30' \# the IPv4 tunnel endpoint at the tunnel provider
option ip6addr '2001:0db8:1f0a:1359::2/64' \# the IPv6 tunnel address
option ip6prefix '2001:db8:1234::/48' \# Your routed prefix (required)
\# configuration options below are only valid for HE.net tunnels, ignore them for other tunnel providers.
option tunnelid '12345' \# HE.net tunnel id
option username 'username' \# HE.net username used to login into tunnelbroker, not the User ID shown after login in.
option updatekey 'updatekey' \# HE.net updatekey instead of password, default for new tunnels
See below for advanced configuration options.
In a typical tunnel configuration (e.g. HE.net) you get two different ipv6 addresses/prefixes from the tunnel provider:
* **ip6addr**: The tunnel endpoint address is like '2001:DB8:2222:EFGH::2/64'. This ...::2 address is only used for the tunnel interface endpoint. It is not a routable address and it can't be used for anything else than connecting to the other end of the tunnel, typically ...::1 .
* **ip6prefix**: The tunnel provider gives you also a routable prefix, typically either /48 or /64, for example '2001:DB8:1112::/48' or '2001:DB8:1234:ABCD::/64'. Your LAN clients will get addresses from that prefix. Using a wider prefix helps delegate IPv6 to several downstream networks.
#### Firewall
Some users may require to add extra firewall rules to allow 6in4 traffic to always reach their tunnel endpoint. The package [iptables-mod-ipopt](https://openwrt.org/packages/pkgdata/iptables-mod-ipopt "packages:pkgdata:iptables-mod-ipopt")
must be installed for length matching.
\# /etc/config/firewall
config rule
option name 'Allow-protocol-41'
option src 'wan'
option proto '41'
option target 'ACCEPT'
config rule
option name 'Allow-protocol-59'
option src 'wan'
option proto '59'
option target 'ACCEPT'
option extra '-m length --length 40'
#### Default route
Provide default route to override `sourcefilter`.
\# /etc/config/network
config route6
option interface 'wan6'
option target '::/0'
Protocol 6in4 (IPv6-in-IPv4 Tunnel)
-----------------------------------
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `ipaddr` | IPv4 address | no | Current WAN IPv4 address | Local IPv4 endpoint address |
| `peeraddr` | IPv4 address | yes | _(none)_ | Remote IPv4 endpoint address |
| `ip6addr` | IPv6 address (CIDR) | yes | _(none)_ | Local IPv6 address delegated to the tunnel endpoint |
| `ip6prefix` | IPv6 prefix | no | _(none)_ | Routed IPv6 prefix for downstream interfaces (Barrier Breaker and later only) |
| `tunlink` | Logical Interface | no | _(none)_ | Tunnel base interface. Define which Interface, for example WAN, should be used for outgoing IPv4 traffic to the Remote IPv4 Address |
| `defaultroute` | boolean | no | `1` | Whether to create an IPv6 default route over the tunnel |
| `ttl` | integer | no | `64` | TTL used for the tunnel interface |
| `tos` | string | no | _(none)_ | Type Of Service : either “inherit” (the outer header inherits the value of the inner header) or an hexadecimal value. Also known as DSCP. |
| `mtu` | integer | no | `1280` | MTU used for the tunnel interface |
| `tunnelid` | integer | no | _(none)_ | HE.net global tunnel ID, used for endpoint update |
| `username` | string | no | _(none)_ | HE.net username which you use to login into tunnelbroker, not the User ID shown after you have login in, plaintext, used for endpoint update |
| `password` | string | no | _(none)_ | HE.net password, plaintext, obsolete, used for endpoint update |
| `updatekey` | string | no | _(none)_ | HE.net updatekey, plaintext, overrides password since 2014-02, used for endpoint update |
| `metric` | integer | no | `0` | Specifies the default route metric to use |
 This protocol type does not need the `device` option set in the interface section. The interface name is derived from the section name, e.g. `config interface sixbone` would result in an interface named `6in4-sixbone`.
 Although `ip6prefix` isn't required, `sourcefilter` is enabled by default and prevents forwarding of packets unless `ip6prefix` is specified.
6rd Tunnel (ISP-Provided IPv6 Transition)
-----------------------------------------
6rd is a tunnel mechanism based on 6to4. Unlike other tunneling mechanisms, 6rd is usually provided by the ISP itself.
 The package [6rd](https://openwrt.org/packages/pkgdata/6rd "packages:pkgdata:6rd")
must be installed to use this protocol.
 The configuration of 6rd is usually auto-detected and manual configuration is not needed, simply installing the 6rd package (and rebooting) is usually enough.
 To automatically configure 6rd from dhcp you need to create an interface with `option auto 0` and put its name as the 'iface6rd' parameter. In addition you also need to add its name to a suitable firewall zone in `/etc/config/firewall`.
\# /etc/config/network
config interface 'wan6'
option proto '6rd'
option peeraddr '77.174.0.2'
option ip6prefix '2001:838:ad00::'
option ip6prefixlen '40'
option ip4prefixlen '16'
To debug 6rd via DHCP, enable [DHCP client logging](https://openwrt.org/docs/guide-user/network/protocol.dhcp#dhcp_client_scripts "docs:guide-user:network:protocol.dhcp")
, reboot the router, and check the logs:
\# logread -e ip6rd
ip6rd\=16 40 2001:0838:ad00:0000:0000:0000:0000:0000 77.174.0.2
If this line isn't present, you need to obtain the correct values for peeraddr, ip6prefix, ip6prefixlen and ip4prefixlen from your ISP. The above ip6rd or the obtained values can be used to hardcode the 6rd tunnel. Remove or comment out the iface6rd line in the wan section.
 If you choose a name for your tunnel-interface different from `wan6`, be sure to add that network to the `wan` firewall-zone.
Below configuration options are only needed for hardcoding the 6rd tunnel.
Protocol 6rd
------------
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `peeraddr` | IPv4 address | yes | no | 6rd - Gateway |
| `ipaddr` | IPv4 address | no | Current WAN IPv4 address | Local IPv4 endpoint address |
| `ip6prefix` | IPv6 prefix (without length) | yes | no | 6rd-IPv6 Prefix |
| `ip6prefixlen` | IPv6 prefix length | yes | no | 6rd-IPv6 Prefix length |
| `ip4prefixlen` | IPv6 prefix length | no | 0 | IPv4 common prefix |
| `defaultroute` | boolean | no | `1` | Whether to create an IPv6 default route over the tunnel |
| `ttl` | integer | no | `64` | TTL used for the tunnel interface |
| `tos` | string | no | _(none)_ | Type Of Service: either “inherit” (the outer header inherits the value of the inner header) or an hexadecimal value |
| `mtu` | integer | no | `1280` | MTU used for the tunnel interface |
| `iface6rd` | logical interface | no | _(none)_ | Logical interface template for auto-configuration of 6rd |
| `mtu6rd` | integer | no | _system default_ | MTU of the 6rd interface |
| `zone6rd` | firewall zone | no | _system default_ | Firewall zone to which the 6rd interface should be added |
 This protocol type does not need the `device` option set in the interface section. The interface name is derived from the section name, e.g. `config interface wan6` would result in an interface named `6rd-wan6`.
 Some ISP's give you the number of bytes you should use from your WAN IP to calculate your IPv6 address. `ip4prefixlen` expects the _prefix_ bytes of your WAN IP to calculate the IPv6 address. So if your ISP gives you 14 bytes to calculate, enter 18 (32 - 14).
6pe, L2TP Tunnel (ISP-provided IPv6 Transition)
-----------------------------------------------
This is another transitional mechanism for IPv6 used by some ISPs, it relies on a L2TPv2 tunnel.
 The package [xl2tpd](https://openwrt.org/packages/pkgdata/xl2tpd "packages:pkgdata:xl2tpd")
must be installed to use this protocol. It will handle the L2TP tunnel and PPP session.
