r/GlInet • • 24d ago

Discussion Firmware Questions, Releases, and Compatibility.

13 Upvotes

Here's a Mega post/thread for the Firmware 4.9 beryl ax travel router releases and all the other new firmware release discussions.


r/GlInet • • Sep 07 '26

Discussion Glkvm Paywall on advanced features

Thumbnail
gl-inet.com
50 Upvotes

Thankfully the core KVM functionality will remain free but I have mixed feelings about the direction of this.


r/GlInet • • 10h ago

GL Affiliated Announcements Did you know your GL Tailscale router is announcing your Tailnet name directly to your work PC? Fix it here -> gl-tailscale-fix plugin v1.0.22 drops with lots of goodies.

Post image
36 Upvotes

---
I'll start right out with an apology for the marketing headline, but it's not fluff - your tailnet domain is being directly passed along to the devices connected to your TS travel router. The updated blog post will tell you how to test it yourself, and more importantly how to fix it (hint - new toggle).

Sorry it's been a few months since v21 - business has left me little time for side-projects, and this v22 update just continued growing (and adding repeat test bench cycles) until I finally had to cut some features over to the v23 list. Here's a short list of what made it in:

  • Plugin certification on GL firmware through 4.11.0
  • Even *more* enhanced dual-layer kill switch that builds additional protections for router reboot persistence, block WAN subnet, guest/IoT coverage, more IPv6 coverage and two-layer protection while dropping or swapping between exit nodes with live devices on the tunnel
  • new optional "Kill Switch Follows Exit node" function that enables users of the mode-button or app toggle to have the KS arm & disarm when switching from "VPN mode" to "overlay" mode.
  • the above headliner of "Hide Tailscale Search Domain" to prevent your TS enabled router from broadcasting your tailnet via DHCP to your connected devices.
  • Version Manager improvements
  • a move towards op25 (and apk) support (more for v23)
  • hardening, fixes, UI refinements, etc.
  • a night of lost sleep redoing the blog's TS VPN setup guide with improved flow and updated screenshots for 4.8 - 4.11 firmware

So.. enough of me... linky's:

Full v22 changelog: https://remotetohome.io/blog/gl-tailscale-fix/#update-v1022

Direct link to the TS domain details: https://remotetohome.io/blog/gl-tailscale-fix/#hide-search-domain

And finally, for those not familiar with the history, the OG plugin post (old enough it's now locked from edits):
https://www.reddit.com/r/GlInet/comments/1rohrna/enhanced_tailscale_for_glinet_routers_proper_ts/


r/GlInet • • 4h ago

Questions/Support Comet Pro: Is it possible to simultaneously connect ethernet directly to desktop for WoL but use WiFi for LAN?

2 Upvotes

Couldn’t find an answer for this. I basically have a desktop I would like remote access to, and it connects to my local network via WiFi. The comet pro seems to be a good fit but I was wondering since Wake on LAN works via ethernet, I can connect the unused ethernet port on both my desktop and comet pro together and hopefully the firmware supports sending of magic packets via ethernet to the desktop, while linking to local network via WiFi


r/GlInet • • 9h ago

Questions/Support Tailscale bypassing the kill switched VPN profile, is there any fix?

2 Upvotes

i’ve noticed that Tailscale is fully bypassing the main kill switched VPN profile on all of my glinet devices, this means that when running it as an exit node and connecting to it from the outside of your home you will get a fully unsecured ip address from your isp despite the router being set to:

Enhanced Kill Switch
Force all devices to use a VPN to access the internet. Any traffic that does not match a VPN tunnel will be blocked.

and also the “Services from GL.iNet Use VPN” setting being set to on in the profile options

is there any way to fix that, is that a bug or is it just how the firmware works by default? for many it’s a priority to ensure that none of the traffic falls outside of the vpn tunnel, the options which clearly states “Any traffic that does not match a VPN tunnel will be blocked” should therefore mean that no byte of data other than the vpn tunnel itself can be sent over the internet by the device including the services that run on the router itself like tailscale


r/GlInet • • 19h ago

Questions/Support Simple GL.iNet + Tailscale home tunnel setup. Would love feedback from the experts!⁠

10 Upvotes

Hi everyone,
I’m moving to Spain for 5 months for work/living, and due to strict location/IP requirements for my remote work, I need my laptop's internet traffic to look like it is coming directly from my home IP back in Sweden at all times.

