I wanted to choose which devices on my home Wi-Fi use rule-based proxy routing, without installing a client on every phone or changing network settings each time. That became NAS Device Flow, a small self-hosted dashboard running on my NAS.
The main screen puts devices first. Each device has a switch: enable it to apply the configured routing rules, or disable it for direct access. Traffic charts are visible at the top; subscription management lives in settings so it does not get in the way of the everyday task.
This screenshot uses fictional devices and generated traffic. Update, October 9, 2026: 0.1.0 is now the first regular release, within the documented hardware and network scope.
How the traffic reaches the NAS
My Wi-Fi router remains the access point and upstream router. The NAS runs a Linux gateway container and a controller, with Mihomo handling the proxy rules. For automatic onboarding, DHCP supplies the NAS gateway and DNS address to clients. Existing clients need to renew their leases before they follow those settings.
That last sentence turned out to matter. One tablet kept its old gateway after the DHCP change. Toggling a dashboard switch could not fix a lease that still pointed somewhere else. The release now includes an explicit opt-in authoritative DHCP mode for deployments where this is the only DHCP server, and tests for an old lease being rejected and replaced with the correct gateway and DNS. The upstream router's DHCP must be disabled first in that mode.
A device with its switch enabled still follows the configured rules. It does not send every connection through a proxy. The included regional preset is intended for mainland China, with domestic destinations direct and other matching destinations proxied; users elsewhere should review and adapt it.
Remembering devices
The controller uses MAC addresses to retain device choices. DHCP leases, neighbor information and optional router adapters help discover devices and supply names. You can give a device a friendly name when discovery has no useful answer.
Returning with the same MAC preserves its choice even if its IP changes. A rotating private Wi-Fi address becomes a new device record. Two devices with the same hostname are not automatically merged. The setting for newly discovered devices defaults to direct access and only affects new records.
There is a Huawei adapter tested against my hardware. OpenWrt and MikroTik adapters currently have mock coverage, not hardware validation. Device names are useful labels, not a guarantee that the dashboard knows the exact model of every client.
Making the dashboard useful day to day
Besides the device switches, it shows upload and download rates, sampled proxy traffic beside each device, subscription controls, and basic gateway information. The interface supports Chinese, English, Japanese, Spanish, French and Korean, with a manual language choice that is remembered in the browser.
The traffic counter uses decimal MB. It accumulates sampled connection deltas and saves checkpoints, so it is an operational estimate rather than a billing meter. The interface also separates a configured proxy choice from observed gateway activity: a switch alone is not proof that a device's traffic actually reached the gateway.
Local authentication includes a password-change flow that verifies the current password and invalidates existing sessions after a successful change.
What is ready, and what still needs work
The current v0.1.0 release has 105 automated tests. CI also checks container startup and an isolated Linux DHCP renewal path. My deployment runs on a UGREEN DXP4800, but a fresh installation across other NAS models and router combinations still needs validation.
The gateway requires Linux and macvlan networking. Docker Desktop on macOS or Windows is not a supported gateway host; those systems can use the web interface. IPv6 routing and automatic gateway failover are not implemented. If the NAS is your gateway, its availability matters to the devices using it.
The controller is MIT-licensed. Mihomo and other dependencies retain their own licenses.
Source, installation instructions and limitations
I would appreciate feedback on the device workflow, DHCP migration and naming adapters. In particular, I want the panel to make it easy to tell the difference between a saved preference and traffic that is actually using the gateway.
This article was prepared with AI assistance and checked against the project's documented behavior and tests.

Top comments (0)