Zentrales Cloud-Dashboard für die WireGuard-Verwaltung
Wantastic ist ein zentrales Cloud-Dashboard für die WireGuard-Verwaltung mit sicherem Remote-Winbox-Zugriff auf MikroTik-Router und OpenWrt-Geräte hinter Firewalls und Starlink.
Wantastic USP over WireGuard transportiert Geräteverwaltungsoperationen im bestehenden verschlüsselten Tunnel – ohne zusätzlichen Management-Socket und ohne zweite Vertrauensebene.
WUSP ist ein speziell entwickelter privater Transport für USP-Semantik in Wantastic. Es ist kein direkt austauschbares standardisiertes USP-MTP des Broadband Forum.
Open-Source-Edge-Client
Ein Agent. Jeder Edge. wantasticd.
Ein schlanker WireGuard-Mesh-Daemon für Server, Desktops, OpenWrt-Router und eingebettete IoT-Geräte – mit WUSP-Verwaltung und QR-Claim für die Fertigung.
Wantastic helps network operators manage MikroTik RouterOS devices that sit behind CGNAT, LTE, Starlink, customer firewalls, or dynamic residential ISP links. Instead of exposing Winbox port 8291 or maintaining a separate VPN server for every site, Wantastic gives teams managed remote Winbox access for MikroTik/RouterOS devices and uses secure WireGuard overlays for Linux, Windows, Android, OpenWrt, and other supported endpoints.
Remote Winbox Access Without Port Forwarding
Remote Winbox access should not require a public IP address, inbound firewall rules, shared admin passwords, or a jump server. Wantastic creates controlled Winbox endpoints for MikroTik routers, supports team access, and keeps operations auditable from the cloud management console.
OpenWrt, Linux, Windows, Android and Embedded Device Overlay
The open-source wantasticd agent connects OpenWrt, Linux, Raspberry Pi, containers, Android, macOS and Windows systems to the same management mesh. It is designed for heterogeneous fleets where routers, servers, customer-premises equipment, and embedded devices need secure remote access from one operational workflow.
Open-Source WireGuard Mesh and Self-Hosted Portal
WantasticCore is the open-source self-hosted WireGuard mesh and browser admin portal for teams that need to own the control plane. It combines device onboarding, browser management tools, team access, WebSSH, WebProxy, and policy controls in one deployable platform.
WUSP and Cloud-Native Device Control
Wantastic is moving beyond basic VPN connectivity toward cloud-native device management. WUSP-style workflows, TR-069 and TR-369 device-management ideas, monitoring, browser sessions, topology policy, and managed credentials help operators control devices instead of only tunneling to them.
MikroTik remote management behind CGNAT
Remote Winbox access without exposing port 8291
OpenWrt, Linux, Windows and Android remote access with wantasticd
Self-hosted WireGuard mesh with WantasticCore
WebSSH and WebProxy for private device interfaces
Team access without shared router credentials
WUSP cloud-native device management
RouterOS 7 native WireGuard onboarding
The Dude alternative for remote access and monitoring
Secure network operations for ISPs, WISPs, MSPs and labs
One operating layer
Die Workarounds, die Netzwerkteams ständig bauen, werden ein Workflow.
Remote-Winbox, WebSSH, WebProxy, Monitoring, Teamzugriff und Richtlinien in einer Verwaltungsschicht für MikroTik-, OpenWrt-, Linux-, Windows- und Android-Flotten hinter CGNAT, LTE, Starlink oder restriktiven Firewalls.
01RouterOS 7 mit nativem WireGuard
Native RouterOS-Einbindung ohne Router-Paket
MikroTik-Geräte nutzen den in RouterOS 7 integrierten WireGuard-Client, damit Installationen im Feld einfach und reversibel bleiben.
Fügen Sie das generierte RouterOS-Skript ein, lassen Sie den Router die ausgehende Verbindung starten und vermeiden Sie eigene Binärdateien auf MikroTik-Hardware.
Jedes Konto erhält isoliertes Routing und Richtlinien, damit Geräte für Arbeit erreichbar sind, aber nicht automatisch vertraut werden, nur weil jemand im VPN ist.
Nutzen Sie P2P-Pfade, wenn möglich, Relay nur wenn nötig, und machen Sie Gerätekommunikation über Topologie- und ACL-Regeln ausdrücklich.