The high-level description of the tunneling is the following:
1. An L2TP tunnel is created, encapsulated in UDP packets over IPv4.
2. A PPP session is established inside the tunnel.
3. IPv6CP (see [RFC 5072](http://tools.ietf.org/html/rfc5072 "http://tools.ietf.org/html/rfc5072")
) is used to negotiate link-local IPv6 addresses.
4. An IPv6 prefix is obtained thanks to DHCPv6.
This howto is derived from an experience with SFR, in France (FTTH residential access). It might apply to other ISPs as well. In the case of SFR, steps 1 and 2 require an authentication. Fortunately, the L2TP password is hardcoded. The PPP password is not, but it's sent as cleartext, so a simple sniffing is enough to recover it.
\# /etc/config/network
config interface 6pe
option proto l2tpv2
option server
option username ''
option password ''
option keepalive '6'
option ipv6 '1'
config interface 'wan6'
option device '@6pe'
option proto 'dhcpv6'
If you need authentication at the L2TP level (before PPP):
\# /etc/xl2tpd/xl2tp-secrets
\* \* my\_l2tp\_password
At this point, running `service network reload` or simply running `ifup wan6` should give you a fully working IPv6 setup. To debug, look at the logs (`logread`) and the interfaces status (`ifstatus 6pe` and `ifstatus wan6`).
Advanced options for this protocol are below.
Protocol l2tp (PPP over L2TP Tunnel)
------------------------------------
Most options are similar to protocol “ppp”.
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `server` | string | yes | _(none)_ | L2TP server to connect to. Acceptable datatypes are hostname or IP address, with optional port separated by colon `:`. Note that specifying port is only supported recently and should appear in DD release |
| `username` | string | no | _(none)_ | Username for PAP/CHAP authentication |
| `password` | string | yes if `username` is provided | _(none)_ | Password for PAP/CHAP authentication |
| `ipv6` | bool | no | 0 | Enable IPv6 on the PPP link (IPv6CP) |
| `mtu` | int | no | `pppd` default | Maximum Transmit/Receive Unit, in bytes |
| `keepalive` | string | no | _(none)_ | Number of unanswered echo requests before considering the peer dead. The interval between echo requests is 5 seconds. |
| `checkup_interval` | int | no | _(none)_ | Number of seconds to pass before checking if the interface is not up since the last setup attempt and retry the connection otherwise. Set it to a value sufficient for a successful L2TP connection for you. It's mainly for the case that netifd sent the connect request yet xl2tpd failed to complete it without the notice of netifd |
| `pppd_options` | string | no | _(none)_ | Additional options to pass to `pppd` |
The name of the physical interface will be “l2tp-”.
6to4 Tunnel
-----------
6to4 is the simplest IPv6 tunneling mechanism and relies on publicly available gateways.
 The package [6to4](https://openwrt.org/packages/pkgdata/6to4 "packages:pkgdata:6to4")
must be installed to use this protocol.
\# /etc/config/network
config interface 'wan6'
option proto '6to4'
\# /etc/config/firewall
config rule
option target 'ACCEPT'
option name '6to4'
option src 'wan'
option proto '41'
 If you choose a name for your tunnel-interface different from `wan6`, be sure to add that network to the `wan` firewall-zone.
See below for advanced configuration options.
Protocol 6to4 (IPv6-in-IPv4 Tunnel)
-----------------------------------
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `ipaddr` | IPv4 address | no | Current WAN IPv4 address | Local IPv4 endpoint address |
| `defaultroute` | boolean | no | `1` | Whether to create an IPv6 default route over the tunnel |
| `ttl` | integer | no | `64` | TTL used for the tunnel interface |
| `tos` | string | no | _(none)_ | Type Of Service : either “inherit” (the outer header inherits the value of the inner header) or an hexadecimal value |
| `mtu` | integer | no | `1280` | MTU used for the tunnel interface |
| `metric` | integer | no | `0` | Specifies the default route metric to use |
 This protocol type does not need the `device` option set in the interface section. The interface name is derived from the section name, e.g. `config interface wan6` would result in an interface named `6to4-wan6`.
Dual-Stack Lite tunnel (ds-lite IPv4 in IPv6)
---------------------------------------------
ds-lite is a transitioning-mechanism which is used by ISPs to support legacy IPv4\-connectivity over a native IPv6 connection.
 The package [ds-lite](https://openwrt.org/packages/pkgdata/ds-lite "packages:pkgdata:ds-lite")
must be installed to use this protocol.
 The configuration is usually auto-detected and manual configuration is not needed, simply installing the ds-lite package (and restarting the network interfaces like when changing the configuration) is usually enough.
\# /etc/config/network
config interface 'wan6'
option device 'eth1'
option proto 'dhcpv6'
config interface 'wan'
option proto 'dslite'
option peeraddr '2001:db80::1' \# Your ISP's DS-Lite AFTR
 If you choose a name for your tunnel-interface different from `wan`, be sure to add that network to the `wan` firewall-zone.
See below for advanced configuration options.
Protocol dslite (Dual-Stack Lite)
---------------------------------
| Name | Type | Required | Default | Description |
| --- | --- | --- | --- | --- |
| `peeraddr` | IPv6 address | yes | no | DS-Lite AFTR address |
| `ip6addr` | IPv6 address | no | Current WAN IPv6 address | Local IPv6 endpoint address |
| `tunlink` | Logical Interface | no | Current WAN interface | Tunnel base interface |
| `defaultroute` | boolean | no | `1` | Whether to create an IPv6 default route over the tunnel |
| `ttl` | integer | no | `64` | TTL used for the tunnel interface |
| `mtu` | integer | no | `1280` | MTU used for the tunnel interface |
 ds-lite operation requires that IPv4 NAT is disabled. You should adjust your settings in /etc/config/firewall accordingly.
 This protocol type does not need the `device` option set in the interface section. The interface name is derived from the section name, e.g. `config interface wan` would result in an interface named `dslite-wan`.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/20 17:31
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/network/ipv6_ipv4_transitioning#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Programar tareas con cron
Programar tareas con cron
=========================
Este artículo se basa en lo siguiente:
* Acceder [web interface](https://openwrt.org/es/docs/guide-quick-start/walkthrough_login "es:docs:guide-quick-start:walkthrough_login")
/ [command-line interface](https://openwrt.org/es/docs/guide-quick-start/sshadministration "es:docs:guide-quick-start:sshadministration")
* Administrar [configuraciones](https://openwrt.org/es/docs/guide-user/base-system/uci "es:docs:guide-user:base-system:uci")
/ [paquetes](https://openwrt.org/es/docs/guide-user/additional-software/managing_packages "es:docs:guide-user:additional-software:managing_packages")
/ [servicioss](https://openwrt.org/es/docs/guide-user/base-system/managing_services "es:docs:guide-user:base-system:managing_services")
/ [registros](https://openwrt.org/es/docs/guide-user/base-system/log.essentials "es:docs:guide-user:base-system:log.essentials")
Introducción
------------
* OpenWrt puede ejecutar tareas programadas usando el servicio [cron](https://en.wikipedia.org/wiki/Cron "https://en.wikipedia.org/wiki/Cron")
.
* Este tutorial describe el método para configurar tareas cron.
* Ver también [Watchcat](https://openwrt.org/es/docs/guide-user/advanced/watchcat "es:docs:guide-user:advanced:watchcat")
para reiniciar según el horario o la conectividad.
Objetivos
---------
* Ejecutar programas o scripts en un momento específico.
* Automatizar la gestión de tareas programadas.
Instrucciones de la interfaz web
--------------------------------
Configurar tareas cron usando la interfaz web.
1. Navegue a **LuCI → System → Scheduled Tasks**.
2. Edite la configuración y haga clic en el botón **Save**.
Instrucciones de línea de comando
---------------------------------
Configurar tareas cron usando la interfaz de línea de comandos.
