Panel centralizado en la nube para gestionar WireGuard
Wantastic es un panel centralizado en la nube para gestionar WireGuard, con acceso remoto seguro mediante Winbox a routers MikroTik y dispositivos OpenWrt situados detrás de firewalls y Starlink.
Wantastic USP over WireGuard transporta las operaciones de gestión de dispositivos dentro del túnel cifrado existente, sin exponer otro socket de administración ni crear una segunda capa de confianza.
WUSP es un transporte privado creado para la semántica USP en Wantastic. No es un MTP USP estándar e intercambiable del Broadband Forum.
Cliente edge open source
Un agente. Cualquier entorno. wantasticd.
Un daemon mesh WireGuard ligero para servidores, escritorios, routers OpenWrt y dispositivos IoT integrados, con gestión WUSP y registro por QR en fábrica.
Wantastic helps network operators manage MikroTik RouterOS devices that sit behind CGNAT, LTE, Starlink, customer firewalls, or dynamic residential ISP links. Instead of exposing Winbox port 8291 or maintaining a separate VPN server for every site, Wantastic gives teams managed remote Winbox access for MikroTik/RouterOS devices and uses secure WireGuard overlays for Linux, Windows, Android, OpenWrt, and other supported endpoints.
Remote Winbox Access Without Port Forwarding
Remote Winbox access should not require a public IP address, inbound firewall rules, shared admin passwords, or a jump server. Wantastic creates controlled Winbox endpoints for MikroTik routers, supports team access, and keeps operations auditable from the cloud management console.
OpenWrt, Linux, Windows, Android and Embedded Device Overlay
The open-source wantasticd agent connects OpenWrt, Linux, Raspberry Pi, containers, Android, macOS and Windows systems to the same management mesh. It is designed for heterogeneous fleets where routers, servers, customer-premises equipment, and embedded devices need secure remote access from one operational workflow.
Open-Source WireGuard Mesh and Self-Hosted Portal
WantasticCore is the open-source self-hosted WireGuard mesh and browser admin portal for teams that need to own the control plane. It combines device onboarding, browser management tools, team access, WebSSH, WebProxy, and policy controls in one deployable platform.
WUSP and Cloud-Native Device Control
Wantastic is moving beyond basic VPN connectivity toward cloud-native device management. WUSP-style workflows, TR-069 and TR-369 device-management ideas, monitoring, browser sessions, topology policy, and managed credentials help operators control devices instead of only tunneling to them.
MikroTik remote management behind CGNAT
Remote Winbox access without exposing port 8291
OpenWrt, Linux, Windows and Android remote access with wantasticd
Self-hosted WireGuard mesh with WantasticCore
WebSSH and WebProxy for private device interfaces
Team access without shared router credentials
WUSP cloud-native device management
RouterOS 7 native WireGuard onboarding
The Dude alternative for remote access and monitoring
Secure network operations for ISPs, WISPs, MSPs and labs
One operating layer
Los parches que los equipos de red repiten ahora son un solo flujo.
Winbox remoto, WebSSH, WebProxy, monitoreo, acceso de equipo y políticas en una capa de gestión para flotas MikroTik, OpenWrt, Linux, Windows y Android detrás de CGNAT, LTE, Starlink o firewalls cerrados.
01WireGuard nativo en RouterOS 7
Onboarding nativo de RouterOS, sin paquete en el router
Los dispositivos MikroTik se unen con el cliente WireGuard incluido en RouterOS 7, manteniendo las instalaciones simples y reversibles.
Pega el script RouterOS generado, deja que el router inicie la conexión saliente y evita binarios personalizados en hardware MikroTik.
Cada cuenta obtiene enrutamiento y políticas aisladas para que los dispositivos sean accesibles para trabajar, no confiables por defecto solo por entrar a una VPN.
Usa rutas P2P cuando sea posible, relay solo cuando haga falta, y mantén la comunicación entre dispositivos explícita mediante topología y ACL.
WISP Manager · 48 active services across the demo fleet
From endpoint to console
De dispositivo inalcanzable a endpoint gestionado.
Wantastic sigue el camino real de soporte: conectar el dispositivo, aislarlo, conceder acceso y trabajar desde el navegador.
01
Conecta sin abrir la firewall entrante
Onboarding outbound-first
Conecta RouterOS con WireGuard nativo o instala wantasticd en OpenWrt y Linux. El dispositivo inicia la conexión, así CGNAT y enlaces ISP dinámicos dejan de bloquearte.
Sin puerto Winbox público
WireGuard nativo en RouterOS
wantasticd para Linux y OpenWrt
Funciona detrás de NAT y CGNAT
02
Coloca cada dispositivo en una malla privada de gestión
Enrutamiento con políticas
Los dispositivos entran en un overlay aislado donde el acceso es intencional. Los técnicos llegan a los flujos necesarios sin unirse a una red privada plana.
Routing virtual por tenant
Direcciones overlay automáticas
P2P cuando sea posible
Relay fallback cuando sea necesario
03
Controla sesiones, credenciales y rutas entre dispositivos
Operaciones de mínimo privilegio
Modela grupos, enlaces y reglas por protocolo desde el portal. Da acceso a Winbox, SSH o web sin entregar llaves permanentes de red.
Políticas granulares
Credenciales Winbox gestionadas
Invitación y revocación de equipo
Controles por protocolo
04
Trabaja en el navegador, no en un cliente VPN
Winbox, WebSSH, WebProxy, WUSP
Lanza acceso Winbox, WebSSH persistente, interfaces web privadas, monitoreo y control tipo WUSP desde la misma consola.
Flujos Winbox remotos
Sesiones WebSSH persistentes
WebProxy para UIs privadas
Vistas de uptime y alcance
What users are saying
Loved by network engineers worldwide
Field notes from operators solving remote Winbox, CGNAT, OpenWrt and browser-based support workflows.
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
Aug 2024
Frequently Asked Questions
Common Questions
Practical answers about remote Winbox, CGNAT, OpenWrt, Linux, Windows, Android, WebSSH and self-hosted WantasticCore.
Empieza con Wantastic alojado para ir rápido, o explora WantasticCore open source cuando necesites una malla WireGuard self-hosted y portal de gestión en navegador.