Connect a Nano Pi or OpenWrt router
Use a FriendlyElec Nano Pi (R2S, R4S, R5S, R6S) or any OpenWrt router as your gateway. One command sets it up; here's what it changes and how to undo it.
A Nano Pi or an OpenWrt router can be the gateway for a location instead of a MikroTik. Customers see the same Wi-Fi page, pay the same way, and get the same plans, speeds and data limits.
Before you start
- OpenWrt 21.02 or newer. Nano Pi boards ship with FriendlyWrt, which is OpenWrt: that's fine.
- The router is connected to the internet on its WAN port (on a Nano Pi R2S or R4S, that's eth0).
- You can reach it over SSH as root (
ssh [email protected], or an app like Termius on your phone). - Your access points are plugged into the port(s) you'll use for guests (on a Nano Pi R2S or R4S, eth1), set to access point or bridge mode.
Important: the ports you choose for guests stop being part of the router's own network. Set the router up from its WAN side or over Wi-Fi, not from a computer plugged into one of those ports.
1. Register the router
- Go to Locations, open the location, and under Gateways register a new one.
- Pick your model under Nano Pi and OpenWrt (or Other OpenWrt router).
2. Get the install command
In the router's card, under Install on the router:
- Tick the guest ports (usually eth1 on a Nano Pi).
- If the router has its own Wi-Fi, you can also tick broadcast guest Wi-Fi from this router. It uses your location's Wi-Fi name.
- Choose Me, now (works for 1 hour) or Someone at the location (works for 24 hours), then Get install command.
You get one line like this:
wget -qO /tmp/wispot.sh "https://api.wispot.net/i/…" && sh /tmp/wispot.sh
Paste it into the router's SSH session and press Enter. To have someone else do it, use Copy message and send it on WhatsApp: it includes simple steps.
The command works once. If it's used or expires, make a new one. Nobody else can use it.
3. Watch it connect
The panel shows each step as it happens: command ready → router downloaded its setup → connected to Wispot → online. Installing packages takes 1–3 minutes.
Then buy your cheapest plan from a phone on the guest network. It's the only test that proves the whole chain works. See Make a test purchase.
What the command changes
Everything it adds is named wispot, so it's easy to find:
- Backup first: a full configuration backup in
/root/wispot-backup/. - Packages: WireGuard, CoovaChilli (the captive portal), curl and certificates.
- A secure tunnel from the router to Wispot. The router connects out; nothing is opened to the internet.
- The guest network: a bridge called
br-wispoton your guest ports, handed out by CoovaChilli. - Firewall zones: guests can only reach the internet; Wispot can only send disconnect requests through the tunnel.
- A small agent that checks in every minute, so you can reboot, back up and see the router's health from your dashboard.
- It deletes itself when it's done, because it contains the router's keys.
Every call to Wispot is over HTTPS with the certificate checked.
Undo it
Restore the backup: System → Backup / Flash Firmware → Restore backup in the router's web page, or over SSH:
sysupgrade -r /root/wispot-backup/pre-wispot-<your-router-name>.tar.gz
Then remove the router from your location in Wispot.
If something goes wrong
| What you see | What to do |
|---|---|
wget: not found or an SSL error |
Run opkg update && opkg install ca-bundle libustream-mbedtls (or apk add ca-bundle on the newest OpenWrt), then the command again. |
| Needs OpenWrt 21.02 or newer | Upgrade the firmware first. Nothing was changed. |
| Port … doesn't exist | Pick the right guest ports (the router's ip link lists them) and make a new command. |
| Package install fails | The router can't reach the OpenWrt package servers: check its internet and DNS, then try again. |
| 404 Not Found | The command was already used or has expired. Make a new one. |
| Phones don't see the Wi-Fi page | Check the access points are on the guest port and in bridge mode. See Troubleshooting. |
Last updated 1 Oct 2026