\# Editar configuración
crontab \-e
\# Mostrar configuración
crontab \-l
\# Aplicar cambios
service cron restart
Esto editará el archivo de configuración `/etc/crontabs/root` en el [editor vi](https://openwrt.org/es/docs/guide-user/base-system/user.beginner.cli#editing_files "es:docs:guide-user:base-system:user.beginner.cli")
.
 Debe haber un carácter EOL en la última línea del archivo crontab. Simplemente deje una línea vacía al final para estar seguro.
Especificación de tarea
-----------------------
Cada línea es una tarea separada escrita en la especificación:
\* \* \* \* \* comando a ejecutar
- - - - -
| | | | |
| | | | ----- Día de la semana (0 - 6) (Domingo =0)
| | | ------- Mes (1 - 12)
| | --------- Día (1 - 31)
| ----------- Hora (0 - 23)
------------- Minuto (0 - 59)
Ejemplos de especificación de tiempo:
| min 0-59 | hora 0-23 | día del mes 1-31 | mes 1-12 | día de la semana 0-6 | Descripción |
| --- | --- | --- | --- | --- | --- |
| \*/5 | \* | \* | \* | \* | Cada 5 minutos |
| 12 | \*/3 | \* | \* | \* | Cada 3 horas a los 12 minutos |
| 57 | 11 | 15 | 1,6,12 | \* | A las 11:57 Hrs el día 15 de Ene, Jun & Dic |
| 25 | 6 | \* | \* | 1-5 | A las 6:25 AM cada día laboral (Lun-Vie) |
| 0 | 0 | 4,12,26 | \* | \* | A la medianoche los días 4, 12 y 26 de cada mes |
| 5,10 | 9,14 | 10 | \* | 0,4 | A las 9:05AM, 9:10AM, 2:05PM y 2:10PM cada domingo y jueves |
 0 (cero) se trata como domingo. Si configura el día de la semana en 7, BusyBox se volverá loco y ejecutará su comando todos los días.
**Tabla de atajos:**
| Atajo | Equivalencia | Descripción |
| --- | --- | --- |
| `@reboot` | | Ejecutar una vez, al inicio |
| `@yearly` | `0 0 1 1 *` | Cada año |
| `@annually` | `0 0 1 1 *` | Cada año |
| `@monthly` | `0 0 1 * *` | Cada mes |
| `@weekly` | `0 0 * * 0` | Cada semana |
| `@daily` | `0 0 * * *` | Cada día |
| `@midnight` | `0 0 * * *` | Cada día |
| `@hourly` | `0 * * * *` | Cada hora |
 Los atajos de tiempo no están habilitados de forma predeterminada. Los accesos directos requieren compilar Busybox con FEATURE\_CROND\_SPECIAL\_TIMES habilitado en las opciones de compilación de Busybox.
Solución de problemas
---------------------
Puede leer mensajes de registro con:
logread \-e cron
No todos los mensajes se registran, para aumentar el registro cambie la opción `[nivel de registro cron](https://openwrt.org/es/docs/guide-user/base-system/system_configuration "es:docs:guide-user:base-system:system_configuration") `.
Extras
------
### Referencias
* [crontab(1)](http://man.cx/crontab%281%29 "http://man.cx/crontab%281%29")
, [crontab(5)](http://man.cx/crontab%285%29 "http://man.cx/crontab%285%29")
* [BusyBox crontab](https://busybox.net/downloads/BusyBox.html#crontab "https://busybox.net/downloads/BusyBox.html#crontab")
* [Crontab quick reference](http://adminschoice.com/crontab-quick-reference "http://adminschoice.com/crontab-quick-reference")
### Reinicio periódico
Una solución sencilla para algunos problemas difíciles de resolver (pérdida de memoria, degradación del rendimiento,...) es reiniciar el enrutador periódicamente, por ejemplo cada noche.
Sin embargo, esto no es tan sencillo como parece, ya que el router no suele tener un reloj en tiempo real. Esto podría provocar un ciclo interminable de reinicios.
En el proceso de arranque, el reloj se configura inicialmente mediante “sysfixtime” con la marca de tiempo más reciente de cualquier archivo que se encuentre en /etc. El archivo más reciente es posiblemente un archivo de estado o un archivo de configuración, modificado quizás 30 segundos antes del reinicio iniciado por cron. Entonces, en el proceso de arranque, el reloj se retrasa unos segundos hasta la marca de tiempo de ese archivo. Luego, cron se inicia y unos segundos más tarde nota que el momento de inicio requerido ha llegado de nuevo y se reinicia nuevamente... Al final del proceso de arranque, se inicia ntpd, y también puede pasar un tiempo antes de que ntpd obtenga y establezca la hora correcta, por lo que cron puede iniciar el reinicio en el medio.
Una solución para cron es utilizar un retraso y tocar un archivo en `/etc` antes de reiniciar.
\# Reiniciar a las 4:30 a. m. todos los días
\# Nota: Para evitar un bucle de reinicio infinito, espere 70 segundos
\# y toque un archivo en /etc para configurar el reloj
\# correctamente a las 4:31 a.m. al reiniciar antes de que comience cron.
30 4 \* \* \* sleep 70 && touch /etc/banner && reboot
 En muchas plataformas `shutdown` no funciona; simplemente detendrá la CPU pero no apagará el dispositivo. Por lo general, no hay ningún circuito programable para apagar la unidad. `reboot` funciona, en caso de que desee reiniciar el enrutador periódicamente.
### Reinicio periódico de la red
Una solución sencilla para reiniciar toda su red (lan, wan y wifi) cada 10 minutos es esta:
\*/10 \* \* \* \* service network restart
### Despertador
Si tiene [DST - Hora de verano](https://en.wikipedia.org/wiki/Daylight%20saving%20time "https://en.wikipedia.org/wiki/Daylight saving time")
podría escribirse un bonito despertador. Cuando comienza el horario de verano en Europa Central, los relojes avanzan de las 02:00 CET a las 03:00 CEST del último domingo de marzo. Seis días antes, podría hacer que su WoL le despierte 10 minutos antes. Más tarde no funcionará, llegará tarde. Cuando finaliza el horario de verano en Europa Central, los relojes retroceden de las 03:00 CEST a las 02:00 CET del último domingo de octubre.
\# min hora día mes día-de-la-semana comando
59 05 \* \* 1 /usr/bin/wol \-h 192.168.1.255 xx:xx:xx:xx:xx:xx
\# crontab debe terminar con la última línea como espacio o comentario
### Mantener el número de configuraciones/instantáneas de configuración
Para mantener un número N de configuraciones/valores en el directorio “/root”, también puede utilizar cron. De esta forma podrá acceder y restaurar configuraciones de los últimos N días. El cronjob se puede ampliar fácilmente para copiar la configuración a otro dispositivo, para poder replicar desde cero en un dispositivo OpenWRT roto.
#Hacer una nueva instantánea de copia de seguridad/configuraciones durante la noche a la 12:01 a. m., conserve las últimas N=100 instantáneas
#01 00 \* \* \* sysupgrade -b "/root/backup-${HOSTNAME}.tar.gz" # <-- mantiene solo una configuración
01 00 \* \* \* find "/root" \-type f \-name "backup-\*.tar.gz" | sort \-r | awk 'NR > 100' | xargs rm \-f; sysupgrade \-b "/root/backup-${HOSTNAME}\-$(date +\\%Y-\\%m-\\%d-\\%H-\\%M-\\%S).tar.gz"
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/26 18:26
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/base-system/cron#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:chroot
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/chroot#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:snort
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/snort#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:rng
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/rng#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:python
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/python#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:ugps
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/ugps#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:fwknop
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/fwknop#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:usb.iptunnel
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/usb.iptunnel#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:honeypots
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/honeypots#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:xmpp.server
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/xmpp.server#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:geoip-shell
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/geoip-shell#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:telegraf
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/telegraf#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:dhcp_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/dhcp_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:services:tftp.pxe-server
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/services/tftp.pxe-server#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:fusion
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/fusion#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:virtualbox-advanced
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/virtualbox-advanced#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:mikrotik_metarouter_openwrt
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/mikrotik_metarouter_openwrt#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:sudo
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/sudo#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:dhcp
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/dhcp#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:firewall:firewall_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/firewall/firewall_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:hotplug
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/hotplug#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:backup_restore
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/backup_restore#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:base-system:uci
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/base-system/uci#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:vmware
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/vmware#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:qemu
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/qemu#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:ucicheatsheet
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/ucicheatsheet#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:dropbear.public-key.auth
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/dropbear.public-key.auth#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:vendor_specific_rescue
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/vendor_specific_rescue#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:xen
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/xen#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:generic.debrick
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/generic.debrick#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:metarouter
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/metarouter#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:obtain.firmware.docker
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/obtain.firmware.docker#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:ead
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/ead#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:virtualization:docker_openwrt_image
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/virtualization/docker_openwrt_image#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:network:tunneling_interface_protocols
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/network/tunneling_interface_protocols#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt como host de contenedor Docker
This translation is older than the [original page](https://openwrt.org/docs/guide-user/virtualization/docker_host)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/virtualization/docker_host?do=diff&rev=1701110221)
.
