Centralized Proxy Router Gateway for OpenWrt

Standalone .ipk package turning your OpenWrt router into a high-performance proxy gateway. Dispatches per-device routes with zero DNS and WebRTC leaks.

  • Per-Device Route Assignment

    Assign independent proxy tunnels to individual client IP or MAC addresses directly at the gateway. Connected computers, phones, and VMs route traffic automatically with zero client software.

  • Hardware-Level DNS & WebRTC Leak Shield

    Intercepts and routes all DNS queries and WebRTC STUN requests through upstream proxy tunnels at Layer 3/4. Stops IP leaks before packets leave your local router.

  • Virtual Gateway Identifier (VGI)

    Isolate internal gateway parameters for each connected device. Prevents cross-session network correlation and topology discovery across local subnets.

  • Centralized Proxy Dispatcher

    Manage HTTP, HTTPS, SOCKS5, and Shadowsocks tunnels from a unified web interface. Monitor throughput and active status across all client routes in real time.

  • Zero-Trust Client LAN Isolation

    Blocks lateral communication and port scanning between connected client devices. Keeps every workstation, test device, or VM completely isolated.

Get License & Download .ipk
Verified for:OpenWrt 21 • 22 • 23 • 24Layer 3/4 GatewayDigital License (Proprietary)
wifisocks-gw@openwrt:~#
Active Routing
OpenWrt Gateway Controller
Package: wifisocks-core.ipk
RAM <60MB
DNS Leak Shield: 100%WebRTC STUN: Masked
Workstation PC
192.168.1.101
🇺🇸 US • SOCKS5
198.51.100.24
Mobile Device
192.168.1.102
🇯🇵 JP • HTTPS
203.0.113.88
Virtual Machine / Test Bed
192.168.1.103
🇩🇪 DE • Shadowsocks
192.0.2.15
# Real-time policy dispatcher status
> [OK] VGI MAC Isolation: 3 Endpoints Active
> [OK] DNS Gateway Interceptor: Bound to Upstream
> [OK] Client Zero-Setup: No Apps on Devices
Supported Architectures:
x86_64arm64mipsel

Install in 3 Simple Steps on OpenWrt

Self-install the standalone .ipk package on your existing OpenWrt router via terminal SSH or LuCI Web Interface in under 2 minutes.

1
Check Architecture & RAM

Verify that your router runs OpenWrt (21.02+) and satisfies the minimum hardware requirements:

Architecture: x86_64, arm64, or mipsel (MT7621AT)
Memory: Minimum 256MB RAM
Storage: ~20MB free space

Run uname -m in terminal or check Status > Overview in LuCI.

2
Install the .ipk Package

Transfer the package file to your router and execute the standard OpenWrt package manager command:

# Via SSH Terminal
$ opkg update
$ opkg install /tmp/wifisocks_*.ipk

Alternatively, upload via System > Software > Upload Package in LuCI.

3
Machine ID & Route Setup

Upon installation, WifiSocks automatically generates a unique hardware-based Machine ID on your router. Open the Web Dashboard to assign routes:

Admin URL: http://[ROUTER_IP] (Port 80, based on router LAN IP)
Hardware Machine ID auto-generated on screen
Assign SOCKS5/HTTP routes per client IP or MAC

All connected client devices route through their designated proxies immediately with zero client-side configuration.

Why a Hardware Proxy Router Outperforms Client Apps

Eliminate endpoint friction. Running a centralized router proxy at the OpenWrt OS layer protects all connected devices with zero client configuration.

