Wake-on-LAN (WoL) Setup Guide: BIOS, Windows 11 & Remote VPN Wake
To make Wake-on-LAN (WoL) work reliably from a Windows 11 shutdown (ACPI S5), enable Power On By PCI-E in your motherboard BIOS, disable ErP Ready, enable Wake on Magic Packet in Device Manager, and uncheck Turn on fast startup in Control Panel. For remote internet wake, send the UDP port 9 Magic Packet over WireGuard, Tailscale, or your router's built-in WoL utility.
- 102-Byte Magic Packet Structure: A WoL frame consists of 6 bytes of
FF:FF:FF:FF:FF:FFfollowed by 16 contiguous repetitions of the target NIC's 48-bit MAC address encapsulated in UDP port9(or7). - The #1 Windows 11 Culprit: Windows Fast Startup (Hybrid Shutdown S4) locks the NIC driver state on shutdown and blocks Magic Packets—disable it via
powercfg /h offor Control Panel. - Disable BIOS ErP / Deep Sleep: Energy-related Products (
ErP Ready S4+S5) cuts the+5VSBstandby rail to the onboard Ethernet controller when the PC powers off. - Never Forward WAN Port 9: Router ARP caches expire 2–5 minutes after your PC shuts down; use a VPN subnet router or your router's built-in WoL button instead of WAN port forwarding.
How Wake-on-LAN Magic Packets Work at Layer 2 and Layer 3
Developed jointly by AMD and Hewlett-Packard, Wake-on-LAN (WoL) keeps your motherboard's integrated Ethernet PHY powered in an ultra-low-wattage (`0.5W–1.2W`) listening state via the ATX power supply's `+5VSB` standby rail even when the main system is in ACPI `S3` (Sleep), `S4` (Hibernate), or `S5` (Soft Off). Because a powered-down PC has no running TCP/IP stack and does not hold an IP address, the NIC hardware scans raw incoming Ethernet frames purely for a specific 102-byte payload called a Magic Packet.
The Magic Packet contains a 6-byte synchronization stream (`FF FF FF FF FF FF`) immediately followed by 16 repetitions of the target NIC's 6-byte MAC address (`96 bytes`). For convenience, WoL apps wrap this 102-byte payload inside a standard IPv4 subnet broadcast packet (`192.168.1.255`) sent to UDP Port 9 (Discard) or UDP Port 7 (Echo) so switches flood the frame to every port on the local VLAN without needing an active ARP entry.
Step 1: Motherboard BIOS Setup (PCI-E Wake & Disabling ErP / Deep Sleep)
Before touching Windows or Linux settings, reboot your PC and press Del or F2 to enter UEFI/BIOS setup. Motherboard manufacturers hide WoL settings under different power management labels, and strict European Union standby power regulations (`< 0.5W`) force many boards to disable standby NIC power out of the box:
- ASUS (ROG / TUF / Prime): Go to Advanced Mode (F7) > Advanced > APM Configuration. Set ErP Ready to
Disabledand set Power On By PCI-E toEnabled. - MSI: Navigate to Settings > Advanced > Wake Up Event Setup. Change Resume By PCI-E Device to
Enabled, then check Settings > Advanced > Power Management Setup and set ErP Ready toDisabled. - Gigabyte / Aorus: Open Settings > Platform Power and set ErP to
Disabled(and Wake on LAN toEnabledif listed). - ASRock: Go to Advanced > ACPI Configuration and set PCIE Devices Power On to
Enabledand Deep Sleep toDisabled.
Step 2: Windows 11 NIC Driver Properties & Disabling Fast Startup
Even when BIOS settings are correct, Windows 11 blocks Wake-on-LAN from a full shutdown unless you adjust both the Realtek/Intel NIC driver and Windows Hybrid Shutdown:
- Configure NIC Advanced & Power Management: Right-click the Start button, open Device Manager > Network adapters, and double-click your Intel (`I219-V`, `I225-V`, `I226-V`) or Realtek (`RTL8125`, `RTL8111`) controller. In the Advanced tab, set Wake on Magic Packet to
Enabled, and set Energy Efficient Ethernet (EEE), Green Ethernet, and Ultra Low Power Mode toDisabled(also set Shutdown Wake-On-Lan toEnabledon Realtek). In the Power Management tab, check all three boxes: Allow the computer to turn off this device, Allow this device to bring the computer out of standby, and Only allow a magic packet to wake the computer. - Disable Windows 11 Fast Startup: Press
Win + R, runcontrol powercfg.cpl, click Choose what the power buttons do > Change settings that are currently unavailable, and uncheck Turn on fast startup (recommended). Save changes.
Step 3: Waking Your PC Across VLANs or Remotely Over VPN
Never forward WAN UDP port 9 from the public internet to your PC's internal IP. Aside from allowing random internet scanners to power on your workstation at 3:00 AM, your router's ARP table flushes your offline PC's IP-to-MAC mapping 2 to 5 minutes after shutdown, causing unicast port forwarding to fail.