OpenWrt como host de contenedor Docker
======================================
OpenWrt puede ser un host [Docker](https://en.wikipedia.org/wiki/Docker_(software) "https://en.wikipedia.org/wiki/Docker_(software)")
en x86-64, Aarch64 y otras arquitecturas compatibles.
Hay dos formas de utilizar Docker como host: instalar Docker Community Edition o utilizar herramientas nativas OpenWrt que admitan la especificación del contenedor Docker.
Probablemente, primero necesitará [configurar el almacenamiento](https://openwrt.org/es/docs/guide-user/storage/usb-drives "es:docs:guide-user:storage:usb-drives")
como lugar para almacenar los contenedores y los datos.
Además, en la mayoría de los casos ejecutará el contenedor como un usuario específico y le dará acceso a alguna carpeta fuera del contenedor, donde podrá almacenar su configuración y los datos. Por lo tanto, probablemente necesitará [crear nuevos usuarios y grupos para aplicaciones o servicios del sistema](https://openwrt.org/es/docs/guide-user/additional-software/create-new-users "es:docs:guide-user:additional-software:create-new-users")
, crear las carpetas para la configuración y los datos, y luego cambiar el propietario de estas carpetas al usuario con el que ejecutará el contenedor.
Instalar Docker Community Edition
---------------------------------
* Instala el paquete **docker-ce** para herramientas de línea de comandos
* Instala el paquete **luci-app-dockerman** para obtener un panel de control para contenedores en Luci
La carpeta predeterminada para Docker en la interfaz Dockerman de Luci es **/opt/docker**, por lo que es deseable montar su almacenamiento en **/opt** o cambiar la carpeta en **Docker** > **Overview** > **Docker Root Dir** y luego reiniciar el servicio Dockerd.
### Añadir una imagen
Para agregar una imagen, búsquela en [Docker Hub](https://hub.docker.com/ "https://hub.docker.com/")
y luego copie el nombre de imagen desde el cuadro de texto **Docker Pull Command**. Por ejemplo, si el texto es **docker pull linuxserver/transmission**, copie **linuxserver/transmission**.
En Luci, vaya a **Docker** > **Images** y pegue ese texto en el cuadro **Pull Image**, luego haga clic en **Pull**. La página mostrará el progreso de la descarga.
Para extracciones de contenedores más largas, Luci puede agotar el tiempo de espera, por lo que deberá usar la línea de comando. Por ejemplo, las imágenes del controlador unifi incluyen el entorno de ejecución de Java y se acercan a los 500 MB, por lo que puede acceder mediante SSH e ingresar: docker pull linuxserver/unifi-controller.
Luego, en Luci, vaya a **Docker** > **Containers** > **Add**. En la página del nuevo contenedor, seleccione la imagen de docker en el menú **Docker Image**, y luego configure todos los demás parámetros (normalmente los parámetros disponibles/útiles se describen en la descripción del contenedor en Docker Hub), luego presione Enviar (Submit) para crear el contenedor.
### Configurar el demonio del motor Docker CE
La configuración está ubicada en `/etc/config/dockerd`.
* `data_root` es una carpeta donde almacenar imágenes y contenedores. Esta también es montada por un docker. Puede que desee cambiarla a un disco USB. Su sistema de archivos no puede ser fat o ntfs. De manera predeterminada es `/opt/docker/`
* `log_level` predeterminado `warn`.
* `hosts` es un detector de API. De manera predeterminada se utiliza un socket UNIX `/var/run/docker.sock`.
* `iptables` Habilita las reglas de iptables. Predeterminado `1`
* `bip` puente de red IP. Predeterminado `172.18.0.1/24`
* `fixed_cidr` Asigna IPs desde un rango. Predeterminado `172.17.0.0/16`
* `fixed_cidr_v6` igual que fixed\_cidr para IPv6. Predeterminado 'fc00:1::/80'
* `ipv6` Habilita redes IPv6. Predeterminado `1`
* `ip` Predeterminado `::ffff:0.0.0.0`
* `dns` Servidores DNS. Predeterminado `172.17.0.1`
* `registry_mirrors` URL de un registro. Predeterminado `[https://hub.docker.com](https://hub.docker.com/ "https://hub.docker.com") `
Las siguientes configuraciones requieren reiniciar (restart) docker para que surta efecto completo. Una recarga (reload) solo tendrá efecto parcial o ningún efecto:
* bip
* blocked\_interfaces
* extra\_iptables\_args
* device
Usar herramientas nativas OpenWrt
---------------------------------
El sistema Procd init ahora admite la especificación de tiempo de ejecución de Open Container Initiative, ampliando su capacidad de contenedores delgados (“ujail”).
La herramienta de línea de comandos uxc maneja las operaciones básicas en contenedores según lo definido por la especificación.
Esto permite usarlo como reemplazo directo del 'runc' (o 'crun') de Docker en hosts OpenWrt con un espacio significativamente reducido.
Información detallada pero posiblemente desactualizada disponible en [https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc](https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc "https://gitlab.com/prpl-foundation/prplos/prplos/-/wikis/uxc")
### instalar paquetes
Para 20.0x instale lo siguiente:
opkg install kmod-veth uxc ujail-console
Para nuevas instantáneas:
opkg install kmod-veth uxc procd-ujail procd-ujail-console
### crear par veth (virtual ethernet) para el contenedor
uci batch <), cambie sus _additionalimagestores_ nuevamente a \[\], deshabilite el servicio podman y asegúrese de que el servicio podman no comience con la creación /inicio de contenedores durante el arranque. Luego elimine todos los archivos, de /srv/.podman/images:
rm -rf /srv/.podman/images
reinicie nuevamente y comience esto nuevamente desde el inicio de esta sección de la guía.
**Pod** Empezaremos creando un pod. El pod puede contener varios contenedores y comparten algunos atributos, como la dirección IP. Mientras intentamos crear una configuración de servidor web, queremos que la dirección IP sea siempre la misma para este pod. He creado un script /srv/create.sh para construir este pod:
#!/bin/sh
podman pod create \\
\--replace \\
\--name servers \\
\--hostname srv \\
\--ip 10.129.0.2
podman pod start servers
Esto crea, o reemplaza, si existe, servidores con nombres de pod, le asigna un nombre de host srv (no importante) y una dirección IP estática 10.129.0.2.
