"How to use the GL.iNet Mango 2 as a travel router, tunnel every connected device home with WireGuard, and reach internal homelab services without installing a VPN client on each device."
Disclosure: GL.iNet provided the Mango 2 review unit free of charge through its Creator Program and asked to review the content link before publication. The technical limits and configuration notes below are included so you can decide whether this setup fits your own network.
Public Wi-Fi is rarely the part of travel I look forward to. Every hotel has a different captive portal, every device needs to be connected again, and reaching services inside my homelab usually means installing and maintaining a VPN client on each device.
That is why the GL.iNet Mango 2 (GL-MG1300) is interesting to me. Instead of treating it as just a tiny Wi-Fi repeater, I see it as a portable network edge:
Laptop / phone / tablet
|
Mango 2 Wi-Fi
|
Hotel Wi-Fi, Ethernet, or phone tethering
|
WireGuard tunnel
|
Home network + homelab services
The Mango 2 becomes the WireGuard client. Everything behind it can use that tunnel without needing a separate VPN app. That opens up two practical scenarios:
- Securely reaching dashboards, NAS shares, development tools, and other private services in a home lab while traveling.
- Connecting a locked-down laptop to the home tunnel without installing VPN software on the laptop itself, provided that doing so is allowed by the employer's policies.
This article walks through the design, setup, trade-offs, and the claims that still need real-world testing.
Mango 2 hardware at a glance
The Mango 2 is a significant upgrade over the original Mango while staying genuinely pocket-sized.
| Specification | Mango 2 |
|---|---|
| Model | GL-MG1300 |
| Dimensions | 89 x 63 x 15 mm |
| Weight | 100 g |
| CPU | MediaTek dual-core, 880 MHz |
| Memory | 128 MB DDR3L |
| Wi-Fi | Dual-band Wi-Fi 5 |
| 2.4 GHz rate | Up to 400 Mbps |
| 5 GHz rate | Up to 866 Mbps |
| Ethernet | 1x WAN, 1x LAN, Gigabit |
| USB | USB 3.0 Type-A |
| Power | USB-C, 5V/2A |
It runs GL.iNet firmware 4.x on OpenWrt and includes WireGuard and OpenVPN support. GL.iNet rates WireGuard client throughput at up to 184 Mbps and OpenVPN-DCO at up to 95 Mbps. Those are manufacturer maximums measured under controlled conditions, not results from my own network. Real performance will depend on the VPN server, home upload speed, travel connection, latency, Wi-Fi conditions, encryption settings, and firmware.
At the time of writing on September 19, 2026, the product was listed as pre-order/upcoming rather than generally shipping. Announced pricing was $49.99 list with a $39.90 launch price shown on GL.iNet's site. Check the current listing before publishing or buying because price and availability can change.
Other useful travel features include:
- Repeater mode for hotel or café Wi-Fi
- Captive-portal login support and MAC camouflage
- USB tethering and USB modem support
- Multi-WAN failover across available uplinks
- SMB network storage using a USB 3.0 drive
- Tailscale and GoodCloud remote management
- GoodPAS, which uses AmneziaWG-based obfuscation
- Per-device and per-domain VPN policies
One notable omission: AdGuard Home is not supported on this model. The 128 MB RAM also makes this a network appliance first, not a platform for loading up many extra OpenWrt packages.
Why put WireGuard on the router?
Installing WireGuard directly on a laptop is simple when you own and administer that laptop. It is less convenient when you travel with several devices, use streaming hardware with no WireGuard app, or have a managed computer where software installation is blocked.
Putting the client on the travel router changes the trust boundary. Devices connect to a familiar Wi-Fi network, while the router handles the encrypted tunnel.
That gives me:
- One VPN configuration: Import the profile once instead of configuring every device.
- Transparent homelab access: Devices behind the router can reach permitted private subnets.
- A home egress IP: Full-tunnel traffic appears to originate from the home connection.
- A fail-closed option: The kill switch can prevent devices from falling back to the unencrypted WAN if the tunnel drops.
