GL.iNet Travel Router Setup: Captive Portals & WireGuard
Set up your GL.iNet Beryl AX (GL-MT3000) or Slate AX (GL-AXT1800) travel router by navigating to http://192.168.8.1, joining hotel WiFi via Repeater (WISP) mode, and temporarily disabling DNS Rebinding Protection and VPN kill switches until the captive portal login succeeds. Once authenticated, enable your WireGuard client and turn on Block Non-VPN Traffic to secure all laptops and phones behind a single encrypted tunnel.
- Default Admin Portal: Connect to your travel router's SSID and browse to
http://192.168.8.1to configure OpenWrt-backed GL.iNet Admin Panel 4.x. - Captive Portal Golden Rule: Always toggle off WireGuard VPN, AdGuard Home, and
DNS Rebinding Attack Protectionbefore loading a hotel or airline splash page (http://neverssl.com). - One-Device Voucher Bypass: Authenticate on your smartphone first, then go to
Network > MAC Addresson the travel router and select Clone (Your Phone's MAC). - WireGuard Kill Switch: Upload your home router's
.confprofile, set MTU to1380for cellular/hotel networks, and enable Block Non-VPN Traffic.
Initial Configuration at 192.168.8.1 & Repeater (WISP) Mode
GL.iNet pocket routers—including the Beryl AX (GL-MT3000), Slate AX (GL-AXT1800), and Wi-Fi 7 Slate 7 (GL-BE3600)—run a customized OpenWrt firmware designed specifically for untrusted hotel, cruise ship, airplane, and Airbnb networks. Before leaving home, power the router via its 5V/3A USB-C adapter, join its default Wi-Fi network, and open http://192.168.8.1 to set a strong administrator password and customize your private 2.4 GHz and 5 GHz SSIDs to match your home Wi-Fi name so your family's devices connect automatically.
When you arrive at a hotel, check whether the room desk has an active Ethernet wall jack for the router's 2.5GbE WAN port. If only Wi-Fi is available, open http://192.168.8.1 > Internet > Repeater and click Scan. Select the hotel's 5 GHz SSID if its RSSI is stronger than -70 dBm for maximum throughput, or pick 2.4 GHz if the hallway access point is distant, and lock the Band Selection setting so the repeater does not hunt across dead channels.
How to Clear Stubborn Hotel, Cruise & Airline Captive Portals
Hotel captive portals (operated by Marriott Bonvoy, Hilton Honors, Boingo, or Viasat) work by intercepting your first unencrypted DNS and HTTP request and returning a local private IP (such as 10.x.x.x or 172.16.x.x) hosting the room-number login screen. If your GL.iNet router has DNS Rebinding Protection, Encrypted DNS (DoH/DoT), or an active VPN Kill Switch enabled when you first join the hotel Wi-Fi, the router will block that private IP response as a security threat, preventing the login splash page from ever appearing.
Follow this exact 4-step sequence whenever a captive portal refuses to load:
- 1. Pause Security Interceptors: Turn off your WireGuard/OpenVPN client and AdGuard Home. Go to
Network > DNS, set DNS Mode to Auto (From ISP), and toggle off DNS Rebinding Attack Protection. - 2. Trigger the Splash Page: Open a browser on your connected laptop or phone and navigate to
http://neverssl.comorhttp://captive.apple.com. - 3. Use MAC Cloning if Blocked: If the portal still fails (or on airlines/cruises that charge per device), disconnect from the GL.iNet, connect your phone directly to the hotel/airline Wi-Fi, sign in on the portal, then reconnect to the GL.iNet and go to
Network > MAC Address > Clone Client MACto impersonate your already-authenticated phone. - 4. Re-Enable Protection: Immediately turn your WireGuard VPN and Kill Switch back on.
Setting Up WireGuard Client + Global Kill Switch for Remote Work
For remote engineers working from abroad or public networks, running a WireGuard Client on the GL.iNet router pointing back to a home router (such as a GL.iNet Flint 2, Ubiquiti UniFi gateway, ASUS router, or Tailscale exit node) ensures every packet leaves your residential home IP address—without installing VPN software on locked-down corporate laptops.
Navigate to VPN > WireGuard Client and upload your WireGuard configuration file. Because hotel Wi-Fi, PPPoE uplinks, and cellular tethering frequently reduce available path MTU, edit the tunnel settings inside the GL.iNet UI and change the MTU from 1420 to 1380 (or 1280 on satellite/LTE connections) to prevent stalled Slack calls and broken HTTPS handshakes. Next, go to VPN > VPN Dashboard, click the gear icon next to Global Options, and enable Block Non-VPN Traffic so zero packets ever leak onto the hotel LAN if the tunnel drops. You can also bind the physical side toggle switch under System > Toggle Button Settings to control WireGuard on/off with a physical click.