**Contenedores** Todas las configuraciones y los datos exportados estáticamente también se encuentran en /srv. En /srv/caddy tengo todo lo necesario para construir mi contenedor caddy, como las configuraciones y cualquier contenedor caddy que necesite. También tengo un script de compilación allí, /srv/caddy/create.sh:
#!/bin/sh
podman create \\
\--name caddy \\
\--pod servers \\
\--replace \\
\--systemd false \\
\--label app\=caddy \\
\--volume /srv/caddy/conf/:/etc/caddy/:Z,rw \\
\--volume /srv/caddy/htdocs/:/var/htdocs/:z,rw \\
\--volume /srv/caddy/logs/:/var/log/:z,rw \\
\--volume /dev/log:/dev/log:Z,rw \\
\--mount\="type=bind,src=/etc/acme/domain.tld\_ecc/domain.tld.cer,dst=/etc/caddy/ssl/server.pem,ro=true,idmap=uids=0-82-1;gids=0-82-1" \\
\--mount\="type=bind,src=/etc/acme/domain.tld\_ecc/domain.tld.key,dst=/etc/caddy/ssl/server.key,ro=true,idmap=uids=0-82-1;gids=0-82-1" \\
docker.io/me/my\_caddy\_image:latest
podman start caddy
En esta guía no reviso la configuración de Caddy, la busco en los documentos de Caddy. Mi caddy está configurado para ejecutarse como usuario www:www-data, que en esa configuración son uid 82 y gid 82, acme se usa para obtener certificados, pero el usuario www(82) no puede leer archivos de propiedad raíz, por lo que usamos idmapping para asignar estos 2 archivos para el usuario www:www-data. Hay varias formas de hacer esto, este es solo un enfoque. También puede configurar un sistema que modifique esos archivos para que estén disponibles para que todos los lean, o al menos para el usuario y/o el grupo 82. O cópielos localmente y cópielos estáticamente en esa ubicación.
Y tengo un script similar para nginx:
#!/bin/sh
podman create \\
\--name nginx \\
\--pod servers \\
\--replace \\
\--systemd false \\
\--label app\=nginx \\
\--volume /srv/nginx/conf/:/etc/nginx/:Z,rw \\
\--volume /srv/nginx/logs/:/var/log/nginx/:Z,rw \\
\--volume /srv/nginx/htdocs/:/var/htdocs/:z,rw \\
\--volume /dev/log:/dev/log:Z,rw \\
docker.io/me/my\_nginx\_image:latest
podman start nginx
Ahora, después de haber configurado correctamente su caddy y nginx, deberíamos tener un servidor funcionando correctamente. Necesitamos configurar redirecciones desde wan.
**Exponer a wan**
Ahora que tenemos caddy sirviendo en 10.129.0.2, puertos 80 y 443, editamos /etc/config/firewall nuevamente:
config redirect
option name 'Allow-HTTP'
option src 'wan'
option dest 'podman'
option src\_dport '80'
option dest\_ip '10.129.0.2'
option dest\_port '80'
option proto 'tcp'
option reflection '0'
option target 'DNAT'
option enabled '1'
config redirect
option name 'Allow-HTTPS'
option src 'wan'
option dest 'podman'
option src\_dport '443'
option dest\_ip '10.129.0.2'
option dest\_port '443'
option proto 'tcp'
option reflection '0'
option target 'DNAT'
option enabled '1'
**Automatización**
Finalmente, queremos que nuestro pod y contenedores se construyan y se inicien durante el arranque, también tenemos acme manejando nuestros certificados, por lo que queremos reiniciar caddy cuando se renuevan los certificados.
Agregué el directorio /srv/scripts y agregué allí el archivo restart\_caddy.sh:
#!/bin/sh
/etc/init.d/podman enabled || exit
logger \-t acme \-p daemon.info "SSL certificates renewed, restarting container servers:caddy"
podman stop caddy
sleep 1
podman start caddy
Y luego el resto lo maneja /etc/rc.local:
\# Put your custom commands here that should be executed once
\# the system init finished. By default this file does nothing.
add\_podman\_trigger() {
local counter\=10
local running\=0
\[ \-x "/etc/init.d/acme" \] || exit
/etc/init.d/acme enabled || exit
while \[ "$counter" \-gt 0 \]; do
\[ "$(service podman status)" = "running" \] && {
running\=1
counter\=0
} || {
sleep 1
counter\=$(($counter\-1))
}
done
\[ "$running" \-eq 1 \] && {
ubus call service set '{ "name": "podman", "triggers": \[\[ "acme.renew", \[\[ "run\_script", "/srv/scripts/restart\_caddy.sh" \]\], 2000 \]\], "data": {}}'
logger \-t podman \-p daemon.info "podman: added service trigger for acme.renew event to restart servers:caddy"
}
}
start\_podman\_services() {
/etc/init.d/podman enabled && {
\[ \-f /tmp/.podman\_created \] || {
touch /tmp/.podman\_created
sleep 1
/srv/create.sh
sleep 2
/srv/caddy/create.sh
sleep 2
/srv/nginx/create.sh
add\_podman\_trigger &
}
}
}
Es por eso que iniciar el servicio podman con /etc/init.d/podman resulta útil; podemos ignorar todos los contenedores relacionados durante el arranque, simplemente deshabilitando el servicio, ya que no se inicia nada relacionado con podman si el servicio está deshabilitado. Esto construye nuestro pod y ambos contenedores y luego agrega un activador para que el servicio podman reinicie caddy cuando se renuevan los certificados SSL. Hay una rutina que verifica si el servicio podman se ha iniciado, porque el disparador debe agregarse DESPUÉS de que se haya iniciado el servicio podman.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2023/12/03 16:01
* by brodrigueznu
[](https://openwrt.org/es/docs/guide-user/virtualization/docker_host#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:security_guide_for_the_paranoid
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/security_guide_for_the_paranoid#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:recovering_from_clientmode
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/recovering_from_clientmode#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:troubleshooting:tftpserver
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/troubleshooting/tftpserver#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:secure.access
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/secure.access#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] OpenWrt en contenedores LXC
This translation is older than the [original page](https://openwrt.org/docs/guide-user/virtualization/lxc)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/virtualization/lxc?do=diff&rev=1570206647)
.
 **Esta página aún no está completamente traducida. Ayude a completar la traducción.**
_(elimine este párrafo una vez que la traducción haya finalizado)_
OpenWrt en contenedores LXC
===========================
OpenWrt puede ejecutarse dentro de un contenedor LXC, utilizando el mismo kernel que se ejecuta en el sistema host. Esto puede resultar útil tanto para el desarrollo como para el alojamiento de máquinas virtuales.
Privilegiado vs no privilegiado
-------------------------------
Consulte su distribución para obtener instrucciones actualizadas sobre la configuración de cualquiera de las funciones de HostOS.
Descripción básica
------------------
A continuación, se ofrece una idea aproximada de cómo poner las cosas en marcha. Antes que nada, instale LXC en la máquina host y asegúrese de que admita la ejecución de contenedores sin privilegios. Es probable que también necesite funcionalidad de puente y / o subsistemas relacionados subyacentes adicionales (macvlan, etc.) si se utilizan.
Actualmente no hay una plantilla para OpenWrt disponible, por lo que se requieren algunos pasos manuales.
1. Cree la carpeta VM manualmente en`.local/share/lxc//`
2. Descargue una instantánea rootfs de OpenWrt y descomprímala en `.local/share/lxc//rootfs`
3. Crear un`.local/share/lxc//config` que contiene el siguiente contenido:
lxc.include = /etc/lxc/default.conf
lxc.include = /usr/share/lxc/config/common.conf
lxc.include = /usr/share/lxc/config/userns.conf
lxc.arch = linux64
# encuentra tus identificadores a través de
# cat /etc/s\*id|grep $USER
lxc.idmap = u 0 100000 65536
lxc.idmap = g 0 100000 65536
lxc.mount.auto = proc:mixed sys:ro cgroup:mixed
# interfaz lan
lxc.net.0.type = veth
# interfaz wan
lxc.net.1.type = veth
lxc.net.1.link = lxcbr0
# cambiar y
lxc.rootfs.path = dir:/home//.local/share/lxc//rootfs
4. run `chmod` on the rootfs folder with the id you obtained earlier
5. run `lxc-start -n `
6. run `lxc-attach -n `
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2020/09/25 02:25
* by geryescalier
[](https://openwrt.org/es/docs/guide-user/virtualization/lxc#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] es:docs:guide-user:security:openwrt_security
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/es/docs/guide-user/security/openwrt_security#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] Como correr OpenWrt en VirtualBox
This translation is older than the [original page](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm)
and might be outdated. See what has [changed](https://openwrt.org/docs/guide-user/virtualization/virtualbox-vm?do=diff&rev=1627051420)
.