- One captive-portal login: Authenticate the router, then attach the rest of the travel devices to it.
This does not make endpoints invisible or magically trusted. A managed laptop can still report activity through MDM or EDR software, and the local network can still observe metadata such as a connection to the VPN endpoint. The router protects the network path; it does not defeat endpoint monitoring or company controls.
Before leaving home
A travel-router VPN is only as reliable as the server it calls back to. Test the complete path from an external network before packing the router.
1. Confirm that the home side is reachable
The WireGuard server needs a public endpoint. Compare the WAN address on the home router with the public IP reported by an external IP-checking service.
If the ISP places the connection behind CGNAT, normal inbound port forwarding will not work. Options include requesting a public IP from the ISP or using an overlay/relay design such as Tailscale. Do not discover this after arriving at the hotel.
2. Reserve the server's LAN address
If the WireGuard server sits behind another router, give it a DHCP reservation. A port-forward rule aimed at a changing LAN address will eventually break.
3. Forward the WireGuard port
Forward the server's WireGuard UDP port from the primary home router to the WireGuard server. GL.iNet uses 51820/UDP in its example configuration, but use the port configured on your own server.
Do not expose homelab dashboards directly to the internet. The VPN endpoint is the only service that needs to be reachable for this design.
4. Configure DDNS when the public IP is dynamic
A dynamic DNS name keeps the client profile usable after the ISP changes the home IP. Put the DDNS hostname in the WireGuard Endpoint field.
5. Permit access to the home LAN
On a GL.iNet WireGuard server, enable Allow Remote Access the LAN Subnet. If the server is another WireGuard implementation, make sure its forwarding, firewall, and peer routes permit the exact home subnet you intend to reach.
Grant the minimum access you need. A dedicated VPN VLAN or firewall policy is safer than giving a travel device unrestricted access to every trusted segment.
6. Export a dedicated client profile
Create a separate peer for the Mango 2. Do not reuse the private key from a phone or laptop. A unique peer can be revoked without breaking other clients.
A full-tunnel client profile will look broadly like this:
[Interface]
PrivateKey = <CLIENT_PRIVATE_KEY>
Address = <CLIENT_TUNNEL_IP>/32
DNS = <SERVER_TUNNEL_IP>
[Peer]
PublicKey = <SERVER_PUBLIC_KEY>
PresharedKey = <OPTIONAL_PRESHARED_KEY>
Endpoint = <YOUR_DDNS_NAME>:51820
AllowedIPs = 0.0.0.0/0, ::/0
PersistentKeepalive = 25
Replace every value in angle brackets. Never publish real private or preshared keys.
AllowedIPs = 0.0.0.0/0, ::/0 creates a full tunnel. If you only want homelab access, use the WireGuard tunnel subnet and selected home LAN subnets instead. Split tunneling preserves the travel connection for ordinary internet traffic, while full tunneling provides the home egress IP.
For internal names such as grafana.home.arpa, set DNS to the WireGuard server's tunnel IP and confirm that server can resolve the local zone. GL.iNet also supports DNS host entries when a few static mappings are enough.
Configure the Mango 2 as the client
Firmware labels can move between releases, but the workflow in GL.iNet firmware 4.x is straightforward.
Step 1: Initialize the router
- Power the Mango 2 from a stable 5V/2A USB-C source.
- Join its default Wi-Fi or connect by Ethernet.
- Open the admin panel at
192.168.8.1. - Set a strong admin password and update to the latest stable firmware offered for the device.
- Replace the default Wi-Fi name and password.
Step 2: Avoid overlapping subnets
The default Mango 2 LAN is 192.168.8.0/24. If the home LAN or a frequently used hotel network uses the same range, routing becomes ambiguous.
Change the Mango 2 LAN address before importing the VPN profile. For example:
Mango 2 router: 192.168.10.1
Mango 2 clients: 192.168.10.0/24
Home LAN: 192.168.8.0/24
WireGuard: 10.0.0.0/24
Use ranges that do not overlap with each other. The specific values above are examples, not mandatory settings.