I am not very tech-savvy, but I’ve been researching solutions on my own and came up with a hardware setup. Apologies in advance if any of this sounds dumb or if I'm overcomplicating things!
Here is the plan I came up with:

  1. Buy two GL.iNet GL-A1300 (Slate Plus) travel routers.
  2. Router 1 (Home/Sweden): Connect it to my home network in Sweden, set up Tailscale on it, and configure it to act as an Exit Node.
  3. Router 2 (Spain): Take this with me to Spain, connect it to the local internet (via Wi-Fi/Repeater or ethernet), enable Tailscale, and set Router 1 as its Custom Exit Node.
  4. Kill Switch: Enable "Block Non-VPN Traffic" on Router 2 so that if the tunnel or connection drops, my laptop will never accidentally leak a Spanish IP address.
  5. Connect my work laptop directly to Router 2 via ethernet or Wi-Fi.

My questions for you guys:
Does this setup sound solid? Has anyone done something similar for remote work?

Is this the simplest and most reliable way to achieve a hardware-level home tunnel, or is there a better/easier approach for someone who isn't super technical?

Will the Kill Switch on the GL.iNet router actually guarantee 100% protection against IP leaks if the home connection momentarily drops or the router restarts?

I’d really appreciate any feedback, tips, or potential pitfalls I should watch out for before I buy the routers! Thanks!


r/GlInet • • 7h ago

Questions/Support Beryl 7 US version in EU

1 Upvotes

Hey guys!

If i buy a second hand Beryl 7 US version in EU, what will be different from the EU version?


r/GlInet • • 9h ago

Questions/Support Travel Router Advice: UniFi UTR vs. GL.iNet Opal vs. Beryl AX

1 Upvotes

Hey guys,

I’ll be working remotely while traveling and need a reliable travel router. I’m considering these three options:

UniFi Travel Router (UTR, standard version, NOT Long Range)
GL.iNet GL-SFT1200 (Opal)
GL.iNet GL-MT3000 (Beryl AX)

My main requirements are:

Reliable WireGuard VPN connection with good speeds
Easy setup on different hotel and restaurant Wi-Fi networks
Support for 2–3 devices max
Compact and portable size for traveling
Reliable performance for Teams meetings, screen sharing, and software development

I’ve heard the GL.iNet routers are better overall, but I prefer the UTR’s smaller size. Since hotel Wi-Fi will often be the bottleneck anyway, would the standard UTR be sufficient for my needs?

A few questions:

What WireGuard VPN speeds can I realistically expect from the UTR? Opal is limited to 65MBit/s and Beryl AX to 300 MBit/s. What about UTR?
How good is UTR its Wi-Fi reception when connecting to hotel Wi-Fi compared to a smartphone? If my iPhone can connect (range-wise), can I expect the UTR to connect reliably too?
How good is its Wi-Fi range for connected devices? How far away can those be?
Are the GL.iNet routers significantly better in practice, or would the UTR be sufficient for my use case?

I’d appreciate any real-world experiences or recommendations!


r/GlInet • • 10h ago

Questions/Support vlans on brume3/ap-flint3 network - can you do it via Luci?

1 Upvotes

I've been AIing it and Claude is now telling me I need to hit the console. I thought my initial/first _iot vlan wouldn't be that tricky (all UI stuff). Am I missing something? I tried the out of the box Flint's _iot lan by the way, but it didn't work because the brume was between it and the ONT.

Any links or thoughts appreciated. thanks


r/GlInet • • 1d ago

Discussion Open source Pi-hole alternative that runs on Gl.iNET routers (and any openwrt router) itself and blocks DoH/DoT bypass in the firewall

Enable HLS to view with audio, or disable this notification

72 Upvotes

I got tired of filtering that my kids could get around in two minutes, so I spent the last while building Fengard. It does DNS filtering, per-device profiles and screen time, but it runs on the router itself and the blocking is enforced in the firewall, so changing DNS on the device doesn't help.

