Have you ever stayed at a hotel with a device limit on its Wi-Fi, struggled to connect devices such as a Chromecast to a public network, or simply wanted your own private network while traveling?
I built a portable Raspberry Pi OpenWrt travel router to solve those problems. Using a Raspberry Pi 3B with two Wi-Fi radios, it connects to an upstream Wi-Fi network through a USB adapter and creates a separate private wireless network for my devices using the Pi’s built-in Wi-Fi.
Unlike a basic Wi-Fi repeater, this setup uses OpenWrt to route traffic between the two networks. My devices stay behind their own firewall and NAT, while the router handles issues such as subnet conflicts, multiple upstream Wi-Fi profiles, and roaming between access points.
This guide walks through exactly how I built and configured it, including the USB Wi-Fi adapter drivers, network interfaces, wireless configuration, firewall rules, DHCP, and profile switching.
The Hardware Setup
Affiliate disclosure: Some links below are affiliate links. If you purchase through them, I may earn a commission at no additional cost to you.
You will need:
- Raspberry Pi 3B – This is the Raspberry Pi I used for the project. You don’t need the newest Raspberry Pi just to build this router.
- Edimax EW-7811Un V2 USB Wi-Fi Adapter — This serves as the upstream Wi-Fi radio. Make sure you’re looking at the V2 model, since this guide is specifically based on its RTL8188EUS chipset.
- microSD card — Holds OpenWrt and the router configuration.
- Raspberry Pi power supply — A reliable power supply is particularly important for this project because the Pi is also powering the USB Wi-Fi adapter.
Why two radios?
Using a single radio for both the upstream connection and your private Wi-Fi network forces both connections to share the same radio and available airtime, which can significantly reduce throughput. Using a dedicated USB adapter for the upstream connection keeps the two wireless roles separate and helps your private network remain fast and stable.
Step 0: The “Chicken and Egg” Problem (Internet Access)
Before we can install anything, the Pi needs internet access. But the WiFi adapter doesn’t work yet because we haven’t installed the drivers!
The Solution:
We must temporarily use an Ethernet cable and configure the Pi to “borrow” internet from your home router.
Important: Before connecting the Raspberry Pi to your home router, make sure the router and the Pi do not use the same IP address. OpenWrt commonly uses
192.168.1.1by default, which may also be the address of your existing router. If both devices use the same address, change one of them before continuing. The gateway address used below must also be on the same subnet as the Pi’s Ethernet interface.
- Connect an Ethernet cable from your Home Router to the Pi.
- SSH into the Pi.
- By default, OpenWrt’s LAN interface uses a static IP address and provides DHCP service to devices connected to the LAN. For this temporary setup, we need to tell OpenWrt to use your home router as its gateway to the Internet.
Run these commands (Replace 192.168.1.254 with your Home Router’s IP address):
# Point the Pi to your home router for internet
uci set network.lan.gateway='192.168.1.254'
uci set network.lan.dns='8.8.8.8'
uci commit network
/etc/init.d/network restart
# Test connection
ping -c 1 8.8.8.8
Note: Keep this temporary Ethernet connection in place while completing the initial configuration. In Step 2, Ethernet remains available as a management interface. Once the USB Wi-Fi (wwan) is working and providing Internet access, the temporary gateway and DNS settings added above can be removed so that wwan becomes the router’s Internet connection.
Step 1: Installing Drivers
For this build, I selected the Edimax EW-7811Un V2. It’s tiny, cheap, and perfect for travel. However, it uses the Realtek RTL8188EUS chipset, which is not supported out-of-the-box by the default OpenWrt installation.
Why install specific drivers?
OpenWrt is designed to be lightweight and does not include drivers and firmware for every possible USB device by default. The Edimax EW-7811Un V2 uses the Realtek RTL8188EUS chipset, so we need to install the appropriate OpenWrt driver and firmware packages before using it as our upstream Wi-Fi adapter.
How to do it:
SSH into your OpenWrt device and run:
opkg update
opkg install usbutils
opkg install kmod-rtl8xxxu rtl8188eu-firmware
# Reboot so the driver and firmware are loaded cleanly
reboot
After the Raspberry Pi reboots, SSH back into OpenWRT and verify that the USB adapter is detected.
lsusb
You should see the EdiMax/Realtek USB adapter listed.
You can also check the kernel log for the Realtek adapter and driver:
dmesg | grep -i -E 'rtl|8188|usb'
Finally, check that OpenWrt has created a wireless interface for the adapter:
iw dev
Once the second wireless radio is detected, we can configure it as the upstream Wi-Fi connection.