Como correr OpenWrt en VirtualBox
=================================
This article may contain network configuration that depends on migration to DSA in OpenWrt 21.02
* Check if your device uses DSA or swconfig as not all devices have been migrated
* ifname@interface has been moved to device sections
* [DSA Networking](https://openwrt.org/docs/guide-user/network/dsa/start "docs:guide-user:network:dsa:start")
* [Mini tutorial for DSA network config](https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998 "https://forum.openwrt.org/t/mini-tutorial-for-dsa-network-config/96998")
on the forum
* [DSA in the 21.02 release notes](https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change "https://openwrt.org/releases/21.02/notes-21.02.0#new_network_configuration_syntax_and_boardjson_change")
Este documento describe como correr la imagen x86-6 de OpenWRT en MV [VirtualBox](https://www.virtualbox.org/ "https://www.virtualbox.org")
, o abreviado VBox.
Pre requisitos
--------------
* Descarga e instala [VirtualBox](https://www.virtualbox.org/wiki/Downloads "https://www.virtualbox.org/wiki/Downloads")
* Descargar e instalar Adiciones de invitados de VirtualBox <> (Necesaria para connectividad USB entre otras)
### Selecciona una imagen OpenWrt
Necesitas la [version de x86 64 bit de OpenWrt](https://openwrt.org/docs/guide-user/installation/openwrt_x86 "docs:guide-user:installation:openwrt_x86")
. Hay dos versiones de ella:
* `combined-squashfs.img.gz` Esta imagen usa el diseño tradisional de OpenWrt, un sistema de archivos raiz de solo lectura squashfs, y una partición de lectura-escritura donde se almacenan las configuraciones y los paquetes que se instalan. Debido a como está ensamblada la imagen tendrás solo 230 MB de espacio de almacenamiento de paquetes adicionales y configuraciones, y Extroot no funciona.
* `combined-ext4.img.gz` Esta imagen usa una simple partición de lectura-escritura sin sistema de archivos raiz squashfs de solo lectura, el cual puedes incrementar el tamaño de la partición. Las funciones como el modo a prueba de errores restablecimiento de fabrica no estarán disponibles ya que necesitan una partición squashfs de solo lectura para funcionar
En la guía usaremos _openwrt-x86-64-combined-ext4.img.gz_ por que tiene menos limitaciones.
* Descarga una versión estable de la imagen _openwrt-x86-64-combined-ext4.img.gz_ de [targets/x86/64/ folder](https://downloads.openwrt.org/ "https://downloads.openwrt.org/")
Ejemplo: [19.07.2](https://downloads.openwrt.org/releases/19.07.2/targets/x86/64/openwrt-19.07.2-x86-64-combined-ext4.img.gz "https://downloads.openwrt.org/releases/19.07.2/targets/x86/64/openwrt-19.07.2-x86-64-combined-ext4.img.gz")
. O puedes probar con la imagen más reciente pero inestable [snapshot](https://downloads.openwrt.org/snapshots/targets/x86/64/openwrt-x86-64-combined-ext4.img.gz "https://downloads.openwrt.org/snapshots/targets/x86/64/openwrt-x86-64-combined-ext4.img.gz")
* Descomprime el archivo gziped img. En Linux usa el comando `gzip -d openwrt-*x86-64-combined*.img.gz`.Como resultado, deberia obtener el archivo de imagen sin procesar`openwrt-x86-64-combined-ext4.img`
#### Imagenes Personalizadas
Puedes compilar tu propia imagen (_Target System → x86-64_ and _Target Images → Build VirtualBox image files_). Necesita primero ser habilitado `ext4` .
### Convierte openwrt.img a unidad VBox
* Abre una termian y ve al direcotorio en donde has descargado el archivo (disculpa, la herramiento tiene solo interfaz por linea de comandos)
* Convierte al nativo formato VBox escribiendo esto en la linea de comandos (es lo mismo para Windows, Mac y Linux. Tristemente esta herramienta no tiene interfaz de usuario grafica): `VBoxManage convertfromraw --format VDI openwrt-*x86-64-combined*.img openwrt.vdi`. Esto creará el archivo `openwrt.vdi` que es una unidad virtual para la maquina virtual VBoxrtual drive for VBox virtual machine.
#### Error
Si recibes un error similar a:
VBoxManage: error: VD: The given disk size 19444018 is not aligned on a sector boundary (512 bytes)
VBoxManage: error: Error code VERR\_VD\_INVALID\_SIZE at /Users/vbox/tinderbox/5.1-mac-rel/src/VBox/Storage/VD.cpp(7002) in function int VDCreateBase(PVBOXHDD, const char \*, const char \*, uint64\_t, unsigned int, const char \*, PCVDGEOMETRY, PCVDGEOMETRY, PCRTUUID, unsigned int, PVDINTERFACE, PVDINTERFACE)
VBoxManage: error: Cannot create the disk image "openwrt.vdi": VERR\_VD\_INVALID\_SIZE
Es posible que debas rellenar la imagen `dd if=openwrt-x86-64-combined-ext4.img of=openwrt.img bs=128000 conv=sync` y use la imagen rellenada de entrada para VBoxManage convertfromraw.
* Alargar la imagen a un tamaño util (El tamaño esta en MB)
$ VBoxManage modifymedium openwrt.vdi --resize 128
0%...10%...20%...30%...40%...50%...60%...70%...80%...90%...100%
Configuración VM en VirtualBox
------------------------------
### Creación de VM
 Tutorial y capturas de pantalla desde VirtualBox 5.1.8 en un equipo anfitrión GNU/Linux , en Windows o macOS el equipo anfitrión habrán algunas diferencias cosmeticas entre sistemas operativos (una barra superior diferente) pero los paneles y botones de VirtualBox serán exactamente los mismos
[](https://openwrt.org/_media/docs/guide-user/vboxstart.png "docs:guide-user:vboxstart.png")
Inicia VirtualBox y has clic en _Nuevo_ para agregar una Maquina Virtual (MV)
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm1.png "docs:guide-user:vboxaddvm1.png")
Elige un _Nombre_ para tu maquina virtual, elige `Linux` para _Tipo_, y `Linux 2.6 / 3.x / 4.x (64-bit)` para la _Version_, después has clic en _Siguiente_.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm2.png "docs:guide-user:vboxaddvm2.png")
OpenWrt funcionará bien con mucha menos RAM de la cantidad recomendada, 128MiB será suficiente.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxaddvm3.png "docs:guide-user:vboxaddvm3.png")
Elige _Usar un archivo de disco duro existente_ , has clic en el icono _archive_ para abrir _Virtual Media Manager_, has clic en _Agregar_ y luego elige tu archivo `openwrt.vdi` usando la ventana de elección de archvio. Has clic _Crear_ para finalizar este procedimiento.
* * *
 Se recomienda colocar la imagen del disco en un lugar permanente _antes_ de enlazarlo con VBox. Si lo mueves _después_, VBox ya no lo encontrará y se quejará de este problema en el proximo inicio (o cuando intentes reiniciar la MV). Se ofrecerá un procedimiento guiado para vincular la imagen del disco nuevo, así que no te preocupes.
### Configuración de la MV
Esta parte de la configuracion se ocupará de configurar la red manualmente.
La configuración que va a configurar siguendo este tutorial es:
* **eth0** de la MV en la interfaz **mng** (management/administración), la dirección estatica 192.168.56.2, configurada en VirtualBox como **Adaptador solo-anfitrion** en el adaptador **vboxnet0**. Esta interfaz estará_siempre_ disponible para el anfitrion incluso si el anfitrion o la MV está desconectada de cualquier red.