Traditional Client-Side Apps

High Friction & Frequent IP Leaks
  • Requires manual proxy configuration and separate app installation on every phone, computer, and VM.
  • WebRTC STUN requests often bypass client proxy apps, leaking your real public ISP IP address to target platforms.
  • DNS queries fall back to local network ISP resolvers, exposing your true geographical location and ISP logs.
  • High background CPU usage, rapid battery drain on mobile fleets, and frequent app crashes under heavy load.
  • Identical router MAC addresses and local gateway topology link all client devices to the same local network.
RECOMMENDED

WifiSocks OpenWrt .ipk Gateway

Kernel-Level Isolation & Zero Client Setup
  • Zero client setup: devices connect via standard Wi-Fi or Ethernet with automatic, transparent proxy routing.
  • Hardware-Level WebRTC Shield intercepts STUN/TURN packets inside the Linux kernel, preventing IP leaks at the router.
  • Remote proxy DNS resolvers process all domain queries, completely blocking ISP DNS inspection and tracking.
  • Zero client CPU overhead: packet routing runs entirely on the router hardware with lightweight RAM footprint (< 60MB).
  • Virtual Gateway Identifier (VGI) isolates router parameters per device, preventing cross-session network correlation.

Real-World Practical Applications

WifiSocks delivers neutral, high-performance proxy router software for OpenWrt hardware. Operating on a strict Bring Your Own Device (BYOD) and Bring Your Own Network (BYON) model, our userspace router proxy daemon enables enterprise engineering teams and modern connected homes to manage centralized proxy pipelines with zero client overhead.

QA & Software Automation Labs
Multi-Region Mobile & Web App Testing
QA Engineering

Software development teams building international mobile apps, fintech platforms, and SaaS products need to test localization, localized pricing, and CDN failovers across physical device fleets and emulator test beds.

  • Per-Device Route Assignment: Each test device connects via standard Wi-Fi and automatically receives its designated regional route without installing proxy client apps.
  • Zero Sandbox Contamination: Keeps test devices in stock OS condition with no root or jailbreak, background proxy daemons, or SSL inspection certificates needed on endpoints.
Per-Device Dispatching0 Client AppsMulti-SSID
Cross-Border E-Commerce Studios
Multi-Regional Store Operations & Compliance
Global Commerce

Export businesses and e-commerce agencies operating official stores across global marketplaces and international storefronts require pristine network isolation to prevent false cross-session IP correlations.

  • Virtual Gateway Identifier (VGI): Virtualizes gateway MAC identifiers per workstation, eliminating cross-session local subnet fingerprinting between operations teams.
  • Hardware Leak Shield: Intercepts and blocks WebRTC STUN requests and DNS queries at Layer 3/4, preventing domestic IP exposure during active store management.
VGI MAC IsolationHardware Leak ShieldHigh Concurrency
Market Research & Ad Verification
Competitive Intelligence & SERP Auditing
Digital Marketing

Digital marketing agencies and SEO/SEM analysts must audit localized search engine results, verify international advertising display fidelity, detect ad fraud, and gather regional competitive price data in real time.

  • Centralized Proxy Dispatcher: Switch and re-route target regions across analyst workstations from a unified web interface in seconds.
  • Rule-Based Traffic Routing: Route only target research domains through upstream proxy tunnels while keeping internal office tools direct on WAN to preserve bandwidth.
Proxy DispatcherRule-Based RoutingMulti-Protocol
Zero-Trust Network & Infrastructure Isolation
Enterprise Device Segmentation & Security Labs
Network Security

Enterprise environments, smart offices, and security research labs require strict network segmentation for guest workstations and sandbox machines without investing in expensive enterprise L3 managed switches.

  • Zero-Trust Client LAN Isolation: Blocks all lateral Layer 2/3 peer-to-peer communications, preventing unauthorized subnet discovery, ARP poisoning, and port scans.
  • Isolated WAN Egress: Guarantees that untrusted guest hardware or sandbox test systems communicate only through strictly designated egress channels.
Client LAN IsolationZero-Trust ArchitectureSubnet Security

Supported Architectures & Sizing Guide

WifiSocks .ipk is compiled and optimized for AMD64, ARM64, and MIPS router chipsets. Choose the architecture matching your router hardware.