USB Smartphone Tethering, Subnet Collisions & Travel Hardening
When hotel Wi-Fi is congested during evening peak hours, plug an iPhone or Android phone into the GL.iNet router's USB 3.0 port and enable Internet > Tethering. USB tethering shares your phone's 5G hotspot across all your wired and Wi-Fi devices while trickling charge to the phone and completely avoiding extra wireless hops.
Finally, watch out for RFC 1918 Subnet Collisions. Most GL.iNet routers default to the 192.168.8.0/24 LAN subnet specifically to avoid clashing with hotels that use 192.168.1.0/24 or 10.0.0.0/8. However, if you connect to a campground or Airbnb router that also uses 192.168.8.x, your repeater will lose routing. Change your GL.iNet LAN IP under Network > LAN to an uncommon subnet like 192.168.88.1 or 10.99.88.1 before traveling, and reduce 5 GHz transmit power to Low/Medium inside your hotel room to minimize battery draw and RF visibility.
GL.iNet Travel Router Lineup Comparison (2026)
| Model | Wi-Fi Standard | Ethernet Ports | Max WireGuard Speed |
|---|---|---|---|
| Beryl AX (GL-MT3000) | Wi-Fi 6 (AX3000 Dual-Band) | 1x 2.5GbE WAN + 1x 1GbE LAN | 300 Mbps |
| Slate AX (GL-AXT1800) | Wi-Fi 6 (AX1800 Dual-Band) | 1x 1GbE WAN + 2x 1GbE LAN + microSD | 550 Mbps |
| Slate 7 (GL-BE3600) | Wi-Fi 7 (BE3600 Dual-Band MLO) | 2x 2.5GbE (WAN + LAN) | 540 Mbps |
| Mudi V2 (GL-E750V2) | Wi-Fi 5 + Built-in 4G LTE Modem | 1x 1GbE via USB-C Dock + 7000mAh Battery | 50 Mbps |
| Spitz AX (GL-X3000) | Wi-Fi 6 + Dual-SIM 5G NR Modem | 1x 2.5GbE WAN + 1x 1GbE LAN | 300 Mbps |
Pre-Trip GL.iNet Travel Router Configuration Checklist
- Update GL.iNet firmware at http://192.168.8.1 > System > Upgrade before leaving home and export a configuration backup.
- Upload and test at least two WireGuard client profiles (e.g., your home WireGuard server plus a commercial backup VPN) with MTU set to 1380.
- Enable 'Block Non-VPN Traffic' under VPN Dashboard > Global Options and verify 'Allow Access to WAN' is unchecked.
- Disable 'DNS Rebinding Attack Protection' temporarily when joining new hotel networks, then re-enable it once the captive portal clears.
- Bookmark http://neverssl.com and http://192.168.8.1 on your phone and laptop for instant captive portal triggering.
- Pack a short flat Cat6 patch cable and a 30W+ USB-C PD wall charger so the router never brown-outs under heavy Wi-Fi 6 + WireGuard load.
Frequently Asked Questions
Why does my hotel Wi-Fi connect to the GL.iNet router but say 'No Internet Access'?
The hotel network is waiting for you to complete its captive portal login, or its DNS server is returning a private IP that GL.iNet's DNS Rebinding Protection is blocking. Turn off WireGuard and DNS Rebinding Protection, visit http://neverssl.com to complete the room login, and then re-enable your VPN.
Can my employer detect that I am using a GL.iNet travel router with a home WireGuard server?
When your corporate laptop connects via Ethernet (with laptop Wi-Fi and Bluetooth turned off for location privacy) to a GL.iNet travel router running a WireGuard tunnel to your home router with Block Non-VPN Traffic enabled, all IP traffic and DNS queries exit through your residential ISP IP address.
Should I buy the GL.iNet Beryl AX (GL-MT3000) or Slate AX (GL-AXT1800)?
Buy the Beryl AX (GL-MT3000) if you want a lighter, cooler-running MediaTek Filogic 820 router with 160 MHz Wi-Fi 6 channels, a 2.5GbE WAN port, and mainline OpenWrt 23.05+ compatibility. Buy the Slate AX (GL-AXT1800) if you need three physical Gigabit Ethernet ports, a built-in microSD card slot for NAS sharing, or higher 550 Mbps WireGuard speeds.
How do I use Tailscale on a GL.iNet travel router?
Navigate to Applications > Tailscale in the GL.iNet web UI, toggle Tailscale on, and click the authentication link to bind the router to your Tailnet. You can also select a home Tailscale Exit Node directly from the dropdown menu so all connected travel devices route through your home connection.