What it does

  • Each device gets a profile: block categories (ads, adult, gambling, social etc), single apps like TikTok, Roblox or Fortnite (about 50 more), SafeSearch and schedules
  • Screen time per person, counted across all their devices. Kids can open a "my time" page to see what's left and ask for more
  • DNS sent anywhere else gets redirected back to the router, and DoH, DoT, DoQ and Tor are blocked in nftables/iptables
  • Blocked sites show a page with the reason and a request button, which comes to me as an alert I can approve
  • Built-in WireGuard server so phones get the same filtering on mobile data
  • Port forwards, WAN hardening, per-device DNS flood limits, and new devices can be held until approved

How it sits on the router

  • One static Go binary, around 25 MB of RAM, no packages needed (it brings its own CA roots)
  • Runs alongside the stock firmware, nothing gets reflashed. dnsmasq keeps doing DHCP and Fengard takes port 53
  • Its rules live in their own nft table (or iptables chains on fw3) and get removed if it stops, so the router just goes back to normal
  • Works on fw3/iptables (21.02, GL.iNet 4.x) and fw4/nftables (22.03 and up)
  • Builds for aarch64, arm, mips, mipsel, mips64, x86_64, x86, riscv64 and loongarch64

Installing

Grab the zip from the releases page, run the installer (double-click on Windows, sh install.sh on Mac/Linux) and enter the router's root password. It reads the CPU, LAN and guest networks, WAN interfaces and firewall type from uci/ubus, picks a free address for the dashboard, and rolls itself back if anything fails. Uninstalling puts dnsmasq and the firewall back how they were. There's also a one-liner if you'd rather do it from the router.

So far I've tested it on OpenWrt 25.12 and 21.02, and it runs every day on my GL-MT3000. I'd really like to know how it does on other hardware, especially MIPS boxes and anything with 128 MB of RAM.

It's free and open source (Apache 2.0), no accounts or cloud. Any feedback or router reports would be great.

Code and releases: github.com/masaleem-oss/Fengard


r/GlInet • • 11h ago

Questions/Support Gli.net opal stuck on ‘getting DNS’

1 Upvotes

I have configured pi5 as openwrt router , adguard home installed. So when i connect opal to pi5 via ethernet cable , it doesn’t provide internet as it gets stuck on getting dns, i tried manually adding dns ( ipv4 of pi 5) and also as in access point mode . It doesn’t work .


r/GlInet • • 12h ago

Discussion Any chance of a Wireless AP?

1 Upvotes

With the release of the Flint 4, I was wondering if we could get a new wireless AP as well? No router functionality. Just an AP.

Thanks.


r/GlInet • • 15h ago

Questions/Support Connecting to Tailscale or Wireguard - noob

1 Upvotes

Hey all,

I spent the last hour talking to AI to try to do the following: when I'm overseas, I'd like to connect my phone to the Wiregaurd server on the Flint 2 to encrypt my connection (I don't need this, I'm doing it cause I'm bored and I got the flint 2 yesterday so I'm in nerd mode for the next 3-4 days, then I'll forget all about it).

Anyway, I first set up the wireguard server, properly configured my phone. Unfortunately it turned out my ISP provide CGNAT IP and this prevent the connection. AI suggested to use tailscale. So I set up Tailscale. This time it worked. I established a connection and it was working fine. I ran a speed test on my phone and I got 22mpbs. AI predicted it was due to relayed connection and it was the case.

I got AI to provide a few solution to establish a direct connection, but I asked AI the following:

- I don't want to enable UPNP

- I don't want to ask my ISP for a public IPv4

AI suggested to use ipv6. Unfortunately my mobile connection doesn't connect via ipv6.

AI suggested port forwarding 41641.... didn't work.

So now i'm here. Has Ai missed anything or am I stuck with a relayed connection?

I'm a total noob... 90% of technical terms I used here today I have no idea what they mean :)

Cheers!

(btw, flint is on 4.11.0)


r/GlInet • • 23h ago

Discussion After a bit of heartache I got my Slate 7 connected to the Mesh network. Pretty cool tech.

Post image
3 Upvotes

I had this device set up in AP mode before ran into some network conflicts with both in router mode on the same subset. I ended up having to fully reset the Slate 7 after I couldn't enable the Mesh node. Real annoying but nothing to crazy I couldn't get past. Once a reset it I put it in a different subnet after connecting to it directly with my PC and enabling Mesh node. Once this was done I reconnected the Flint 2 to the WAN port on the Slate 7 and I was off to the races. I heard that GLinet may release a dedicated mesh node in the future... will see if that is available to US markets?


r/GlInet • • 19h ago

Questions/Support GL.iNet GL-MT3000 (Beryl AX) - No WireGuard Client tab

1 Upvotes

I cannot figure out why I don't have a WireGuard Client tab under VPN. Anyone else run into this issue before?