* **eth1** de la MV en la interfaz **wan** , dirección dinámica, configurarla en VirtualBox como **NAT**. Esta interfaz será usada para acceder a Internet a través de cualquier configuración que utilice el anfitrion.
* _(opcional) **eth2** de la VM en la interfaz **lan**, configurada en función de su red local, establecer en VirtualBox como **Adaptador Puente**. Esta interfaz permite que otros dispositivos (incluido el anfitrion) se conecte a la MV como si fuera un equipo físico en la red local. Sólo funcionará si ya existe una red local de algún tipo._
* _Para una configuración con 2 tarjetas de red físicas con configuración puente WAN/LAN consulte [troubleshooting](https://openwrt.org/es/docs/guide-user/virtualization/virtualbox-vm#troubleshooting "es:docs:guide-user:virtualization:virtualbox-vm ↵")
. El resto de esta guía se aplica a una configuración con dos tarjetas físicas._
Tenga en cuenta que el _orden_ del Adaptador solo-anfitrión como “Adaptador 1” y “NAT” como “Adaptador 2” es importante para una operación como llave de seguridad de OpenWrt en la MV. Si bien se puede configurar mediante la consola, la configuración de esta manera simplifica el acceso a una configuración en ejecución.
#### Ajustes de Virtualbox
##### Adaptador de Red solo-anfitrión
Primero debemos asegurarnos de que haya un adaptador de red solo-anfitrión y que tenga la configuración correcta.
Nota: esto se encuentra en VBox 6.0 (al menos para Windows) en Herramentas y está pre-configurada.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network1.png "docs:guide-user:vboxvmhost-only-network1.png")
Has en la pestaña clic en **Archivo** → **Preferencias** → **Red**
En macOS, ésta configuración se puede encontrar en Archivo > Administrador de Red anfitrión...
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network2.png "docs:guide-user:vboxvmhost-only-network2.png")
Has clic en la pestaña de Red solo-anfitrion y luego si no se vé **vboxnet0** hags clic en el icono **+** a la derecha de la ventana para agregar una nueva.
Ahora seleccione la entrada **vboxnet0**, y haga clic en el icono del destornillador a la derecha para abrir su configuración.
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network3.png "docs:guide-user:vboxvmhost-only-network3.png")
La **Dirección IPv4** debe de ser **192.168.56.1**, la **Mascara de Red IPv4** debe de ser **255.255.255.0**,la **Dirección IPv6** debe de estar vacía y la **Mascara de Red IPv6** debe de ser **0**
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmhost-only-network4.png "docs:guide-user:vboxvmhost-only-network4.png")
_(opcional)También puedes configurar el servidor DHCP como se muestra en la captura de pantalla si deseas tener direcciones dinámicas para la MV, pero para este tutorial no es necesario, ya que configuramos la IP estática en la propia MV._
* * *
Presiona OK para guardar y cerrar hasta que vuelva la Interfaz del Gestor de VirtualBox.
##### Configuraciones de Red
[](https://openwrt.org/_media/docs/guide-user/vboxvmsettings1.png "docs:guide-user:vboxvmsettings1.png")
Abre las configuraciones de la MV
* * *
[](https://openwrt.org/_media/docs/guide-user/vboxvmsettings2.png "docs:guide-user:vboxvmsettings2.png")
Selecciona la pestana **Red** ---- [](https://openwrt.org/_media/docs/guide-user/vboxvmsettings3.png "docs:guide-user:vboxvmsettings3.png")
Configura el **Adaptador 1**:
1. con **Adaptador solo-anfitrion**
2. Selecciona vboxnet0 (adaptador ) como **Nombre**
3. Has clic en **Avanzado** y en **Tipo de Adaptador** selecciona **Intel PRO/1000 MT Desktop**
4. **Modo promiscuo** debe estar establecido en **Denegar** a menos que tenga razones para habilitarlo.
* Configurar el **Adaptador 2**
1. con **NAT**
* _(opcional) Configurar el **Adaptador 3**_
1. _con **Adaptador puente**_
2. _en el campo Nombre selecciona el nombre de la tarjeta de red (ethernet or wifi) de la PC que se conectó a la red local. En Windows tiene un nombre de dispositivo completo, en Linux tendrá nombres en codigo como **eth0**, **eth1** para ethernet o **wlp2s0** para wifi._
3. _Has Clic en **Avanzado** y has lo mismo que se realizó en las opciones avanzadas del **Adaptador 1**_
#### Configuraciones de la Maquina Virtual
 Debido a las limitaciones, el teclado en el terminal de la maquina virtual está configurado en EE.UU, Por lo que algunas (o la mayoria) de sus teclas pueden no escribir los simbolos marcados en las teclas.
Además, debido al hecho de que lo que ve es un terminal de maquina limpia y no algo como un programa SSH (Putty/Kitty/cualquier otro) o un programa emulador de terminal, no puedes copiar-pegar en él.
No te preocupes, la mayor parte de la configuración se realizará después de que te conectes por SSH(terminal remota) que no tiene ninguno de estos problemas.
[](https://openwrt.org/_media/docs/guide-user/1280px-qwerty.png "docs:guide-user:1280px-qwerty.png")
Mira esta distribución de teclado de EE.UU. Para encontrar que botón debes presionar en tu teclado para generar el simbolo correcto.
* * *
1. Arranca tu Maquina Virtual
2. Espera 4 segundos para que el GRUB arranque automaticamente
3. Presiona Enter para activar la consola cuando los mensajes de inicio hayan terminado de desplazarse. La entropia puede tardar 2 o 3 minutos en generarse (`random: crng init done` with OpenWrt 17.01.4). Hasta que haya suficiente entropía, SSH y otras funciones criptográficas pueden fallar.
4. Mostrar la configuración de red actual
root@openwrt:~# uci show network
network.loopback=interface
network.loopback.ifname='lo'
network.loopback.proto='static'
network.loopback.ipaddr='127.0.0.1'
network.loopback.netmask='255.0.0.0'
network.globals=globals
network.globals.ula\_prefix='fd1b:e541:8f1a::/48'
network.lan=interface
network.lan.type='bridge'
network.lan.ifname='eth0'
network.lan.proto='static'
network.lan.netmask='255.255.255.0'
network.lan.ip6assign='60'
network.lan.ipaddr='192.168.1.1'
network.wan=interface
network.wan.ifname='eth1'
network.wan.proto='dhcp'
network.wan6=interface
network.wan6.ifname='eth1'
network.wan6.proto='dhcpv6'
Tenga en cuenta que la dirección LAN predeterminada en el primer arranque es 192.168.1.1.
1. Edita la configuración de red para permitir el acceso SSH escribiendo estos comandos y presionando Enter:
1. **uci set network.lan.ipaddr='192.168.56.2'**
2. **uci commit**
3. **reboot**
2. Ahora tu MV deberia de ser accesible desde SSH, usuario **root** (sin contraseña) dirección **192.168.56.2**
3. Después de que hayas conectado correctamente, podremos hacer la verdadera configuración, por favor copia y pega el siguiente bloque de codigo y presiona Enter:
uci batch < to firmware ...
Appending jffs2 data from /tmp/sysupgrade.tgz to firmware...TRX header not found
Error fixing up TRX header
Writing from to firmware ...
Upgrade completed
Rebooting system...
* Anschließend sollte das Gerät automatisch neu starten, und die Dateien/Verzeichnisse aus `[/etc/sysupgrade.conf](https://openwrt.org/docs/guide-user/base-system/notuci.config#etcsysupgradeconf "docs:guide-user:base-system:notuci.config") ` auf die JFFS2-Partition schreiben. Warten bis das abgeschlossen ist und jetzt bitte nochmal manuell neu starten.
* OpenWrt sollte jetzt mit den ganzen alten Einstellungen hochgefahren sein, bitte auf Fehler prüfen:
dmesg
uname \-a
iptables \-V
...
