Tableau de bord cloud centralisé de gestion WireGuard
Wantastic est un tableau de bord cloud centralisé de gestion WireGuard offrant un accès Winbox distant sécurisé aux routeurs MikroTik et aux appareils OpenWrt situés derrière des pare-feu ou Starlink.
Découvrez WUSP : la sémantique USP, native WireGuard.
Wantastic USP over WireGuard transporte les opérations de gestion d’appareils dans le tunnel chiffré existant, sans exposer de socket de gestion supplémentaire ni créer une seconde couche de confiance.
WUSP est un transport privé conçu pour la sémantique USP dans Wantastic. Ce n’est pas un protocole MTP USP standard et interchangeable du Broadband Forum.
Client edge open source
Un agent. Tous les environnements. wantasticd.
Un daemon mesh WireGuard léger pour serveurs, postes de travail, routeurs OpenWrt et appareils IoT embarqués, avec gestion WUSP et attribution par QR en usine.
Wantastic helps network operators manage MikroTik RouterOS devices that sit behind CGNAT, LTE, Starlink, customer firewalls, or dynamic residential ISP links. Instead of exposing Winbox port 8291 or maintaining a separate VPN server for every site, Wantastic gives teams managed remote Winbox access for MikroTik/RouterOS devices and uses secure WireGuard overlays for Linux, Windows, Android, OpenWrt, and other supported endpoints.
Remote Winbox Access Without Port Forwarding
Remote Winbox access should not require a public IP address, inbound firewall rules, shared admin passwords, or a jump server. Wantastic creates controlled Winbox endpoints for MikroTik routers, supports team access, and keeps operations auditable from the cloud management console.
OpenWrt, Linux, Windows, Android and Embedded Device Overlay
The open-source wantasticd agent connects OpenWrt, Linux, Raspberry Pi, containers, Android, macOS and Windows systems to the same management mesh. It is designed for heterogeneous fleets where routers, servers, customer-premises equipment, and embedded devices need secure remote access from one operational workflow.
Open-Source WireGuard Mesh and Self-Hosted Portal
WantasticCore is the open-source self-hosted WireGuard mesh and browser admin portal for teams that need to own the control plane. It combines device onboarding, browser management tools, team access, WebSSH, WebProxy, and policy controls in one deployable platform.
WUSP and Cloud-Native Device Control
Wantastic is moving beyond basic VPN connectivity toward cloud-native device management. WUSP-style workflows, TR-069 and TR-369 device-management ideas, monitoring, browser sessions, topology policy, and managed credentials help operators control devices instead of only tunneling to them.
MikroTik remote management behind CGNAT
Remote Winbox access without exposing port 8291
OpenWrt, Linux, Windows and Android remote access with wantasticd
Self-hosted WireGuard mesh with WantasticCore
WebSSH and WebProxy for private device interfaces
Team access without shared router credentials
WUSP cloud-native device management
RouterOS 7 native WireGuard onboarding
The Dude alternative for remote access and monitoring
Secure network operations for ISPs, WISPs, MSPs and labs
One operating layer
Les bricolages répétés des équipes réseau deviennent un seul workflow.
Winbox distant, WebSSH, WebProxy, supervision, accès équipe et politiques dans une couche de gestion pour flottes MikroTik, OpenWrt, Linux, Windows et Android derrière CGNAT, LTE, Starlink ou pare-feu stricts.
01WireGuard natif RouterOS 7
Onboarding RouterOS natif, sans paquet routeur
Les appareils MikroTik rejoignent le mesh avec le client WireGuard intégré à RouterOS 7, pour des installations simples et réversibles.
Collez le script RouterOS généré, laissez le routeur initier la connexion sortante et évitez les binaires personnalisés sur le matériel MikroTik.
Chaque compte obtient un routage et des politiques isolés pour que les appareils soient joignables pour travailler, pas automatiquement fiables parce qu’un utilisateur rejoint un VPN.
Utilisez les chemins P2P si possible, le relay seulement si nécessaire, et rendez les communications entre appareils explicites via topologie et ACL.