A Note on Editing Files
OpenWrt uses vi as its text editor, which can be confusing for beginners.
- Open a file:
vi /etc/config/network - Edit mode: Press
ito start typing. - Save & Exit: Press
ESC, then type:wqand hit Enter. - Discard changes: Press
ESC, then type:q!and hit Enter.
Step 2: Solving the “Subnet Conflict” (Crucial)
The Problem:
Many home, hotel, and public networks use private address ranges such as 192.168.1.x. OpenWrt also defaults to 192.168.1.1. If the upstream network uses the same subnet as one of your local networks, routing conflicts can occur because OpenWrt cannot properly distinguish between the two networks.
The Fix:
We move our internal AP to a custom subnet: 192.168.10.x.
Edit file: /etc/config/network
We configure three interfaces:
- lan: Ethernet (Management only). We give it a high “metric” (cost) so the router doesn’t try to use it for internet.
- wwan: The USB WiFi. We give it a low metric so it’s the preferred internet source.
- internal_ap: Our new custom subnet.
Why use a separate subnet?
The private Wi-Fi network created by the Raspberry Pi uses192.168.10.0/24, keeping it separate from the upstream Wi-Fi network. This is important because many home, hotel, and public networks use private address ranges such as192.168.1.0/24. The Ethernet LAN remains on192.168.1.1for local management, while devices connected to the travel router’s Wi-Fi receive192.168.10.xaddresses.
config interface 'lan'
option device 'br-lan'
option proto 'static'
option ipaddr '192.168.1.1'
option netmask '255.255.255.0'
option metric '100' # High number = Low Priority
config interface 'wwan'
option proto 'dhcp'
option metric '10' # Low number = High Priority (Internet)
config interface 'internal_ap'
option proto 'static'
option ipaddr '192.168.10.1' # Separate subnet for the private AP
option netmask '255.255.255.0'
Step 3: Wireless Configuration & Roaming
Now we configure the radios.
Roaming with bgscan
If you use the travel router at work, on a campus, or anywhere multiple access points share the same SSID, the USB Wi-Fi client may remain associated with an access point even as its signal becomes weaker.
The bgscan setting tells the wireless client to perform background scans based on signal strength, allowing it to discover stronger access points using the same network as you move around.
Edit file: /etc/config/wireless
Country code: The examples below use
US. Set the country code to the country where the router is actually being operated so OpenWrt uses the appropriate wireless frequencies and transmit-power limits.
# --- RADIO 0: INTERNAL AP (Your Devices Connect Here) ---
config wifi-device 'radio0'
option type 'mac80211'
option band '2g'
option channel '1'
option country 'US' # Set this to the country where the router is being used
config wifi-iface 'default_radio0'
option device 'radio0'
option network 'internal_ap'
option mode 'ap'
option ssid 'My_Secure_Travel_Net'
option encryption 'psk2'
option key 'SuperSecurePassword'
# --- RADIO 1: USB CLIENT (Connects to Internet) ---
config wifi-device 'radio1'
option type 'mac80211'
option band '2g'
option channel 'auto' # MUST be auto to follow the upstream AP
option country 'US' # Set this to the country where the router is being used
config wifi-iface 'wan_profile'
option device 'radio1'
option network 'wwan'
option mode 'sta'
option ssid 'Public_Coffee_WiFi'
option encryption 'psk2'
option key 'CoffeeShopPassword'
# Simple Roaming: Scan if signal drops below -70dBm
option bgscan 'simple:30:-70:300'
Connecting to open Wi-Fi and captive portals:
Some public Wi-Fi networks, such as those found in stores and hotels, do not require a Wi-Fi password but use a captive portal before allowing Internet access. For an open network, configure the upstream Wi-Fi profile withoption encryption 'none'and omit theoption keyline. After the Raspberry Pi connects to the Wi-Fi network, connect a phone or laptop to your private travel-router Wi-Fi and open a browser. The public network’s captive portal should then appear so you can complete its sign-in or accept its terms.config wifi-iface 'public_wifi' option device 'radio1' option network 'wwan' option mode 'sta' option ssid 'Public_WiFi' option encryption 'none'
Step 4: Firewall Rules (NAT)
We need to allow traffic from our private network (internal_ap) through the trusted lan firewall zone and out through the wan zone, which contains our upstream Wi-Fi interface (wwan). Masquerading (NAT) on the WAN zone allows devices on the private network to share the upstream connection while unsolicited incoming traffic from the public network remains blocked.