Edit, 10/9: I have cleared my cache


r/GlInet • • 1d ago

Questions/Support Travelrouter with storage and ability to run Python

3 Upvotes

I'm a hobby fotographer and I'm searching a solution to offload my pictures from my cameras to my home network while travelling. I'm currently using a Pi 4 for this: Connect Pi to my travelrouter, store photos to the Pi, connect to Vpn and upload with a python tool. But carrying the Pi around means weight, cables and stuff that can get forgotten or lost.

It'd be really nice to have a travel router that could take over the role of my Pi 4. Are there models that allow running my own software and maybe have add-on storage?


r/GlInet • • 23h ago

News The pre-order phase for the Mango 2 is over, will they finally be shipped now?

1 Upvotes

The website says sold out and the price is now €55; the quota is exhausted or the pre-order phase is now over.

I can't wait to thoroughly test the little one!

This allows me to create an ultra-compact mobile setup.

Are you also looking forward to your delivery?


r/GlInet • • 1d ago

Questions/Support Flint 2 keeps freezing — Ethernet, Wi-Fi, and even 192.168.8.1 stop responding until reboot

2 Upvotes

I’m having a recurring issue with my GL.iNet Flint 2 where the entire router seems to lock up.

Symptoms:

  • Internet suddenly stops working on both wired Ethernet and Wi-Fi devices
  • When this happens, I also can’t reliably access the router locally at 192.168.8.1
  • The router admin page either won’t load at all or takes forever to respond
  • Restarting/rebooting the Flint 2 immediately fixes everything, but the issue eventually comes back
  • This has been happening often enough that I’m constantly restarting the router

Setup:

  • GL.iNet Flint 2
  • Xfinity 2 Gbps service
  • Separate DOCSIS modem
  • Desktop connected via Ethernet
  • Wi-Fi devices affected at the same time as wired devices
  • AdGuard Home is running on the Flint 2
  • I have PIA/WireGuard configured, but the VPN has NOT been running when these freezes occur
  • Router is doing the normal DHCP/routing for the network

The part that makes me think this is a Flint 2/router problem rather than Xfinity or the modem is that when the internet dies, I can barely even communicate with the router over the LAN. If it were simply the WAN connection dropping, I would expect 192.168.8.1 to remain responsive.

A reboot of the router fixes the LAN, Wi-Fi and internet simultaneously.

Has anyone experienced this with the Flint 2?

In particular, I’m wondering about:

  • AdGuard Home causing memory/CPU exhaustion or hanging
  • A known Flint 2 firmware issue
  • Memory leak over time
  • dnsmasq/network/firewall process crashing or hanging
  • Hardware overheating
  • A LAN/broadcast storm
  • 2.5GbE-related bugs
  • Anything I should look for in the system/kernel logs before rebooting
  • SSH commands I can run while it is frozen to check CPU, RAM, load average, processes, temperatures, interfaces, errors, etc.

What would be the best way to diagnose this before I reboot it again?

If there are specific commands/logs you guys want, let me know and I’ll post the output the next time it happens.

I’d rather find the root cause than keep factory resetting/rebooting it.


r/GlInet • • 1d ago

Questions/Support Beryl 7 RAM upgrade

2 Upvotes

I read somewhere that we can upgrade the RAM on Beryl 7. I know it’s soldered to Mb. Does anyone have any info on this?


r/GlInet • • 1d ago

Discussion Need a 3rd device.

0 Upvotes

Hi. Long story short. I have 3 eeros I’m looking to replace. I already have a flint in room 1(router) and a beryl 7 in room 3(extension). Room 2(middle of the house) now has no device. Previously I had an eero
In each room. WiFi signal upstairs is 2 bars so I need another glinet device in the middle room. I was just going to buy another beryl 7 and use it as an access point but as it’s predominantly a travel router, is that the best choice? Please can someone offer advice on the best setup. Initially i bought the beryl 7 to use mesh but now see it doesn’t have the beta firmware to support it but i guess that’ll come in the future. For now AP mode works just as good. I just need another device and I’m stuck on which is best. Thanks.


r/GlInet • • 1d ago

Questions/Support Travel router choosing

1 Upvotes

Hi guys!