Erreichen Sie MikroTik-Router über verwaltete Overlay-Endpunkte, statt Winbox für Scanner freizugeben oder fragile Jump-Hosts zu pflegen.
Geben Sie jedem Techniker eine kontrollierte Sitzung, rotieren Sie verwaltete Zugangsdaten, auditieren Sie Zugriffe und behalten Sie native RoMON-Workflows für nachgelagerte Geräte.
Winbox accounts · secure access without exposing port 8291
04Zugriff pro Benutzer
Teamzugriff ohne Router-Geheimnisse zu teilen
Hören Sie auf, Admin-Passwörter, VPN-Dateien oder permanente Jump-Server-Zugänge weiterzugeben, nur um einen Kundensite zu reparieren.
Laden Sie Teammitglieder ein, erlauben Sie nur die nötigen Workflows, verfolgen Sie Sitzungen und entziehen Sie Zugriff zentral, ohne jeden Router umzuschreiben.
WebSSH sessions · browser access with no inbound SSH port
06WantasticCore + wantasticd
Open-Source-Agenten und selbst gehosteter Core
WantasticCore ist ein MIT-lizenziertes Self-Hosted-WireGuard-Mesh-Portal, und wantasticd verbindet Linux-, OpenWrt-, macOS- und Windows-Geräte.
Nutzen Sie die gehostete Konsole für Geschwindigkeit oder betreiben Sie den Open-Source-Core, wenn Kunden, Compliance oder Laborarbeit Kontrolle über die Control Plane verlangen.
WISP Manager · 48 active services across the demo fleet
From endpoint to console
Vom unerreichbaren Gerät zum verwalteten Endpunkt.
Wantastic folgt dem echten Support-Pfad: Gerät verbinden, isolieren, Zugriff vergeben und dann im Browser arbeiten.
01
Verbinden ohne eingehende Firewall-Löcher
Outbound-first Onboarding
Verbinden Sie RouterOS nativ mit WireGuard oder installieren Sie wantasticd auf OpenWrt und Linux. Das Gerät startet die Verbindung, sodass CGNAT und dynamische ISP-Links keine Blocker mehr sind.
Kein öffentlicher Winbox-Port
RouterOS mit nativem WireGuard
wantasticd für Linux und OpenWrt
Funktioniert hinter NAT und CGNAT
02
Jedes Gerät in ein privates Management-Mesh bringen
Richtlinienbewusstes Routing
Geräte treten einem isolierten Overlay bei, in dem Zugriff bewusst vergeben wird. Techniker erreichen die nötigen Workflows, ohne einem flachen privaten Netzwerk beizutreten.
Virtuelles Routing pro Mandant
Automatische Overlay-Adressierung
P2P wenn möglich
Relay-Fallback wenn erforderlich
03
Sitzungen, Zugangsdaten und Gerätepfade kontrollieren
Least-Privilege-Betrieb
Modellieren Sie Gruppen, Links und Protokollregeln im Portal. Geben Sie Zugriff auf Winbox, SSH oder Weboberflächen, ohne permanente Netzwerkschlüssel zu verteilen.
Granulare Zugriffspolitiken
Verwaltete Winbox-Zugangsdaten
Team-Einladungen und Entzug
Kontrollen pro Protokoll
04
Im Browser arbeiten, nicht im VPN-Client
Winbox, WebSSH, WebProxy, WUSP
Starten Sie Winbox-Zugriff, persistente WebSSH-Sitzungen, LAN-only-Weboberflächen, Monitoring und WUSP-artige Gerätesteuerung aus derselben Konsole.
Remote-Winbox-Workflows
Persistente WebSSH-Sitzungen
WebProxy für private UIs
Uptime- und Erreichbarkeitsansichten
What users are saying
Loved by network engineers worldwide
Field notes from operators solving remote Winbox, CGNAT, OpenWrt and browser-based support workflows.
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
Aug 2024
Frequently Asked Questions
Common Questions
Practical answers about remote Winbox, CGNAT, OpenWrt, Linux, Windows, Android, WebSSH and self-hosted WantasticCore.
Keine Einmal-Zugangswege mehr für jeden Standort bauen.
Starten Sie schnell mit gehostetem Wantastic oder erkunden Sie WantasticCore als Open-Source-Option für ein selbst gehostetes WireGuard-Mesh mit Browser-Management-Portal.