Step 3: Connect the travel uplink
Choose whichever upstream connection is available:
- Ethernet: Connect the hotel or rental's Ethernet to the WAN port.
- Repeater: Join the venue's Wi-Fi from the Mango 2 admin panel.
- USB tethering: Connect a phone and enable tethering.
- USB modem: Use a supported cellular modem.
For a captive portal, connect the Mango 2 to the venue network first, then open a plain HTTP page from a device behind it to trigger the login page. If the network has already authorized a phone or laptop by MAC address, MAC camouflage can make the router present the authorized address. Use this only within the venue's terms and device limits.
Multi-WAN can keep a second uplink ready for failover. That is useful when hotel Wi-Fi is unstable and a phone tether is the backup.
Step 4: Import the WireGuard profile
- Open VPN -> WireGuard Client.
- Select Add Manually.
- Create a profile group.
- Upload the
.conffile, paste its contents, or enter the fields manually. - Apply the profile and start the tunnel.
- Check the VPN dashboard for a successful handshake and traffic counters.
GL.iNet supports WireGuard client and server modes, but the router cannot run both roles simultaneously. For this design, the Mango 2 is the client and a device at home is the server.
Step 5: Enable leak protection
Enable the VPN kill-switch behavior. Depending on firmware version, the setting may appear as Block Non-VPN Traffic, Tunnel Kill Switch, or an enhanced policy-mode option.
Test it deliberately:
- Confirm the public IP matches the home connection while WireGuard is active.
- Resolve an internal hostname and open a private homelab service.
- Stop the home WireGuard server or temporarily break the endpoint.
- Confirm the connected test device loses internet access rather than falling back to the hotel WAN.
- Restore the tunnel and confirm recovery.
Firmware 4.8 separates tunnel and policy-mode kill-switch behavior, so verify the exact policy you are relying on. A green VPN indicator is useful, but a controlled failure test is better.
Scenario one: carry the homelab with you
Once the tunnel is up, the Mango 2 can act as a small site-to-site gateway. A laptop on its LAN can reach services at home by private IP or internal DNS name:
https://grafana.home.arpa
https://proxmox.home.arpa
smb://nas.home.arpa
ssh admin@devbox.home.arpa
Those names are examples. Do not expose an administrative interface simply because a VPN exists. Keep authentication enabled, patch services, and use firewall rules between the VPN subnet and sensitive networks.
This approach is useful for:
- Checking Proxmox or container dashboards
- Reaching a NAS without publishing SMB to the internet
- Using private Git, CI, monitoring, or documentation services
- Administering lab machines over SSH or a web console
- Accessing services that are intentionally bound only to the home LAN
The limiting speed will often be the home upload rate, not the Mango 2's advertised WireGuard ceiling. A 184 Mbps-capable client cannot pull 184 Mbps through a home connection that uploads at 20 Mbps.
Scenario two: a laptop with no VPN client
A managed or locked-down laptop may not allow WireGuard installation. With the tunnel running on the Mango 2, the laptop only needs to join the router's Wi-Fi or LAN port.
Managed laptop -> Mango 2 -> WireGuard -> Home
Nothing is installed on the laptop, and the network route can fail closed if the VPN disconnects. This can also make the laptop's public traffic exit from the normal home IP.
There are important boundaries:
- Check the employer's acceptable-use, remote-work, travel, and location policies first.
- Do not use the router to bypass geographic, security, or compliance controls.
- MDM, EDR, browser management, and corporate applications still see activity on the laptop.
- A mandatory corporate VPN may create a nested tunnel or conflict with routing and DNS.
- Some hotel and enterprise networks block UDP or VPN-like traffic.
- Keep a phone tether or another approved connection method as a fallback.
This is a way to move VPN enforcement to the network edge, not a way to make a managed endpoint invisible.