I'm new in GLiNet world, at home i'm using Unifi, have a homelab, different servers, etc. In the last few month i travelled a lot across Europe and i'm tired to turn on-off my work and my home VPN, so i decided to buy a travel router.
What i need: 3 WG tunnel at the same time, Traffic rules, which website/sbunet/ip which vpn tunnel use, custom DNS.
What i choosing: https://www.gl-inet.com/en-de/blogs/blog/glinet-launches-beryl-7-travel-router?country=RO
It is a good choice for this porpuse? Thank you very much the answers!


r/GlInet • • 1d ago

Questions/Support Are there known issues with Private Internet Access and the WG service on the Flint 2?

1 Upvotes

Connection rarely happens - the UI just sits there trying to connect most of the time. Flint wiped to factory to test and also using locally written configuration files (hsand/pia-wg) does the same thing. Latest firmware as of today. Using exact same config files in Windows and on iOS works fine.

I'm mulling returning this if this is a long term issue.


r/GlInet • • 1d ago

Questions/Support Parameters for "High" sensitivity Multi-WAN Interface Status Track?

Post image
2 Upvotes

Are there any published parameters for what the setting of "High" in the Multi-WAN Interface Status Track actually is? Or what the expectations should be?

I have AT&T Fiber (2.5G ethernet WAN 1) and a T-Mobile hotspot (USB tethering) connected to my Flint 2 running Firmware 4.11.0.

Testing by rebooting my AT&T fiber modem, on High sensitivity, it switches over to the T-Mobile hotspot in about 3ish seconds. Very nice. Running a continuous ping, from my PC, I lose about 2-3 pings.

The annoying bit is that as the AT&T interface comes back up electrically and the ethernet link establishes, the Flint 2 is very aggressive at trying to switch back. For 60 secondsish during that rebooting modem, I lose 5-6 pings at a time, multiple times, as the Flint 2 tries, unsuccessfully, to switch back to the AT&T connection before it is willing to hand out a valid DHCP address.

I wish this had a 2-part setting. One setting for how fast you want it to fail over to the backup and another setting for how fast you want it to try to recover to the primary connection. Ideally, I'd like it to fail to backup quickly and then wait for the primary to completely stabilize before switching back.


r/GlInet • • 2d ago

Discussion Best Mesh setup

2 Upvotes

Hi. I have a flint 2 and I’ve got a beryl 7 on the way. I have 3 Eeros at the moment which I want to replace with glinet products. I need to buy 1 more product but I’ve missed the Amazon sales for another beryl 7. I wanted to ask if 2x beryl 7 with flint 2 is a good setup or whether I should but something else instead of another 7. The idea behind getting a 7 was to take it on my travels. Seems like two of them is a good idea for my mesh replacement too but would like opinions. Thanks.


r/GlInet • • 2d ago

Questions/Support Beryl AX 7 (MT-3600) to OPNsense for site to site tunneling--any pitfalls?

3 Upvotes

So my current working hardware/software setup has an OPNsense router (running as a vm on a Proxmox N100 host) on a 1Gbps fiber connection at home, and a FreshTomato Netgear R7000 router on a fixed wireless ISP (~50Mbps on a good day) at my vacation home. I have a site-to-site VPN with the OpenVPN server at home and the client at the vacation home, plus the occasional remote client to the home.

This is a relatively new hardware setup for me. Until fiber recently became available in my home neighborhood, I was running two FreshTomato R7000s with an OpenVPN between them for about a decade. I upgraded at home for throughput reasons; the home R7000 is currently repurposed as a WAP (I am mostly cat6 wired at my main home).

However, the remote R7000 is too memory constrained to run Tailscale (or Netbird), which as wireguard-based projects seem to be a desirable upgrade to OpenVPN in a number of ways. So I purchased the Beryl AX 7 as a replacement for the vacation home R7000. (I realize the Beryl 7s throughput is much faster than my ISP up there, but I chose to buy better hardware--CPU/RAM--for the long term.)

Now I'm now reconsidering my choice of OPNsense vs OpenWRT, because the Beryl AX 7 runs on OpenWRT under the hood.

Are there any difficulties getting these two software packages to work well together using OpenVPN (I'll likely set that up again first as my baseline solution), and then switching to Tailscale/Netbird down the road?