Winbox accounts · secure access without exposing port 8291
04Contrôle par utilisateur
Accès équipe sans partager les secrets routeur
Arrêtez de transmettre mots de passe admin, fichiers VPN ou accès jump-server permanents pour dépanner un site client.
Invitez les membres, accordez seulement les workflows nécessaires, suivez les sessions et révoquez l’accès centralement sans reconfigurer chaque routeur.
WISP Manager · 48 active services across the demo fleet
From endpoint to console
De l’appareil inaccessible à l’endpoint géré.
Wantastic suit le vrai parcours support : connecter, isoler, accorder l’accès, puis travailler depuis le navigateur.
01
Connecter sans ouvrir de ports entrants
Onboarding outbound-first
Connectez RouterOS avec WireGuard natif ou installez wantasticd sur OpenWrt et Linux. L’appareil initie la connexion, donc CGNAT et liens ISP dynamiques ne bloquent plus.
Pas de port Winbox public
WireGuard natif RouterOS
wantasticd pour Linux et OpenWrt
Fonctionne derrière NAT et CGNAT
02
Placer chaque appareil dans un mesh privé de gestion
Routage conscient des politiques
Les appareils rejoignent un overlay isolé où l’accès est intentionnel. Les techniciens atteignent les workflows nécessaires sans rejoindre un réseau privé plat.
Routage virtuel par tenant
Adressage overlay automatique
P2P si possible
Relay fallback si requis
03
Contrôler sessions, identifiants et chemins appareil-à-appareil
Opérations en moindre privilège
Modélisez groupes, liens et règles par protocole depuis le portail. Donnez accès à Winbox, SSH ou interfaces web sans distribuer de clés réseau permanentes.
Politiques d’accès granulaires
Identifiants Winbox gérés
Invitations et révocation d’équipe
Contrôles par protocole
04
Travailler dans le navigateur, pas dans un client VPN
Winbox, WebSSH, WebProxy, WUSP
Lancez accès Winbox, WebSSH persistant, interfaces web LAN-only, supervision et contrôle type WUSP depuis la même console.
Workflows Winbox distants
Sessions WebSSH persistantes
WebProxy pour UIs privées
Vues uptime et joignabilité
What users are saying
Loved by network engineers worldwide
Field notes from operators solving remote Winbox, CGNAT, OpenWrt and browser-based support workflows.
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
“The real win is not having to expose Winbox or maintain a separate VPN path for every customer site. Devices behind CGNAT are reachable from the console, and the support workflow is much cleaner.”
“Remote Winbox over the overlay solved the annoying Starlink and NAT problem for MikroTik support. I can keep native Winbox and RoMON habits without opening ports at the customer edge.”
“wantasticd makes the Linux and OpenWrt side feel like part of the same management plane. That matters when a site has routers, small servers, and embedded devices on unreliable LTE links.”
“The team access model is the feature I care about most. I can stop handing out shared router credentials and give technicians the exact workflows they need for a device.”
“I used to maintain a WireGuard jump server just to reach routers. Wantastic gives me the tunnel, the browser tools, and the device list in one place, which is the part generic VPN tools miss.”
“The P2P-first design is the right architecture for interactive work. When a direct path is possible, Winbox and SSH feel much better than a relay-only remote access stack.”
“The free plan was enough to test the real workflow: add a router, connect through Winbox, try WebSSH, and see whether it fits support operations before rolling it wider.”
“The open-source direction changed how I looked at the product. WantasticCore and wantasticd make it possible to inspect the architecture instead of trusting a black-box remote access service.”
Aug 2024
Frequently Asked Questions
Common Questions
Practical answers about remote Winbox, CGNAT, OpenWrt, Linux, Windows, Android, WebSSH and self-hosted WantasticCore.
Arrêtez de créer un accès unique pour chaque site.
Commencez avec Wantastic hébergé pour aller vite, ou explorez WantasticCore open source quand vous avez besoin d’un mesh WireGuard auto-hébergé et d’un portail de gestion navigateur.