* Packages reinstallieren:
opkg update
opkg install tc iptables-mod-ipopt wol
| | |
| --- | --- |
|  | Ein Kalt-Reset scheint notwendig zu sein, das ist im Falle eines sysupgrades aus der Ferne sehr sehr schlecht! |
Via Web-Oberfläche
------------------
1. passendes OpenWrt Firmware Image-Datei herunterladen (auf die eigene Festplatte)
2. auf der Web-Oberfläche auswählen: _System_ ⇒ _System_ ⇒ _Custom Files_ [](https://openwrt.org/_detail/doc/howto/luci.sysupgrade.conf.png?id=de%3Adocs%3Aguide-user%3Ainstallation%3Ageneric.sysupgrade "doc:howto:luci.sysupgrade.conf.png")
3. dann _System_ ⇒ _Flash Firmware_ [](https://openwrt.org/_detail/doc/howto/luci.sysupgrade.png?id=de%3Adocs%3Aguide-user%3Ainstallation%3Ageneric.sysupgrade "doc:howto:luci.sysupgrade.png")
4. die OpenWrt Firmware Image-Datei wird nun in das `/tmp`\-Verzeichnis kopiert
5. LuCI wird die MD5 Checksumme überprüfen und den Update-Vorgang ansstoßen
6. warten bis alles wieder online kommt
Alternativen zu OpenWrt Sysupgrade
----------------------------------
Einige sind hier zu finden: [upgrading.openwrt](https://openwrt.org/toh/tp-link/tl-wr1043nd#upgradingopenwrt "toh:tp-link:tl-wr1043nd")
.
### mtd
1. In dem Fall, dass `sysupgrade` ihr Gerät (noch) nicht unterstützt, können Sie `[mtd](https://openwrt.org/docs/techref/mtd "docs:techref:mtd") ` benutzen, z.B.:
mtd -r write /tmp/openwrt-ar71xx-generic-wzr-hp-ag300h-squashfs-sysupgrade.bin firmware
### netcat
Netcat könnte eingesetzt werden, wenn nicht genug Arbeitsspeicher frei gemacht werden kann. Siehe [netcat](http://man.cx/netcat "http://man.cx/netcat")
. Netcat needs to be installed first.
| | |
| --- | --- |
|  | Diese Methode wird **NICHT** empfohlen! |
1. On the router run:
nc -l -p 1234 | mtd write - firmware
2. On your Linux PC run:
nc -q0 192.168.1.1 1234 < openwrt-ar71xx-tl-wr1043nd-v1-squashfs-sysupgrade.bin
* * *
Sie können auch, auch wenn dies nicht empfohlen wird, nectat mit pipes benutzen anstatt das Image auf die RAMFS-Partition zu kopieren:
* Auf Ihrem PC wiesen Sie netcat an, auf Port 5050 zu hören und das Image zu senden, sobald Verbindung besteht:
nc -l -p 5050 -q 1 < openwrt-XXXX-XXXX.trx
* Separat dazu auf dem Gerät ausführen:
nc 192.168.1.6 5050 | mtd -e linux -r write - linux
 Diese Vorgehensweise wird nicht empfohlen, könnte aber im Falle von wenig freiem Arbeitsspeicher auf dem Gerät notwendig werden.
* * *
Arbeitsspeicher freiräumen
--------------------------
First check memory usage with the `free` or `top` or `cat /proc/meminfo` commands; proceed if you have as much free RAM as the image is in size plus an some additional MiB of free memory.
`root@openwrt:/$ free total used free shared buffers Mem: 29540 18124 **11416** 0 1248 -/+ buffers: 16876 12664 Swap: 0 0 0`
In this example there are precisely 11.416 KiB of RAM unused. All the rest 32.768 - 11.416 = 21.352KiB are used somehow and a portion of it can and will be made available by the kernel, if it be needed, the problem is, we do not know how much exactly that is. Make sure _enough_ is available.
* der schnellste Weg etwas Arbeitsspeicher freizuräumen besteht darin, die `[opkg](https://openwrt.org/docs/guide-user/additional-software/opkg "docs:guide-user:additional-software:opkg") `\-Package-Dateien zu löschen:
rm -r /tmp/opkg-lists/
* caches löschen:
echo 3 > /proc/sys/vm/drop\_caches
* verhindern, dass die IEEE802.11-Treiber beim nächsten Reboot geladen werden und dann das Gerät neu starten, z.B.:
rm /etc/modules.d$/\*80211\*
rm /etc/modules.d$/\*ath9k\*
reboot
Notes
-----
* [Sysupgrade – Technical Reference](https://openwrt.org/docs/techref/sysupgrade "docs:techref:sysupgrade")
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
* Last modified: 2018/06/07 19:10
* by tmomas
[](https://openwrt.org/de/docs/guide-user/installation/generic.sysupgrade#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:managing_services
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/managing_services#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:dns_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/dns_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:ipv6_ipv4_transitioning
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/ipv6_ipv4_transitioning#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:log.essentials
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/log.essentials#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:mptcp
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/mptcp#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:singleportrouter
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/singleportrouter#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:led_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/led_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:luci.secure
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/luci.secure#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:cron
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/cron#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:basic-networking
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/basic-networking#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:users
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/users#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:dashboard
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/dashboard#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:system_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/system_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:base-system:dhcp.dnsmasq
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/base-system/dhcp.dnsmasq#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:integrating-openwrt-introduction
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/integrating-openwrt-introduction#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:openwrt_as_routerdevice
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/openwrt_as_routerdevice#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:luci.themes
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/luci.themes#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:statistics.chart.public
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/statistics.chart.public#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:luci_app_statistics
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/luci_app_statistics#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:luci.essentials
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/luci.essentials#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:protocol.static
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/protocol.static#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:luci.on.lighttpd
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/luci.on.lighttpd#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:static_ip
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/static_ip#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:high-availability
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/high-availability#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:protocol.dhcp
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/protocol.dhcp#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:routedclient
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/routedclient#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:switch_router_gateway_and_nat
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/switch_router_gateway_and_nat#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:start
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/start#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:network_interface_alias
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/network_interface_alias#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:map
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/map#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:network_configuration
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/network_configuration#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:luci:webinterface.overview
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/luci/webinterface.overview#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:bonding
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/bonding#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:architecture
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/architecture#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] de:docs:guide-user:network:openwrt_as_clientdevice
This topic does not exist yet
=============================
You've followed a link to a topic that doesn't exist yet. If permissions allow, you may create it by clicking on **Create this page**.
This website uses cookies. By using the website, you agree with storing cookies on your computer. Also you acknowledge that you have read and understand our Privacy Policy. If you do not agree leave the website.OK[More information about cookies](https://en.wikipedia.org/wiki/HTTP_cookie)
[](https://openwrt.org/de/docs/guide-user/network/openwrt_as_clientdevice#dokuwiki__top "skip to content")

---
# [OpenWrt Wiki] LEDE 설정 방법
LEDE 설정 방법
----------
**LEDE** 는 UCI(Unified Configuration Interface) 를 사용하여 모든 설정을 저장하고 조작합니다.
LEDE 시스템을 설정할 때 UCI의 커맨드 라인을 사용하는 것을 추천합니다.
이 방법을 사용할 때 설정 파일의 문법이나 어디에 있어야 하는지 걱정하지 않아도 됩니다.
CLI를 사용하여 값을 수정할 때, 모든 변경 사항은 바로 저장되지 않습니다. 그렇기 때문에 설정후에는 변경 사항을 저장해야 합니다.
### UCI 설정 내부구조
설정은 서브시스템으로 나누어 집니다. 또한 각각의 서브시스템은 세션들로 나누어집니다. 세션은 리스트의 키 = ‘값’ 으로 이루어져 있습니다.
사용 가능한 서브시스템으로 **dnsmasq**, **dropbear**, **firewall**, **fstab**, **net**, **qos**, **samba**, **system**, **wireless** 들이 있습니다.
모든 UCI설정은 다음과 같은 구조로 저장됩니다.
**..