Connect a Nano Pi or OpenWrt router

Use a FriendlyElec Nano Pi (R2S, R4S, R5S, R6S) or any OpenWrt router as your gateway. One command sets it up; here's what it changes and how to undo it.

A Nano Pi or an OpenWrt router can be the gateway for a location instead of a MikroTik. Customers see the same Wi-Fi page, pay the same way, and get the same plans, speeds and data limits.

Before you start

  • OpenWrt 21.02 or newer. Nano Pi boards ship with FriendlyWrt, which is OpenWrt: that's fine.
  • The router is connected to the internet on its WAN port (on a Nano Pi R2S or R4S, that's eth0).
  • You can reach it over SSH as root (ssh [email protected], or an app like Termius on your phone).
  • Your access points are plugged into the port(s) you'll use for guests (on a Nano Pi R2S or R4S, eth1), set to access point or bridge mode.

Important: the ports you choose for guests stop being part of the router's own network. Set the router up from its WAN side or over Wi-Fi, not from a computer plugged into one of those ports.

1. Register the router

  1. Go to Locations, open the location, and under Gateways register a new one.
  2. Pick your model under Nano Pi and OpenWrt (or Other OpenWrt router).

2. Get the install command

In the router's card, under Install on the router:

  1. Tick the guest ports (usually eth1 on a Nano Pi).
  2. If the router has its own Wi-Fi, you can also tick broadcast guest Wi-Fi from this router. It uses your location's Wi-Fi name.
  3. Choose Me, now (works for 1 hour) or Someone at the location (works for 24 hours), then Get install command.

You get one line like this:

wget -qO /tmp/wispot.sh "https://api.wispot.net/i/…" && sh /tmp/wispot.sh

Paste it into the router's SSH session and press Enter. To have someone else do it, use Copy message and send it on WhatsApp: it includes simple steps.

The command works once. If it's used or expires, make a new one. Nobody else can use it.

3. Watch it connect

The panel shows each step as it happens: command ready → router downloaded its setup → connected to Wispot → online. Installing packages takes 1–3 minutes.

Then buy your cheapest plan from a phone on the guest network. It's the only test that proves the whole chain works. See Make a test purchase.

What the command changes

Everything it adds is named wispot, so it's easy to find:

  • Backup first: a full configuration backup in /root/wispot-backup/.
  • Packages: WireGuard, CoovaChilli (the captive portal), curl and certificates.
  • A secure tunnel from the router to Wispot. The router connects out; nothing is opened to the internet.
  • The guest network: a bridge called br-wispot on your guest ports, handed out by CoovaChilli.
  • Firewall zones: guests can only reach the internet; Wispot can only send disconnect requests through the tunnel.
  • A small agent that checks in every minute, so you can reboot, back up and see the router's health from your dashboard.
  • It deletes itself when it's done, because it contains the router's keys.

Every call to Wispot is over HTTPS with the certificate checked.

Undo it

Restore the backup: System → Backup / Flash Firmware → Restore backup in the router's web page, or over SSH:

sysupgrade -r /root/wispot-backup/pre-wispot-<your-router-name>.tar.gz

Then remove the router from your location in Wispot.

If something goes wrong

What you see What to do
wget: not found or an SSL error Run opkg update && opkg install ca-bundle libustream-mbedtls (or apk add ca-bundle on the newest OpenWrt), then the command again.
Needs OpenWrt 21.02 or newer Upgrade the firmware first. Nothing was changed.
Port … doesn't exist Pick the right guest ports (the router's ip link lists them) and make a new command.
Package install fails The router can't reach the OpenWrt package servers: check its internet and DNS, then try again.
404 Not Found The command was already used or has expired. Make a new one.
Phones don't see the Wi-Fi page Check the access points are on the guest port and in bridge mode. See Troubleshooting.

Last updated 1 Oct 2026