Instead, use one of three reliable remote wake methods: (1) Router Built-in WoL Utility: Connect to your home router via WireGuard VPN or OpenVPN, open the router GUI (e.g., ASUSWRT Network Tools > Wake on LAN, GL.iNet Admin Panel, or UniFi device menu), and click the saved MAC address to broadcast a local Layer 2 Magic Packet. (2) Always-On Tailscale Node or NAS: SSH into a Raspberry Pi, Apple TV, or Synology NAS on your LAN over Tailscale and run wakeonlan AA:BB:CC:DD:EE:FF or etherwake -i eth0 AA:BB:CC:DD:EE:FF. (3) Cross-VLAN Directed Broadcast: On MikroTik or enterprise L3 switches, use the `/tool wol interface=vlan10 mac=AA:BB:CC:DD:EE:FF` command to inject the frame directly into the target VLAN.
Motherboard BIOS & OS Wake-on-LAN Configuration Reference
| System Layer / Vendor | Setting to ENABLE | Setting to DISABLE | Symptom if Misconfigured |
|---|---|---|---|
| ASUS / MSI / Gigabyte BIOS | Power On By PCI-E / Resume By PCI-E | ErP Ready (S4+S5) / Deep Sleep | Switch port link LEDs turn completely dark on PC shutdown |
| Windows 11 Power Options | Standard ACPI S5 Shutdown | Turn on Fast Startup (Hybrid S4) | WoL works from Sleep (S3) but fails from Shut Down (S5) |
| Intel / Realtek NIC Driver | Wake on Magic Packet + Shutdown WoL | Energy Efficient Ethernet (EEE) / Green | NIC drops link speed to 10 Mbps or ignores Magic Packets |
| Ubuntu / Debian Linux (ethtool) | ethtool -s eth0 wol g (systemd unit) | WOL=d (disabled on shutdown by TLP) | ethtool eth0 shows Wake-on: d after reboot |
| Remote Access / Router | WireGuard / Tailscale + Local Broadcast | WAN Port Forward UDP 9 to Unicast IP | WoL stops working 5 minutes after shutdown when ARP expires |
Wake-on-LAN Verification & Troubleshooting Checklist
- Enter motherboard UEFI/BIOS, enable Power On By PCI-E (or Resume By PCI-E Device), and disable ErP Ready / Deep Sleep.
- Verify the physical RJ45 link LED on your PC's Ethernet port or switch port stays illuminated (usually amber/orange for 10/100 Mbps standby) after shutting down.
- In Windows 11 Device Manager, enable Wake on Magic Packet, check all three Power Management boxes, and disable Energy Efficient Ethernet.
- Disable Windows Fast Startup in Control Panel > Power Options so shutdowns enter standard ACPI S5 instead of locked S4 hibernation.
- Record your PC's physical Ethernet MAC address (ipconfig /all) and test local wake from a phone app (Wake On Lan on Android / Mocha WOL on iOS) using broadcast IP 192.168.1.255 port 9.
- Configure WireGuard, Tailscale, or your router's built-in Wake-on-LAN web tool for secure remote wake outside your home.
Frequently Asked Questions
Why does Wake-on-LAN work for 3 minutes after I turn off my PC and then stop working?
You are sending the Magic Packet to your PC's unicast IP address (such as 192.168.1.100) instead of the subnet broadcast address (192.168.1.255). Once the PC has been off for 2 to 5 minutes, your router's ARP cache expires and forgets which switch port owns 192.168.1.100; switching your WoL app's destination IP to 192.168.1.255 forces a Layer 2 broadcast to all ports.
Can I use Wake-on-LAN over WiFi (Wake on Wireless LAN / WoWLAN)?
True power-on from a full shutdown (ACPI S5) is virtually never supported over WiFi because wireless cards cannot maintain WPA2/WPA3 association and key rotation without system power. Select Intel AX200/AX210 cards support WoWLAN only from Modern Standby (S0 Low Power Idle) or Sleep (S3), making wired Ethernet mandatory for reliable S5 power-on.
Why does my PC wake up randomly by itself after enabling Wake-on-LAN?
You enabled Wake on Pattern Match in the NIC Advanced tab or forgot to check 'Only allow a magic packet to wake the computer' under the Power Management tab in Device Manager. Without that checkbox, routine ARP requests or mDNS multicast packets on your LAN will wake the PC immediately.
How do I make Wake-on-LAN persistent on Ubuntu or Proxmox Linux?
Install ethtool (sudo apt install ethtool) and run sudo ethtool -s eno1 wol g to enable Magic Packet wake ('g'). Because many Linux distros reset this flag on reboot, set WakeOnLan=magic inside your /etc/systemd/network/ or Netplan configuration file.
Related Wired LAN Setup & Engineering Guides
- Port Forwarding Guide for Home Routers — Set up port forwarding safely on any router: create static DHCP reservations, map TCP/UDP ports, troubleshoot CGNAT/Double NAT, and avoid exposing RDP or NVR.
- Cat5e vs Cat6 vs Cat6a Ethernet Cables Compared — Compare Cat5e, Cat6, and Cat6a Ethernet cables across 1Gbps, 2.5GbE, and 10GBASE-T distances, MHz bandwidth, PoE heat, CMR vs CMP, and solid copper vs CCA.
- NAS Network Setup Guide for Home and Small Office — Configure a Synology, QNAP, or TrueNAS server with DHCP reservations, 2.5GbE/10GbE switching, SMB3 multichannel vs LACP, and WireGuard/Tailscale access.
- Small Business Network Setup Checklist — Build a reliable small business network with our checklist covering Dual-WAN failover, 4-VLAN segmentation, PoE budgets, UPS sizing, and WPA3 WiFi security.