Edit file: /etc/config/firewall
# LAN Zone: Trusted (Your devices)
config zone
option name 'lan'
list network 'lan'
list network 'internal_ap'
option input 'ACCEPT'
option output 'ACCEPT'
option forward 'ACCEPT'
# WAN Zone: Untrusted (The Internet)
config zone
option name 'wan'
list network 'wan'
list network 'wwan'
option input 'REJECT'
option output 'ACCEPT'
option forward 'REJECT'
option masq '1' # Enables NAT (Sharing the connection)
option mtu_fix '1'
# Allow private devices to reach the Internet
config forwarding
option src 'lan'
option dest 'wan'
Step 5: DHCP (Handing out IPs)
Finally, enable DHCP on the internal_ap interface so phones, laptops, and other devices connected to the travel router automatically receive an IP address on the 192.168.10.0/24 network.
Edit file: /etc/config/dhcp
config dhcp 'internal_ap'
option interface 'internal_ap'
option start '100'
option limit '50'
option leasetime '12h'
Step 6: Apply the Configuration and Test the Router
Now that the network, wireless, firewall, and DHCP configuration is complete, restart the affected services to apply the changes:
/etc/init.d/network restart
/etc/init.d/firewall restart
/etc/init.d/dnsmasq restart
wifi reload
Note: Restarting the network may temporarily disconnect your SSH session. If that happens, reconnect using the Ethernet management interface at
192.168.1.1or connect to the private Wi-Fi network you configured above.
Verify the upstream Wi-Fi connection
Check the status of the wwan interface:
ifstatus wwan
A successful connection should show that the interface is up and has received an IPv4 address from the upstream network.
You can also check the routing table:
ip route
Once the USB Wi-Fi connection is active, the Internet-bound default route should use the wwan connection.
Remove the temporary Ethernet Internet settings
Remember the temporary gateway and DNS settings we added in Step 0? Once wwan is working and providing Internet access, they are no longer needed.
Remove them with:
uci delete network.lan.gateway
uci delete network.lan.dns
uci commit network
/etc/init.d/network restart
Your Ethernet LAN remains available at 192.168.1.1 for local management. Removing the gateway and DNS settings only stops the Ethernet connection from being used as the router’s temporary path to the Internet.
Test the private Wi-Fi network
Connect a phone or laptop to the private Wi-Fi network configured in Step 3.
Using the example configuration in this guide, the device should:
- Connect to
My_Secure_Travel_Net - Receive an address in the
192.168.10.100–192.168.10.149range - Use
192.168.10.1as its gateway - Reach the Internet through the USB Wi-Fi (
wwan) connection
If all four are working, the Raspberry Pi is now functioning as a portable OpenWrt travel router.
Bonus: Switching Upstream Wi-Fi Profiles via SSH
If you regularly use the travel router in several locations, you can save multiple upstream Wi-Fi profiles in /etc/config/wireless instead of entering the SSID and password every time you move.
For example, you might have one profile for home and another for work:
config wifi-iface 'home_wan'
option device 'radio1'
option network 'wwan'
option mode 'sta'
option ssid 'Home_WiFi'
option encryption 'psk2'
option key 'HomePassword'
option disabled '0'
config wifi-iface 'work_wan'
option device 'radio1'
option network 'wwan'
option mode 'sta'
option ssid 'Work_WiFi'
option encryption 'psk2'
option key 'WorkPassword'
option disabled '1'
In this example, home_wan is enabled and work_wan is disabled.
When I arrive at work, I can switch profiles over SSH without editing the wireless configuration manually:
uci set wireless.home_wan.disabled='1' && \
uci set wireless.work_wan.disabled='0' && \
uci commit wireless && \
wifi reload
To switch back, reverse the enabled and disabled values.
This works well for manually switching among a few known networks. If you want the Raspberry Pi to automatically detect and switch among saved Wi-Fi networks, the next guide expands this setup with automated network switching and additional management features.
Next: Automate Network Switching, Updates, and Poweroff
Conclusion
You now have a portable Raspberry Pi OpenWrt travel router with two separate Wi-Fi radios: one connecting to the upstream network and the other providing a private network for your devices.
With the configuration in this guide, OpenWrt handles routing, NAT, DHCP, firewall protection, and upstream Wi-Fi connectivity while keeping your devices on their own 192.168.10.0/24 network. You can use the same setup with home networks, hotels, public Wi-Fi, and captive portals, then switch among saved upstream networks as needed.
For me, the biggest advantage is that my devices connect to the same private Wi-Fi network wherever I take the router. Instead of reconfiguring every device for each new network, I only need to connect the Raspberry Pi to the new upstream Wi-Fi.
If you want to take the project further, continue with the automated network-switching guide above.