AMD64 / x86_64
Mini PC & Soft Routers
Supported
Min RAM
1GB – 8GB
Capacity
100 – 300+
Compatible Hardware:
  • Intel N100, N150, J4125, N5105 Mini PCs
  • Multi-NIC Soft Routers (Intel 2.5GbE i225/i226)
  • Virtual Machines: Proxmox, VMware ESXi, KVM
Package:.ipk (x86_64_generic)
Best for: Automation studios & multi-gigabit labs.
ARM64 (aarch64)
Wi-Fi 6 Router Hardware
Supported
Min RAM
512MB – 2GB
Capacity
50 – 200
Compatible Hardware:
  • MediaTek Filogic 820/830 (MT7981, MT7986)
  • Rockchip RK3568, Allwinner, ARM Cortex-A53
  • Single-Board Computers: Raspberry Pi 4 / Pi 5
Package:.ipk (aarch64_generic)
Best for: High-speed Wi-Fi 6 fleets & test devices.
MIPS Softfloat
MT7621AT Optimized
Supported
Min RAM
256 MB
Capacity
10 – 50
Compatible Hardware:
  • MediaTek MT7621AT / MT7621 Dual-Core SoC
  • Xiaomi CR660x, Redmi AC2100 / RM2100
  • Newifi D2, YouHua WR1200JS, D-Link DIR-882
Package:.ipk (mipsel_24kc)
Best for: Compact test beds & budget-friendly setups.
MIPS Softfloat Optimization: Compiled with softfloat flags specifically for MT7621AT (MIPS 1004Kc). Eliminates floating-point emulation bottlenecks, maintaining high throughput on 256MB routers.
Multi-Gigabit x86 Scalability: AMD64 / x86_64 builds take full advantage of multi-queue NICs (2.5GbE / 10GbE) and multi-core CPU threading for high-density automation studios.
Low Memory Footprint: The userspace routing daemon uses less than 60MB of RAM under active load, leaving ample memory for OpenWrt wireless drivers and connection tracking tables.

Core Capabilities of the WifiSocks Proxy Router

Virtual Gateway Isolation

Virtualizes gateway MAC identifiers and local network parameters per client. Prevents cross-session network topology profiling across subnets.

Multi-SSID & BSSID Support

Broadcast up to 32 independent Wi-Fi SSIDs on compatible dual-band hardware. Group devices by team or project with isolated proxy assignments.

High-Density Device Routing

Route 10 to 300+ devices concurrently based on your router SoC and RAM. Dedicated kernel packet queues maintain stable throughput per client.

Centralized Proxy Dispatcher

Configure, assign, and switch HTTP, HTTPS, SOCKS5, and Shadowsocks tunnels across hundreds of endpoints from one web console.

Hardware-Level DNS Protection

Resolves all DNS requests through designated upstream proxy DNS resolvers at the OS gateway level. Blocks ISP inspection completely.

Gateway WebRTC Leak Shield

Intercepts STUN/TURN traffic and forces all WebRTC communications through the assigned proxy path. Protects your true gateway IP address.

Rule-Based Traffic Routing

Optimize proxy bandwidth. Route selected domains and ports through proxy tunnels while sending default local traffic direct to WAN.

Zero-Trust Client LAN Isolation

Isolates connected clients at Layer 2/3. Prevents connected workstations or mobile devices from discovering and probing each other.

Lightweight 256MB RAM Footprint

Highly optimized C/Go userspace daemon engineered for efficient memory and CPU usage on 256MB RAM embedded routers like MT7621AT.

Broad Client Compatibility (BYOD)

Connect any Ethernet or Wi-Fi device directly through your OpenWrt router gateway. All proxy dispatching, hardware leak protection, and LAN isolation execute transparently with zero endpoint software.