How it compares
The original Mango was inexpensive and tiny, but its 2.4 GHz-only Wi-Fi, 100 Mbps Ethernet, USB 2.0, and lower VPN ceiling made it easy to outgrow. Mango 2 adds dual-band Wi-Fi 5, Gigabit Ethernet, USB 3.0, USB-C power, and a much faster CPU.
| Device | Wi-Fi generation | WireGuard max |
|---|---|---|
| Mango | Wi-Fi 4, 2.4 GHz | 45 Mbps |
| Opal | Wi-Fi 5 | 65 Mbps |
| Beryl | Wi-Fi 5 | 91 Mbps |
| Slate Plus | Wi-Fi 5 | 170 Mbps |
| Mango 2 | Wi-Fi 5 | 184 Mbps |
| Beryl AX | Wi-Fi 6 | 300 Mbps |
| Slate AX | Wi-Fi 6 | 550 Mbps |
These are GL.iNet's advertised client-mode maxima, not a single controlled cross-device benchmark. Server mode is slower, and real-world results vary.
On paper, Mango 2 offers the fastest advertised WireGuard performance among these lower-cost Wi-Fi 5 travel routers while targeting a sub-$50 price. Beryl AX and Slate AX remain the better fit when Wi-Fi 6, more memory, higher VPN throughput, or AdGuard Home support matters more than minimum size and cost.
What I would test before calling it a review
Specifications tell me whether the design is possible; they do not tell me how it behaves on a bad hotel network. My practical test plan would include:
- Wired throughput without a VPN
- Repeater throughput on both Wi-Fi bands
- WireGuard throughput to a local server and to the home server
- Latency added by the home tunnel
- Captive-portal login and MAC camouflage
- DNS behavior for public and internal names
- Kill-switch behavior during tunnel failure and reboot
- Multi-WAN failover from hotel Wi-Fi to phone tethering
- USB storage transfer speed over SMB
- Temperature and stability during a long VPN transfer
Until those measurements are run on the review unit, the 184 Mbps WireGuard and 95 Mbps OpenVPN-DCO figures should be described as official maximums, not measured results.
Limitations and gotchas
- Wi-Fi 5 only: Fine for many hotel connections, but not a Wi-Fi 6 upgrade.
- 128 MB RAM: Enough for the intended router features, but limited for heavy OpenWrt customization.
- No AdGuard Home: Use another DNS filtering solution if network-wide blocking is required.
- CGNAT at home: Prevents ordinary inbound WireGuard port forwarding.
- Subnet collisions: A hotel and home LAN using the same range can break routing.
- Home upload dependency: Full-tunnel download speed while away is capped by home upload capacity.
- Captive-portal friction: Some portals and encrypted-DNS settings can make authentication awkward.
- VPN blocking: Some networks block UDP or interfere with VPN protocols.
- Single VPN role: Client and server modes cannot run at the same time on the router.
- Manufacturer speed figures: Maximums are not guaranteed real-world throughput.
For networks that block normal WireGuard traffic, Mango 2 also advertises GoodPAS with AmneziaWG-based obfuscation. That is a separate feature and service path from the self-hosted standard WireGuard configuration in this tutorial.
Final thoughts
The most compelling thing about Mango 2 is not simply that it repeats Wi-Fi. It can carry a consistent, encrypted network policy in a 100-gram box.
For homelab users, that means internal services can stay private while remaining reachable on the road. For devices that cannot run their own VPN client, it means the network can provide the tunnel transparently. Add Gigabit Ethernet, USB-C power, and a claimed 184 Mbps WireGuard ceiling, and the Mango 2 looks much more capable than the original budget Mango.
The setup still demands preparation: confirm the home public IP, handle port forwarding and DDNS, avoid overlapping subnets, configure internal DNS, enable leak protection, and test from an outside connection. Do that before the trip, and the Mango 2 can become more than a hotel Wi-Fi adapter. It can be a pocket-sized bridge back to the homelab.


Top comments (0)
Some comments may only be visible to logged-in visitors. Sign in to view all comments.