📡
← All setup guides

Asus Merlin WireGuard Setup Guide

Manual gateway Works as a gateway for one LAN with no extra steps. Extra VLANs need a few rules added on the device by hand, explained below.

Asus Merlin firmware adds WireGuard client support on WiFi 6/6E/7 (HND platform) routers since firmware 386.4. Older models need Entware. The Merlin UI does not fully support PostUp — use hook scripts instead.

1

Check your router is supported

Native WireGuard is available on: RT-AX86U, RT-AX88U, RT-AX58U, GT-AX6000, RT-AX68U, and other WiFi 6+ models. Check asuswrt-merlin.net for your model.

Older ARM models (RT-AC86U etc.) need Entware: install wireguard-tools via opkg.

2

Create a tunnel in ProxyLink

Go to Devices → + Add → Router / LAN site, select Router / Gateway, enter your LAN subnet (e.g. 192.168.1.0/24), download your .conf file. On the gateway page, switch the download picker to 🌐 Router (MikroTik / pfSense / OpenWRT) before clicking Activate, otherwise you get a RouterOS .rsc script instead of a .conf file.

3

Import the config in Merlin UI

In the Asus router UI go to VPN → VPN Client → WireGuard tab.

Click Add profile and import your .conf file. The profile will be named wg21, wg22, etc.

4

Add NAT masquerade rule (router mode)

The Merlin UI ignores PostUp. Add a persistent rule via JFFS scripts. Enable JFFS scripts in Administration → System first, then SSH in:

cat >> /jffs/scripts/nat-start << 'EOF'
iptables -t nat -A POSTROUTING -s 10.100.0.0/16 -o br0 -j MASQUERADE
EOF
chmod +x /jffs/scripts/nat-start
5

Enable the VPN client

Back in the VPN Client tab, set the profile to ON. The tunnel connects and your LAN devices become reachable via ProxyLink.

Good to know

Asus Merlin uses br0 (not br-lan) as the LAN bridge. Use br0 in all iptables rules.
JFFS scripts in /jffs/scripts/nat-start run on every NAT table initialization — they survive reboots and firmware updates (as long as JFFS is enabled).

Reaching more than one VLAN

One LAN needs nothing beyond this guide. If the site has several VLANs (a camera VLAN, a PBX VLAN, a guest network), there is one more thing to know.

ProxyLink gives every gateway its own private address range and translates between that range and your real LAN addresses. That is what lets two different clients both use 192.168.1.0/24 without colliding. The translation rules live in the PostUp and PostDown lines of the config we generate.

Asus Merlin cannot run those rules for itself, so extra VLANs are routed directly instead of being translated. Two consequences worth knowing:

If a site has several VLANs and you would rather not maintain that by hand, put a small Linux box (a Raspberry Pi is plenty) or a MikroTik beside the router and use it as the gateway. Both are managed, so every VLAN is handled automatically and the existing router is left alone. See the Linux and MikroTik guides.

What you get once the tunnel is up

Ready to connect?

Create a free account and set up your first tunnel in minutes. Free during early access — no card required.

Setup guides for other platforms