Workstations & Laptops
Desktop OS Environments
0 Apps
Supported Platforms:
  • Windows 10 & 11 (x86_64 / ARM64)
  • macOS (Apple Silicon & Intel)
  • Linux (Ubuntu, Debian, Fedora, Arch)
  • Assign dedicated proxy paths per IP or MAC address via Ethernet or Wi-Fi.
  • Zero background software crashes, CPU throttling, or root requirements on endpoints.
Ethernet / Wi-FiLayer 3/4 Routing0 Admin Rights
Mobile Fleets & Handhelds
Smartphones & Tablets
No Jailbreak
Supported Platforms:
  • iOS & iPadOS (All Versions)
  • Android (Stock, LineageOS, Custom ROMs)
  • Portable Consoles & Handheld Terminals
  • Maintains 100% stock OS condition for authentic mobile testing without sandbox pollution.
  • Zero mobile battery drain from background VPN clients or persistent daemon connections.
Stock Mobile OSZero Battery DrainMulti-SSID Auto-Bind
VMs, Smart Displays & IoT
Virtual & Connected Hardware
Hardware Gateway
Supported Platforms:
  • Proxmox VE, VMware ESXi, VirtualBox
  • Android Studio & Cloud Emulators
  • Smart TVs, Media Players & IoT Devices
  • Dispatches multi-instance VM fleets with unique Virtual Gateway Identifiers (VGI).
  • Direct streaming for closed Smart TV operating systems and Layer 2/3 IoT isolation.
VGI IsolationMulti-Instance VMsClosed OS Support

Frequently Asked Questions

Answers to common questions about installing and configuring the WifiSocks OpenWrt .ipk package.

You can install WifiSocks in two ways: via SSH terminal using the standard command opkg update && opkg install /tmp/wifisocks_*.ipk, or directly through the OpenWrt LuCI web interface at System > Software > Upload Package. After installation, access the Web Admin Dashboard directly at http://[ROUTER_IP] (default Port 80, where [ROUTER_IP] is the current LAN IP configured for your router). During installation, any conflicting processes occupying port 80 are automatically terminated to dedicate the port to WifiSocks.

WifiSocks provides standalone .ipk packages for three major architectures:
  • AMD64 (x86_64): Intel/AMD Mini PCs (N100, N150, J4125, N5105), multi-NIC appliances, Proxmox/VMware VMs. Requires 1GB+ RAM.
  • ARM64 (aarch64): Wi-Fi 6 routers (MediaTek Filogic 820/830 MT7981/MT7986, Rockchip RK3568, Cortex-A53), Raspberry Pi 4/5. Requires 512MB+ RAM.
  • MIPS Softfloat (mipsel_24kc): MediaTek MT7621AT/MT7621 routers (Xiaomi CR660x, RM2100, Newifi D2). Requires 256MB RAM.
All architectures require OpenWrt 21.02+ or ImmortalWrt with ~20MB free storage.

No. WifiSocks runs as an independent userspace daemon communicating with standard Linux networking tools (iptables, nftables, policy routing). It does not replace or modify your base OpenWrt Linux kernel, preserving your existing router configuration, LuCI themes, and installed packages.

No client-side software, root access, or browser plugins are required. Computers, mobile phones, and virtual machines connect normally to the router via standard Wi-Fi or Ethernet. The router automatically binds each device to its designated proxy route based on IP or MAC address.

Under our Bring Your Own Network (BYON) model, you provide your own external proxies. WifiSocks supports HTTP, HTTPS, SOCKS5, and Shadowsocks proxies. All TCP, UDP, QUIC, HTTP/3, WebRTC, and WebTransport traffic is routed transparently at Layer 3/4.

When installed on your router, WifiSocks automatically generates a unique hardware Machine ID for direct digital license activation. When new software releases become available, updates are applied automatically or notified directly on your Web Admin Dashboard without requiring manual terminal commands or user intervention, backed by continuous engineering support on Telegram.
Software Licensing & Compliance Notice

WifiSocks is distributed solely as a Digital Software License and OpenWrt package (.ipk). WifiSocks does not manufacture, import, or distribute physical hardware. Users are solely responsible for procuring compliant hardware meeting applicable national telecommunication regulations (QCVN / FCC / CE) and for their own external network configurations.

The software is designed strictly for lawful network routing, QA testing, and privacy purposes. Any unlawful usage violating computer crime regulations or network security laws is strictly prohibited. For details, review our Terms of Use.

Ready to deploy WifiSocks on OpenWrt? Let's talk. Contact our team for software licenses, package downloads, and technical setup.

WifiSocks technical team ready to assist